Jump to content

Malwarebytes

tdss.sys rootkit detected but not removed


11 replies to this topic

#1
Tiny_Glow

    New Member

  • Members
  • Pip
  • 3 posts
Hello everybody ...
I need help with this f.... tdss malware, MB correctly detects the concerned registry key being infected, allows deletion and all seems to proceed the right way. Once I reboot the PC the infection is still there, I've disabled-rebooted PC and then uninstall the tdss.sys driver with no success.
I think the rootkit hides all files having tdss into filename .. though .. because I've never been able to see such files anywhere in the drive. ???
Please help me I'm desperate ...

Attached Images

  • Attached Image: cntdss.JPG


#2
Rorschach112

    Regular Member

  • Experts
  • PipPip
  • 55 posts
I think it would be easier if you just went to the HJT forum, this is a nasty infection
By the power of truth, I, while living, have conquered the universe.

~Scratch~

#3
Tiny_Glow

    New Member

  • Members
  • Pip
  • 3 posts

View PostEliteKiller, on Nov 1 2008, 01:38 AM, said:


Although not done what is suggested there it helped to find the way to solve the problem, as follows:

a) from DeviceManager -> Show hidden peripherals
:) disable Tdssxyx.sys where xyz are random characters (found on non plug and play peripherals)
c) REBOOT SAFE MODE (press F8 while Windows boots) no command prompt
d) move to Windows\system32 and NOW the tdssxyz.xyz files become visible!! Deleted them all.
e) move to system32\drivers, deleted tdssxyz.sys
f) reboot safe mode (?) and unistall the peripheral driver tdssxyx.sys
g) reboot normal - deleted all what possible from registry - search tdss (all values) if and when found -> delete
h) Scan MB did not found any tdss anymore !!! Neither tdss.sys has been installed nor process explorer (www.sysinternals.com) finds any handle or dll attached.
Victory
Seriously thinking to upgrade to MBPro, MB has been the only malware fighter capable of removing AntivirXp 2009. The rest is ordinary routine.
I want to thanks all the people spending their time to give me this help that solved (almost I think so) the infection.
THANKS YOU ALL

Quote

Malwarebytes' Anti-Malware 1.30
Versione del database: 1345
Windows 5.1.2600 Service Pack 3

01/11/2008 14.16.47
mbam-log-2008-11-01 (14-16-47).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 104800
Tempo trascorso: 13 minute(s), 2 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 0

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
(Nessun elemento malevolo rilevato)


#4
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
A note on this infection .

MBAM should get all be the service (that is protected by removing all permissions from the key) but the file the service points to does die so it is only a trace .

In future versions of MBAM we will be looking at both better crippled permissions handling and DRA (Direct Registry Access) , DRA bypasses permissions .

If anyone has a scan log (with current MBAM version and defs) where we do not remove the FILES I need to know about it ASAP .


Another note on this infection , the TDSS guy modifies the scan results to make it look like MBAM is trying to remove the system32 folder . MBAM neiter has this ability nor attempts to do what the modified log shows .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
Tiny_Glow

    New Member

  • Members
  • Pip
  • 3 posts
Thanks for the attention.
Attached are 4 logs zipped, they should show the history of the infection(s). The keypoint is in the third log, where it says tdss deletion successfully but it is not. Hope it helps ...
:)

Attached Files



#6
SJK2

    New Member

  • Members
  • Pip
  • 1 posts

View PostTiny_Glow, on Nov 2 2008, 06:19 AM, said:

Thanks for the attention.
Attached are 4 logs zipped, they should show the history of the infection(s). The keypoint is in the third log, where it says tdss deletion successfully but it is not. Hope it helps ...
:huh:

Does anyone know HOW OR WHERE this TDSS infection comes from....

#7
elero

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 110 posts
  • Gender:Male
High risks (like Rootkit.TDss.Gen) are typically installed without user interaction through security exploits, and can severely compromise system security. Such risks may open illicit network connections, use polymorphic tactics to self-mutate, disable security software, modify system files, and install additional malware. These risks may also collect and transmit personally identifiable information (PII) without your consent and severely degrade the performance and stability of your computer :huh:

#8
JeanInMontana

    Delete this account!!

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,867 posts
  • Interests:would love to see some honesty around this site.

View PostSJK2, on Nov 22 2008, 02:50 PM, said:

Does anyone know HOW OR WHERE this TDSS infection comes from....


Most likely your using an unsecured connection, and it is your router that is infected. It will require a special process to remove it.
Hi read and follow the instructions here then post a log here . Someone will be happy to help you.


#9
cart0181

    New Member

  • Members
  • Pip
  • 1 posts

View PostJeanInMontana, on Nov 22 2008, 07:30 PM, said:

[color="#800080"]Most likely your using an unsecured connection, and it is your router that is infected. It will require a special process to remove it.

Why would you say that? If his router is "infected", wouldn't he just have to reset it? Correct me if I'm wrong, but that comment almost scared the crap out of me. I had to check on that for a minute.

#10
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,571 posts
  • Gender:Male
  • Location:US
This is a 6 month old post and Jean does not currently participate on the site anymore.

There are a couple of methods to infect a router, in general the most common is by someone using one that does not have a password on it. They then modify setting, usually DNS to point elsewhere or block out security sites. There is another that attempts to actually update the firmware of the router.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#11
Sal

    New Member

  • Members
  • Pip
  • 1 posts
This still isn't being completely removed in the latest version of mbam. I've attached a log from the system. I hope this can help somehow.

Attached Files



#12
yardbird

    Forum Deity

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,726 posts
  • Gender:Male
  • Location:Sedona. Arizona, USA
  • Interests:Where we keep the World Safe
@ Sal

There kinda busy in that forum. It may take a couple of days..
follow these instructions & post it in the HiJackLog Forum please

Scan and post logs - read note at bottom in green
If you're having Malware related issues with your computer that you're unable to resolve.
  • Please do not post any logs in the General forum. We do not work on any logs posted in the General forum.
  • Please do not install any software or use any removal/scanning tool except for those you're requested to run by the Helper that will assist you.
  • Using these other tools often makes the cleanup task more difficult and time consuming.
  • If you have already submitted for assistance at one of the other support sites on the Internet then you should not post a new log here, you should stay working with the Helper from that site until the issue is resolved.
  • Do not assume you're clean because you don't see something in the logs. Please wait until the person assisting you provides feedback.
  • There are often many others that require asistance as well, so please be patient. If no one has responded within 48 hours then please go ahead and post a request for review

NOTE: If for some reason you're unable to run some or any of the tools in the first link, then skip that step and move on to the next one. If you can't even run HijackThis, then just proceed and post a NEW topic as shown in the second link describing your issues and someone will assist you as soon as they can.
Posted Image
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us