Computing.Net > Forums > Security and Virus > rootkit tdss

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

rootkit tdss

Reply to Message Icon

Name: abck
Date: September 1, 2009 at 20:12:28 Pacific
OS: Windows XP
Subcategory: Viruses
Comment:

I appear to have a rootkit.tdss on my XP. I have run malwarebytes...it detects and removes the problem, but on restart it is still there. Kapersky: same thing, or no detection at all. Please help me remove this thing!



Sponsored Link
Ads by Google

Response Number 1
Name: paulsep
Date: September 1, 2009 at 21:32:55 Pacific
Reply:

Make sure, that there is no internet connection possible, while you use that tools to remove the rootkit. Otherwise, it still downloads itself again and you are still at the beginning.
Best is to start windows in safe mode, with no internet connection and then run e.g. malwarebytes.

Please send a reply, if you solved the problem !!!


0

Response Number 2
Name: abck
Date: September 2, 2009 at 07:28:12 Pacific
Reply:

still the same result. Evidently malwarebytes is not removing it and kapersky does not recognize that it is there?

same results with hijack this. trying another download this AM.

will uninstalling everything and reinstalling all software help? I have backup--will start over if need be.


0

Response Number 3
Name: Jack Frost46
Date: September 2, 2009 at 08:24:24 Pacific
Reply:

What does Malwarebyte's Antimalware report ?
There are a few anti root kit solutions , So help us out here , perhaps you could post the MBAM log .

PS. uninstalling software programs will not help , the root kit is in the operating system .


0

Response Number 4
Name: abck
Date: September 2, 2009 at 11:28:12 Pacific
Reply:

malwarebytes log is:
Malwarebytes' Anti-Malware 1.40
Database version: 2723
Windows 5.1.2600 Service Pack 3

9/2/2009 2:26:23 PM
mbam-log-2009-09-02 (14-26-23).txt

Scan type: Quick Scan
Objects scanned: 95511
Time elapsed: 4 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kbiwkmloyxvklr (Rootkit.TDSS) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


0

Response Number 5
Name: Jack Frost46
Date: September 2, 2009 at 13:14:51 Pacific
Reply:

This link below shows how to use Rootrepeal ,

http://www.malwarebytes.org/forums/...

Rootrepeal you get from this link ,

http://rootrepeal.googlepages.com/

Remember we are looking for kbiwkmloyxvklr

You could try Sophos Anti rootkit free
http://www.sophos.com/products/free...

Or the fully functional evaluation copy of Unhackme

http://greatis.com/unhackme/downloa...

PS. If you have Spybot s&d close teatimer .
..........



0

Related Posts

See More



Response Number 6
Name: abck
Date: September 2, 2009 at 13:23:20 Pacific
Reply:

had to uninstall spybot in order to install kaspersky, so no problem there. thanks for the info--will run some of that and get back in a bit...
thx.


0

Response Number 7
Name: Blasty711
Date: September 3, 2009 at 09:23:01 Pacific
Reply:

I also had Rootkit.TDSS, something about SKYNET. Malwarebytes detected it but could not remove it. I tried Spyware Doctor and it did the trick. No more problems.


0

Response Number 8
Name: abck
Date: September 3, 2009 at 12:45:51 Pacific
Reply:

I seem to be clear now--did spyware doctor earlier and nothing showing on scan. I will keep these suggestions if I need in the future. Thank you all for your help!
CK


0

Response Number 9
Name: Jack Frost46
Date: September 3, 2009 at 13:55:53 Pacific
Reply:

Thanks for getting back to us as you feedback will help others


0

Sponsored Link
Ads by Google
Reply to Message Icon





Use following form to reply to current message:

Login or Register to Reply
LoginRegister


Sponsored links

Ads by Google


Results for: rootkit tdss

Rootkit.TDSS - Google redirects www.computing.net/answers/security/rootkittdss-google-redirects/27182.html

infected with WIN32Rootkit.TDSS? www.computing.net/answers/security/infected-with-win32rootkittdss/25114.html

IE hijacked! www.computing.net/answers/security/ie-hijacked/24810.html