Reply
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Group Policy, Regedit, & System Restor Disablede

I have found the _VOID disallowed entries looking through folders on my PC from when I was testing this TDL2 variant some time ago

 

See attached text file

 

Quads

Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restor Disablede

So should I use aregeditor and deleate the _Void entries?

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Group Policy, Regedit, & System Restor Disablede

[ Edited ]

TDSSkiller will get the _VOID TDL2 and check for TDL3, when you run that

 

As previous instructions

 

 


TDL2 and this variant a lot of times comes with TDL3,   That is why you can't run a long list of security programs due to a disallowed list

 

 

Find and run TDSSkiller, with Vista and Windows 7 right click and "Run as Administrator"


 

 

Quads

Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restore Disabled

I ran the TDSSkiller after renaming it and it appears to have fixed the problem I can now run all my Anti Virus programs and Regedit, Task Mgr and Sysrestore.

 

I have ran Spybot, Ad-Aware, Malwarebytes, and Symantec 360 each found some spyware/viruses and removed them.  I just ran the Sophos Rootkit revealer and it found nothing else on my system either.

 

I thank all of you for your help with this issue and truly appreciate saving me from reformatting and reinstalling all my software again.

 

Thank you all again.  :manvery-happy:

floplot
Posts: 9,952
Topics: 200
Kudos: 1,892
Solutions: 354
Registered: ‎04-11-2009

Re: Group Policy, Regedit, & System Restore Disabled

Hello bghanson

 

I'm glad your problem seems to be fixed now. Could you please mark the post which gave you the answer so that everyone will know that the problem has been solved and will find the solution quickly also. Please keep an eye out to check if any of the malware comes back again. If it does, you can open up a new thread. Thanks

Success always occurs in private and failure in full view.




Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Group Policy, Regedit, & System Restore Disabled

 

 


bghanson wrote:

I ran the TDSSkiller after renaming it and it appears to have fixed the problem I can now run all my Anti Virus programs and Regedit, Task Mgr and Sysrestore.

 

I have ran Spybot, Ad-Aware, Malwarebytes, and Symantec 360 each found some spyware/viruses and removed them.  I just ran the Sophos Rootkit revealer and it found nothing else on my system either.

 

I thank all of you for your help with this issue and truly appreciate saving me from reformatting and reinstalling all my software again.

 

Thank you all again.  :manvery-happy:


 

Malwarebytes would have as it has the ability to  reset "Regedit, Task Mgr and Sysrestore."  in the registry (System Restore as "systemTools").

 

Warning: Sophos Rootkit revealer (Anti-Rootkit) shows false positives.

 

With Spybot S&D and Ad-Aware don't have the realtime components running as they could conflict with Norton's realtime protection.

 

Quads

 

Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restore Disabled

I wanted to wait a couple of days before I mamrked it "as solution for problem".  Everything apaired to be working as it should until Monday when using the computer I would hear the audio from a vidio, but no vidio was running and IE* was closed.  I re ran the TDSSkikker again and it said I was Infected with TDSS ap.  I then ran Malwarebytes' Anti-Malware, Symantec 360 (whicn would never finish the virus scan), Ad-aware & spybot.  I rebooted and ran the TDSSkiller again and it said it was still there.

 

Yesterday I used a bootable USB with the Kasperski resque disk install.  It also found the TDSS ap, and said it cleaned it this morning.  I will check when I get home tonight and see if it is in fact gone now.  This has been one persistent Malware.  If the system is finally clean I will test it through the weekend and mark the thread accordingly next week.

Contributor
bghanson
Posts: 18
Registered: ‎01-22-2009

Re: Group Policy, Regedit, & System Restore Disabled

I forgot to add "Win32.TDSS ap"  not just "TDSS ap" if that makes any differance.

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Group Policy, Regedit, & System Restore Disabled

Also check to see if you have the latest version of TDSSKiller.   They are updating that as fast as they can get samples of the new variants. 

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Group Policy, Regedit, & System Restore Disabled

"Win32.TDSS ap" is a variant that randomly selects a Windows Driver to infect

 

It's only persistent if  the wrong driver to swap is being looked at.

 

Quads