Posts Topics Forums Images
Search videos from message boards Videos Search messages from microblogs Microblogs Search messages from imdb.com Imdb Search messages from yuku.com Yuku Search messages from lefora.com (free forums) Lefora
My account: Login | Sign Up
Loading... 

Thread: Is this rootkit.tdss?

Started 2 months, 3 weeks ago by heatheroo
I think my Sony VAIO (Windows XP Home Edition Version 2002 Service Pack 3) is infected with rootkit.tdss. I was on Limewire, downloading a recording of a seminar, when my PC started browsing weird websites by itself. The browser is not actually visiting these sites in front of my eyes, but when I look in my browser history, there are hundreds of strange websites listed (...
Site: Sysinternals Forums  Sysinternals Forums - site profile
Forum: Malware  Malware - forum profile
Total authors: 3 authors
Total thread posts: 6 posts
Thread activity: no new posts during last week
Domain info for: sysinternals.com

Other posts in this thread:

redhawk replied 2 months, 3 weeks ago
One thing to start with do not connect to the internet until it's fixed because it sound like this virus/rootkit infection is downloading and installing more junk to your computer. You will need a special CD something like BartPE or Hiren's Tools, they provide a bootable Windows Operating System with the all important command prompt. Once you have access to the file ...

heatheroo replied 2 months, 3 weeks ago
Dear Redhawk, thank you - but what if I can't get BartPE or Hiren's Tools? Is there a way online I can do all that? I'm critically low on funds - can't afford to buy a CD

heatheroo replied 2 months, 3 weeks ago
Wait -- Am Googling BartPE or Hiren's Tools now. Am going to try to download them, they're available at the author's sites (Hirem is). Crossing fingers.

redhawk replied 2 months, 3 weeks ago
BartPE or Hirens either will do since both provide safe access to you hard drive. If you're unfamiliar with the Command Prompt (dos prompt / cmd shell) then this site should provide you with help on the commands. The basic commands you need are: c: (switch to C drive) cd \ (change directory to root) cd \windows\system32\drivers (change directory to...) cd .. (...

F16_Pilot replied 2 months, 2 weeks ago
If safe mode does not help, I guess some key driver files are either modified or corrupted. Usually in this case, I would use raw disk backup to backup important data first, then reinstall OS. Good luck!

 

Top contributing authors

Name
Posts
heatheroo
3
user's latest post:
Is this rootkit.tdss?
Published (2009-09-25 13:49:00)
Wait --   Am Googling BartPE or Hiren's Tools now.  Am going to try to download them, they're available at the author's sites (Hirem is). Crossing fingers.
redhawk
2
user's latest post:
Is this rootkit.tdss?
Published (2009-09-25 17:40:00)
BartPE or Hirens either will do since both provide safe access to you hard drive. If you're unfamiliar with the Command Prompt (dos prompt / cmd shell) then this site should provide you with help on the commands. The basic commands you need are: c: (switch to C drive) cd \ (change directory to root) cd \windows\system32\drivers (change directory to...) cd .. (change directory down a level) dir /a-d /o-d /p (show all files / in date order...
F16_Pilot
1
user's latest post:
Is this rootkit.tdss?
Published (2009-10-02 23:17:00)
If safe mode does not help, I guess some key driver files are either modified  or corrupted. Usually in this case, I would use raw disk backup to backup important data first, then reinstall OS. Good luck!

Related threads on "Sysinternals Forums":

Related threads on other sites:

Thread profile page for "Is this rootkit.tdss?" on http://www.sysinternals.com. This report page is a snippet summary view from a single thread "Is this rootkit.tdss?", located on the Message Board at http://www.sysinternals.com. This thread profile page shows the thread statistics for: Total Authors, Total Thread Posts, and Thread Activity