Jump to content

Recommended Posts

Hi,

 

I use Sophos Safeguard to encrypt my laptop. Recently I ran a scan and noticed a unknown.rootkit.MBR showing up. Upon quarantining my laptop would no longer boot. It seems that Malwarebytes is seeing my Safeguard install as a rootkit.

 

To get my laptop booting to windows again I had to boot using the safeguard bootdisk and restore my MBR.

 

Is there a way to update the program or hard code an exception for Safeguard so I do not have this problem?

 

Or is the fix to just uncheck 'scan for rootkits'?

Link to post
Share on other sites

  • Staff

Please ignore David's instructions this is a special case being its a MBR.

 

I am getting in touch with the devs to see what info we need to get this corrected. Will be back in touch shortly.

 

What may help in the mean time is if possible to run our MBAR utility with the /v switch.

 

Let me know if you need more specific instructions.

 

https://www.malwarebytes.org/antirootkit/

 

and attaching the system.log.txt here.

 

Just dont select to fix it or remove. at the end of the scan.

 

Basically we need a dump of the MBR to start off with.

 

Thanks.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.