System32 Rootkit.ttds Help Needed/Won't Delete

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gamedude07, Jul 6, 2010.

Thread Status:
Not open for further replies.
  1. gamedude07

    gamedude07 Private E-2

    Okay so, I've got a rootkit on my computer, here's the fairly long issue: It all started a few days ago (I think) when I was normally browsing but my PC started going very slowly, and the taskbar would freeze up constantly, and I would need to restart. Afterwards, I would randomly get a small pop up of Machine Debug Manager (MDM.exe) I knew something was wrong, and I browsed Google and thought maybe MDM.exe was infected. So I ran Malwarebyte's Anti-Malware, and it did indeed find 6 infections, 2 being registry keys. I removed them all and restarted, but now, Malwarebyte's detected the rootkit running on startup and asked me to quarantine. The location is C:\WINDOWS\SYSTEM32\KBIWKMIAOEKPEW.DLL and it's classified as a ROOTKIT.TDSS. Now, I searched around and downloaded many specific rootkit removers like one from Sophos, AVG, RootRepeal, TDSSKiller, and many more. Eset NOD 32 is my AV, and I also had it find 2 infections, but now it finds none, one was in C:\Recycler, so I used command prompt to delete that folder to force Windows to make a new one, and it helped. Once I restarted the computer but it stayed stuck on the XP booting screen, the blue bar continuely ran for over half an hour. I even ran GMER and while it ran I had a fatal system error with a blue screen making me restart the PC. Everytime I restart MBAM still detects KBIWKMIAOEKPEW.DLL and asks to quarantine, but it doesn't help. My PC has gotten considerably slower. Finally, I had an issue of Windows Installer randomly flickering, but I managed to remove that. Right now I am running SpywareDoctor, and I'll paste my HiJackThis log here just in case. I still haven't ran ComboFix, and even though I'm a fairly advanced user, I don't want to risk running it myself. I haven't ran any programs that just generated logs which I'm supposed to paste to you guys, this is the first time I'm doing it. Hopefully I can fix this.

    Hijackthis Log:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 10:29:42 AM, on 7/6/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal


    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.
     
    Last edited by a moderator: Jul 7, 2010
  2. gamedude07

    gamedude07 Private E-2

    CLOSE this thread, I am receiving assistance on another site, if it doesn't work there, maybe I can reopen this thread?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Thanks for letting us know.

    If in the future you need help, please do not post HijackThis logs, we don't need them or want them and they are not useful at all for rootkits, TDSS infections or similar. We have sticky/pinned threads with our required cleaning procedures. ;)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds