Page 2 of 2 FirstFirst 12
Results 11 to 11 of 11

Thread: Win32.TDSS.rtk Infected

  1. #11
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hi,

    Just want to do doublecheck and make sure these are gone.

    Redownload Combofix and rename as you did before, then do this.

    Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


    Code:
    Driver::
    geyekrwdaulytl.sys
    
    Rootkit::
    C:\WINDOWS\system32\drivers\geyekrwdaulytl.sys
    C:\WINDOWS\system32\geyekrtqktotxl.dll
    C:\WINDOWS\system32\geyekrxyunkoqc.dll
    C:\WINDOWS\system32\geyekrdwivjaxl.dat
    C:\WINDOWS\system32\geyekriosfoonb.dat
    Save this as CFScript to your desktop.

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.




    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
    Last edited by tashi; 2009-08-11 at 19:47. Reason: Timestamp Archive
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •