Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

8/4: MBAM finds TROJAN.TDSS repeatedly. McAfee finds nothing.


  • Please log in to reply
1 reply to this topic

#1 atroutcatcher

atroutcatcher

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United States
  • Local time:04:09 AM

Posted 04 August 2009 - 11:23 PM

Today I received a desktop with Windows XP Media Edition Version 2002, SP3 with a high level of pollution. MBAM ran and found a multitude of issues that have apparently been resolved. The remaining item is TROJAN.TDSS. MBAM finds it and deletes / quarantines it. However, each time I restart the system (as instructed by MBAM) and then run MBAM again, the TROJAN.TDSS is back.

While I'm unclear on the effect of this trojan, it remains on the system. Eventually, it will disable McAfee Security Center from receipt of updates and performance degrades (I presume some internet activity is running behind the scenes). After running MBAM a few times, occasionally, McAfee comes back to life and will run a scan of the system. It finds nothing.

Anyway, again, I'm new to the process and system and look forward to hearing from you guys on what I should do to properly enlist your help.

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:09 AM

Posted 05 August 2009 - 03:04 PM

Hello,this may be a nasty rootkit.Please post your last MBAM log.
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.


We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop:
  • Extract RootRepeal.exe from the zip archive.
  • Open Posted Image on your desktop.
  • Click the Posted Image tab.
  • Click the Posted Image button.
  • Check all six boxes: Posted Image
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the Posted Image button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

EDIT about this backdoor trojan...
A backdoor Trojan can allow an attacker to
gain control of the system, log keystrokes, steal passwords, access personal
data, send malevolent outgoing traffic, and close the security warning
messages displayed by some anti-virus and security programs.

I would advise you to disconnect this PC from the Internet, and then go to
a known clean computer and change any passwords or security information held
on the infected computer. In particular, check whatever relates to online
banking financial transactions, shopping, credit cards, or sensitive
personal information. It is also wise to contact your financial institutions
to apprise them of your situation.

We will do our best to clean the computer of any infections seen on the log.
However, because of the nature of this Trojan, I cannot offer a total
guarantee that there are no remnants left in the system, or that the
computer will be trustworthy.

Many security experts believe that once infected with this type of Trojan,
the best course of action is to reformat and reinstall the Operating System.
Making this decision is based on what the computer is used for, and what
information can be accessed from it.

Edited by boopme, 05 August 2009 - 03:05 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users