tdss rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by mchapman1, Jan 25, 2010.

  1. mchapman1

    mchapman1 Private E-2

    tdss rootkit HELP!!!

    First off please excuse my ignorance with this stuff, and thanks in advance for helping me. I followed the removal guide to a T and here is what I have. Please review and let me know where I stand.

    I picked this thing up on Thursday of last week searching for myspace scripts!

    I could not get mgtools to work properly, I followed install instructions perfectly! it says I need a script, but unless I am missing something there was no mention of a script on the guide

    Here are the logs

    I recieved a lot of errors using root repeal, I attached that as well.
     

    Attached Files:

    Last edited: Jan 25, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: tdss rootkit HELP!!!

    Well for a start you missed out running SUPERantispyware. Then it appears that you did not have Malware Bytes fix what it found. (If you did so after attaching the log then ignore my next step)

    Open up MBAM > let it update > re scan with it > let it fix all it finds and attach the log it creates into your next reply here.

    You also should have run Combofix which was affected by a bug and taken offline but now it is up and running again and available for download and use.

    We did not request a log from running Rooter and what are you doing running avenger on your own? Are you having assistance with malware removal in another forum?

    What exactly happens when you try to run MGTools. Try to run it again after running SUPERantispyware (if you havent done so already) and Combofix, and in that order. Only then try to run MGTools ensuring that it is indeed on your C Drive and not anywhere else. If a dialogue box pops up about the script could you screenshot it for us, or at least note down it down word for word?

    Thanks
    Kes13!
     
  3. mchapman1

    mchapman1 Private E-2

    Malware says it is the latest version. I did run anti spyware and I cant seem to get a log out of it when it finishes it. It did not find anything when I ran the scan. I did not run avenger because there was nothing to run. Like I said it asked for a script. I followed the steps here from the malware removal guide in this forum:



    I have not had any help elsewhere.
     
  4. mchapman1

    mchapman1 Private E-2

    Ohh yeah the reason I didnt run combofix because of all of the issues. In the guide it doesn't say anything about combofix being fixed.
     
    Last edited: Jan 25, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I did not ask you if MBAM was the latest version, I know it is, all I asked you to do was to update the database version and then attach a new log after rescanning to show me that you had indeed fixed all you found as looking at your previous log, it shows nothing was fixed. I am here to help you and I like to do a thorough job.

    OK we will deal with this later. I do like to always see a log even if nothing was found.

    I am confused because you attached a log from avenger into your thread, as well as a log from running Rooter.

    And you are saying that MGTools.exe asks you to run a script before it will let you run the actual program. Well I asked you for a word for word message that you see regarding it, or even a screengrab. There shouldn't be any problems running MGTools but let's do this:
    Okay, but I can tell you that combofix is now up and running again and online, so considering you are having so many problems with MGTools, I want you to download and run Combofix now from your desktop (Go back to the R&R to download it)

    Attach the C:\Combofix.txt into your next reply please.

    Then try running MGTools.exe again. If you have trouble running tools in normal mode then do try safe mode. Do try and describe as best you can what happens if you do have any problems and I will do my best to help you as much as I can. If I am to be successful in removing malware from your machine I need to at LEAST see logs from running MGTools.exe ---> C:\Mglogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds