Possible TDL3 Rootkit
Started by
fleggy1
, May 29 2011 05:29 AM
#16
Posted 29 May 2011 - 03:05 PM
#17
Posted 29 May 2011 - 03:09 PM
after 3 anda half hours am done lol
Attached Files
#18
Posted 29 May 2011 - 03:44 PM
Yep. I'm always here.hello are you still there?
How is your computer running now? Any problems?
Do this:
- Re-run AVPTool
- Select the Manual Disinfection tab
- Where it states Step 3 paste in the following disinfection script and press execute
begin SetAVZPMStatus(True); SearchRootkit(true, true); SetAVZGuardStatus(True); DeleteFile('C:\WINDOWS\Downloaded Program Files\Launcher.dll'); BC_DeleteFile('C:\WINDOWS\Downloaded Program Files\Launcher.dll'); BC_ImportDeletedList; ExecuteSysClean; BC_Activate; RebootWindows(true); end.
- Your system will reboot on completion, if it does not please do so yourself
- On completion please run another analysis scan and attach the zip file
#19
Posted 29 May 2011 - 03:54 PM
no problems as of yet and when u say re run the scan you mean on the manual disinfection tab right?
#20
Posted 29 May 2011 - 03:58 PM
Yep. And copy and paste that script inside code block. Then click on Execute button.
#21
Posted 29 May 2011 - 03:59 PM
ive done the script bit just doing another gather info thing that is right?
#22
Posted 29 May 2011 - 04:04 PM
Yes. And attach this file: C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip in your next reply please.
#23
Posted 29 May 2011 - 04:05 PM
there we go
Attached Files
#24
Posted 29 May 2011 - 04:20 PM
is everything good to go or os there more?
#25
Posted 29 May 2011 - 04:30 PM
Hi,
Well... It looks good except your master boot record is somehow weird. I would like you to temporally un-install Daemon Tools and then run aswMBR scan once again:
Well... It looks good except your master boot record is somehow weird. I would like you to temporally un-install Daemon Tools and then run aswMBR scan once again:
- Double click the aswMBR.exe to run it.
- Click the Scan button to start scan.
- On completion of the scan click Save log, save it to your desktop and post in your next reply.
#26
Posted 29 May 2011 - 04:32 PM
erm i dont have deamon tools...
#27
Posted 29 May 2011 - 04:36 PM
oh it could be wiered because i used custom boot screen loader thingd instead of the standard XP home one
#28
Posted 29 May 2011 - 04:38 PM
OK. Then is orphaned driver. Please follow the steps below:
Step 1
We need to run an OTL Fix
Step 2
Step 1
We need to run an OTL Fix
- Please rigt click on on your desktop and click on Run as administrator.
- Copy (select all lines inside quote box and press CTRL+C) and Paste (press CTRL+V) the following code into the textbox.
:OTL DRV - [2009/06/08 15:11:38 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd) :Files ipconfig /flushdns /c :Reg :Commands [emptytemp] [emptyflash] [createrestorepoint] [reboot]
- Click on button.
- OTL may ask to reboot the machine. Please do so if asked.
- Click on button.
- A report will open. Copy and Paste that report in your next reply.
- If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Step 2
- Double click the aswMBR.exe to run it.
- Click the Scan button to start scan.
- On completion of the scan click Save log, save it to your desktop and post in your next reply.
#29
Posted 29 May 2011 - 04:43 PM
Ups. That explains it. Anyway please proceed with steps above.oh it could be wiered because i used custom boot screen loader thingd instead of the standard XP home one
#30
Posted 29 May 2011 - 04:52 PM
done
Attached Files
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users