Hey guys I did a f-secure online scan and it came up with this spyware: Gen:TDss.Patched.1 and said it could not be cleaned. I've tried installing Spybot but it won't even let me do that and I keep getting random websites popping up and alerts saying "Ztl.exe has stopped working". It's also impossible for me to download attachments from my email so my whole system seems to be a bit crazy! Can you please help me fix things up?

I followed the preliminary instructions (except I couldn't install Spybot) and here is my DDS log:

And my Attach log:


Thanks for what you guys are doing on these forums, it really helps poor clueless souls like me! :)

2010-05-19, 14:53

Welcome to Safer Networking.

Please read Before You Post
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

You have a real mess going on, besides a Rootkit , your computer is being hijacked by the lovely people in the uKraine

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)



* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

2010-05-20, 23:21
Thanks so much for the advice! Unfortunately, every time I try to run Combo-Fix, it comes up with a little window that says: "GSAR.cfxxe has stopped working" :(

2010-05-21, 02:12

Try this, right click on Combofix and select rename and rename it sisik.exe.

Then try to run one of these programs first

Please download and run the following tool to help allow other programs to run. (Thanks to Grinler of BleepingComputer.com)

RKill.exe (http://download.bleepingcomputer.com/grinler/rkill.exe)
RKill.com (http://download.bleepingcomputer.com/grinler/rkill.com)
RKill.scr (http://download.bleepingcomputer.com/grinler/rkill.scr)
RKill.pif (http://download.bleepingcomputer.com/grinler/rkill.pif)

There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
You will know one ran when a box opens up with a report

Now try running Combofix

2010-05-22, 05:22
Thanks for that - I did exactly as you said...renamed it, ran RKill.exe but it came up with the same message as before when I tried to run ComboFix :( sorry my laptop is such a pain!

2010-05-22, 13:41
Take Combofix you renamed and drag it to the trash and download via my previous links a fresh copy as its updated daily.

Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

Go to http://www.techsupportforum.com/sectools/tetonbob/StartBtn.gif -> Run -> copy/paste in the following single line command & click OK

"%userprofile%\desktop\combofix.exe" /killall


Click OK and this will start ComboFix in a special way.
When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply .

2010-05-23, 00:29
That didn't work either, it still comes up with the same "GSAR..." message as before! I'm getting a little worried :( but I do really appreciate your patience with this problem :)

2010-05-23, 03:47
A rootkit is most likely responsible for this, they are designed to block most programs from running, there is away around it we just have not hit it yet. I am going to give you a few options to follow, if one won't work just move on to the other.

Like before, drag Combofix to the trash and download a fresh copy to your desktop, then rename it to sisik.exe

Please download exeHelper (http://www.raktor.net/exeHelper/exeHelper.com) to your desktop.

Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Then try Combofix again, if you have not done so before, right click on sisik.exe and select RUN AS ADMINISTRATOR.

If Combofix still wont run, try running it in Safemode.

To Enter Safemode

Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)

If it still wont run, then run this program.

Download TDSSKiller and save it to your Desktop.

Extract the file and run it.
Once completed it will create a log in your C:\ drive
Please post the contents of that log

2010-05-23, 12:22
That's so fabulous! I've been worried about the ComboFix thing but it finally worked in Safe Mode, thanks so much Ken.

Here is the exehelperlog:

exeHelper by Raktor
Build 20100414
Run at 17:11:00 on 05/23/10
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...

And the ComboFix log:
2010-05-23, 12:57
Great :bigthumb:

Malware will infect anything it can, in the first part of your CF log

Infected copy of c:\windows\system32\drivers\pci.sys was found and disinfected
Restored copy from - Kitty had a snack :p

pci.sys <-- PCI Bus Driver, this was infected

CF also removed a rootkit and some other misc bad files, i need to check a few over but before I do lets do this and see if there removed.

Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

Download DDS by sUBs from one of the following links. Save it to your desktop.

DDS.com (http://www.techsupportforum.com/sectools/sUBs/dds)
DDS.scr (http://download.bleepingcomputer.com/sUBs/dds.scr)
DDS.pif (http://www.forospyware.com/sUBs/dds)

Double click on the DDS icon, allow it to run.
A small box will open, with an explaination about the tool. No input is needed, the scan is running.
Notepad will open with the results, click no to the Optional_Scan
Follow the instructions that pop up for posting the results.
Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control Here (http://www.bleepingcomputer.com/forums/topic114351.html)

Post the Malwarebytes log and the DDS log please

2010-05-24, 05:18
Thanks Ken. :)

Malwarebytes' Anti-Malware 1.46

Database version: 4132

Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18904

24/05/2010 6:32:40 AM
mbam-log-2010-05-24 (06-32-40).txt

Scan type: Quick scan
Objects scanned: 127639
Time elapsed: 11 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07286.TBSB07286Toolbar (Adware.Ecobar) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\spool\prtprocs\w32x86\b00006749.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\winset.ini (Malware.Trace) -> Quarantined and deleted successfully.

2010-05-24, 11:47

Looking better all the time.

Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.

You need to enable windows to show all files and folders, instructions Here (http://www.bleepingcomputer.com/tutorials/tutorial62.html)

Go to VirusTotal (http://www.virustotal.com/) and submit these files for analysis, just use the BROWSE feature and then Send File , you will get a report back, post the report into this thread for me to see. If the site says this file has already been checked, have them check it again


If the site is busy you can try this one


c:\users\sisi\AppData\Local\Omahevifohahuro.dat <--Right click on this file and delete it

2010-05-25, 07:04
Hi Ken, that sounds very positive yay!

c:\windows\iwcdc8684.exe VirusTotal report:

C:\32788R22FWJFW.1.tmp was actually a folder...not sure which file you wanted me to scan?

2010-05-25, 11:20

Download and Run SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (http://jpshortstuff.247fixes.com/SystemLook.exe)
Download Mirror #2 (http://images.malwareremoval.com/jpshortstuff/SystemLook.exe)

Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield:


Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

2010-05-25, 14:57
I hope it's good news. Thanks so much!

2010-05-25, 15:19

I need to have someone else take a peak at that file, it looks ok but really not sure.

These have to go

These have to go

Please download OTM by OldTimer (http://oldtimer.geekstogo.com/OTM.exe) and save it to your desktop.
Double click the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/OTMdesktopicon.png icon on your desktop.
Paste the following code under the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/pasteline.png area.
Do not include the word "Code".



[start explorer]

Push the large http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/btnmoveit.png button.
OTM may ask to reboot the machine. Please do so if asked.
Copy/Paste the contents under the http://billy-oneal.com/Canned%20Speeches/speechimages/OTM/results.png line here in your next reply.
If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

2010-05-26, 03:31
Still looking into that file

2010-05-26, 11:07
That file should be removed

C:\32788R22FWJFW.1.tmp <--Just right click on it and delete it

2010-05-26, 15:51
Hi brilliant boy. I am so grateful for all your help! Here is the log you asked for:

2010-05-26, 15:53
P.S. That "C:\32788R22FWJFW.1.tmp" folder isn't there anymore, though there is a "C:\32788R22FWJFW" folder...do I need to delete that?

2010-05-26, 15:58
Yes, long story , you can just delete it

How are things running now ?

2010-05-27, 02:27
So much better thanks! I don't remember when my laptop used to run as fast as it does now! And no more crazy pop-up ads! Love your work :)

2010-05-27, 03:14
Great :bigthumb:

ATF Cleaner <-- Yours to keep, run it now and then to clean out the clutter.

Malwarebytes <-- Yours to keep also, check for updates and run a scan now and then.

Combofix <---Is not a general cleaning tool, just run it with supervision or you can bork your system

Click START then RUN
Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.


When shown the disclaimer, Select "2"

The above procedure will:

Delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Reset System Restore.

Now to remove most of the tools that we have used in fixing your machine:
Make sure you have an Internet Connection.
Download OTC (http://oldtimer.geekstogo.com/OTC.exe) to your desktop and run it
A list of tool components used in the cleanup of malware will be downloaded.
If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
Click Yes to begin the cleanup process and remove these components, including this application.
You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)

Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .

Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community

Spybot Search and Destroy 1.6 (http://www.safer-networking.org/en/download/)
Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.

Spyware Blaster (http://www.javacoolsoftware.com/spywareblaster.html) It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.

Spyware Guard (http://www.javacoolsoftware.com/spywareguard.html) It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.

IE-Spyad (http://www.pcworld.com/downloads/file/fid,23332-order,1-page,1-c,antispywaretools/description.html)
IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.

Firefox 3 (http://www.mozilla.org/products/firefox/) It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.

Safe Surfn

2010-05-27, 12:50
You are awesome, thanks!

I actually just ran a Spybot Search & Destroy scan and it came up with this:

Fraud.Sysguard: [SBI $1D5B98D0] User settings (Registry value, fixed)

Fraud.Sysguard: [SBI $1D5B98D0] User settings (Registry value, fixing failed)

Fraud.Sysguard: [SBI $F3B45CE7] Settings (Registry key, fixed)

Fraud.Sysguard: [SBI $F3B45CE7] Settings (Registry key, fixed)

Fraud.Sysguard: [SBI $F4F42B59] Settings (Registry key, fixed)

Fraud.Sysguard: [SBI $F4F42B59] Settings (Registry key, fixed)

MediaPlex: Tracking cookie (Internet Explorer: sisi) (Cookie, fixed)

DoubleClick: Tracking cookie (Internet Explorer: sisi) (Cookie, fixed)

MediaPlex: Tracking cookie (Internet Explorer: sisi) (Cookie, fixed)

Right Media: Tracking cookie (Internet Explorer: sisi) (Cookie, fixed)

Statcounter: Tracking cookie (Internet Explorer: sisi) (Cookie, fixed)

WebTrends live: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

Tradedoubler: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

Tradedoubler: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

Statcounter: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

DoubleClick: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

MediaPlex: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

MediaPlex: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

MediaPlex: Tracking cookie (Firefox: sisi (default)) (Cookie, fixed)

One of the registry values couldn't be fixed or something?

2010-05-27, 14:25
Reboot and run it again. Looks like just some leftover registry entries plus some tracking cookies

2010-05-31, 23:13
Just did another scan and all is fine :) thanks so much for all your help Ken, you have been amazing! All the best in your endeavours :D:thanks:

2010-06-01, 00:04
Your very welcome,

ken :)

ken :)