Reply
Bot Obliterator
Quads
Posts: 13,244
Registered: ‎07-21-2008

Re: Boot.Tidserv Infection

Please read carefully and follow these steps.


Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684  click on the TDSSkiller.exe green link.

 

Double click on TDSSKiller.exe to run the application,

Open the Change Parameters option and select the detect TDL File system

 

TDSSKiller Parameters.jpg

 

Click OK

 

Then on Start Scan.


If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.

 

Look for the Filesystem detection

 

TDSSFS.jpg


It may ask you to reboot the computer to complete the process. Click on Reboot Now.


If no reboot is require, click on Report. A log file should appear. Please copy and paste into Notepad and attach back here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ ) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.

 

Quads

Contributor
cinagro
Posts: 19
Registered: ‎07-19-2012

Re: Boot.Tidserv Infection

Attached the log. 

Bot Obliterator
Quads
Posts: 13,244
Registered: ‎07-21-2008

Re: Boot.Tidserv Infection

[ Edited ]

OK

 

Start TDSSkiller again, all the same settings, after the scan, change the below detection to Delete

 

16:46:15.0375 4760 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
16:46:15.0375 4760 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

 

Don't know where partition 4 is in that log , hmmmm

 

Disk: 0
Partition 2
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

==================================================================================

Disk: 0
Partition 4
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

 

 

Might have to use listparts and cmd yet.

 

Quads

Contributor
cinagro
Posts: 19
Registered: ‎07-19-2012

Re: Boot.Tidserv Infection

I accidentally ran a a new scan before taking the log of the scan with the deletion since I got a pop up from 360's auto-protect and thought norton blocked TDSSKiller. 

 

Bot Obliterator
Quads
Posts: 13,244
Registered: ‎07-21-2008

Re: Boot.Tidserv Infection

[ Edited ]

Norton will probably detect the quarantined files that were inside the partition taken.

 

Download  use listparts  http://www.bleepingcomputer.com/download/listparts/  and run a scan  64 Bit version

 

Quads

Contributor
cinagro
Posts: 19
Registered: ‎07-19-2012

Re: Boot.Tidserv Infection

Didn't use the "List BCD" option. 

Bot Obliterator
Quads
Posts: 13,244
Registered: ‎07-21-2008

Re: Boot.Tidserv Infection

[ Edited ]

Partition 2 first

 

21:58:27.666 Disk 0 Partition 2 00 17 Hidd HPFS/NTFS NTFS 2 MB offset 1250258625
21:58:27.673 Disk 0 Partition 2 **INFECTED** MBR:Alureon-K [Rtk] 

Disk: 0
Partition 2
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

 

 

Work very slowly making sure you understand and have the correct commands and number entered.

 

 

go to start => Run (or press Windows key+R) to bring up the Run box.
Type cmd in the run box and click OK.  Or Type CMD in the search box for Win 7 or Vista and cmd.exe appears in the search list to click and run.


A black command windows opens.

 

Please copy or type in each red line separately, if copied then right-click in the command windows and select Paste then press Enter after each line.

 

Or you can type the bold lines one by one and press Enter after each line. (note that you should not copy all the lines at the same time, it should be executed line by line:

 

diskpart

 

Press Enter and wait (you get "Diskpart>")

 

select disk=0

 

(Note that this is disk zero) Press Enter.

 

You should get notified that "Disk 0 is now the selected disk".

 

select partition=2

 

Press Enter. You should get notified that "Partition 2 is now the selected partition".

 

delete partition override

 

Press Enter.

 

You should get notified that "DiskPart successfully deleted the selected partition".

 

 

Quads

Contributor
cinagro
Posts: 19
Registered: ‎07-19-2012

Re: Boot.Tidserv Infection

Alright, partition 2 deleted. 

Bot Obliterator
Quads
Posts: 13,244
Registered: ‎07-21-2008

Re: Boot.Tidserv Infection

Partition 4 now

 

21:58:27.778 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 0 MB offset 1250263712
21:58:27.786 Disk 0 Partition 4 **INFECTED** MBR:Alureon-K [Rtk]
Disk: 0
Partition 4
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

 

 

Work very slowly making sure you understand and have the correct commands and number entered.

 

 

go to start => Run (or press Windows key+R) to bring up the Run box.
Type cmd in the run box and click OK.  Or Type CMD in the search box for Win 7 or Vista and cmd.exe appears in the search list to click and run.


A black command windows opens.

 

Please copy or type in each red line separately, if copied then right-click in the command windows and select Paste then press Enter after each line.

 

Or you can type the bold lines one by one and press Enter after each line. (note that you should not copy all the lines at the same time, it should be executed line by line:

 

diskpart

 

Press Enter and wait (you get "Diskpart>")

 

select disk=0

 

(Note that this is disk zero) Press Enter.

 

You should get notified that "Disk 0 is now the selected disk".

 

select partition=4

 

Press Enter. You should get notified that "Partition 4 is now the selected partition".

 

delete partition override

 

Press Enter.

 

You should get notified that "DiskPart successfully deleted the selected partition".

 

 

Quads

Contributor
cinagro
Posts: 19
Registered: ‎07-19-2012

Re: Boot.Tidserv Infection

Alright, partition 4 deleted.