F5F Stay Refreshed Hardware Desktop Restarting, scanning and fixing the disk?

Restarting, scanning and fixing the disk?

Restarting, scanning and fixing the disk?

G
GodSaidHi
Junior Member
49
03-16-2023, 08:50 AM
#1
Hello, After completing a full MalwareBytes scan for approximately 30 hours, I restarted my system. This is the second time I’ve experienced a disk check and repair during boot. I’ve attached the relevant images, including the drive's SMART data. Should I run the CHKDSK command? Would it be sufficient? And for Drive C? Why am I seeing checks for all drives? https://forums. Do I also need to run the fsutil dirty command? Thank you
G
GodSaidHi
03-16-2023, 08:50 AM #1

Hello, After completing a full MalwareBytes scan for approximately 30 hours, I restarted my system. This is the second time I’ve experienced a disk check and repair during boot. I’ve attached the relevant images, including the drive's SMART data. Should I run the CHKDSK command? Would it be sufficient? And for Drive C? Why am I seeing checks for all drives? https://forums. Do I also need to run the fsutil dirty command? Thank you

A
andreuka10
Junior Member
8
03-16-2023, 11:15 AM
#2
Did the MalwareBytes scan complete? Were there any positive detections and fixes? It's likely it identified and resolved some malware in a critical area. If CHKDSK detected issues, it would create folders like Check.001, 002, etc. Also, you should re-evaluate disk health. If everything checks out, you can disable the automatic verification process.
A
andreuka10
03-16-2023, 11:15 AM #2

Did the MalwareBytes scan complete? Were there any positive detections and fixes? It's likely it identified and resolved some malware in a critical area. If CHKDSK detected issues, it would create folders like Check.001, 002, etc. Also, you should re-evaluate disk health. If everything checks out, you can disable the automatic verification process.

B
bei_si
Junior Member
14
03-20-2023, 12:39 AM
#3
Hello, thank you for your reply. Initially, I performed a quick scan and discovered 8 threats. Two of these were related to Drives/HOSTS, which were replaced. Five others concerned recently installed files with a total available size. I installed one folder in Local \Temp\ containing a DLL (ISHASH.DLL) that I couldn't locate. All of them were removed. During the next scan after 30 hours, only 2-3 less important files remained, which I quarantined and plan to delete as well. A few weeks ago, I also ran a full scan with Bitdefender Premium and found nothing unusual. Therefore, I need to run CHKDSK on which drive? Also, during the restart it checked and repaired all of them? What about using F-Secure Dirty Checker? Is that necessary? Thank you.
B
bei_si
03-20-2023, 12:39 AM #3

Hello, thank you for your reply. Initially, I performed a quick scan and discovered 8 threats. Two of these were related to Drives/HOSTS, which were replaced. Five others concerned recently installed files with a total available size. I installed one folder in Local \Temp\ containing a DLL (ISHASH.DLL) that I couldn't locate. All of them were removed. During the next scan after 30 hours, only 2-3 less important files remained, which I quarantined and plan to delete as well. A few weeks ago, I also ran a full scan with Bitdefender Premium and found nothing unusual. Therefore, I need to run CHKDSK on which drive? Also, during the restart it checked and repaired all of them? What about using F-Secure Dirty Checker? Is that necessary? Thank you.

S
SRAuronPlay1
Junior Member
4
03-20-2023, 01:01 AM
#4
I've encountered this issue before when restarting from various Windows versions on the same storage device. When the dirty bit was enabled, the system had to scan all my hard disks, which took a long time. We need to figure out why your system is acting strangely.

I tend to rely heavily on Malwarebytes scans, which often flag some of my desired programs—especially certain Nirsoft applications—as potentially malicious. They display "malware-like" traits, so I usually run an Advanced Scan and set Detection to Warn User. Although I've made Warn User the default in Settings, the regular scan still ignores this setting and quarantines files without warning. Better safe than sorry, right?

When Malwarebytes finds something, I review it carefully before deciding to quarantine or delete suspicious files. If I forget to adjust Advanced Scan, the next time I attempt to run a Nirsoft tool, it disappears.

If your system is heavily infected, it would be faster and safer to erase the boot drive (or switch to a new one) and reinstall Windows along with all your programs from the ground up. This process should take no more than 8 hours, not the typical 30.

I usually restrict Malwarebytes scans to my C: drive. Analyzing up to 20TB of data on other drives is inefficient and unlikely to catch everything that AV software misses. Of course, I remain cautious, so I maintain backups on other machines and tapes.

You might save time by limiting scans to just the Windows boot drive in Advanced Scan. This should reduce scan times to under 6 hours, or even faster with a modern multi-core CPU and an M.2 NVMe boot drive.
S
SRAuronPlay1
03-20-2023, 01:01 AM #4

I've encountered this issue before when restarting from various Windows versions on the same storage device. When the dirty bit was enabled, the system had to scan all my hard disks, which took a long time. We need to figure out why your system is acting strangely.

I tend to rely heavily on Malwarebytes scans, which often flag some of my desired programs—especially certain Nirsoft applications—as potentially malicious. They display "malware-like" traits, so I usually run an Advanced Scan and set Detection to Warn User. Although I've made Warn User the default in Settings, the regular scan still ignores this setting and quarantines files without warning. Better safe than sorry, right?

When Malwarebytes finds something, I review it carefully before deciding to quarantine or delete suspicious files. If I forget to adjust Advanced Scan, the next time I attempt to run a Nirsoft tool, it disappears.

If your system is heavily infected, it would be faster and safer to erase the boot drive (or switch to a new one) and reinstall Windows along with all your programs from the ground up. This process should take no more than 8 hours, not the typical 30.

I usually restrict Malwarebytes scans to my C: drive. Analyzing up to 20TB of data on other drives is inefficient and unlikely to catch everything that AV software misses. Of course, I remain cautious, so I maintain backups on other machines and tapes.

You might save time by limiting scans to just the Windows boot drive in Advanced Scan. This should reduce scan times to under 6 hours, or even faster with a modern multi-core CPU and an M.2 NVMe boot drive.

P
PrTrN
Junior Member
20
03-21-2023, 12:54 AM
#5
Also, is it essential that all critical information is stored in at least two separate locations, away from the system and its drives? Check that the backups can be recovered and accessed properly.
P
PrTrN
03-21-2023, 12:54 AM #5

Also, is it essential that all critical information is stored in at least two separate locations, away from the system and its drives? Check that the backups can be recovered and accessed properly.

D
DarkenGames
Junior Member
28
04-06-2023, 06:54 PM
#6
Thank you for your detailed reply. Please clarify what you're referring to by misbehaving...?
A 30-hour session is atypical for a rootkit, as all features remain active.
Yes, registry and bootloader files are typically found on C: I activated every option while testing all drives.
D
DarkenGames
04-06-2023, 06:54 PM #6

Thank you for your detailed reply. Please clarify what you're referring to by misbehaving...?
A 30-hour session is atypical for a rootkit, as all features remain active.
Yes, registry and bootloader files are typically found on C: I activated every option while testing all drives.