Windows Updates & Site Blocked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mr_pickles, Oct 3, 2010.

  1. mr_pickles

    mr_pickles Private E-2

    Hello all,

    I am having some troubles and hope someone can help me out.
    Several days ago my computer would start crashing because of a generic win32 process. I started to look into it and noticed svchost.exe using lots of memory. So I did a command (cmd): netstat -on
    Sure enough, svchost.exe was sending requests to all sorts of IPs.
    Windows Updates stopped working, I couldn't get to the Windows Update site either. Microsoft Security Essentials could no longer update as well.

    I decided to uninstall MSSE and try to reinstall it. It wouldn't reinstall and then I started getting a popup for consumernews24.com

    I am running Windows XP Pro SP3 (32-bit)

    I ran SuperAntiSpyware several times, at first it found tracking cookies and such, but now it finds nothing.
    I ran Malewarebytes, originally it had found 2 Trojans, but now it finds nothing.
    I ran ComboFix, and the only weird thing I saw was:
    called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A7c7c76]<<
    I tried to run RootRepeal, but it never finishes and just locks up my system. The only thing it reported was a hidden process "tmcomm" (which I believe is part of TrendMicro.
    I ran MGTools, ATF-Cleaner, CCleaner, GMER, HiJackThis, SmitfraudFix, TDSSKiller, RUBotted, Win32Diag, Kaspersky Virus Removal Tool, RootkitBuster, and DDS.
    GMER will do all scans except files, it locks up the computer.
    HiJackThis will run and then produces "An unexpected error has occurred at..."

    I installed a trial version of Kaspersky Anti-Virus 2011, it found nothing.
    My HOSTS file is clean and I've checked my LAN settings and no proxy is being used.
    I've uninstalled all Java and JRE just to be sure as well.

    I am at a loss here, any kind of help would be appreciated.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You indicated that you ran TDSSKiller, but you did not attach the log. I would like to see it as it looks like an MBR infection.
     
  3. mr_pickles

    mr_pickles Private E-2

    Thank you for the response!

    I ran TDSSKiller again, as in the past, I ran it in safe mode and got the same blank DOS screen that disappeared. I decided to go ahead and run it in normal mode and I actually saw a GUI this time.
    I scanned and it reported that it did in fact find:
    Code:
    Rootkit.Win32.TDSS.tdl4
    MBR
    Name: \HardDisk0\MBR
    My options were to: Skip, Quarantine, or Cure.
    I chose to Cure.

    The log is attached.
    I won't be able to truely verify if it is gone until tomorrow morning.
    But I do feel like I made some kind of progress as I've ran so many scans in Safe / Normal Mode, I can't remember which scans were in which mode.
    At least I saw something different this time.
    I can't thank you enough for the response as it prompted me to run it again in both modes.

    I will certainly provide a response as soon as I can tomorrow.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if you are still having malware issues. If so, we will need to double check the MBR.
     
  5. mr_pickles

    mr_pickles Private E-2

    I'm back in action! Everything is fine now after running TDSSKiller again.

    I can't thank you enough TimW, you saved me a ton of headaches.
    You sir, are a life saver! Thank you again!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. And you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds