rootkit.boot.pihar.c On toshiba satellite

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ficklefinn, Aug 5, 2012.

  1. ficklefinn

    ficklefinn Private E-2

    My daughters laptop is infected, but I can't even boot to run tdsskiller!
    Thanks for the help.
    Mike

    Here is the log:
     

    Attached Files:

    Last edited by a moderator: Aug 5, 2012
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.


    ------------------------------

    Now run these procedures please.
    READ & RUN ME FIRST. Malware Removal Guide

    Next...re run FRST - no fix - just a scan and attach the log as well as the other logs I need to see.
     

    Attached Files:

  3. ficklefinn

    ficklefinn Private E-2

    Should I run tdsskiller at this time?
     
  4. ficklefinn

    ficklefinn Private E-2

    Here are the 4 logs.
     

    Attached Files:

  5. ficklefinn

    ficklefinn Private E-2

    Sorry, forgot to say thanks! The Laptop is up and seems to be working.
    Waiting on your next direction.
    Mike
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good afternoon. :)

    I had said:

     
  7. ficklefinn

    ficklefinn Private E-2

    I did sent the logs, please see my post at 16:36 yesterday.
    Thanks,
    Mike
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Mike, you attached a log from the fix! I would like to see a FRESH log from you running FRST with NO FIX just a scan please, as requested :) Thanks.
     
  9. ficklefinn

    ficklefinn Private E-2

    Sorry, I sent the laptop back to my daughter, is it too late to run FRST?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Up to you, would your daughter like to run it?
     
  11. ficklefinn

    ficklefinn Private E-2

    Hi again, I went to my daughters last nite and ran the file, here it is.
    Mike
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It looks to be ok but cannot make a correct judgement until you run the tool correctly.
     
  13. ficklefinn

    ficklefinn Private E-2

    I did not run it from a recovery environment.

    I booted the system normally, copied the FRST file to the desktop, ran the file from the desktop and after it completed and put the log file on the desktop exited the program.

    I copied the log file to the flash drive and sent it to you this morning.

    Why would it think I am running it from a recovery environment?

    Thanks,
    Mike
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You managed to do it the first time, in the very first post with the FRST log.

    For reference, here are the instructions
     
  15. ficklefinn

    ficklefinn Private E-2

    I followed instructions, after I selected the "Repair your computer" screen it said it was loading, then gave me a F3-F100-0010 error and said to shutdown the computer.

    If I let it boot normally it seems to book into W7 OK.

    Thanks,
    Mike
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you saying we are all done Mike? Ready for final steps?
     
  17. ficklefinn

    ficklefinn Private E-2

    Yes we are!

    What did the error messge mean?

    Thanks,
    Mike
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not satisfied that all traces of malware have gone. :(

    Run this:

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  19. ficklefinn

    ficklefinn Private E-2

    Here are the 2 files.
    Mike
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run TDSSKiller and have it fix this that you previously skipped:

    Re run again, and attach the new log.

    That was a malware remnant!

    Now try and run FRST again in the correct way, and attach the log if successful.
     
  21. ficklefinn

    ficklefinn Private E-2

    Ran Tdsskiller, deleted the item and reran, here is the log.

    Tried to go into repair and got the same error message F3-F100-0010.

    Thanks,
    Mike
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am thinking it would be best now if I referred you onto the software forum. Let's just do this.

    Run this and attach the results.

    Using ESET's Online Scanner
     
  23. ficklefinn

    ficklefinn Private E-2

    Here ya go!

    Mike
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can follow the final steps below and post about remaining issues in software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  25. ficklefinn

    ficklefinn Private E-2

    Thank you!

    I went thru the checklist and completed all items.

    When I attempted to boot and go to repair computer I still get the error: F3-F100-0010.

    I booted using a windows 7 disk and was able to enter the repair mode. I selected repair computer, the repair ran @15 minutes and finally gave up and said it could not repair the computer!

    The error message says: Unspecified changes to system configuration might have caused the problem.

    Repair Action: System files integrity check and repair
    Result: Failed. Error code = 0x490
    Time Taken 987829 ms

    Thanks for any help,
    Mike
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry Mike, you'll be better off in software asking about that. :)
     
  27. ficklefinn

    ficklefinn Private E-2

    Thanks for the help, I will do that.
    Mike
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome, safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds