09-09-2012 04:28 PM
Please read carefully and follow these steps.
Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684 click on the TDSSkiller.exe green link.
Double click on TDSSKiller.exe to run the application,
Open the Change Parameters option and select the detect TDL File system
Click OK
Then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
Look for the Filesystem detection
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste into Notepad and attach back here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ ) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.
Quads
09-09-2012 04:47 PM
Attached the log.
09-09-2012 04:53 PM - edited 09-09-2012 04:56 PM
OK
Start TDSSkiller again, all the same settings, after the scan, change the below detection to Delete
16:46:15.0375 4760 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
16:46:15.0375 4760 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Don't know where partition 4 is in that log , hmmmm
Disk: 0
Partition 2
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================
Disk: 0
Partition 4
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
Might have to use listparts and cmd yet.
Quads
09-09-2012 05:10 PM
I accidentally ran a a new scan before taking the log of the scan with the deletion since I got a pop up from 360's auto-protect and thought norton blocked TDSSKiller.
09-09-2012 05:18 PM - edited 09-09-2012 05:21 PM
Norton will probably detect the quarantined files that were inside the partition taken.
Download use listparts http://www.bleepingcomputer.com/download/listparts
Quads
09-09-2012 05:21 PM
Didn't use the "List BCD" option.
09-09-2012 05:37 PM - edited 09-09-2012 05:41 PM
Partition 2 first
21:58:27.666 Disk 0 Partition 2 00 17 Hidd HPFS/NTFS NTFS 2 MB offset 1250258625
21:58:27.673 Disk 0 Partition 2 **INFECTED** MBR:Alureon-K [Rtk]
Disk: 0
Partition 2
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
Work very slowly making sure you understand and have the correct commands and number entered.
go to start => Run (or press Windows key+R) to bring up the Run box.
Type cmd in the run box and click OK. Or Type CMD in the search box for Win 7 or Vista and cmd.exe appears in the search list to click and run.
A black command windows opens.
Please copy or type in each red line separately, if copied then right-click in the command windows and select Paste then press Enter after each line.
Or you can type the bold lines one by one and press Enter after each line. (note that you should not copy all the lines at the same time, it should be executed line by line:
diskpart
Press Enter and wait (you get "Diskpart>")
select disk=0
(Note that this is disk zero) Press Enter.
You should get notified that "Disk 0 is now the selected disk".
select partition=2
Press Enter. You should get notified that "Partition 2 is now the selected partition".
delete partition override
Press Enter.
You should get notified that "DiskPart successfully deleted the selected partition".
Quads
09-09-2012 05:42 PM
Alright, partition 2 deleted.
09-09-2012 05:47 PM
Partition 4 now
21:58:27.778 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 0 MB offset 1250263712
21:58:27.786 Disk 0 Partition 4 **INFECTED** MBR:Alureon-K [Rtk]
Disk: 0
Partition 4
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No
There is no volume associated with this partition.
Work very slowly making sure you understand and have the correct commands and number entered.
go to start => Run (or press Windows key+R) to bring up the Run box.
Type cmd in the run box and click OK. Or Type CMD in the search box for Win 7 or Vista and cmd.exe appears in the search list to click and run.
A black command windows opens.
Please copy or type in each red line separately, if copied then right-click in the command windows and select Paste then press Enter after each line.
Or you can type the bold lines one by one and press Enter after each line. (note that you should not copy all the lines at the same time, it should be executed line by line:
diskpart
Press Enter and wait (you get "Diskpart>")
select disk=0
(Note that this is disk zero) Press Enter.
You should get notified that "Disk 0 is now the selected disk".
select partition=4
Press Enter. You should get notified that "Partition 4 is now the selected partition".
delete partition override
Press Enter.
You should get notified that "DiskPart successfully deleted the selected partition".
Quads
09-09-2012 05:52 PM
Alright, partition 4 deleted.
