Hi guys, sorry for my bad English and sorry if I can't post any log file because the infected notebook is not mine and so not present (at the moment).
I nearly completely cleaned this notebook but I can't get rid of a TDL3 rootkit; several antivirus now (even professional one such as NOD32 Smart Security, Hitman Pro, Spybot, DrWeb, Prevx 3.0 ) consider the notebook cleaned but is not for other tools such as some TDSS Remover, like TDSSKiller from Kaspersky that says me exactly this (I quote):
But can't remove the infection neither after reboot.
I even tried to replace atapi.sys from Windows XP CD, with the windows repair console, but infection is still present :( any hint?
Thanks
edit, OS Windows XP Service Pack 2
I nearly completely cleaned this notebook but I can't get rid of a TDL3 rootkit; several antivirus now (even professional one such as NOD32 Smart Security, Hitman Pro, Spybot, DrWeb, Prevx 3.0 ) consider the notebook cleaned but is not for other tools such as some TDSS Remover, like TDSSKiller from Kaspersky that says me exactly this (I quote):
TDSS rootkit removing tool, Kaspersky Lab, 2010
version 2.2.8.1 Mar 22 2010 10:43:04
Scanning Services ...
Scanning Kernel memory ...
Driver "atapi" infected by TDSS rootkit!
File "C:\WINDOWS\system32\drivers\atapi.sys" infected by TDSS rootkit ... will b
e cured on next reboot
Completed
Results:
Memory objects infected / cured / cured on reboot: 1 / 0 / 0
Registry objects infected / cured / cured on reboot: 0 / 0 / 0
File objects infected / cured / cured on reboot: 1 / 0 / 1
To finalize removal of infection and avoid loosing of data program will
reboot your PC now.
Close all programs and choose Y to restart or N to continue
But can't remove the infection neither after reboot.
I even tried to replace atapi.sys from Windows XP CD, with the windows repair console, but infection is still present :( any hint?
Thanks
edit, OS Windows XP Service Pack 2