
rootkit.tdss
#1
Posted 03 June 2010 - 12:22 PM
Register to Remove
#2
Posted 03 June 2010 - 01:08 PM
If you have already received help elsewhere please inform me so that this topic can be closed.
If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:
- Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
- Please make sure to carefully read any instruction that I give you.
Reading too lightly will cause you to miss important steps, which could have destructive effects. - If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
- These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
- Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
- If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
- Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
- I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together
Because of this, you must reply within three days failure to reply will result in the topic being closed! - Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 4 days) and you need an explanation. If that's the case, just send me a message to me on here.
- Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
- Download TDSSKiller and save it to your Desktop.
Extract the file and run it.
If TDSSKiller asks you to close all programs please allow it to do so.
Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)
If TDSSKiller asks to reboot your computer please allow it to do so.
Please post the content of that log TDSSKiller
NEXT:
Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
- Double click on ComboFix.exe & follow the prompts.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

- Click on Yes, to continue scanning for malware.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
NEXT:
Please make sure you include the following items in your next post:
1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that is produced after running TDSSKiller.
3. The log that is produced after running the ComboFix scan.
4. An update on how your computer is currently running.
Proud Graduate of the WTT Classroom
#3
Posted 04 June 2010 - 08:47 AM
#5
Posted 04 June 2010 - 05:36 PM

#6
Posted 04 June 2010 - 05:42 PM
#7
Posted 04 June 2010 - 06:15 PM
Download PragmaFix
Download Pragmafix by Noahdfear from here and save it in a place you can remember such as, your desktop.
- Click on Pragmafix.exe to run it
- It shall produce PragmaFix.log in the C:\ folder.
- Please post the results here.
Proud Graduate of the WTT Classroom
#8
Posted 04 June 2010 - 06:17 PM
#9
Posted 04 June 2010 - 06:22 PM
Proud Graduate of the WTT Classroom
#10
Posted 04 June 2010 - 08:20 PM
Register to Remove
#11
Posted 04 June 2010 - 08:22 PM
Please download ComboFix from: Here to your Desktop.
**Note:**In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
- During the download, rename Combofix to the name provided in the image below:
- It is important you rename Combofix during the download, but not after.
- Please do not rename Combofix to other names, but only to the one indicated.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
- Close any open browsers.
- Double click on the renamed version of ComboFix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the ComboFix log which can be found in the root drive (usually the C: Drive) for further review.
Proud Graduate of the WTT Classroom
#12
Posted 05 June 2010 - 05:30 AM
#14
Posted 05 June 2010 - 12:41 PM

#15
Posted 05 June 2010 - 12:46 PM
It's suppose to be renamed differently each time.I want to ask you one curious question, Whenever i opened this forum and see your last posting the rename of the combofix is appeared to be different, why is that?
Which name i should use finally
You should use whatever name it gives you at the time of download.
Proud Graduate of the WTT Classroom
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users