Rookit dl4 Infection, Recovery Question

Discussion in 'Malware Help (A Specialist Will Reply)' started by Brewp, Apr 20, 2011.

  1. Brewp

    Brewp Private E-2

    Hi, I was infected by "rootkit.win32.TDSS.tdl4" virus, which Kaspersky's
    TDSSKiller found, and said it had cured it.
    The major symptoms of the attack (excessive CPU usage by SVCHOST.exe -
    ntsvcs, unable to run Windows Update and lots of error messages from Rapport banking software with "Blocked process alteration events".)

    I'm still getting some suspicious activity (a few error messages in Rapport
    about "attempt to alter function URLDownLoadToFileW blocked", and every time I boot up there are attempts to communicate with IP adddress 221.192.199.49 which when I google it looks like a very active Chinese hacker!).

    I have a firewall rule blocking all communications with this IP address and
    a few others that were appearing in the Norton Firewall Activity log around
    the time of my infection.

    Question: I have an 7 year old DELL machine with the Dell PC Restore
    partition, so I have the option to return my main partition to the pristine
    state it was in when it left the factory. (with XP sp1!!). Is this a viable
    recovery option with this sort of infection??

    This link describes the inner workings of the Restore
    http://www.goodells.net/dellrestore/.

    The alternative looks like going into a complicated comboFix. At least with
    the Delll restore it just allows me to run mormal windows updates etc. plus
    backing up data.

    Many thanks for your help
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's really up to you. We can try cleaning your system, for which you would need to follow these instructions:
    READ & RUN ME FIRST. Malware Removal Guide

    However, your best bet to be certain that your system is clean might be to restore it to factory settings.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds