| | |
Thread Solved |
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Sickofit,
==Download this file to your DESKTOP: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
.....or this file: http://subs.geekstogo.com/ComboFix.exe
-IMPORTANT! : disconnect from the web, turn off your Antivirus, Antispyware and Firewall for the duration of this scan. Don't forget to reset them before you go back on the web!
- to run it dclick the Combofix.exe icon and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
If by some chance Combofix will not run try renaming the combofix.exe to mycomfx.exe, and dclicking it.
==Download this file to your DESKTOP: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
.....or this file: http://subs.geekstogo.com/ComboFix.exe
-IMPORTANT! : disconnect from the web, turn off your Antivirus, Antispyware and Firewall for the duration of this scan. Don't forget to reset them before you go back on the web!
- to run it dclick the Combofix.exe icon and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
If by some chance Combofix will not run try renaming the combofix.exe to mycomfx.exe, and dclicking it.
Last edited by gerbil; Dec 1st, 2008 at 11:43 pm.
Deep, deep in the woods, but walking about.
Try renaming MBAM and run it again.
•
•
Join Date: Mar 2005
Posts: 25
Reputation:
Solved Threads: 0
Gerbil
When I try to click on the link, my Internet Explorer will not let me get to the link. Says the page is unavailable. This is the problem I was telling you about, apparantely whatever this virus is, it has the ability to see if I am trying to access a page that has any type of spyware removal tools on it and it gives me the unavailable page.
When I try to click on the link, my Internet Explorer will not let me get to the link. Says the page is unavailable. This is the problem I was telling you about, apparantely whatever this virus is, it has the ability to see if I am trying to access a page that has any type of spyware removal tools on it and it gives me the unavailable page.
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Sickofit, can you try to access a Combofix dl site from Safe Mode with Networking? If successful, run Combofix from Safe mode.
You could try these scans, one should do, again from safe mode:
==Please use IE or Firefox to do an online scan at panda:- http://www.pandasecurity.com/activescan/index/
-First Register [otherwise there will be no disinfection, merely detection] with a valid email address for the free online virus scan and follow through.
Unlike Kaspersky this scan does not require Java. Panda will clean only virii, but it is superb at listing other malwares which can then be targeted.
Please ATTACH to your post the log it produces.
==Kaspersky Online Scan, from http://www.kaspersky.com/virusscanner -press the Kaspersky Online Scanner button, follow through....
You could try these scans, one should do, again from safe mode:
==Please use IE or Firefox to do an online scan at panda:- http://www.pandasecurity.com/activescan/index/
-First Register [otherwise there will be no disinfection, merely detection] with a valid email address for the free online virus scan and follow through.
Unlike Kaspersky this scan does not require Java. Panda will clean only virii, but it is superb at listing other malwares which can then be targeted.
Please ATTACH to your post the log it produces.
==Kaspersky Online Scan, from http://www.kaspersky.com/virusscanner -press the Kaspersky Online Scanner button, follow through....
Deep, deep in the woods, but walking about.
•
•
Join Date: Mar 2005
Posts: 25
Reputation:
Solved Threads: 0
Ok, I can get to panda in safe mode. No luck on Kaspersky or on the Combo. Same problem.
I registered with panda, downloaded 2.0, enabled active x control, however, when it sets to update the active scan 2.0 I get an error and cant get any further.
sickofit
I registered with panda, downloaded 2.0, enabled active x control, however, when it sets to update the active scan 2.0 I get an error and cant get any further.
sickofit
Last edited by sickofit; Dec 2nd, 2008 at 1:28 am.
Do a system search for files named TDSSserv.*** and delete any that are found.
If you do find find and delete them, try running MBAM again and also Gerbil's advice.
If you do find find and delete them, try running MBAM again and also Gerbil's advice.
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Ok. How annoying. You have a version of ISpyNow which is protected by a rootkit, it is very likely TDSS. So a few things we can try before you have to go walking with a flashdrive in your hot lil hand, to find a friendly type who will let you dl Combofix. We need it. Make sure to load the dl addy into the flashdrive... But first:
There is always another online scan: http://www.f-secure.com/security_center/
If it won't run, then:
==Download [currently it will not dl correctly with Opera; use IE] the latest standalone version of Blacklight from ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe - Start it, accept the agreement and Scan.
Else if we assume that it is TDSS, go into C:\WINDOWS\system32 and rename every file commencing with the letters TDSS to XXXTDSS. Here is a typical selection.. you may have some or none or similar others :
c:\windows\system32\TDSSblal.dat
c:\windows\system32\TDSScshc.dll
c:\windows\system32\TDSSdlpb.dll
c:\windows\system32\TDSSkfkl.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSojtp.dll
c:\windows\system32\TDSSqogd.log
c:\windows\system32\TDSSurev.dll
c:\windows\system32\TDSSwhke.log
c:\windows\system32\TDSSxnyq.dll
You may find some in c:\windows\system32\drivers\...
eg: c:\windows\system32\drivers\TDSSrfpc.sys
Try to run MBAM now [rename mbam.exe to mybm.exe first]. And then try to dl Combofix...
As crunchie said, you could delete any TDSS... files in system32 if you so wished. TDSS is a play on TSDDD, which is a valid displaydriver.
There is always another online scan: http://www.f-secure.com/security_center/
If it won't run, then:
==Download [currently it will not dl correctly with Opera; use IE] the latest standalone version of Blacklight from ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe - Start it, accept the agreement and Scan.
Else if we assume that it is TDSS, go into C:\WINDOWS\system32 and rename every file commencing with the letters TDSS to XXXTDSS. Here is a typical selection.. you may have some or none or similar others :
c:\windows\system32\TDSSblal.dat
c:\windows\system32\TDSScshc.dll
c:\windows\system32\TDSSdlpb.dll
c:\windows\system32\TDSSkfkl.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSojtp.dll
c:\windows\system32\TDSSqogd.log
c:\windows\system32\TDSSurev.dll
c:\windows\system32\TDSSwhke.log
c:\windows\system32\TDSSxnyq.dll
You may find some in c:\windows\system32\drivers\...
eg: c:\windows\system32\drivers\TDSSrfpc.sys
Try to run MBAM now [rename mbam.exe to mybm.exe first]. And then try to dl Combofix...
As crunchie said, you could delete any TDSS... files in system32 if you so wished. TDSS is a play on TSDDD, which is a valid displaydriver.
Last edited by gerbil; Dec 2nd, 2008 at 2:11 am.
Deep, deep in the woods, but walking about.
If you get to the stage where you can download combofix, rename it BEFORE you actually save it to your desktop.
![]() |
Similar Threads
- Monitoring remote client (Network Security)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Bogus email account
- Next Thread: HijackThis Log File - Help Needed Please
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia education email europe exam exploit facebook fake fancheckvirus gaming gumblar halloween herss.exe hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec trojan unwanted update usa virus viruses vista war warning windows worm yahoo zeroday






