Had TDSS, still Chrome problems READ&RUN ME DONE

Discussion in 'Malware Help (A Specialist Will Reply)' started by ologgio, Jul 23, 2010.

  1. ologgio

    ologgio Private E-2

    Hi,

    I had TDSS and ran everything in the READ & RUN ME guide. Everything ran, except ComboFix which hangs. I believe I also had the Google reirect, but Spyware Blaster seems to have stopped it (but may still be lurking somewhere). The main problem that I still see after running everything in the READ and RUN ME is that Google Chrome hangs in the beginning. I have uninstalled and reinstalled it deleting the whole Chrome folder and it still hangs. The other browsers seem to work fine, but this chrome behavior only started after I got infected. I attach all the log files, except combofix because it hanged. My computer still has UAC off until I get a reply from you. Thanks for your help!

    In the Holy Eucharist.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this whilst I review the logs that you have already provided.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now I want you to reboot into safemode and attempt to run combofix again, ensuring that before you do so, it is directly on the desktop as requested.

    Attach the log if you are successful and also include the log from TDSSKiller.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If this is your only remaining problem then I think you would be better off hitting up the software forum for advice on this matter. :)

    I shall still await to see your combofix log and the log from TDSSKiller just to cover all angles but I am not seeing much to do given the information in the logs you have supplied:

    Why are you not using any anti virus???

    Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).
    Please go to Add/Remove programs and uninstall the following software:
    • Java(TM) 6 Update 16

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6
     
  4. ologgio

    ologgio Private E-2

    Not really, as you can see in the TDSSKiller log, TDSS was still present in the volume manager driver. Thanks so much for pointing to TDSS Killer, it found it and things seems to be clean now.

    ComboFix still hangs even in safe mode.

    I uninstalled AVG because combofix kept saying it was still running (even when it was disabled).

    I deleted them all from Linux (I have dual boot)

    I also updated Java as you mentioned.

    This TDSS is very hard to kill. I did all the steps in the RUN ME and before that I had run myriads of antyspyware. Even you thought it was gone when I sent you the logs, but it was still there. Only TDSSKiller found it and ClamAV run from Linux.
    TDSSKiller finally killed it and Chrome worked fine immediately after the reboot without even reinstalling it.

    I attach the TDSSKiller log, but as I said, combofix still hangs, but I believe the machine is clean now. I will run ClamAV from linux and let you know if it finds anything (ClamAV was the only one besides TDSSKiller that found the volume manager infected).

    Thank you so much! And I hope my experience may help someone else. My homepage in Chrome was the google search page, so if you see anybody for whom firefox and IE works, but chrome simply hangs (it seems to be really secure and does not allow the redirect) then you have reason to suspect TDSS.

    In the Holy Eucharist.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's great! Then if all is well....

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. ologgio

    ologgio Private E-2

    Thanks! ClamAV ran from Linux says everything is clean. I'll finish up the cleanup procedures you mentioned. Again, thank you very much!

    In the Holy Eucharist.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I did say:
    ;)

    You're welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds