Another major infection; Rootkits!


  1. Posts : 20
    Windows 7 64 bit
       #1

    Another major infection; Rootkits!


    Okay.. A few of you vets out there might cringe upon hearing this; but yes. I've (or my brother) has come across a rootkit or two; which constantly redirect google links unless using a VPN.

    Malwarebytes scan followed up with this list of bad files : http://puu.sh/17YRJ

    (I recently did a system restore; which is why some of those are listed twice. )

    I tried using Combofix; which managed to murder my Wireless drivers and was the cause of doing a system restore.

    How can I safely remove these without them coming back?
      My Computer


  2. Posts : 2,240
    Windows 7 Ultimate 64 bit
       #2

    Use TDSSKillier in safe mode. Then re-run all your malware software in safe mode as well doing full scans.

    Anti-rootkit utility TDSSKiller
      My Computer


  3. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #3

    Kaoruko

    The answer is simple use WDO.

    We have a tutorial on how to use WDO:
    Windows Defender Offline

    Here's the procedure I use, which is basically the same:
    HOW TO USE MICROSOFT'S OFFLINE MALWARE REMOVER
    Windows Defender Offline
    · performs an offline scan of an infected PC to remove viruses, rootkits and other advanced malware.
    · is a free standalone, bootable malware and virus remover from Microsoft.

    Download Windows Defender Offline (about 785 kB)
    You will have the choice of downloading the 32bit version (x86) or the 64 bit version (x64).
    The link will help you determine whether you are running a 32 bit version or 64 bit version of Windows

    NOTE!! You can download and prepare a 32 bit version using a 64 bit version of Windows
    NOTE!! You can download and prepare a 64 bit version using a 32bit version of Windows.

    You run the 32 bit version on a 32 bit version of Windows.
    You run the 64 bit version on a 64 bit version of Windows.

    The 32 bit download file name is: mssstool32.exe
    The 64 bit download file name is: mssstool64.exe

    For the curious, this program was originally name Microsoft Standalone System Sweeper.


    INSTALLATION:
    · Requires an Internet Connection.
    · Insert 512 mB or larger USB stick into a usb port.
    · Run the downloaded program--mssstool64.exe or mssstool32.exe
    · NEXT button
    · Choose the option On a USB flash drive that is not password protected
    · NEXT button
    · NEXT button
    .
    The install program will:
    · format the usb stick using the NTFS format.
    · download less than 230 mB.
    · name the USB stick WDO_Media32 or WDO_Media64
    · use less than 300 mB.

    How to UPDATE the Windows Defender Offline USB stick:
    · reinsert the usb stick
    · run the installation program, mssstool64.exe or mssstool32.exe, again.
    · the update will download less than 65 mB.

    Since the malware database is sometimes updated several times in a day, always update before running.

    PERFORM AN OFFLINE SCAN
    Bootup your computer from the USB stick
    Windows Defender Offline will automatically perform a quick scan.
    After the quick scan finishes, Choose Full Scan
    Select all of your drives

    The initial, full scan can easily take several hours, but
    Remember, your computer is being very thoroughly checked for all types of malware.
      My Computer


  4. Posts : 20
    Windows 7 64 bit
    Thread Starter
       #4

    bassfisher6522 said:
    Use TDSSKillier in safe mode. Then re-run all your malware software in safe mode as well doing full scans.

    Anti-rootkit utility TDSSKiller
    I can't seem to find the safe mode boot. f8, f1, and f2 don't show boot options.
      My Computer


  5. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #5

    kaoruko,
    malware seldom travels alone.
    One of the main reasons I strongly recommend WDO.
      My Computer


  6. Posts : 20
    Windows 7 64 bit
    Thread Starter
       #6

    karlsnooks said:
    kaoruko,
    malware seldom travels alone.
    One of the main reasons I strongly recommend WDO.
    I'm downloading it now; thanks :)
      My Computer


  7. Posts : 20
    Windows 7 64 bit
    Thread Starter
       #7

    bassfisher6522 said:
    Use TDSSKillier in safe mode. Then re-run all your malware software in safe mode as well doing full scans.

    Anti-rootkit utility TDSSKiller
    The TDSKiller found services.exe to be high threat, but "cure" does nothing and after re-scanning it show is again; along with the items MBam found.
      My Computer


  8. Posts : 10,200
    MS Windows 7 Ultimate SP1 64-bit
       #8

    Run WDO.
      My Computer


  9. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #9

    Hi Kaoroku,

    Unfortunately, if some specialist generic tools such as TDSKiller do not fix the problem, then a disk wipe and clean install are usually the only method to ensure that the rookits have been completely removed.

    Regards,
    Golden
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:23.
Find Us