Restarting, scanning and fixing the disk?
Restarting, scanning and fixing the disk?
Hello, After completing a full MalwareBytes scan for approximately 30 hours, I restarted my system. This is the second time I’ve experienced a disk check and repair during boot. I’ve attached the relevant images, including the drive's SMART data. Should I run the CHKDSK command? Would it be sufficient? And for Drive C? Why am I seeing checks for all drives? https://forums. Do I also need to run the fsutil dirty command? Thank you
Did the MalwareBytes scan complete? Were there any positive detections and fixes? It's likely it identified and resolved some malware in a critical area. If CHKDSK detected issues, it would create folders like Check.001, 002, etc. Also, you should re-evaluate disk health. If everything checks out, you can disable the automatic verification process.
Hello, thank you for your reply. Initially, I performed a quick scan and discovered 8 threats. Two of these were related to Drives/HOSTS, which were replaced. Five others concerned recently installed files with a total available size. I installed one folder in Local \Temp\ containing a DLL (ISHASH.DLL) that I couldn't locate. All of them were removed. During the next scan after 30 hours, only 2-3 less important files remained, which I quarantined and plan to delete as well. A few weeks ago, I also ran a full scan with Bitdefender Premium and found nothing unusual. Therefore, I need to run CHKDSK on which drive? Also, during the restart it checked and repaired all of them? What about using F-Secure Dirty Checker? Is that necessary? Thank you.
I've encountered this issue before when restarting from various Windows versions on the same storage device. When the dirty bit was enabled, the system had to scan all my hard disks, which took a long time. We need to figure out why your system is acting strangely.
I tend to rely heavily on Malwarebytes scans, which often flag some of my desired programs—especially certain Nirsoft applications—as potentially malicious. They display "malware-like" traits, so I usually run an Advanced Scan and set Detection to Warn User. Although I've made Warn User the default in Settings, the regular scan still ignores this setting and quarantines files without warning. Better safe than sorry, right?
When Malwarebytes finds something, I review it carefully before deciding to quarantine or delete suspicious files. If I forget to adjust Advanced Scan, the next time I attempt to run a Nirsoft tool, it disappears.
If your system is heavily infected, it would be faster and safer to erase the boot drive (or switch to a new one) and reinstall Windows along with all your programs from the ground up. This process should take no more than 8 hours, not the typical 30.
I usually restrict Malwarebytes scans to my C: drive. Analyzing up to 20TB of data on other drives is inefficient and unlikely to catch everything that AV software misses. Of course, I remain cautious, so I maintain backups on other machines and tapes.
You might save time by limiting scans to just the Windows boot drive in Advanced Scan. This should reduce scan times to under 6 hours, or even faster with a modern multi-core CPU and an M.2 NVMe boot drive.
Thank you for your detailed reply. Please clarify what you're referring to by misbehaving...?
A 30-hour session is atypical for a rootkit, as all features remain active.
Yes, registry and bootloader files are typically found on C: I activated every option while testing all drives.