after RK delete, i try scan MGR but after few minutes an error window has been showed and scan stopped, so i close and restar MGR… and it done same things.
so i have reboot notebook. At window start a multiple choice of boot has been showed for few seconds (never done before) i cant' read but i can try if you want it is very fast.
Finally when windows start, Norton still Autodetect Boot.Tidserv (same image i've already send)… what do you think?
i try scan MGR but after few minutes an error window has been showed and scan stopped, so i close and restar MGR… and it done same things.
I don't understand what you mean here? Could you explain it more please?
The screen you are seeing briefly at start up about boot options is not a problem. It occurred because of the tools we put on your system. Nothing to worry about.
I think that a complete uninstall and then reinstall of Norton would be the best route right now. See if that clears up the problem. Let me know if that helps.
i mean that the same window error appear after MGR restart… with rebooting MGR cad do completely scan of pc… but norton alway detect Boot.Tidserv at the start up… now what do you want to do? reinstall norton?
but virus was removed?
Give the uninstall of Norton a try and a fresh install and let me know if that fixes things.
Let's get on offline MBR dump
You'll need a CD and a USB flashdrive that has some space on it. We
will not be changing any of the data on the usb device just using it for a file.
You will also need to use
FireFox to download a file as Internet Explorer seems to mangle the download.
If you have any problems with these steps please let me know. It may look complicated but it's fairly straight forward and for the most part automated.
Download
GETxPUD.exe to your desktop
Run GETxPUD.exe by double clicking it. A new folder will appear on the desktop. Open the GETxPUD folder and click on the get&burn.bat The program will download xpud_0.9.2.iso, and when finished, it will open BurnCDCC which will be ready to burn the image. Click on Start and follow the prompts to burn the image to your CD
Using
FireFox , please download and save
dumpit to your
usb device .
You may want to print out this part as you will not be able to view these instructions once booted with the CD you just made.
Leave the usb device attached to the computer Now boot your computer with the CD you just burned
with the CD in the computer, restart the computer The computer must be set to boot from the CD,depending on your computer you can either do this by pressing F12 and selecting the CD as the first boot option or it can be set in the BIOS Once you have the computer set to boot from the CD allow it to boot A Welcome to xPUD screen will appear Click on File Expand mnt sda1 ,or sda2 …usually corresponds to your HDDsdb1 is likely your USB Click on the folder that represents your USB drive (sdb1 ?)
(you will be able to tell if it the right one as the screen will populate with your files) Locate the file you downloaded and saved earlier, dumpit double click it to run it a black window will open, follow the instructions to close the window when it's finished a file called MBR.zip should now be placed in the right hand panel Click the Home icon at top Remove the CD and click Power off Click restart
Once the computer has rebooted open the usb device and
attach the
MBR.zip file to your next reply.
———-
ok so first step, it's to install firefox… i think i'm going to do tonight, to stay calm and pay attention
i've a problem, i can't find any sdb… no one. I can see n°3 sda: sda1 seem my C drive, sd2 seem D drive while sd3 is blank nothing inside…
Let's give this a shot….
Malwarebytes Anti-Rootkit
Please download
Malwarebytes Anti-Rootkit and save it to your desktop.
Be sure to print out and follow the instructions provided on that same page. Caution : This is a beta version so please be sure to read the disclaimer and back up all your data before using.Scan your system for malware If malware is found, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
If no malware is found please let me know.
———-
jeff do u think i can create dvd of my data and be sure that virus doesn't move inside?
Sure you can do that to back up your data.
When you get the MBAR Rootkit tool ran post the log.
yes, here i'm coming back now i'm going to scan…
scan finish… said that no malware founds… i'm becoming crazy!!!!
—————————————
Malwarebytes Anti-Rootkit BETA 1.01.0.1009
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
Java version: 1.6.0_25
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 1.828000 GHz
Memory total: 3623202816, free: 2517237760
———— Kernel report ————
11/15/2012 14:27:27
———— Loaded modules ———–
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
ohci1394.sys
\WINDOWS\system32\DRIVERS\1394BUS.SYS
compbatt.sys
\WINDOWS\system32\DRIVERS\BATTC.SYS
pciide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
intelide.sys
viaide.sys
aliide.sys
pcmcia.sys
MountMgr.sys
ftdisk.sys
ACPIEC.sys
\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
PartMgr.sys
VolSnap.sys
atapi.sys
iaStor.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
SYMDS.SYS
sr.sys
SYMEFA.SYS
DRVMCDB.SYS
PxHelp20.sys
KSecDD.sys
WudfPf.sys
Ntfs.sys
NDIS.sys
Mup.sys
hpdskflt.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\b57xp32.sys
\SystemRoot\system32\DRIVERS\w39n51.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\nic1394.sys
\SystemRoot\system32\drivers\tifm21.sys
\SystemRoot\system32\DRIVERS\sdbus.sys
\SystemRoot\system32\DRIVERS\gtipci21.sys
\SystemRoot\system32\DRIVERS\SMCLIB.SYS
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\IFXTPM.SYS
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\System32\Drivers\DLACDBHM.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\Accelerometer.sys
\SystemRoot\system32\DRIVERS\cpqbttn.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\btkrnl.sys
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\ADIHdAud.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\AEAudio.sys
\SystemRoot\system32\DRIVERS\HSFHWAZL.sys
\SystemRoot\system32\DRIVERS\HSF_DPV.sys
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\drivers\psd.sys
\SystemRoot\system32\drivers\N360\1402000.013\ccSetx86.sys
\SystemRoot\system32\drivers\N360\1402000.013\Ironx86.SYS
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\Drivers\DLARTL_N.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\system32\drivers\N360\1402000.013\SYMTDI.SYS
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
\SystemRoot\system32\DRIVERS\arp1394.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\eabfiltr.sys
\SystemRoot\system32\drivers\N360\1402000.013\SRTSPX.SYS
\??\C:\Programmi\SUPERAntiSpyware\SASKUTIL.SYS
\??\C:\Programmi\SUPERAntiSpyware\SASDIFSV.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\??\C:\Programmi\File comuni\Symantec Shared\EENGINE\eeCtrl.sys
\??\C:\Programmi\File comuni\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
\SystemRoot\System32\Drivers\Fastfat.SYS
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\SystemRoot\System32\ATMFD.DLL
\??\C:\WINDOWS\system32\drivers\mbam.sys
\SystemRoot\System32\Drivers\DRVNDDM.SYS
\SystemRoot\System32\DLA\DLADResN.SYS
\SystemRoot\System32\DLA\DLAIFS_M.SYS
\SystemRoot\System32\DLA\DLAOPIOM.SYS
\SystemRoot\System32\DLA\DLAPoolM.SYS
\SystemRoot\System32\DLA\DLABOIOM.SYS
\SystemRoot\System32\DLA\DLAUDFAM.SYS
\SystemRoot\System32\DLA\DLAUDF_M.SYS
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\System32\Drivers\SENTINEL.SYS
\??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS
\??\C:\WINDOWS\system32\drivers\hardlock.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\system32\drivers\N360\1402000.013\SRTSP.SYS
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\NuidFltr.sys
\SystemRoot\system32\DRIVERS\WDFLDR.SYS
\SystemRoot\system32\DRIVERS\Wdf01000.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\??\C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20121106.001\BHDrvx86.sys
\??\C:\Documents and Settings\All Users\Dati applicazioni\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20121114.001\IDSxpx86.sys
\SystemRoot\system32\drivers\kmixer.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR3
Upper Device Object: 0xffffffff8a1cf610
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\000000b7\
Lower Device Object: 0xffffffff8a388be0
Lower Device Driver Name: \Driver\USBSTOR\
Driver name found: USBSTOR
DriverEntry returned 0x0
Function returned 0x0
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff8af16ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-0\
Lower Device Object: 0xffffffff8af15030
Lower Device Driver Name: \Driver\iaStor\
Driver name found: iaStor
DriverEntry returned 0x0
Function returned 0x0
Downloaded database version: v2012.11.15.05
Downloaded database version: v2012.11.14.03
Initializing…
Done!
Scanning directory: C:\WINDOWS\system32\drivers…
<<<2>>>
Device number: 0, partition: 1
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff8af16ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8af968f8, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff8af16ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8af96b10, DeviceName: Unknown, DriverName: \Driver\hpdskflt\
DevicePointer: 0xffffffff8af32b50, DeviceName: \Device\000000a4\, DriverName: \Driver\ACPI\
DevicePointer: 0xffffffff8af15030, DeviceName: \Device\Ide\IAAStorageDevice-0\, DriverName: \Driver\iaStor\
———— End ———-
Upper DeviceData: 0xffffffffe7f11f48, 0xffffffff8af16ab8, 0xffffffff8941eab8
Lower DeviceData: 0xffffffffe3f63b18, 0xffffffff8af15030, 0xffffffff87f5bb60
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: F98DF98D
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 252020097
Partition file system is NTFS
Partition is bootable
Partition 1 type is Other (0xc)
Partition is NOT ACTIVE.
Partition starts at LBA: 252020223 Numsec = 16405137
Partition 2 type is Extended with LBA (0xf)
Partition is NOT ACTIVE.
Partition starts at LBA: 268425360 Numsec = 981832320
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 640135028736 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-62-1250243728-1250263728)…
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff8a1cf610, DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8a17abf0, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff8a1cf610, DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8a201ed0, DeviceName: Unknown, DriverName: \Driver\DRVMCDB\
DevicePointer: 0xffffffff8a388be0, DeviceName: \Device\000000b7\, DriverName: \Driver\USBSTOR\
———— End ———-
Done!
Performing system, memory and registry scan…
Read File: File "C:\WINDOWS\$NtUninstallKB2686509$\update.ver" is compressed (flags = 1)
Read File: File "C:\WINDOWS\$NtUninstallKB2686509$\updatebr.inf" is compressed (flags = 1)
Read File: File "C:\WINDOWS\$NtUninstallKB2695962$\update.ver" is compressed (flags = 1)
Read File: File "C:\WINDOWS\$NtUninstallKB2695962$\updatebr.inf" is compressed (flags = 1)
Done!
Scan finished
=======================================