Hi, I'm new here.
My i7 laptop is running Win7 Home Premium 64 bit and I have just managed to remove several instances of the TDSS rootkit (I hope!).
However, the rootkit has somehow disabled the windows security center service and with it, microsoft security essentials.
I have looked for problems in the registry and cannot find anything, including the psuedo graphics entry which is mentioned elsewhere on the web.
I have also tried to make windows security center automatic and start in the services manager, but after a few seconds it stops and gets set back to disabled. I have checked it's dependencies and they all seem to be running ok.
I have also searched the net, but cannot find a fix to this particular problem.
I have run several malwarebytes scans in safe mode, but it finds nothing. Trend Micro |Housecall fails to find anything too.
I have run a Sophos rootkit scan before the rootkit was eliminated, but now when I try to run it it tells me that windows needs to restart to enable sophos to remove some files. The problem is, the machine has been restarted several times and still sophos is saying the same thing, it appears to be stuck in mid-removal. Also, the scan running processes checkbox is greyed out - i think this is related to the earlier rootkit infection.
I have run GMER, but it finds nothing at all - I find this very odd, I have never had GMER return a completely blank screen to me before|! Also, in GMER, most of the checkboxes are greyed out, such as sections and services and IAT.
Kaspersky TDSSkiller was completely useless and achieved nothing.
The rootkit had damaged the MBR and I could not boot into windows or any of the safemodes - I just got a bsod just after the MS splash screen which was saying that iastor.sys was damaged. Luckily, I run a dual boot system and Linux was ok, which meant I could get on the net and research the problem.
I think the problems I now have are just fallout from the rootkit infection, I'm pretty sure I have killed the rootkit itself.
Does anyone know how I might get the security service up and running again?
Finally, getting rid of the rootkit was pretty involved and it was something I worked out for myself - I have not seen any consistant method to remove the rootkit on the net - most people seem to go for a re-format after days of trying. Would it be useful for me to post my symptoms and removal method here in the hope of helping others?
Thanks guys, in advance