Welcome, Guest. Please login or register.
November 18, 2008, 05:33:41 PM

Login with username, password and session length

212214 Posts
24527 Topics
57705 Members

Latest Member: Kenneth

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  DNSChanger / 216.255.186.11 / kdhaq.exe?
« previous next »
Pages: 1 2 [3] Go Down Print
Author Topic: DNSChanger / 216.255.186.11 / kdhaq.exe?  (Read 2988 times)
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3328



« Reply #30 on: October 02, 2008, 04:24:17 AM »

This looks like a dangerous variant.

And probably a Reformat is worth it, It's the only way to make sure your 100% malware free.

Josh
Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: Windows XP 32bit SP3, CIS 3.5.
Specialty: Malware Removal & Remote Helper.
brithelp
Newbie
*
Offline Offline

Posts: 4


« Reply #31 on: October 02, 2008, 05:51:39 AM »

oK this is now moved into the memory ,,,,, so time to wipe....... unless someone as a magic fix i would suggest back up everything you got today because this virus is not being picked up nor deleted by anything that out there and its changing everytime you delete  or move!!!!!!!!!!!. Back up everything then reinstall
 well gl may the force be on yourside
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2773


Why not ? The choice is yours !


« Reply #32 on: October 02, 2008, 11:34:21 AM »

Have you tried killing it using defence + (making it a blocked rule ?)

Xan
Logged

OK, we'll see each other outside  Angry. But err... different countries ?

 Vista Ultimate 64bit SP1  l  Comodo Internet Security  l  Comodo BoClean
UncleDoug
Comodo's Hero
*****
Offline Offline

Posts: 261


« Reply #33 on: October 02, 2008, 12:19:43 PM »

This is a nasty one! I would have thought combofix and/or smitfraud, VundoFix etc.  at least one least would have found something in Safe Mode.  Sometimes I have found a tool might need to be run 3 or more times in a row after reboots and each time it found more.

I would have thought you would have been able to manually change your DNS in Safe Mode following the OpenDNS instructions.

I also found that a few times some installs do not take even Microsoft, and I found that running Reset_subinacl would change security settings to allow those installs.  Some of the programs might install in safe mode.

As you posted you have tried several programs, including anti rootkit, and you have Comodo Memory Firewall, and BoClean,  and System Resore is OFF  malware replicates from there, have you been able to run HiJack This in either normal or safe mode?

Your problem is more critical than mine but I still have not solved the problem I posted a few days ago, and I know searching and reading and trying all the different suggestions and get tiring and frustrating when the results stay the same with no changes.

Patience and Good Luck
UncleDoug
« Last Edit: October 02, 2008, 12:22:19 PM by UncleDoug » Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2773


Why not ? The choice is yours !


« Reply #34 on: October 02, 2008, 12:35:50 PM »

Damn I want that malware   Smiley

Uncledoug, have you tried disabling it with defense+, also, have you searched in the task manager if it uses some processes, if so,which ones ?

(he posted his Hijackthis log, it's at page 1 I think)


Xan
Logged

OK, we'll see each other outside  Angry. But err... different countries ?

 Vista Ultimate 64bit SP1  l  Comodo Internet Security  l  Comodo BoClean
brithelp
Newbie
*
Offline Offline

Posts: 4


« Reply #35 on: October 03, 2008, 07:11:17 AM »

Ok  Thinking  Jiggy
 ok this is what i done 
i have avast antivirus   
i downloaded the following and run rebooting every time
superantispyware 
reboot
run anti virus
a squared
reboot
run anti virus
reboot
mam malwarebytes anti malware
reboot
 mmmm and then antivirus pickedup and killed
make sure you have system restore switched off  and gl and ty  to all who helped
now i must have about 6 anti malware programes Smiley running  Bounce Clapping








Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\ (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssinit.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssmain.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssserf.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tdssserv.sys (Rootkit.Agent) -> Delete on reboot.
« Last Edit: October 03, 2008, 07:13:17 AM by brithelp » Logged
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3328



« Reply #36 on: October 03, 2008, 07:27:57 AM »

Well done!!!

Anything else you need help with?

Josh
Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: Windows XP 32bit SP3, CIS 3.5.
Specialty: Malware Removal & Remote Helper.
grue155
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1016


« Reply #37 on: October 03, 2008, 11:23:25 AM »

Quote
C:\WINDOWS\system32\drivers\tdssserv.sys (Rootkit.Agent) -> Delete on reboot.

From what I've observed in other malware clenaup forums, this is a very very nasty rootkit. It may say "it's gone", but it may not be. Keep scanning, as this thing may regenerate itself.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2773


Why not ? The choice is yours !


« Reply #38 on: October 08, 2008, 02:47:25 AM »

This should be a site which will help you deleting it manually

http://www.exterminate-it.com/malpedia/remove-TDSServ

Xan
Logged

OK, we'll see each other outside  Angry. But err... different countries ?

 Vista Ultimate 64bit SP1  l  Comodo Internet Security  l  Comodo BoClean
Tags:
Pages: 1 2 [3] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 18.851 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com