TechTalkz.com Logo Ask the Expert

Go Back   TechTalkz.com Technology & Computer Troubleshooting Forums > Tech World > Computer Security

Notices

Cannot access Antivirus Sites/Google/Avast etc.

Computer Security


Reply
 
Thread Tools Display Modes
Old 22-01-2009, 02:49 PM   #201
ƒ(ψ)=ΘΊΧφ
 
bakuryu's Avatar
 
Join Date: May 2006
Location: India
Age: 24
Posts: 6,621
Thanks: 19
Thanked 649 Times in 605 Posts
Rep Power: 87 bakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant future


OS: Windows XP Windows Vista Windows 7


Send a message via Yahoo to bakuryu
Re: Cannot access Antivirus Sites/Google/Avast etc.

Okk ..... for the registry entries they belong to the last known good configurations and since the files are deleted, those entries won't harm.

For fixdownadup try this link : fixdownadup (from rapidshare)

Also make sure your Windows is updated from automatic updates and if that remote code vulnerability doesn't fix mentioned in the other thread doesn't fix the problem, reboot and post the new combofix log file.
__________________
Please don't click here
bakuryu is offline   Reply With Quote
Old 22-01-2009, 03:39 PM   #202
Newbie
 
Join Date: Jan 2009
Posts: 12
Thanks: 4
Thanked 0 Times in 0 Posts
Rep Power: 0 kenzie is an unknown quantity at this point


OS: Windows XP


Re: Cannot access Antivirus Sites/Google/Avast etc.

I'm downloading fixdownadup.exe now. The other problem is I can't get to microsoft.com either. Last time my automatic updates gives my computer an svchost.exe error ( now sometimes it comes back again ), so I've disabled my automatic updates. Is it OK to enable it now?
kenzie is offline   Reply With Quote
Old 22-01-2009, 05:02 PM   #203
ƒ(ψ)=ΘΊΧφ
 
bakuryu's Avatar
 
Join Date: May 2006
Location: India
Age: 24
Posts: 6,621
Thanks: 19
Thanked 649 Times in 605 Posts
Rep Power: 87 bakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant future


OS: Windows XP Windows Vista Windows 7


Send a message via Yahoo to bakuryu
Re: Cannot access Antivirus Sites/Google/Avast etc.

yes, enable Windows Update and update Windows.
bakuryu is offline   Reply With Quote
Old 22-01-2009, 05:34 PM   #204
Newbie
 
Join Date: Jan 2009
Posts: 9
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0 Ardiem is an unknown quantity at this point


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7


Re: Cannot access Antivirus Sites/Google/Avast etc.

Quote:
Originally Posted by Strider View Post
Hi Ardiem,

A good organized post. Thanks a lot for that. : )

Like you mentioned, the Hijackthis log appears to be clean. So if your machine is still infected it must be Rootkit. Try the following suggestions:

1. Update Kaspersky Via the offline update method. Get the Cumulative update zip file from another computer with Internet Connection. Take it to your PC and extract the zip file. Arrange Kasperky to update from this folder, update it and do a full system scan.

More Info: Setting Updater

2. Try to download Spybot S&D, install, update and do a scan. It should take care of the Rouge Anti virus problem. ( If this website is also not accessible get the installer and updates from another computer.

3. Use OpenDNS.
Hi Strider, I've done as you suggested which enabled me to run Kasperski's rootkit scanner and lo and behold it discovered a rootki and deleted the affected files. I finished off by doing a full system scan and no further problems were discovered and I was able to update from the Kasperski website.

After a reboot (required to get rid off rootkit) windows started and flagged up various messages about explorer, cmd and any other executable that was starting - something about 'bad server' (can't remember exact message but I can reproduce it if required). I installed Spybot but it won't start so I can't run any scans (it was able to update from website at install time though).

I tried running the Kasperski rootkit scan again and it found the same rootkit again which is clearly not great news as it is proving rather awkward to remove. Is there anything else I can try short of rebuilding the machine?

Many thanks for your assistance so far!
Ardiem is offline   Reply With Quote
Old 22-01-2009, 05:57 PM   #205
ƒ(ψ)=ΘΊΧφ
 
bakuryu's Avatar
 
Join Date: May 2006
Location: India
Age: 24
Posts: 6,621
Thanks: 19
Thanked 649 Times in 605 Posts
Rep Power: 87 bakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant future


OS: Windows XP Windows Vista Windows 7


Send a message via Yahoo to bakuryu
Re: Cannot access Antivirus Sites/Google/Avast etc.

What is the name of the rootkit Kaspersky finds ? Disable System Restore and run that rootkit scanner. Also run a scan using RootkitRevealer

can you post a screenshot of the error messages that you receive while running exe files ?
bakuryu is offline   Reply With Quote
Thanked Users:
kenzie (23-01-2009)
Old 22-01-2009, 06:05 PM   #206
Newbie
 
Join Date: Jan 2009
Posts: 9
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0 Ardiem is an unknown quantity at this point


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7


Re: Cannot access Antivirus Sites/Google/Avast etc.

Quote:
Originally Posted by bakuryu View Post
What is the name of the rootkit Kaspersky finds ? Disable System Restore and run that rootkit scanner. Also run a scan using RootkitRevealer

can you post a screenshot of the error messages that you receive while running exe files ?

I'm at work at the moment but I'll do that when I get in and post the screenshot too.

Cheers
Ardiem is offline   Reply With Quote
Old 23-01-2009, 09:27 AM   #207
Newbie
 
Join Date: Jan 2009
Posts: 12
Thanks: 4
Thanked 0 Times in 0 Posts
Rep Power: 0 kenzie is an unknown quantity at this point


OS: Windows XP


Re: Cannot access Antivirus Sites/Google/Avast etc.

bakuryu and Strider
It seems like my computer is okay now, hopefully I don't have to disturb yous guys and waste you time anymore ( for this case ).
You guys ROCK
kenzie is offline   Reply With Quote
Old 23-01-2009, 06:06 PM   #208
Newbie
 
Join Date: Jan 2009
Posts: 9
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0 Ardiem is an unknown quantity at this point


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7


Re: Cannot access Antivirus Sites/Google/Avast etc.

Quote:
Originally Posted by bakuryu View Post
What is the name of the rootkit Kaspersky finds ? Disable System Restore and run that rootkit scanner. Also run a scan using RootkitRevealer

can you post a screenshot of the error messages that you receive while running exe files ?
Hi Bakuryu/Strider

Ok I've uploaded the screenshots so you can see what I'm getting. The bad image messages I'm getting seem to affect every executable at start up and any new programs run. The following executables throw up exactly the same message and in the following order:

services.exe
lsass.exe
userinit.exe
explorer.exe
rundll.exe
soundman.exe
jusched.exe
qttask.exe
realsched.exe
avp.exe
ctfmon.exe
regsvr32.exe

I can see what is happening - all executables seem to be vetted by this TDSS rootkit but now that it is removed (seemingly temporarily) the referenced file throws an error. Not sure how to get rid of it though as there rookitrevealer shows these registry entires are hidden so I can't access them to delete the keys in regedit. Hope this helps...
Attached Images
File Type: jpg rootkit.JPG (22.4 KB, 9 views)
File Type: jpg error.JPG (14.3 KB, 9 views)
File Type: jpg rootkitrevealer.JPG (66.5 KB, 9 views)

Last edited by Ardiem; 23-01-2009 at 06:17 PM..
Ardiem is offline   Reply With Quote
Old 23-01-2009, 06:20 PM   #209
ƒ(ψ)=ΘΊΧφ
 
bakuryu's Avatar
 
Join Date: May 2006
Location: India
Age: 24
Posts: 6,621
Thanks: 19
Thanked 649 Times in 605 Posts
Rep Power: 87 bakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant futurebakuryu has a brilliant future


OS: Windows XP Windows Vista Windows 7


Send a message via Yahoo to bakuryu
Re: Cannot access Antivirus Sites/Google/Avast etc.

Delete the files using Killbox (set to delete on reboot)
C:\Windows\System32\TDSScfub.dll
C:\Windows\System32\drivers\TDSSserv.sys

delete these registry entries :
HKEY_LOCAL_MACHINE\Software\Classes\webcal\URL Protocol
HKEY_LOCAL_MACHINE\Microsoft\Windows NT\CurrentVersion\tssdata
HKEY_LOCAL_MACHINE\Software\Tdss
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\T DSSserv.sys
HKEY_LOCAL_MACHINE\System\ControlSet002\Services\T DSSserv.sys
HKEY_LOCAL_MACHINE\System\ControlSet003\Services\T DSSserv.sys
bakuryu is offline   Reply With Quote
Old 23-01-2009, 06:43 PM   #210
Newbie
 
Join Date: Jan 2009
Posts: 9
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0 Ardiem is an unknown quantity at this point


OS: Windows XP Windows Server 2003 / Windows Server 2008 Windows Vista Windows 7


Ok I've run killbox and deleted those files and they seem to have gone. The only registry entry from that list that I could find was the first one - the others just weren't there or at least weren't visible.

I've found a key HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSER V.SYS

I tried to delete it but won't let me: 'Error while deleting key'

Same with ControlSet002 and CurrentControlSet.

Last edited by bakuryu; 23-01-2009 at 07:10 PM..
Ardiem is offline   Reply With Quote
Reply

Tags
antivirus, cleanup, infection, virus, virus removal

Thread Tools
Display Modes



< Home - Windows Help - MS Office Help - Hardware Support >


New To Site? Need Help?

All times are GMT +5.5. The time now is 10:10 PM.


vBulletin, Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO
Copyright © 2005-2010, TechTalkz.com. All Rights Reserved - Privacy Policy
Valid XHTML 1.0 Transitional