This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

cannot remove Rootkit.TDSS.v3 from XP system [Solved]

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Cavan

Please navigate to and delete the following directory. Let us know if you have any issues performing this task:

C:\Documents and Settings\All Users\Application Data\529C535703E4E89B00006564D151FC4E


Next, Scan For Malware:

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



Next, Do An Online Scan For Viruses:

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
In your next reply please post the logs created by Malwarebytes and the ESET Online Scan.
Sunyata,

No problem with MBAM, no malicious items found , here's the log:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.29.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Emmet Smith :: EMMET [administrator]

1/29/2012 11:53:29 PM
mbam-log-2012-01-29 (23-53-29).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 186831
Time elapsed: 6 minute(s), 6 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

ESET log:

C:\Documents and Settings\Joanne\My Documents\SetupArcadeWeb.exe a variant of Win32/Adware.Gamevance.BE application
C:\Program Files\Uniblue\RegistryBooster\Launcher.exe a variant of Win32/RegistryBooster application
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application
C:\RECYCLER\S-1-5-21-329068152-1770027372-725345543-1003\Dc1\529C535703E4E89B00006564D151FC4E.exe Win32/Adware.SystemSecurity.AJ application
Hello Cavan

Let's run an OTL Fix

  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Files
    C:\Documents and Settings\Joanne\My Documents\SetupArcadeWeb.exe 
    C:\Program Files\Uniblue\RegistryBooster\Launcher.exe 
    C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe 
    
    :Commands
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Sunyata, Here is the OTL log: All processes killed ========== FILES ========== C:\Documents and Settings\Joanne\My Documents\SetupArcadeWeb.exe moved successfully. C:\Program Files\Uniblue\RegistryBooster\Launcher.exe moved successfully. C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Emmet Smith ->Temp folder emptied: 31637 bytes ->Temporary Internet Files folder emptied: 48946851 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 2604 bytes User: Joanne ->Temp folder emptied: 710 bytes ->Temporary Internet Files folder emptied: 29293290 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 1460 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 399738 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 50742 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 315712 bytes Total Files Cleaned = 75.00 mb [EMPTYFLASH] User: All Users User: Default User ->Flash cache emptied: 0 bytes User: Emmet Smith ->Flash cache emptied: 0 bytes User: Joanne ->Flash cache emptied: 0 bytes User: LocalService ->Flash cache emptied: 0 bytes User: NetworkService ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 01302012_133930 Files\Folders moved on Reboot… C:\Documents and Settings\Emmet Smith\Local Settings\Temporary Internet Files\Content.IE5\U3LM0D0C\iframe[2].htm moved successfully. C:\Documents and Settings\Emmet Smith\Local Settings\Temporary Internet Files\Content.IE5\JSB4JCGK\index[1].htm moved successfully. C:\Documents and Settings\Emmet Smith\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot…
Hello Cavan

Looking good :thumbup:

We need to clean up our tools now:

Please remove from your desktop…

  • All the logs we created
  • MBR.dat
  • aswMBR.exe
  • RogueKiller.exe
  • GetxPUD.exe
  • SystemLook.exe

Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]

The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Next, Please re-enable any security that was disabled.


Next,

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.
ESET online scan can be removed via add/remove programs.

Next, we have a few recommendations to help you stay malware-free:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Please download JavaRa and unzip it to its own folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista or Windows 7), pick the language of your choice and click "Select".
  • Then click "Remove Older Versions".
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista or Windows 7) again and select "Search For Updates".
  • Select "Update Using Sun Java's Website".
  • Then click "Search" and click on the "Open Webpage" button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.
Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.


WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE.

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer has always the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site
until there are no more critical updates.

Only run one Anti-Virus and Firewall program.

I would suggest you read:
PC Safety and Security–What Do I Need?
How to Prevent Malware


If there is nothing else, we will close this thread
Take care and safe computing
:wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI