Security [CENTRAL] Forum - SCforum.info
23. May 2012., 17:52:52 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11256
Latest: rbraik
Stats
Total Posts: 15636
Total Topics: 4337
Online Today: 2742
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1 2 »
  Print  
Author Topic: help with rootkit (Alureon, TDSS, Tidserv, TDL3)  (Read 5272 times)
0 Members and 1 Guest are viewing this topic.
rkprd
SCF Member
**

KARMA: 3
Posts: 11


« on: 23. February 2010., 03:05:37 »

hello i posted this question in another section and was told to ask here- http://scforum.info/index.php?topic=3849.msg9946#msg9946
i already downloaded kaspersy rescue disk 2009 and it wont boot from the cd and i know i burned it right. i also tried with the malware programs  on ultimate boot cd and they didnt work either something about some missing files. are there other programs i can use to get rid of this rootkit?
Logged
Security [CENTRAL] Forum - SCforum.info
« on: 23. February 2010., 03:05:37 »



 Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #1 on: 23. February 2010., 22:06:37 »

Hi R.,

for the start please download and run this tool provided by Kaspersky: http://support.kaspersky.com/downloads/utils/tdsskiller.zip 

After that download, install, update and make a Full scan with SUPERAntiSpyware: http://scforum.info/index.php/topic,116.0.html

Finally provide us new logs from HJT, Bitdefender and Windows Live OneCare: http://scforum.info/index.php/topic,734.0.html

I'll wait your next reply (with logs).

Regards,

S.
Logged

rkprd
SCF Member
**

KARMA: 3
Posts: 11


« Reply #2 on: 26. February 2010., 06:08:09 »

samker  the problem is I cant log into windows to download  tdsskiller.exe i get a blue screen as soon as windows starts to load due to the recent windows update that messed up computers infected with this rootkit .  I think i am going to wait until windows comes up with a fix for this since Im tired of trying to fix it to no avail  if you have any other possible solutions let me know thanks for your help I appreciate it
Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #3 on: 26. February 2010., 14:26:38 »

samker  the problem is I cant log into windows to download  tdsskiller.exe i get a blue screen as soon as windows starts to load due to the recent windows update that messed up computers infected with this rootkit .  I think i am going to wait until windows comes up with a fix for this since Im tired of trying to fix it to no avail  if you have any other possible solutions let me know thanks for your help I appreciate it



HERE IS THE PROBABLE SOLUTION:

Follow these steps:

1. Boot from your Windows XP CD or DVD and start the recovery console (see this  link http://support.microsoft.com/default.aspx/kb/307654  on how to use recovery console)

Once you are in the Repair Screen..

2. Type this command: CHDIR $NtUninstallKB978262$\spuninst

3. Type this command: BATCH spuninst.txt

4. Type this command: systemroot

5. Repeat steps 2 - 4 for each of the following updates:

    * KB978262
    * KB971468
    * KB978037
    * KB975713
    * KB978251
    * KB978706
    * KB977165
    * KB975560
    * KB977914

6. When complete, type this command: exit

Your computer should restart and everything should be back to normal.

Good Luck!


After all, follow my earlier instructions for removing these rootkit...

Logged

rkprd
SCF Member
**

KARMA: 3
Posts: 11


« Reply #4 on: 28. February 2010., 18:28:57 »

I dont have a windows cd or dvd my computer didnt come so I tried with some programs on ultimate boot cd and I couldnt get past the first command it says chdir failed on whatever the file name is I was able to go into the C:\windows directory and see those files installed but I guess that command only works with the windows cd.
Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #5 on: 28. February 2010., 21:13:33 »

shit...  Angry


...but I have another solution for you. Wink

For that We need another PC, hope that isn't to big problem for you?

Just took the HD out, and put it in a External HD chaise, you can do the same by putting it in another PC with and open HD slot….. get a good copy of atapi.sys or go to the GOOD Pc’s Wn/Sys32/dir folder.. and copy it to the desktop… when you open the BAD HD go to that folder and replace it with the good one…. put the HD back in, and reboot, as you hit the F8 key, go to \most resent Config\ ( or how ever it reads) and click that….. Wink

Let me know did you have success this time?

Regards,

S.
Logged

rkprd
SCF Member
**

KARMA: 3
Posts: 11


« Reply #6 on: 04. March 2010., 23:15:25 »

hey samker I was finally able to get my pc running again by doing a combination of both of the things you told me, I installed the hard drive into another pc and was able to use the command prompt to uninstall the update with the commands you gave me thanks alot you are the man! but I am still not in the clear yet now my pc is full of adware when I click on a search result in google it redirects me to other pages I was shocked when I found out because I never had any problems with this before this mess Undecided so now I am looking for some good adware removal programs I will look around your forum to see what I can find let me know if you have any good recommendations thanks again for your help!
Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #7 on: 05. March 2010., 07:11:43 »

Excellent news my friend... don't worry next part is much easier.  Wink

Now please follow my instructions from the start of this Topic:

Quote

please download and run this tool provided by Kaspersky: http://support.kaspersky.com/downloads/utils/tdsskiller.zip

After that download, install, update and make a Full scan with SUPERAntiSpyware: http://scforum.info/index.php/topic,116.0.html

Finally provide us new logs from HJT, Bitdefender and Windows Live OneCare: http://scforum.info/index.php/topic,734.0.html




I'll wait your next reply (with logs).

Regards,

S.

Logged

rkprd
SCF Member
**

KARMA: 3
Posts: 11


« Reply #8 on: 18. March 2010., 19:46:21 »

hello samker sorry for not getting back to you earlier my computer had been running fine since the problem I did a scan with malwarebytes and removed the infections or so I thought and it was running fine until yesterday it started running way slower than usual. so I did a scan on bitdefender online scanner and found out I still have an infection but that is another different infection from this topic so I will post another thread with the logs hopefully you can help me out.
Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #9 on: 18. March 2010., 20:02:50 »

Quote
so I did a scan on bitdefender online scanner and found out I still have an infection but that is another different infection from this topic so I will post another thread with the logs hopefully you can help me out.



No problem pal, We'll resolve that problem also. Wink

Please open New Topic in SCF "PC Help Center": http://scforum.info/index.php?action=forum and provide us:

1. All possible details related to yours problems / infection.

2. Run BitDefender Online AntiVirus Scan: http://scforum.info/index.php/topic,734.0.html

3. Download & run HijackThis: http://scforum.info/index.php/topic,785.0.html


cya later,

S.
Logged

Pages: 1 2 »
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 20. May 2012., 10:20:01