Inactive System Check virus, a lot of problems

bootrec /fixboot still didnt work, only the fixmbr worked


Bootkit Remover
(c) 2009 Esage Lab
www.esagelab.com

Program version: 1.2.0.1
OS Version: Microsoft Windows 7 Ultimate Edition Service Pack 1 (build 7601), 32
-bit

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`06500000

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Controlled by rootkit!

Boot code on some of your physical disks is hidden by a rootkit.
To disinfect the master boot sector, use the following command:
remover.exe fix <device_name>
To inspect the boot code manually, dump the master boot sector:
remover.exe dump <device_name> [output_file]


Done;
Press any key to quit...
 
ListParts by Farbar
Ran by Simon on 10-02-2012 at 17:57:33
Windows 7 (X86)
Running From: C:\Users\Simon\Desktop
Language: 0409
************************************************************

========================= Memory info ======================

Percentage of memory in use: 30%
Total physical RAM: 3327.18 MB
Available physical RAM: 2321.02 MB
Total Pagefile: 6652.64 MB
Available Pagefile: 5451.73 MB
Total Virtual: 2047.88 MB
Available Virtual: 1963.08 MB

======================= Partitions =========================

1 Drive c: (System) (Fixed) (Total:78.03 GB) (Free:31.39 GB) NTFS
2 Drive d: (Backup) (Fixed) (Total:387.63 GB) (Free:148.05 GB) NTFS
3 Drive e: (Reparationsskiva för Windows 7, ) (CDROM) (Total:0.14 GB) (Free:0 GB) UDF

Disk nr Status Storlek Ledigt Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk nr 0 Online 465 G B 0 B

DiskPart avslutas...

Partitions of Disk Disk nr 0 Online 465 G B 0 B :
===============

Argumenten som angetts f”r kommandot „r inte giltiga.
Om du vill ha mer information om kommandot skriver du: HELP SELECT DISK

Ingen disk har valts.


****** End Of Log ******
 
Create new restore point.

Download the FixTDSS.exe

Save the file to your Windows desktop.
Close all running programs.
If you are running Windows XP, turn off System Restore. How to turn off or turn on Windows XP System Restore
Double-click the FixTDSS.exe file to start the removal tool.
Click Start to begin the process, and then allow the tool to run.
OK any security prompts.
Restart the computer when prompted by the tool.
After the computer has started, the tool will inform you of the state of infection (make sure to let me know what it said)
If you are running Windows XP, re-enable System Restore.
 
ok, it restarted, got bluescreen AGAIN when it was gonna startup, used the cd and fixmbr worked but fixboot says : The volume does not contain a recognized file system. please make sure that all required file system drivers are loaded and that volume is not corrupted.

Once again i had to use " start with last knowing config that worked" to get the computer running
 
Boot back to System Recovery Options.

At the command prompt type:
DISKPART
Press Enter.

Type:
LIST DISK
Press Enter.

Let me know what EXACTLY you see on your screen after entering the above command.
Stay there as more questions will follow.
 
Disk ### Status Size Free Dyn Gpt
------------ ------- ------ ------ ------ -----
Disk 0 online 465 GB 0B
 
Type:
SELECT DISK 0 (<-----that's "zero", not capital "o")
Press Enter.

Type:
LIST DISK
Press Enter.

Do you see a "*" now?
 
Very well.

Type:
LIST PARTITION
Press Enter.

Let me know what exactly is listed and if you see any "*" there.
 
there is no " * " there.

Partition ### Type Size Offset
---------------- ----- ------ ---------
Partition 1 primary 100 mb 1024 kb
Partition 2 primary 78 GB 101 mb
Partition 3 primary 378 GB 78 GB
partition 4 primary 2064 kb 465 GB
 
OK, we're getting somewhere.
It looks like you have a fake partition created by TDL rootkit.

Type:
EXIT
Press Enter.

Restart normally and re-run ListParts by Farbar
 
ListParts by Farbar
Ran by Simon on 10-02-2012 at 21:30:32
Windows 7 (X86)
Running From: C:\Users\Simon\Desktop
Language: 0409
************************************************************

========================= Memory info ======================

Percentage of memory in use: 27%
Total physical RAM: 3327.18 MB
Available physical RAM: 2424.45 MB
Total Pagefile: 6652.64 MB
Available Pagefile: 5623.79 MB
Total Virtual: 2047.88 MB
Available Virtual: 1963.08 MB

======================= Partitions =========================

1 Drive c: (System) (Fixed) (Total:78.03 GB) (Free:31.13 GB) NTFS
2 Drive d: (Backup) (Fixed) (Total:387.63 GB) (Free:148.05 GB) NTFS
3 Drive e: (Reparationsskiva för Windows 7, ) (CDROM) (Total:0.14 GB) (Free:0 GB) UDF

Disk nr Status Storlek Ledigt Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk nr 0 Online 465 G B 0 B

DiskPart avslutas...

Partitions of Disk Disk nr 0 Online 465 G B 0 B :
===============

Argumenten som angetts f”r kommandot „r inte giltiga.
Om du vill ha mer information om kommandot skriver du: HELP SELECT DISK

Ingen disk har valts.


****** End Of Log ******
 
OK, we have to proceed carefully here.

Boot back to System Recovery Options.

At the command prompt type:
DISKPART
Press Enter.

Type:
LIST DISK
Press Enter.

Let me know if "Disk 0" still has a "*" next to it.
If no let me know.

If yes type:
LIST PARTITION
Press Enter.

Post what is listed there.
 
Type:
SELECT DISK 0
Press Enter.

Type:
LIST DISK
Press Enter.
Do we have a "*" next to "Disk 0" now?

If so type:
LIST PARTITION
Press Enter.

Post what is listed there.
 
same as before:

Partition ### Type Size Offset
---------------- ----- ------ ---------
Partition 1 primary 100 mb 1024 kb
Partition 2 primary 78 GB 101 mb
Partition 3 primary 378 GB 78 GB
partition 4 primary 2064 kb 465 GB
 
OK.

Type:
SELECT PARTITION 2
Press Enter.

Type:
LIST PARTITION
Press Enter.

Do we have a "*" next to "Partition 2"?
 
Good.
We're almost ready to get rid of that SOB.

Restart normally, post new ListParts by Farbar log.
 
Back