Reply
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Cannot boot computer after running Norton Power Eraser

The Bootkit code is now gone.

 

can you now boot into windows normally??

 

Quads

Contributor
B_chicago
Posts: 11
Registered: ‎03-03-2012

Re: Cannot boot computer after running Norton Power Eraser

Yes, I can. I don't think I was ever so happy to see the Windows logo. Your help was immense, thank you so much!

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Cannot boot computer after running Norton Power Eraser

Hang Fire, we have to do some checks, now we have got back in.  OK

 

Quads

Contributor
B_chicago
Posts: 11
Registered: ‎03-03-2012

Re: Cannot boot computer after running Norton Power Eraser

ok, i'll standby.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Cannot boot computer after running Norton Power Eraser

Download TDSSkiller from http://support.kaspersky.com/faq/?qid=208280684

 

Click on the TDSSkiller.exe link on that site to download and run,  In the change paramaters select  Detect TDLFS file system, click OK  and scan.

Don't have it fix anything, just see if it detects anything.

 

Quads

 

 

Contributor
B_chicago
Posts: 11
Registered: ‎03-03-2012

Re: Cannot boot computer after running Norton Power Eraser

It appears to have found one suspicious object, medium risk.
physical drive:\Device\Harddisk0\DR0

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Cannot boot computer after running Norton Power Eraser

[ Edited ]

 suspicious object  leave it be as you may be using an OEM MBR, when a program like this says suspicious just leave it is safer.

 

It's also Ok if the detection is actually this TDSS File systemPhysical drive: \Device\Harddisk0\DR0 Suspicious object

 

The only other program that may tell is ASWmbr.

 

Quads

Contributor
B_chicago
Posts: 11
Registered: ‎03-03-2012

Re: Cannot boot computer after running Norton Power Eraser

I found the ASWmbr download from bleepingcomputer.com and will see what it detects. Thank you again.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Cannot boot computer after running Norton Power Eraser

I have tried my system with Boot.Pihar and TDSSkiller with TLFS selected. Maybe an older variant.

 

MBR (0x1B8) (35a4fa451025305a24e864aaa8e364c9) \Device\Harddisk0\DR0
13:15:38.0979 4716 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
13:15:38.0979 4716 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
13:15:39.0004 4716 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
13:15:39.0004 4716 \Device\Harddisk0\DR0 - detected TDSS File System (1)

============================================================
13:15:39.0086 4716 Scan finished
13:15:39.0086 4716 ============================================================
13:15:39.0103 5120 Detected object count: 2
13:15:39.0103 5120 Actual detected object count: 2
13:15:48.0586 5120 \Device\Harddisk0\DR0\# - copied to quarantine
13:15:48.0586 5120 \Device\Harddisk0\DR0 - copied to quarantine
13:15:48.0610 5120 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
13:15:48.0618 5120 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
13:15:48.0622 5120 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
13:15:48.0633 5120 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
13:15:48.0642 5120 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
13:15:48.0645 5120 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
13:15:48.0647 5120 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
13:15:48.0649 5120 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
13:15:48.0652 5120 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
13:15:48.0656 5120 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
13:15:48.0658 5120 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
13:15:48.0658 5120 \Device\Harddisk0\DR0 - ok
13:15:49.0456 5120 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
13:15:49.0462 5120 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
13:15:49.0472 5120 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
13:15:49.0475 5120 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
13:15:49.0487 5120 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
13:15:49.0497 5120 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
13:15:49.0499 5120 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
13:15:49.0500 5120 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
13:15:49.0516 5120 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
13:15:49.0519 5120 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
13:15:49.0523 5120 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
13:15:49.0523 5120 \Device\Harddisk0\DR0\TDLFS - deleted
13:15:49.0523 5120 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete

 

But what I can see happens, Is if the partition TDLS becomes empty, for example Norton removes the files above inside the TDLFS, TDSSkiller finds the empty system but doesn't know what it is as it's empty.

 

Quads

Contributor
B_chicago
Posts: 11
Registered: ‎03-03-2012

Re: Cannot boot computer after running Norton Power Eraser

aswMBR did find some infected files. I attached the log. I have not fixed anything, though.