Endpoint Protection

 View Only
  • 1.  Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 10:50 AM

    I have an issue here where I run a Power Eraser Scan on a System which has Windows Bitlocker. Now as design the Power eraser needed a reboot, so after a reboot I get a screen where the user is required to enter the Bitlocker recovery key, this seem to be obvious as the power eraser injects his Driver in the Kernel mode. 

    Now my question is how to get remove the Kernel intervention/ Injection as whenever I reboot the system I have to enter a Bitlocker Passkey. 

     

    Thanks, 

    Farhan K

     

     



  • 2.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 10:57 AM

    The root kit scan is going to do this so it seems to be pretty standard stuff here. Have you tried in safemode?



  • 3.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:00 AM

    Yes tried in safe and it works, Sorry I mean, I now dont intent to run a Root Kit scan. Just need to get rid of whatever driver is getting injected so that everytime my computer starts it starts normally. 



  • 4.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:02 AM

    Don't select the rootkit scan, does that work?

    If not, there is no option that I know of. Open a support case.



  • 5.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:08 AM

    Here's the complete scenario: 

    1) Selected Root Kit Scan - Started the computer and it asked for a Bitlocker passkey >> Entered and logged in and did not continue the Scan. 

    2) Now whenever I start my computer >> It asks for a Bitlocker Password 

    3) Need to remove that driver which is injected in Windows Kernel and not allowing Winload..exe to proceed with a Normal boot. 

     

    Thanks, 



  • 6.  RE: Symdaig Root Kit Scan/ Power Eraser
    Best Answer

    Posted Feb 27, 2017 11:11 AM

    Gotcha. Manual removal steps are here:

    http://www.symantec.com/docs/TECH201909



  • 7.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:12 AM

    You want to disable Bitlocker Password? 



  • 8.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:24 AM

    No Actually need to remove the Power Eraser Drivers Manually. The one which Bryan just mantioned. 

    Thanks 



  • 9.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:25 AM

    Thanks everyone for your help 



  • 10.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:25 AM

    Thanks, this is the one I was looking for :) 



  • 11.  RE: Symdaig Root Kit Scan/ Power Eraser

    Posted Feb 27, 2017 11:26 AM

    You're welcome.