ThanatosOfOne
Member
- Reaction score
- 2
- Location
- Near Charlotte, NC
I have had 6 machines brought in since Friday that will not boot, only give a flashing cursor in the top left corner. It acts for the world like an MBR issue. All the standard MBR fixes (startup repair, bootrec, bootsect, EasyBCD, MS DaRT, etc) do absolutely nothing. Bootrec /ScanOS actually cannot find an installed copy of windows.
It appears to be a variant of the TDSS/Alureon rootkit/bootkit.
The only "fix" that I have found is to ghost the drive to an image, load it up on another drive, run the startup repair, then ghost back to the old drive. This works, but seems like a ton of extra time to deal with this.
I can only guess that maybe there is still more code hidden in the MBR that points it to maybe some super secret hidden partition and then back to the MBR. There has got to be an easier way to fix this BS, and I hope that one of you guys could maybe point me to a quick fix.
It appears to be a variant of the TDSS/Alureon rootkit/bootkit.
The only "fix" that I have found is to ghost the drive to an image, load it up on another drive, run the startup repair, then ghost back to the old drive. This works, but seems like a ton of extra time to deal with this.
I can only guess that maybe there is still more code hidden in the MBR that points it to maybe some super secret hidden partition and then back to the MBR. There has got to be an easier way to fix this BS, and I hope that one of you guys could maybe point me to a quick fix.