07-20-2012 02:57 PM
It may be a Boot Sector Virus. Your computer MBR (Master Boot Records) may be infected infected.........
To fix this one you have to fix the MBR........
If you are using a Windows then you can use this Norton tool
http://www.symantec.com/content/en/us/global/remov
http://www.symantec.com/security_response/writeup.
This tool will work in Windows Vista and 7 also. If you got any error like start up repair you need to do the follwoing steps also.
Please note this steps
There is a Chance that we will get a Error after a restart.
In that case Follow : http://support.microsoft.com/kb/927392
http://123seminarsonly.com/Blog/launches-startup-r
To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:
Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
Press a key when you are prompted.
Select a language, a time, a currency, a keyboard or an input method, and then click Next.
Click Repair your computer.
Click the operating system that you want to repair, and then click Next.
In the System Recovery Options dialog box, click Command Prompt.
In that Command Prompt Type the Following Command One by one......
bcdedit /export C:\BCD_Backup
c:
cd boot
attrib bcd -s -h -r
ren c:\boot\bcd bcd.old
bootrec /RebuildBcd
07-20-2012 03:27 PM - edited 07-20-2012 04:07 PM
Quads has already identified the malware and advised the user to use only specific tools in a specific order. While I'm sure you have the best interests of the user at heart, using other tools during this time is risky and will undermine the remediation efforts currently under way.
07-20-2012 08:44 PM
CAUGHT giving bad instructions Gotca using the likes of FixTDSS on bootkits that are not Tidserv is bad and as people have found out hurts the system. had some recently where I have had to get the users system back
It may be a Boot Sector Virus. Your computer MBR (Master Boot Records) may be infected infected.........
To fix this one you have to fix the MBR........
If you are using a Windows then you can use this Norton tool
http://www.symantec.com/content/en/us/global/remov
07-20-2012 08:51 PM
Wizard
Please read carefully and follow these steps.
Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684 click on the TDSSkiller.exe green link. Not the .zip download
Double click on TDSSKiller.exe to run the application,
Open the Change Parameters option and select the detect TDLFS (File System)
Then on Start Scan.
I you want you can for each detection change the option to skip So TDSSkiller won't fix anything but will create a log for me to check first.
the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.
Quads
07-21-2012 10:32 AM
I havent done anything yet, other than following your first directions and posting the log. I'm assuming I shouldnt follow the directions posted by Kuttus,and instead should start with your new set of instructions. Is that correct?
07-21-2012 04:41 PM
wizzard166 wrote:I havent done anything yet, other than following your first directions and posting the log. I'm assuming I shouldnt follow the directions posted by Kuttus,and instead should start with your new set of instructions. Is that correct?
No, those instructions are faulty, the user has not got an idea about why not to use tools not created for a different Malware family.
I have had to get users systems back after not being able to boot after using the wrong tool, bye to working Windows.
That is why I ask for logs first to pinpoint the obhects in question and which family invilved.
Quads
07-22-2012 07:19 AM
when i try to attach the log, i get this error message. I don't know what to do, in order for you to see the log. I tried at first to cut and paste the whole log in my reply section, but an error message said it was too large. Maybe I can cut and past it in multiple pieces. What do you suggest?
07-22-2012 07:32 AM
This is the error message I got when I tried to attach the log from my C drive:
The file does not have a valid extension for an attachment. txt,log,lue are the valid extensions.
The odd thing is that the file on my C drive ends in .txt
I tried to copy and paste the log to a Microsoft Word doc, but got the same error message about lack of valid file extension. Maybe that was because the file is a .doc. I don't know how to get the log to you for review. I could email the log to you
07-22-2012 07:43 AM
After failing to attach the log from the Kapersky scan, I looked back at your replies to me and saw the other link for the Norton scan for the TDS virus. I tried that one too, it told me to reboot after the scan, and when I rebooted a message from Symantec said no virus was found. I don't know if that means it removed the TDS virus, or if it was saying the Norton scan couldnt find it.
07-22-2012 07:47 AM
After running the Norton scan and removal, which then said no threat was found, I tried Kapersky again. This time the Kapersky scan did not find a threat.
I'm assuming this means that the TDS virus was removed. Is that your interpretation.
