03-03-2012 09:26 PM
The Bootkit code is now gone.
can you now boot into windows normally??
Quads
03-03-2012 09:33 PM
Yes, I can. I don't think I was ever so happy to see the Windows logo. Your help was immense, thank you so much!
03-03-2012 09:35 PM
Hang Fire, we have to do some checks, now we have got back in. OK
Quads
03-03-2012 09:36 PM
ok, i'll standby.
03-03-2012 09:47 PM
Download TDSSkiller from http://support.kaspersky.com/faq/?qid=208280684
Click on the TDSSkiller.exe link on that site to download and run, In the change paramaters select Detect TDLFS file system, click OK and scan.
Don't have it fix anything, just see if it detects anything.
Quads
03-03-2012 09:55 PM
It appears to have found one suspicious object, medium risk.
physical drive:\Device\Harddisk0\DR0
03-03-2012 10:01 PM - edited 03-03-2012 10:14 PM
suspicious object leave it be as you may be using an OEM MBR, when a program like this says suspicious just leave it is safer.
It's also Ok if the detection is actually this TDSS File system, Physical drive: \Device\Harddisk0\DR0 Suspicious object
The only other program that may tell is ASWmbr.
Quads
03-03-2012 10:17 PM
I found the ASWmbr download from bleepingcomputer.com and will see what it detects. Thank you again.
03-03-2012 10:23 PM
I have tried my system with Boot.Pihar and TDSSkiller with TLFS selected. Maybe an older variant.
MBR (0x1B8) (35a4fa451025305a24e864aaa8e364c9) \Device\Harddisk0\DR0
13:15:38.0979 4716 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
13:15:38.0979 4716 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
13:15:39.0004 4716 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
13:15:39.0004 4716 \Device\Harddisk0\DR0 - detected TDSS File System (1)
==================================================
13:15:39.0086 4716 Scan finished
13:15:39.0086 4716 ==================================================
13:15:39.0103 5120 Detected object count: 2
13:15:39.0103 5120 Actual detected object count: 2
13:15:48.0586 5120 \Device\Harddisk0\DR0\# - copied to quarantine
13:15:48.0586 5120 \Device\Harddisk0\DR0 - copied to quarantine
13:15:48.0610 5120 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
13:15:48.0618 5120 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
13:15:48.0622 5120 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
13:15:48.0633 5120 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
13:15:48.0642 5120 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
13:15:48.0645 5120 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
13:15:48.0647 5120 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
13:15:48.0649 5120 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
13:15:48.0652 5120 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
13:15:48.0656 5120 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
13:15:48.0658 5120 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
13:15:48.0658 5120 \Device\Harddisk0\DR0 - ok
13:15:49.0456 5120 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
13:15:49.0462 5120 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
13:15:49.0472 5120 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
13:15:49.0475 5120 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
13:15:49.0487 5120 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
13:15:49.0497 5120 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
13:15:49.0499 5120 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
13:15:49.0500 5120 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
13:15:49.0516 5120 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
13:15:49.0519 5120 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
13:15:49.0523 5120 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
13:15:49.0523 5120 \Device\Harddisk0\DR0\TDLFS - deleted
13:15:49.0523 5120 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
But what I can see happens, Is if the partition TDLS becomes empty, for example Norton removes the files above inside the TDLFS, TDSSkiller finds the empty system but doesn't know what it is as it's empty.
Quads
03-03-2012 10:54 PM
aswMBR did find some infected files. I attached the log. I have not fixed anything, though.
