• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Virus - Please solve me how to deal with this virus

Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
submit a hijack this report please, if hijack this won't run then rename the file to something else and run it.

i didnt understand.
How to do that?
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
Some infections can only be cured by a reinstall of Windows. This may be one of those times. Back up your files and reformat.
 
Joined
May 27, 2008
Messages
3,628 (0.62/day)
System Name Ultra 64
Processor NEC VR4300 (MIPS R4300i)
Motherboard proprietary design
Cooling Fanless aircooled
Memory 4.5MB 250 MHz RDRAM
Video Card(s) 62.5 MHz Reality Coprocessor
Storage 32 - 512 Mbit ROM Cartridge
Display(s) 720x576
Case Clear Blue Funtastic
Audio Device(s) 16-bit CD quality
Power Supply proprietary design
Mouse N64 mouse for use with N64DD
Keyboard N64 keyboard for use with N64DD
i hate to say it but i agree with everyone else on the reformat, every time ive had a virus infect main windows stuff its been game over and ive had to nuke it, your lucky you can still access your files to back them up i couldnt.
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
i tried to run kaspersky bootcd but it's not detecting any of my harddrive in my laptop so no benifit.

it detects usb drives though..
 
Joined
Feb 19, 2009
Messages
1,828 (0.33/day)
Location
UK Warwickshire
System Name PC-Chips
Processor Ryzen 5 5600x
Motherboard Asus ROG Strix B550-F Gaming.
Cooling Thermalright Peerless Assassin 120 SE CPU Air Cooler 6 heat pipes.
Memory Patriot Viper 32gig dual channel 3600mhz
Video Card(s) PowerColor HellHound RX 7900 GRE OC
Storage 2X Samsung 860 EVO SSD's 500gig / 2TB crucial P3-NVME / WD-BLUE SN550 1TB M.2 / SP A55 512gig
Display(s) Panasonic 40-inch 4k TV
Case Modded NZXT H510
Audio Device(s) Realtek S1220A - Yamaha A-S501 AMP - 4 x Wharfedale diamond 9.1 speakers - Wharfedale SW150 sub
Power Supply EVGA SuperNOVA G6 750W 80+ Gold
Mouse Some cheap wireless thing
Keyboard Razer Cynosa lite
VR HMD Oculus Quest 2 128gig version
Software Windows 11 pro 64bit
Files Infected:
C:\Windows\System32\kbiwkmbitgwgsj.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmciqigqal.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmjwciwovt.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmneckpmii.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmvffpoevc.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmvxepstfk.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmbjoprotq.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmoikuyrfl.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmotaonqts.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmhwubyyih.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmijdcuxsj.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmijhtnyjv.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmjakrmkwx.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmklfwpqur.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmqwmqrnxn.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmrwibvbcs.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmsobtsnwm.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmwsxvowut.dll (Rootkit.TDSS) -> Delete on reboot.

This basicly tells you where the bad files are so what i would now do.

Make sure system restore is turned of because this keeps copys of dodgy files and if you dont turn it of they will keep coming back.

then manulay goto c:\system32 and manulay find the files in that list and delete them one by one (yes it takes time but better than format of you cant be bothered)

after you have deleted the files in the list restart and run the scan again untill you have fully removed the files.

another usefull scanner i use is the norton online scan its free and does a very good job of findind where dodgy files hide, it willl also give you a list at the end with any viruses or bad files that need to be removed. follow the list and manuly delete.
 

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,670 (2.24/day)
Last edited:
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
Files Infected:
C:\Windows\System32\kbiwkmbitgwgsj.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmciqigqal.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmjwciwovt.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmneckpmii.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmvffpoevc.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmvxepstfk.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmbjoprotq.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmoikuyrfl.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmotaonqts.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmhwubyyih.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmijdcuxsj.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmijhtnyjv.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmjakrmkwx.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmklfwpqur.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmqwmqrnxn.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmrwibvbcs.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmsobtsnwm.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmwsxvowut.dll (Rootkit.TDSS) -> Delete on reboot.

This basicly tells you where the bad files are so what i would now do.

Make sure system restore is turned of because this keeps copys of dodgy files and if you dont turn it of they will keep coming back.

then manulay goto c:\system32 and manulay find the files in that list and delete them one by one (yes it takes time but better than format of you cant be bothered)

after you have deleted the files in the list restart and run the scan again untill you have fully removed the files.

another usefull scanner i use is the norton online scan its free and does a very good job of findind where dodgy files hide, it willl also give you a list at the end with any viruses or bad files that need to be removed. follow the list and manuly delete.

Thanks and i've already tried to delete manually but when i try to do that, it shows blue screen and reboot itself.

Even bitdefender and malware bytes arent able to delete it bcz it's in globalroot.
 
Joined
Feb 19, 2009
Messages
1,828 (0.33/day)
Location
UK Warwickshire
System Name PC-Chips
Processor Ryzen 5 5600x
Motherboard Asus ROG Strix B550-F Gaming.
Cooling Thermalright Peerless Assassin 120 SE CPU Air Cooler 6 heat pipes.
Memory Patriot Viper 32gig dual channel 3600mhz
Video Card(s) PowerColor HellHound RX 7900 GRE OC
Storage 2X Samsung 860 EVO SSD's 500gig / 2TB crucial P3-NVME / WD-BLUE SN550 1TB M.2 / SP A55 512gig
Display(s) Panasonic 40-inch 4k TV
Case Modded NZXT H510
Audio Device(s) Realtek S1220A - Yamaha A-S501 AMP - 4 x Wharfedale diamond 9.1 speakers - Wharfedale SW150 sub
Power Supply EVGA SuperNOVA G6 750W 80+ Gold
Mouse Some cheap wireless thing
Keyboard Razer Cynosa lite
VR HMD Oculus Quest 2 128gig version
Software Windows 11 pro 64bit
do you see any of the above files running as a task in task manager?
in the process list>?

if so what happens if you manual end the task? blue screen?

Another thing that might be worth checking is MSCONFIG and see if anything is loading up at the start that is associated with the rootkit.

Start/run/type msconfig look for any dodgy files is the startup tab
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
one file in startup in msconfig which i dont know is "BDAMonitor application" manufactured by eMPIA techology and command hcwemmon.exe.

I dont know wht is it but doesnt seems like virus..
 
Joined
Sep 25, 2006
Messages
2,312 (0.36/day)
Location
Norn Iron
Processor Q9550 @3.8
Motherboard Asus Maximus Extreme
Cooling Custom water cooling
Memory 4GB Patriot Viper DDR3 1600MHz
Video Card(s) 2x HD4870 512MB
Storage 2x 500GB
Display(s) 3x LG L226WTQ 22" Widescreen LCD
Case Modded TJ07
Audio Device(s) On board
Power Supply PC P&C Silencer 750
Software Windows 7 Ultimate
See if this will help you out any -

http://www.gmer.net/

EDIT: Some tips on running Gmer

Note its name and save it to your root folder, such as C:\.

* Disconnect from the Internet and close all running programs.
* Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
* Click on this link to see a list of programs that should be disabled.
* Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
* Allow the driver to load if asked.
* You may be prompted to scan immediately if it detects rootkit activity.
* If you are prompted to scan your system click "No".
* Click the "Rootkit/Malware" tab.
* When the Quick scan is finished, click Save, Then browse to save the scan results to your Desktop.
* Save the file as Results and copy/paste the contents in your next reply.
* Exit the program and re-enable all active protection when done.

You do not need to run a scan. Immediately after the program starts, a Quick Scan is performed.
 
Last edited:
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
i was able to run this program in safe mode only.
Log file attached.

From this program, it showing root of virus.. this virus is in explorer.exe so it's impossible to remove it without bootscan.????
 

Attachments

  • trojen rootkit.tdss.log.txt
    129.9 KB · Views: 446
Last edited:

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.67/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
Joined
Aug 29, 2004
Messages
967 (0.13/day)
Location
Danville IL
Processor I7 4770k
Motherboard ASUS z87 pro
Cooling Corsair a50
Memory 4x4 gig Gskil aries ddr3 1866
Video Card(s) Gigabyte r280x windforce
Storage intel 520 120 gig ssd
Display(s) 24 inch Asus IPS
Case Cool Master
Audio Device(s) realtek onboard
Power Supply hiper 880
Software win 7 ult
I have yet to see mailwarebytes not remove a virus, did you go to the update tab and update mailwarebytes before you scanned?
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
I have yet to see mailwarebytes not remove a virus, did you go to the update tab and update mailwarebytes before you scanned?

i've recently installed so not updated but it's detecting rootkit but not removing. "o action can be taken"

so if i update or not, will it make any difference?
 
Joined
Aug 29, 2004
Messages
967 (0.13/day)
Location
Danville IL
Processor I7 4770k
Motherboard ASUS z87 pro
Cooling Corsair a50
Memory 4x4 gig Gskil aries ddr3 1866
Video Card(s) Gigabyte r280x windforce
Storage intel 520 120 gig ssd
Display(s) 24 inch Asus IPS
Case Cool Master
Audio Device(s) realtek onboard
Power Supply hiper 880
Software win 7 ult
yes it makes a difference, they update it daily and the one you download is out of date from cnet.com when you get it
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
yes it makes a difference, they update it daily and the one you download is out of date from cnet.com when you get it

wht i wanted to say is it will make in detecting trojen and malwares , it shd not make difference in malwarebyte functions.

As it's detecting trojen nothing to do with database though i've just updated it and it hasnt make any difference in terms of deleting trojen which werent being deleted earlier.
 
Joined
Aug 29, 2004
Messages
967 (0.13/day)
Location
Danville IL
Processor I7 4770k
Motherboard ASUS z87 pro
Cooling Corsair a50
Memory 4x4 gig Gskil aries ddr3 1866
Video Card(s) Gigabyte r280x windforce
Storage intel 520 120 gig ssd
Display(s) 24 inch Asus IPS
Case Cool Master
Audio Device(s) realtek onboard
Power Supply hiper 880
Software win 7 ult
If you updated mailwarebytes and scanned your system in the last 3 minutes that weve posted you got another problem. It isnt scanning it takes 5 minutes to scan usually, if you dont want to update it live with the virus
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
Joined
Aug 29, 2004
Messages
967 (0.13/day)
Location
Danville IL
Processor I7 4770k
Motherboard ASUS z87 pro
Cooling Corsair a50
Memory 4x4 gig Gskil aries ddr3 1866
Video Card(s) Gigabyte r280x windforce
Storage intel 520 120 gig ssd
Display(s) 24 inch Asus IPS
Case Cool Master
Audio Device(s) realtek onboard
Power Supply hiper 880
Software win 7 ult
I just updated and ran it and this is how long it took a clean system
 

Boyfriend

New Member
Joined
Nov 30, 2008
Messages
160 (0.03/day)
System Name Black Star
Processor Core2Duo E7200 @ 2.53 GHz
Motherboard Asus P5K-VM (G33)
Cooling Cooler Master Hyper N520 + 3 120 mm Fans
Memory Corsair CM2X1024-6400C4DHX , 4,4,4,12,2T, 2x1 GB
Video Card(s) MSI NX8500GT TD256E
Storage WD Caviar Blue 320GB + Maxtor 500 GB
Display(s) ViewSonic VX1940w 19"
Case Vento ATX
Audio Device(s) Realtek HD (On-Board)
Power Supply Cooler Master Extreme 460 W
Software Windows 7 RTM 32-Bit + KIS 2011 CF2 (ab)
It is really astonishing to know that Kaspersky BootCD don't detect hdd of your laptop. I have used it numerous times to clean many desktops and laptops from very clever malwares, which sometimes even render Windows useless due to excess & exhaustive resources utilization.
One more thing to try is here:
Install Kaspersky 2010. Update it and run a complete system scan. Follow the instructions given here. Upload GSI log. Go to main GUI --> Support --> Support tools --> Create system state report. Also upload it to some server (rapidshare, megashare etc.) and give the links here by starting a new thread. Kaspersky experts will suggest method(s) to remove the malware(s) detected. The suggested script they provide can be run in main GUI --> Support --> Support tools --> Excecute AVZ script.
Then Go to Security+ tab --> Microsoft Windows Settings Troubleshoot and follow the recommended actions.
It might seem you lengthy process, but it is one of the best method to skip format of your hdd. Trust me!

You can also upload GSI log and give a link here and I might do the rest of job for you.
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
If you updated mailwarebytes and scanned your system in the last 3 minutes that weve posted you got another problem. It isnt scanning it takes 5 minutes to scan usually, if you dont want to update it live with the virus

10-31-2009 06:08 PM & 10-31-2009 06:17 PM
Check time duration.
It's around 10 minutes.
and i've updated malwarebytes.
Screenshot:


I dont want to debate here for statistics but according to my knowledge, if it was detecting virus then it has nothing to do witth update, problem was it was not removing virus. though according to ur advice, i've updated, scanned and no difference.


Database version: 3065
Windows 6.0.6000

31-10-2009 18:29:58
mbam-log-2009-10-31 (18-29-58).txt

Scan type: Quick Scan
Objects scanned: 98510
Time elapsed: 9 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 25

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\System32\kbiwkmsfwpvjfx.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\System32\kbiwkmsfwpvjfx.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\kbiwkmbitgwgsj.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmciqigqal.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmdxnexiuf.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmijhtnyjv.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmjwciwovt.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmklfwpqur.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmneckpmii.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmrwibvbcs.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Windows\System32\kbiwkmsfwpvjfx.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Windows\System32\kbiwkmvffpoevc.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmvxepstfk.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmwsxvowut.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmxeqvvcbd.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmxittqpmt.dll (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmbjoprotq.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmoikuyrfl.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\drivers\kbiwkmotaonqts.sys (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmcjulvuyw.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmhwubyyih.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmijdcuxsj.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmjakrmkwx.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmqwmqrnxn.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmsobtsnwm.dat (Rootkit.TDSS) -> Delete on reboot.
C:\Windows\System32\kbiwkmxmwxdjhf.dat (Rootkit.TDSS) -> Delete on reboot.
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
With all the time you've spent on this, you could have been backed up and reinstalled a few days ago. Sometimes the virus wins, amigo. :laugh:
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
It is really astonishing to know that Kaspersky BootCD don't detect hdd of your laptop. I have used it numerous times to clean many desktops and laptops from very clever malwares, which sometimes even render Windows useless due to excess & exhaustive resources utilization.
One more thing to try is here:
Install Kaspersky 2010. Update it and run a complete system scan. Follow the instructions given here. Upload GSI log. Go to main GUI --> Support --> Support tools --> Create system state report. Also upload it to some server (rapidshare, megashare etc.) and give the links here by starting a new thread. Kaspersky experts will suggest method(s) to remove the malware(s) detected. The suggested script they provide can be run in main GUI --> Support --> Support tools --> Excecute AVZ script.
Then Go to Security+ tab --> Microsoft Windows Settings Troubleshoot and follow the recommended actions.
It might seem you lengthy process, but it is one of the best method to skip format of your hdd. Trust me!

You can also upload GSI log and give a link here and I might do the rest of job for you.


Seems complicated.
anyways, i'll try it.
Thanks.

Well, kaspersky bootcd was working and it was detecting removable drives but not my internal hdd, may be bcz it is ntfs system.

anyways, thanks.
 
Joined
Jan 27, 2007
Messages
654 (0.10/day)
Location
India
System Name HP envy 17 3090nr
Processor Intel core i7-2670QM 2.2ghz
Memory 8gb
Storage 1TB
Software Genuine Windows 7 Home Premium
Benchmark Scores Windows experience index 6.9
With all the time you've spent on this, you could have been backed up and reinstalled a few days ago. Sometimes the virus wins, amigo. :laugh:

You're right but i'm not spending my time continously on this , i try to do something suggested here once daily or eve3ry few days and if i format, i'll have to reinstall everything, all settings and data will be lost etc..

Mainthing i'm not formatting is bitdefending & malwarebytes are blocking virus tohugh not removing it so it's not making any effect on my laptop performance as far as i know.

I hope i'll defeat the virus.

Thanks. :toast:
 
Top