<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help in Tech Outpost</title>
    <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/671147#M5187</link>
    <description>&lt;p&gt;With all due respect momoboro ..........&lt;/p&gt;&lt;blockquote&gt;&lt;hr&gt;momoboro wrote:&lt;br&gt;&lt;p&gt;Will Norton have an antirootkit/recovery option for mbr rootkits even when the computer can't boot up?  I already know that Live CDs and Partition managers are good methods to remove the MaxSS/Pihar/TDL4, but is there another way?  &lt;font color="#FF0000"&gt;Also, when Windows 8 comes out, it's going to have a UEFI secure boot feature to get rid of these kinds of rootkits.&lt;/font&gt;&lt;/p&gt;&lt;hr&gt;&lt;br&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;As you must be aware ....we have had the Developer preview...the Windows 8 newest preview was only released moments ago .....and Microsoft plainly tell us that major changes may be implemented before final RTM of Windows 8 ...&lt;/p&gt;&lt;p&gt;So lets' keep an open mind on just what may make it to the Final release candidate ...No one really knows yet :smileywink:&lt;/p&gt;&lt;p&gt;                                                                                                                                                                     ..............Ed&lt;/p&gt;</description>
    <pubDate>Thu, 01 Mar 2012 07:48:25 GMT</pubDate>
    <dc:creator>bleeper24</dc:creator>
    <dc:date>2012-03-01T07:48:25Z</dc:date>
    <item>
      <title>Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/588858#M4588</link>
      <description>&lt;p&gt;My laptop won't boot to windows and sits at a cursor just as soon as I turn it on.  I took off the hard disk and scanned it on another machine as a secondary drive and the ( Rootkit.Boot.SST.b ) came up and no antivirus program can't delete it, cure it or quaranteen it! Please help on how to get it taken off.  I have read many forums and still no luck.  Seems no one knows how so that is why I cam to Norton as Symantec has been the best one I've ever found and has worked for me.  Thanks, Chepo&lt;/p&gt;</description>
      <pubDate>Fri, 18 Nov 2011 01:38:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/588858#M4588</guid>
      <dc:creator>chepo23</dc:creator>
      <dc:date>2011-11-18T01:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/589080#M4589</link>
      <description>&lt;p&gt;SST.B  (and SST.A) is the MaxSS modifcation of TDL4, but with a few differences,  FixMBR and FixBoot commands used via a bootable CD /DVD like the Windows Recovery Console on disc does not cure the problem.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It has it's own partition and appears to not actually alter the sector 0 (boot sector) MBR but has it's own MBR and own files within the likes of it's own partition.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It can stop programs running that may be able to cure these modifications.  In saying that fixing the Boot Sector (MBR) on your hard drive so at least you can load Windows, although still infected to then be able to remove SST (MaxSS) from your Hard Drive.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am unsure how to get the removal (cure) tool to not scan the master drive but instead the infected slave drive. (you may still have to repair the screwed MBR after that).  I am looking at the scanners options.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I would suggest backing up your personal files before going any further..&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Fri, 18 Nov 2011 05:13:00 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/589080#M4589</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2011-11-18T05:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/590072#M4602</link>
      <description>&lt;p&gt;Theory of one way&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;For MaxSS / SST.*&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;People who can't load the Boot Sector (MBR) for the Windows Partition due to MaxSS infection causing Black Screen with blinking white cursor on boot.&lt;/p&gt;&lt;p&gt;Run a Bootable CD partition manager, I think Paragon as a free version,Boot from CD (Quads has different tools) may be others.&lt;/p&gt;&lt;p&gt;Run Partition Manager You will see the MaxSS / SST. (a or b) created partition set to active and the OS /Windows partition not being set to &amp;quot;active&amp;quot;&lt;/p&gt;&lt;p&gt; Reset your OS /Windows partition to &amp;quot;&lt;strong&gt;Active&lt;/strong&gt;&amp;quot; so later when booting from the Hard Drive, it will now boot the Windows partition.&lt;/p&gt;&lt;p&gt;Delete or Deactivate the MaxSS partition by removing the &amp;quot;Active&amp;quot; flag. The MaxSS partition can be deleted later through the Windows Computer Management once the user is sure.&lt;/p&gt;&lt;p&gt;Confirm the changes and restart the PC to boot from the Hard Drive, it should now be loading the Windows Partition and thus loading windows.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I suggest using a bootable CD to be able to recover you personal files off first, there is always a risk of things going wrong with Rookit / Bootkit removal proceedures!!!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 18 Nov 2011 23:35:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/590072#M4602</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2011-11-18T23:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/602268#M4726</link>
      <description>&lt;p&gt;What Partition software was used of interest, just so others know of another Partition software that can do the same cure.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 02 Dec 2011 01:03:13 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/602268#M4726</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2011-12-02T01:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/602646#M4729</link>
      <description>&lt;p&gt; found this at wilders       &lt;a target="_blank" href="http://secure-computer-solutions.com/blog/"&gt;http://secure-computer-solutions.com/blog/&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 02 Dec 2011 15:51:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/602646#M4729</guid>
      <dc:creator>Topopurim47</dc:creator>
      <dc:date>2011-12-02T15:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/602686#M4730</link>
      <description>&lt;p&gt;Just a postsript in case anyone else has to attempt the excellent recovery advice offered by Quads! ...&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The link kindly offered by Topopurim leads to the method of Partition management using GParted !&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I use this software onmy Linux machines and it is a very useful tool !&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Just a polite  word of advice though to anyone not too familiar with the &amp;quot;Volume terminology &amp;quot; used by GParted ........the various partitions on the disk are identified by the &amp;quot;sda &amp;quot; method of terminology ......Just be certain that the correct partition is selected for any operation that is to be carried out , as the different terminology can be a little confusing for new users of GParted :smileywink:&lt;/p&gt;</description>
      <pubDate>Fri, 02 Dec 2011 17:25:36 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/602686#M4730</guid>
      <dc:creator>bleeper24</dc:creator>
      <dc:date>2011-12-02T17:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/603004#M4731</link>
      <description>&lt;p&gt;Thats a nice article but it's wrong.  It's showing a Windows 7 system and it's the &amp;quot;System Reserved Partition&amp;quot; that needs to be set active.  If you set the OS partition active, the system is not going to boot and you would need to do a startup repair.&lt;/p&gt;&lt;p&gt;I tried posting a comment for the article but I'm not sure if it worked.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Dave&lt;/p&gt;</description>
      <pubDate>Sat, 03 Dec 2011 01:52:19 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/603004#M4731</guid>
      <dc:creator>DaveH</dc:creator>
      <dc:date>2011-12-03T01:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614508#M4819</link>
      <description>&lt;div&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#FF0000"&gt;NOTE:&lt;/font&gt;&lt;/strong&gt;  the example for the MaxSS partition below is 1 MB, but depending on your own personal infection the partition involved may be anywhere from 1 MB to 15 MB. &lt;/p&gt;&lt;p&gt;The number of partitions could or will be different including the volume names, sizes, number of Hard Drives and which partition should be Flagged as the &lt;strong&gt;Boot&lt;/strong&gt; partition &lt;/p&gt;&lt;p&gt;This walkthough below uses only the OS partition and the MaxSS partition so it is easier to determine which should be the boot partition.  (there is unallocated also). &lt;/p&gt;&lt;p&gt;Most people with Partitioning experience will see what is shown below with ease to any PC with the MaxSS partition  and fix the problem.&lt;/p&gt;&lt;p&gt;Others may have to ask on another thread or Forum (for others reading out in the WWW) which partition is Bad and which partition should be flagged as Boot.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Backup / Save all personal files (photos, docs, music etc) first  incase, something goes wrong. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Firstly download Gparted, maybe from another  clean computer instead, From &lt;a target="_blank" href="http://sourceforge.net/projects/gparted/files/gparted-live-stable/"&gt;http://sourceforge.net/projects/gparted/files/gparted-live-stable/&lt;/a&gt; chose the stable .iso download.&lt;br&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Now you have to burn the .iso image as an image to CD  You can use ImgBurn do this. &lt;a target="_blank" href="http://www.imgburn.com/index.php?act=download"&gt;http://www.imgburn.com/index.php?act=download&lt;/a&gt;  or any other CD burning program that can handle .iso images.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now boot off of the newly created Gparted CD.  You may have to change the computers boot options, so that you can boot from the CD /DVD from first instead of the Hard Drive.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="Gparted Start Screen.jpg" alt="Gparted Start Screen.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23064i1F3A7373D927FB79/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;You should be here (above)...  Just press &lt;strong&gt;ENTER&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;img title="gpartedkeymaps.jpg" alt="gpartedkeymaps.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23066i0E74B853744FECCA/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;By default, &amp;quot;&lt;strong&gt;do not touch keymap&lt;/strong&gt;&amp;quot; is highlighted. Leave this setting alone and just press &lt;strong&gt;ENTER&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gpartedlanguage.jpg" alt="gpartedlanguage.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23068iB3381F0D4E1FB54B/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;Choose your language and press&lt;strong&gt; ENTER&lt;/strong&gt;. English should be default [33]&lt;/p&gt;&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;NOTE:&lt;/strong&gt;&lt;/font&gt;  If you choose to select another language the reast of this Post (message) may look different as English is used here.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gpartedgui.jpg" alt="gpartedgui.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23070i22574649DFBF555B/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;Once again, at this prompt, press &lt;strong&gt;ENTER &lt;/strong&gt;as 0 should be selected as default&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You will now be taken to the main GUI screen below&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gpartedPartitionlists.jpg" alt="gpartedPartitionlists.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23072i6FE25458FEEDEFED/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Remember in this post the partition that is bad is 1 MB in size, your bad Partition which has been confirmed by someone could be 1 MB to 15 MB, also a different setup can have more partitions to list, so the bad partition needs to be known before just going about deleting partitions &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Select the MaxSS (SST.a, SST.b) partition  then click the &lt;strong&gt;trash can icon&lt;/strong&gt; to delete that bad partition and then click&lt;strong&gt; Apply&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gparted delete MaxSS part.jpg" alt="gparted delete MaxSS part.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23074i9DAD332AD57F06D1/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You should now be here confirming your actions:  Click &lt;strong&gt;Apply  &lt;/strong&gt;Delete Operation Pending&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gpartedconfirmClose.jpg" alt="gpartedconfirmClose.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23076i65A68060AA51D731/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;br&gt;Now you should be here: Just Click &lt;strong&gt;Close&lt;/strong&gt;  and now in this example you will see there is only the Good OS partition and unallocated space, which has gone up in size from 10 MB to 11 MB. No more MaxSS partition.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="Make sure boot workingpart.jpg" alt="Make sure boot workingpart.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23078i40D27D8B2669619F/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now is the &lt;strong&gt; boot&lt;/strong&gt; next to your OS drive? (in the Flags column)&lt;/p&gt;&lt;p&gt;If &amp;quot;boot&amp;quot; is not next to your OS drive under &amp;quot;Flags&amp;quot;, &lt;strong&gt;right-mouse click the OS drive&lt;/strong&gt; while in Gparted and select&lt;strong&gt; Manage Flags&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In the menu that pops up, place a checkmark in the &lt;strong&gt;boot&lt;/strong&gt; column like the picture below and &lt;strong&gt;close&lt;/strong&gt; :  This is where a standard home user may also get confirmation from another thread or forum which partition is to have boot for their PC in question &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gparted manage flags.jpg" alt="gparted manage flags.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23080i0B386352D8CB1D62/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Now &lt;strong&gt;double-click&lt;/strong&gt; on the Exit Button&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gparted exit.jpg" alt="gparted exit.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23082iEF7BB1DB24E0910D/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You should receive a small pop up asking you what you want to do&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img title="gparted reboot.jpg" alt="gparted reboot.jpg" border="0" align="center" src="http://community.norton.com/t5/image/serverpage/image-id/23084i794DDF4A0C7F3E13/image-size/original?v=mpbl-1&amp;amp;px=-1"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Choose&lt;strong&gt; reboot&lt;/strong&gt; and then press &lt;strong&gt;OK&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Take out the CD before it loads, or on the Startup you can change the BIOS load order back to booting from the Hard Drive first.&lt;/p&gt;&lt;p&gt;Now with Windows loaded and no MaxSS partition Norton should no longer detect Boot.Tidserv  or you may have to clear the Unresolved threats listings.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;There Could also be cases where the MBR of the OS partition still has to be fixed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;/div&gt;</description>
      <pubDate>Mon, 19 Dec 2011 05:02:14 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614508#M4819</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2011-12-19T05:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614570#M4820</link>
      <description>&lt;p&gt;Hi all&lt;/p&gt;&lt;p&gt;               I posted earlier in this topic ...and wrote&lt;/p&gt;&lt;p&gt;-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Just a polite  word of advice though to anyone not too familiar with the &amp;quot;Volume terminology &amp;quot; used by GParted ........the various partitions on the disk are identified by the &amp;quot;sda &amp;quot; method of terminology ......Just be certain that the correct partition is selected for any operation that is to be carried out , as the different terminology can be a little confusing for new users of GParted&lt;/strong&gt;&lt;/em&gt; ----------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;A big &amp;quot;Thankyou &amp;quot; to Quads :smileywink:.....for taking the time to add the &amp;quot;step by step &amp;quot; image tutorial outlining the process in detail .This is a big help to anyone not familiar with Gnome terminology which can&amp;quot; baffle &amp;quot; new GParted users ...Excellent post Quads ....all credit due :smileywink:&lt;/p&gt;</description>
      <pubDate>Mon, 19 Dec 2011 07:01:19 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614570#M4820</guid>
      <dc:creator>bleeper24</dc:creator>
      <dc:date>2011-12-19T07:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614948#M4825</link>
      <description>&lt;p&gt;There is another free bootable CD partition manager here &lt;a target="_blank" href="http://www.partitionwizard.com/partition-wizard-bootable-cd.html"&gt;http://www.partitionwizard.com/partition-wizard-bootable-cd.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 19 Dec 2011 21:06:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614948#M4825</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2011-12-19T21:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/638751#M4975</link>
      <description>&lt;p&gt;NOTE:  For MaxSS (SST.*)  Norton is detecting this infection as &amp;quot;Boot.Tidserv&amp;quot;  and giving the link to FixTDSS.  The progam can't fix this.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 20 Jan 2012 22:37:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/638751#M4975</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-01-20T22:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/669951#M5180</link>
      <description>&lt;p&gt;I definitely know that Norton can't detect or even clean these hard to find&amp;amp;remove rootkits and bootbots, so I used the following to get rid of most of them successfully: TDSSKiller by Kaspersky, Malwarebytes, and Emsisoft Antimalware.  I had to use a laptop to download those free malware scanners b/c the fake antivirus known as XP Home Security 2012 had infected my pc.  TDSSKiller cleaned those that were not detectable by Norton's antirootkit that had given me those annoying popups that showed up everytime I started my computer and when I tried going to a website on Internet Explorer 8.  Then I had to look for instructions on how to reinstall Netbt service on Windows, since the netbt.sys file in the system32 folder had a rootkit on it and it was removed by TDSSKiller.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Tue, 28 Feb 2012 03:23:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/669951#M5180</guid>
      <dc:creator>momoboro</dc:creator>
      <dc:date>2012-02-28T03:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/669999#M5181</link>
      <description>&lt;p&gt;Oh, I almost forgot to tell you that TDSSKiller has to be used more than once to actually find all those Tidserv rootkits and if you do lose internet connection like I have, then use another computer to connect and then google this, &amp;quot;How to reinstall NetBT Service on Windows XP.&amp;quot;&lt;/p&gt;</description>
      <pubDate>Tue, 28 Feb 2012 04:51:38 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/669999#M5181</guid>
      <dc:creator>momoboro</dc:creator>
      <dc:date>2012-02-28T04:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670289#M5182</link>
      <description>&lt;p&gt;NOTE:   This thread is for instructions to remove the MaxSS partition detected as Boot.Tidserv, Please ignore the above posts by Momoboro.  None of his tools he used are successful. Let alone the fact:-&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;a)  Sounds like he is not talking about MaxSS.&lt;/p&gt;&lt;p&gt;b)  No details of what was actually detected.&lt;/p&gt;&lt;p&gt;c) Now no Internet Connection for what ever reason, let alone the next users problem file might not be say &amp;quot;netbt.sys&amp;quot; or it's a problem with the I.P. Stack.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;d)  Sounds more like Max++&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Tue, 28 Feb 2012 20:36:12 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670289#M5182</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-02-28T20:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670459#M5183</link>
      <description>&lt;p&gt;um, anyone found this website?    &lt;a target="_blank" href="http://en.kioskea.net/faq/18862-rootkit-boot-sst"&gt;http://en.kioskea.net/faq/18862-rootkit-boot-sst&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 29 Feb 2012 04:14:49 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670459#M5183</guid>
      <dc:creator>momoboro</dc:creator>
      <dc:date>2012-02-29T04:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670483#M5184</link>
      <description>&lt;p&gt;also try GMER’s &lt;strong&gt;mbr.exe&lt;/strong&gt;: http://w ww2.gmer.net/mbr/mbr.exe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;[&lt;font color="#FF0000"&gt;&lt;strong&gt;Edit&lt;/strong&gt;: &lt;font color="#000000"&gt;Removed the direct link to the executable to conform with &lt;a href="http://community.norton.com/t5/About-This-Community/Participation-Guidelines/m-p/5" target="_self"&gt;&lt;font color="#000000"&gt;Participation Guidelines&lt;/font&gt;&lt;/a&gt;&amp;nbsp; and &lt;a href="http://community.norton.com/t5/About-This-Community/Terms-of-Service/m-p/1" target="_self"&gt;&lt;font color="#000000"&gt;Terms of Service&lt;/font&gt;&lt;/a&gt;&lt;/font&gt;&lt;/font&gt; ]&lt;/p&gt;</description>
      <pubDate>Wed, 29 Feb 2012 08:40:24 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670483#M5184</guid>
      <dc:creator>momoboro</dc:creator>
      <dc:date>2012-02-29T08:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670615#M5185</link>
      <description>&lt;p&gt;I don't need to know about other websites or tools,  I can infect my system with MaxSS when I want I have the dropper / installers.  Also it did or does not infect a driver at all,  But instead the partition has to be removed and the flag made sure is set correctly.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;A least 2 or 3 people have use my instructions with success with their own threads and   a) TDSSkiller does not fix the problem of the partition.  &lt;/p&gt;&lt;p&gt;Loads of others unknown (by the amount of views) may have also used my instructions.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Problems occuring with TDSSkiller and what is or looks like MaxSS, after running TDSSkiller&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;span&gt;File Check:&lt;/span&gt;&lt;br&gt;&lt;span&gt;========&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\dhcpcsvc.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;Attention! C:\WINDOWS\system32\Drivers\afd.sys is missing.&lt;/span&gt;&lt;br&gt;&lt;span&gt;Attention! C:\WINDOWS\system32\Drivers\netbt.sys is missing.&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\Drivers\tcpip.sys =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;Attention! C:\WINDOWS\system32\Drivers\ipsec.sys is missing.&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\dnsrslvr.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\ipnathlp.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\netman.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\wbem\WMIsvc.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\srsvc.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\Drivers\sr.sys =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\wscsvc.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\wbem\WMIsvc.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\wuauserv.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\qmgr.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\es.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\cryptsvc.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\svchost.exe =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\rpcss.dll =&amp;gt; MD5 is legit&lt;/span&gt;&lt;br&gt;&lt;span&gt;C:\WINDOWS\system32\services.exe =&amp;gt; MD5 is legit&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;And &lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span&gt;&amp;quot;&lt;span&gt;, I have a laptop that was infected. I had removed pretty much everything that was found but was still getting a kdcom.dll BSOD every hour or so while windows 7 x64 was running. I found that the machine had the&lt;strong&gt; rootkit.boot.sst.b&lt;/strong&gt; infection and attempted to remove it with&lt;strong&gt; TDSSKILLER&lt;/strong&gt;. Afterwards it would not fully boot no matter of Normal modem or Safe Mode. It stops on the 0x7B error every time. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Had a 0.03GB boot patition.&lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Wed, 29 Feb 2012 12:12:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670615#M5185</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-02-29T12:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670877#M5186</link>
      <description>&lt;p&gt;Will Norton have an antirootkit/recovery option for mbr rootkits even when the computer can't boot up?  I already know that Live CDs and Partition managers are good methods to remove the MaxSS/Pihar/TDL4, but is there another way?  Also, when Windows 8 comes out, it's going to have a UEFI secure boot feature to get rid of these kinds of rootkits.&lt;/p&gt;</description>
      <pubDate>Wed, 29 Feb 2012 23:05:13 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/670877#M5186</guid>
      <dc:creator>momoboro</dc:creator>
      <dc:date>2012-02-29T23:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/671147#M5187</link>
      <description>&lt;p&gt;With all due respect momoboro ..........&lt;/p&gt;&lt;blockquote&gt;&lt;hr&gt;momoboro wrote:&lt;br&gt;&lt;p&gt;Will Norton have an antirootkit/recovery option for mbr rootkits even when the computer can't boot up?  I already know that Live CDs and Partition managers are good methods to remove the MaxSS/Pihar/TDL4, but is there another way?  &lt;font color="#FF0000"&gt;Also, when Windows 8 comes out, it's going to have a UEFI secure boot feature to get rid of these kinds of rootkits.&lt;/font&gt;&lt;/p&gt;&lt;hr&gt;&lt;br&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;As you must be aware ....we have had the Developer preview...the Windows 8 newest preview was only released moments ago .....and Microsoft plainly tell us that major changes may be implemented before final RTM of Windows 8 ...&lt;/p&gt;&lt;p&gt;So lets' keep an open mind on just what may make it to the Final release candidate ...No one really knows yet :smileywink:&lt;/p&gt;&lt;p&gt;                                                                                                                                                                     ..............Ed&lt;/p&gt;</description>
      <pubDate>Thu, 01 Mar 2012 07:48:25 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/671147#M5187</guid>
      <dc:creator>bleeper24</dc:creator>
      <dc:date>2012-03-01T07:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Rootkit.Boot.SST.b  is NOT coming off! PLEASE help</title>
      <link>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/672069#M5189</link>
      <description>&lt;p&gt;There is already a Windows 8 Root/Boot kit created &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 02 Mar 2012 23:52:05 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/672069#M5189</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-03-02T23:52:05Z</dc:date>
    </item>
  </channel>
</rss>

