Not sure if I'm infected or not

Discussion in 'Malware Help (A Specialist Will Reply)' started by multimedia, Nov 13, 2008.

  1. multimedia

    multimedia Private E-2

    Well I was infected with a bunch of trojans and stuff but I had a friend take care of all of them and everything seemed good. However, when I turned the computer on there were a bunch of TDSS****.dll files in my system32 folder.

    My antivirus program (Norton Symantec and Windows Defender) did not pick up the files as dangerous even though when I searched google they showed up as rootkits.

    The offending files themselves are

    TDSSmtvd 4KB
    TDSSoiqt.dll 36KB
    TDSSxfum.dll 72KB
    TDSSlxwp.dll 4KB
    TDSShrxm.dll 0KB
    TDSSvtql.dll 0KB

    However for some reason I was able delete them by merely selecting them and pressing the delete button. Should it had been that easy to remove them? I also read on a site that if a computer had been infected by a rootkit that it is not secure and that you should reformat it.
    Is this true? Because I would rather not reformat.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    There will me additional files that will need removing......

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. multimedia

    multimedia Private E-2

    Well here are the logs and to my surprise there were still some trojans and viruses in the computer....
     

    Attached Files:

  4. multimedia

    multimedia Private E-2

    MGlogs
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...the scans picked up the rest of the infections...let's just do this:

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7"
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Use windows explorer to find and delete:
    C:\Windows\VEhVIFRSQU4

    If you aren't having any other malware issues, then:
     
  6. multimedia

    multimedia Private E-2

    Ah thanks!

    Two quick questions.

    Do I have to delete the Java or are they harmful to the computer?

    And, can I continue to do online banking and what not now that the rootkits are gone or am I still in harms way?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry...my bad....yes uninstall old Java, reboot and install:
    Java Runtime 6

    I would suggest that any online site you use, change your passwords using a different computer. :)

    You should be fine.
     
  8. multimedia

    multimedia Private E-2

    Thanks for your help! :-D
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds