Rootkit Help!

Infected? Need help removing malware from your PC ?
Post in here and let our Malware Advisors help you....

If this topic has helped you then please...



 

Rootkit Help!

Postby vman1 » Sat Sep 17, 2011 9:01 pm

I did a scan on my computer with the TDSS Killer and it found sptd.sys in C:\windows\system32\drivers\ and I don't know what to do now I was thinking I should load up the rescue disk and try to clean it or just delete it?
vman1
 
Posts: 4
Joined: Sat Sep 17, 2011 8:55 pm
Has thanked: 0 time
Have thanks: 0 time
OS: Windows Vista Home
Architecture: 32bit

Rootkit Help!

Advertisement

Advertisement
 

Re: Rootkit Help!

Postby gusthebus » Sat Sep 17, 2011 9:37 pm

If you know how to use the Kaspersky rescue disk (assuming that's what you're doing) go ahead and run a scan with that. Keep in mind it could be a false positive, if your AV finds nothing you should post a combofix/OTL log here.
KIS 2012
gusthebus
Global Moderator
 
Posts: 750
Joined: Fri Aug 13, 2010 10:47 pm
Location: St. Louis, Missouri
Has thanked: 70 times
Have thanks: 22 times
OS: Windows 7 Ultimate
Architecture: 64bit

Re: Rootkit Help!

Postby vman1 » Sat Sep 17, 2011 10:14 pm

Would combofix really help
vman1
 
Posts: 4
Joined: Sat Sep 17, 2011 8:55 pm
Has thanked: 0 time
Have thanks: 0 time
OS: Windows Vista Home
Architecture: 32bit

Re: Rootkit Help!

Postby Ramnic » Sat Sep 17, 2011 10:31 pm

Looks like a false positive
http://www.bleepingcomputer.com/startup ... 13477.html

But if you still think there is malware on you computer you should scan with Malwarebytes' Anti-Malware in safe mode.
Ramnic
Junior Contributor
 
Posts: 49
Joined: Sun Jul 17, 2011 3:05 pm
Has thanked: 1 time
Have thanks: 1 time
OS: Windows 7 Home
Architecture: 64bit

Re: Rootkit Help!

Postby vman1 » Sat Sep 17, 2011 10:34 pm

I did a malwarebytes scan before I did tdss killer and it found nothing, then I ran tdss killer and it found that file
vman1
 
Posts: 4
Joined: Sat Sep 17, 2011 8:55 pm
Has thanked: 0 time
Have thanks: 0 time
OS: Windows Vista Home
Architecture: 32bit

Re: Rootkit Help!

Postby vman1 » Sat Sep 17, 2011 10:52 pm

Oh thank you very much Ramnic I am usally good with malware removel but I got conerned since it was in that dierctory, Thank You!
vman1
 
Posts: 4
Joined: Sat Sep 17, 2011 8:55 pm
Has thanked: 0 time
Have thanks: 0 time
OS: Windows Vista Home
Architecture: 32bit

Re: Rootkit Help!

Postby ZOU » Sun Sep 18, 2011 9:42 am

I did a malwarebytes scan before I did tdss killer and it found nothing, then I ran tdss killer and it found that file

In the past, Alureon (TDSS variant) was not spotted by MBAM on my machine, but HitMan Pro did spot it. When dealing with elite malicious rootkits, MBAM is good for a final clean up, but a KAV rescue disk is the nail in the coffin for the worst rootkits (follow up with MBAM). If you don't have a rescue disk, ComboFix would be my second choice. Matt has used TDSS killer, and Bit Defender's TDSS killer in the recent past against the TDSS family with no success.
ZOU
Global Moderator
 
Posts: 750
Joined: Thu Dec 16, 2010 7:48 pm
Has thanked: 0 time
Have thanks: 12 times
Architecture: 32bit

Re: Rootkit Help!

Postby googoo1876 » Sun Sep 18, 2011 12:41 pm

Just saying, but the KAV rescue disk missed a rootkit I was working on, and took a ridiculous long time to run. ComboFix + MBAM totally nailed it though. That may be due to an update issue, but that's my story. Moral is if KAV fails try ComboFix at the direction of the community.
real time:NIS, NAT firewall, and a 64bit os

on demand:Malware Bytes, Super Antispyware

browser:Chrome, Speed dial, Too Many Tabs, WOT, ClearCloud
googoo1876
Regular Contributor
 
Posts: 490
Joined: Fri Nov 13, 2009 11:58 pm
Location: If you are looking at this you are a stocker
Has thanked: 1 time
Have thanks: 2 times
OS: Windows 7 Home
Architecture: 64bit

Re: Rootkit Help!

Postby ZOU » Sun Sep 18, 2011 4:43 pm

Whatever works. I guess there is no sure solution these days; it is all about knowing about the available tools.
ZOU
Global Moderator
 
Posts: 750
Joined: Thu Dec 16, 2010 7:48 pm
Has thanked: 0 time
Have thanks: 12 times
Architecture: 32bit


Return to I'm Infected...Now What?

Who is online

Users browsing this forum: No registered users and 0 guests