IndiGenus wrote:djpnuemo wrote:FYI
ran dr.web cureit (downloaded today) and scanned the infected test system (used sample from http://www.kernelmode.info/forum/viewto ... p=779#p779). it found the pciide.sys infection (cured it about 12 times) and prompted for reboot. upon rebooted, infection is gone (confirmed with RkU and GMER).
Did you run Cureit from within the running system, or with the Live CD?
within running system, not using any CD.
i've infected it again and am running it a second time atm and will update this post with results.
Boooooo wrote:confirmed even by TDSSKiller utility by Kaspersky?
yes.