volsnap.sys, Alureon....newbie here ~ assist por favor!
#1
Posted 11 July 2011 - 03:58 PM
I believe my problems began with the 'Windows Recovery Virus' and they've run their course since then. Unfortunately I did a System Restore just after it hid all of my files before I knew what I had. I have run most supported online fix recommendations including: Avast (which catches the Malicious URLs 64.111.211.158, 64.11.211.164 and 64.11.211.165. Also MBAM, Spybot, Spyware Doctor, WebRoot Spyware Sweeper, Commodo, Registry Booster.....most recently trying to run tdsskiller.exe but it will not initiate even after changing the name and extension. I just downloaded Resource Tuner but don't know exactly what to do with it so I've stopped there.
Visible problems I'm experiencing (but not limited to these I'm sure) -
- Redirects
- No sound in webpages, the box unchecks itself upon restart
- Most streaming video freezes
- My childs online games will not play
- Prior to the 'no sound' issue I could hear audio from commercials without a browser or webpage being open
This is my first post and an intermediate computer user but I have been a fan of the website and learned many helpful things from reading this forum over the last year. In this instance I don't want to overstep my ability so here I am. Again in advance....you guys rock.
Marc aka Fishetti
#2
Posted 11 July 2011 - 06:05 PM
Save the file to your Windows desktop.
Close all running programs.
If you are running Windows XP, turn off System Restore. How to turn off or turn on Windows XP System Restore
Double-click the FixTDSS.exe file to start the removal tool.
Click Start to begin the process, and then allow the tool to run.
Restart the computer when prompted by the tool.
After the computer has started, the tool will inform you of the state of infection (make sure to let me know what it said)
If you are running Windows XP, re-enable System Restore.
—George Bernard Shaw
#3
Posted 11 July 2011 - 06:13 PM
It re-directs from search engine links. What finally cleaned it was to boot off a vista cd (f8 repair your computer from recovery partition would crash had to boot off a installation cd) then went to command prompt and wrote a new MBR. Bootrec /fixmbr
Rebooted, ran tdsskiller which did run but found nothing. Checked search engine search and no more redirection.
Hope this helps.
#4
Posted 12 July 2011 - 12:41 AM
The TDSS Fix Tool says: ***Infected Driver: volsnap.sys
Awaiting instructions...
#5
Posted 12 July 2011 - 01:17 AM
—George Bernard Shaw
#6
Posted 12 July 2011 - 11:02 AM
#7
Posted 12 July 2011 - 04:42 PM
http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller
—George Bernard Shaw
#9
Posted 12 July 2011 - 06:16 PM
Select action for found objects:
Suspicious objects
Forged file Skip
Service
Service name: volsnap
Service type: Kernel driver (0x1)
Service start: Boot (0x0)
File: C:\Windows\systen32\DRIVERS\volsnap.sys
MD5: 48e724d86ea12ec1b827d18c69961374
MD5(forged): c18111166690541d6cb0cfcafe9ef38b
Following the instruction to click 'Continue' it says:
System Scan Completed
Infection: Not Found
*Please advise, thanks.
#10
Posted 12 July 2011 - 06:23 PM
—George Bernard Shaw
#12
Posted 12 July 2011 - 06:57 PM
- Hold down Control and click on this link to open ESET OnlineScan in a new window.
- Click the
button. - For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
- Double click on the
icon on your desktop.
- Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
- Check "YES, I accept the Terms of Use."
- Click the Start button.
- Accept any security warnings from your browser.
- Under scan settings, check "Scan Archives" and "Remove found threats"
- Click Advanced settings and select the following:
- Scan potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Scan potentially unwanted applications
- ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
- When the scan completes, click List Threats
- Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
- Click the Back button.
- Click the Finish button.
—George Bernard Shaw
#13
Posted 12 July 2011 - 09:31 PM
Win32OpenCandy Application
Win32RegistryBooster Application
Java/Agent AC Trojan
Java/TrojanDownloaderOpenStream NCA trojan
a variant of the Win32/SlowPCfighter application
#14
Posted 12 July 2011 - 10:28 PM
C:\ProgramData\ReviverSoft\RegistryReviver\InstallCache\{63E13B95-3168-481C-A8DF-FBE0DCDF5699}\Registry Reviver.msi a variant of Win32/SlowPCfighter application deleted - quarantined
C:\Users\FishLaptop\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\6e45fa36-528c31ff Java/TrojanDownloader.OpenStream.NCA trojan deleted - quarantined
C:\Users\FishLaptop\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\4a5bb93f-31e808f7 Java/Agent.AC trojan deleted - quarantined
C:\Users\FishLaptop\AppData\Roaming\FrostWire\.AppSpecialShare\frostwire-4.21.8.windows.exe Win32/OpenCandy application deleted - quarantined
C:\Users\FishLaptop\AppData\Roaming\Uniblue\RegistryBooster\_temp\ub.exe Win32/RegistryBooster application deleted - quarantined
#15
Posted 12 July 2011 - 10:39 PM
—George Bernard Shaw

Help


Back to top









