This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Used TDSSKiller and my internet won't work now [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last week it started with the XP antivirus 2012 virus and I easily took that out, but I still had Malware on my computer. To make a long story short, I got rid of most of it, but I still had the Google Redirect virus on my computer. Malwarebytes, MSN Spysweeper, and TrojanRemover all couldn't find it on my computer so I used TDSSKiller to fix the problem. I can't be sure if its fixed because now the internet won't work on my computer. I can use my laptop so I know the issues stem from my desktop computer. I can't copy the exact TDSSKiller log, but here is what I can copy. I have an XP if it helps. NetBT (534795b713eb1b302abcdef92b478f4) C:\WINDOWS\system32\Drivers\netbt.sys Suspicious file (Forged): C:\WINDOWS\system32\Drivers\netbt.sys. Real md5: 534795b713eb1b302abcdef92b478f4, Fake md5: 8bb6a19d66525ec5183ele57455c95ab NetBT ( Rootkit.win32.ZAccess.aml ) - Infected NetBT- detected Rootkit.win32.ZAccess.aml ) (0) \MBR (0x1B8) (1f753b394439269a3484aecd505b79bd) \Device\Harddisk0\DR0 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.B ) - infected \Device\Harddisk0\DR0 - detected rootkit.Boot.Pihar.b (0) Detected object count: 2 Actual detected object count: 2 Backup copy found, using it.. C:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured on reboot NetBT ( Rootkit.win32.zaccess.aml ) - user select action: Cure \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - Will be cured on reboot \Device\Harddisk0\Dr0 - ok \Device\Harddisk0\Dr0 ( Rootkit.Boot.Pihar.b ) - user select action: Cure Deinitialize success
Hi

Please run the following: (download to your woking computer and transfer over via USB)

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
I don't have the exact log because I can't copy it to the cd, but here it is. Internet Services: Dhcp service is not running. Checking service configuration: the start type of Dhcp service is ok the imagepath of Dhcp service is ok The servicedll of Dhcp service is ok Netbt service is not running. Checking service configuarion: The start type of Netbt service is ok The imagepath of netbt: "system32\drivers\tskED.tmp". Connection Status: Localhost is accessible There is no connection to network. Attempt to access Google IP returned error: Google IP is unreachable Attempt to access Yahoo IP returned error: Yahoo IP is unreachable File Check: [All of them said they were ok. Here is what was listed: Dhcpcsv.dll afd.sys netbt.sys tchpip.sys ipsec.sys dnsrslvr.dll svchost.exe rpcss.dll services.exe All of the above said => MD5 is legit
Hi

Please do the following

re-run Farbar service scanner

in the search box type the following

netbt.sys

Now click the "search files" button

a log called FSS.txt will be produced in Notepad > go to "File" > "save as" and rename it to FSS1.txt > save it to your desktop

Now go back to Farbar service Scanner

again type netbt.sys into the search box, but this time click the "export service" button

another log will be produced "FSS.txt"

please post the contents of both logs in your next reply

thanks
Thanks for the help, but I have fixed this issue. Someone helped me out by telling me to copy certain code and merge it into the registry. That fixed my issue.

Someone helped me out by telling me to copy certain code and merge it into the registry.

Who? Someone you know or someone from the forum?

I'm glad this worked out for you, but usually registry fixes are machine specific.

Someone helped me out by telling me to copy certain code and merge it into the registry.

Who? Someone you know or someone from the forum?

I'm glad this worked out for you, but usually registry fixes are machine specific.


No. It was on another forum. My internet is fixed now, but the google redirect/zeroaccess virus is still infecting my computer. I'm not sure how I can fully 100% get rid of it. Is there a free program that fully rids of it?
Yes,

Please run the following diagnostic scans and I'll see if I can see what the issue is

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Hi,

Please do the following:

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.

In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes

In FireFox
  • Click on Advanced -> Network -> Settings…
  • the No Proxy option should be selected


NEXT


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Hi,

Please do the following:

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.

In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes

In FireFox
  • Click on Advanced -> Network -> Settings…
  • the No Proxy option should be selected


NEXT


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


I did the first three steps and ran TDSSkiller and this time it did cure the zeroaccess rootkit, though I didn't run combofix yet. So far it doesn't seem like the google redirect is gone. The searches aren't redirecting for now. Plus my MSN Spysweeper in the past few days only created a pop up about ip addresses related to spyware while I was browsing the net. I haven't seen that yet.

If I get the problem again in the next few days, I'll post again and post a combofix log.

Here is the TDSSKiller log for you look at
The absence of symptoms does not mean the machine is clean, plus there are important clean up routines to perform when cleaning up our tools, please stay with me till I give you the "all clean" Please follow the remaining instructions and post the logs thanks
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=121674&pid=765441&st=0&

Collect::
c:\windows\system32\drivers\vaacy.sys

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18001:TCP"=-
"5050:UDP"=-
"5060:TCP"=-
"18002:TCP"=-
"18003:TCP"=-

DDS::
uInternet Settings,ProxyServer = 219.139.132.59:80
uInternet Settings,ProxyOverride = *.local

FireFox::
FF - ProfilePath - c:\documents and settings\Nashih\Application Data\Mozilla\Firefox\Profiles\unz3zo6e.default\
FF - prefs.js: network.proxy.http - 187.111.192.2
FF - prefs.js: network.proxy.http_port - 8080

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI