I´ve reformatted Windows XP without getting rid of "Rootkit.MBR.Whistler(Boot image). What to do?
I have now several times reformatted my hard drive and reinstalled Windows XP without getting rid of "Rootkit.MBR.Whistler(Boot image)". What to do?
not sure how to remove it, didn't find instructions at F-Secure page.
One thing you can try is the rescue CD it boots a Linux image and will scan the drive and might be able to remove.
Second option would be to install a Linux and rewrite MBR. Linux has better tools for that.
My personal experience.
Please refer the KB article below to disinfect MBR in Win XP:
http://support.microsoft.com/kb/314058 (under the fixmbr section)
Just to add an additional information from our Security Lab.