Web redirects, TDSS Killer Stops at 80%

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bobbyt49, Apr 28, 2011.

  1. bobbyt49

    bobbyt49 Private E-2

    In past 2-3 days, started seeing slowed overall performance and odd behavior on Firefox - opening new tabs, redirecting when trying to get to MS windows update site.

    Also noticed that svchost process was running over 90% CPU consistently. Too help with that I disabled Windows automatic updates.

    Initially ran Malwarebytes Anti-Malware and TDSSKiller to solve problem. TDSSKiller initializes up to 80% and crashes.

    I have since followed all of the forum instructions for Malware removal, but am still seeing the problems - TDSSKiller still not running and tabs on browser opening at times on their own. Also can't get to update.microsoft.com from browser - returns a problem loading page message.

    Other note, McAfee had been detecting a Trojan called Artemis, but not removing it.

    Attached are first 4 of 5 logs. I will attach the 5th in next message.

    Thanks for your help
    Bob
     

    Attached Files:

  2. bobbyt49

    bobbyt49 Private E-2

    5th attachment
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have a new form of Master Boot Record infection. You will need your Windows XP CD to fix this.

    Boot your Windows XP CD into the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbrcommand then boot back to normal mode Windows and try running the below and attach the log. Also explain if you are still having any malware problems.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. bobbyt49

    bobbyt49 Private E-2

    - Rebooted from CD.
    - Typed R to get into Recovery Console
    - Typed 1 to get to C: \Windows
    - Typed fixmbr

    System responds with following message:

    ** CAUTION **

    This computer appears to have a non-standard or invalid master boot record. FIXMBR may damage your partition tables if you proceed. This could cause all the partitions on the current hard disk to become inaccessible. If you are not having problems accessing your drive do not continue. Are you sure you want to write a new MBR?

    Questions - is this expected? Should I proceed?

    Thanks, Bob
     
  5. bobbyt49

    bobbyt49 Private E-2

    Success! :)

    I made sure everything was completely backed up on C: drive and finally bit the bullet with fixmbr. It ran fine - very quickly. I then was able to run TDSSKiller which did not report any errors.

    I followed the steps for Toggle System Restore and am hopefully on my way.

    Thanks for the help.
    Bob
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent news. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds