canes1711 Posted March 23, 2009 Posted March 23, 2009 I read over on another thread about how to fix this, but it keeps blocking the programs from downloading. I tried renaming them, but it didn't work. What do I do now? Quote
maynardvdm Posted March 23, 2009 Posted March 23, 2009 Hi Firstly press Alt + Ctrl + Delete to bring up the task manager Look under processes and select TDSS.aru and click on End Process Now try to download. If not try downloading in Safe Mode Start your computer in Safe Mode. If the computer is running, shut down Windows, and then turn off the power. Wait 30 seconds, and then turn the computer on. Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again. If F8 doesn't work try F5. Ensure that the Safe Mode with Networking option is selected. Press Enter. The computer then begins to start in Safe mode. Log on with an account that has administrator priviledges, usually your own account (NOT the account named Administrator). Quote We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs. RaidMax Smilodon Gaming Case | Gigabyte Z77X-UD5H M/B | Intel Core i5 3570K @ 3.4GHz | 8GB Corsair RAM | Nvidia GTX550 Ti 1GB GDDR5 | Corsair 800w PSU Register for FREE >>here<< | If we have helped you, please consider a donation >>here<< SAS | MBAM | WinPatrol | Avira | ERUNT | Nvidia Drivers http://i285.photobucket.com/albums/ll57/mjsmileys/userbarnew4sec.gif
maynardvdm Posted March 23, 2009 Posted March 23, 2009 Hi If you managed to get into safe mode, here is the malware removal process: Your computer appears to be infected with Malware. Malware is software designed to infiltrate or damage a computer system without the owner's informed consent. It is a combination of the words malicious and software. The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code. It is in your best interest to note the following: Please disable your resident security applications (such as AVG, Spybot, WinPatrol, etc.) before performing the below procedure so that they do not interfere with the process. Perform all the steps in the order listed to avoid any conflicts. If unsure, please stop and voice your doubts. You might be required to go offline during the disinfection process. Therefore, it is recommended to print off the instructions below for ease of reference. If you stick to the above guidelines, all should go smoothly. ================================================ STEP 1Download ATF-Cleaner by Atribune. Save the file to your Desktop. Double-click on the file to run the program. On the Main tab, check the Select All button. Next, click on the Firefox tab (if applicable) and check the Select All button. Note: If you would like to preserve your saved passwords in Firefox, then click No at the corresponding prompt. Now, click on the Opera tab (if applicable) and check the Select All button. Note: If you would like to preserve your saved passwords in Opera, then click No at the corresponding prompt. Press the Empty Selected button and click OK to acknowledge the corresponding prompt. Click on the Exit button to quit the program. ================================================ STEP 2Please click here to download Malwarebytes' Anti-Malware. Save the file to your Desktop. Double-click mbam-setup.exe and follow the prompts to install the program. At the end, make sure a check mark is placed next to: Update Malwarebytes' Anti-Malware Launch Malwarebytes' Anti-Malware [*]Click Finish. [*]The program will download and update itself if it finds the necessity to do so. Please allow this. [*]Once the program has loaded, select Perform full scan, then click Scan. Note: Depending on your computer specifications, the scan may take some time to complete. Please wait patiently and do not interrupt the process. [*]When the scan is complete, click OK, and then Show Results to view the results. [*]Make sure that every entry is selected, and click Remove Selected. [*]Restart your computer. ================================================ STEP 3Please click here to download SUPERAntiSpyware (Free Version). Save the file to your Desktop. Double-click SUPERAntiSpyware.exe and follow the prompts to install the program. Open SUPERAntiSpyware. Under Configuration and Preferences, click the Preferences button. Click the Scanning Control tab. Under Scanner Options make sure the following fields checked: [*]Click the Close button to leave the control center screen. [*]On the main screen, under Scan for Harmful Software click Scan your computer. [*]On the left, make sure you check mark C:\Fixed Drive. [*]On the right, under Complete Scan, choose Perform Complete Scan. [*]Click Next to start the scan. Please be patient while it scans your computer. [*]After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK. [*]Make sure every entry has a check mark next to it and click Next. [*]A notification will appear that Quarantine and Removal is Complete. Click OK and then Finish to return to the main menu. [*]Restart your computer. ================================================ STEP 4Please visit the ESET Online Scanner, using Internet Explorer to initiate the scan. Note: If you are running Windows Vista, then you will need Administrative privileges to complete the latter part of the procedure. To do so, right-click on the Internet Explorer icon in the Start Menu and select the Run As Administrator option in the shell context menu. Check mark the YES, I accept the Terms of Use box. Click the Start button. Click the Install button on the following screen. Click Start. This will will initialize and update the scanner engine. Check mark the box beside Remove found threats. Click the Scan button. This will start the scan. Please be patient while it is in progress. Restart your computer. ================================================ STEP 5Click on Start > Programs > Accessories > System Tools and select System Restore. Choose the radio button marked Create a Restore Point on the first screen and click Next. Give the restore point a name then click Create. The new point will be stamped with the current date and time. Keep a note of this so you can find it easily should you need to use System Restore. Next, click on Start > Run, type Cleanmgr and click on OK. Click on the More Options tab. Click the Clean Up button in the System Restore section to remove all previous restore points except the most recent one. This will remove any infected files that have been backed up by Windows. The files in "System Restore" are protected to prevent any programs changing those files. This is the only foolproof way to ensure the deletion of those files. Note: Please don't use it on a regular basis as this will clear all previous restore points. The feature might be very useful to revert your computer to working condition if something goes wrong. Re-enable all your security applications and please return here and tell us how the computer seems to be operating. Close browsers before scanning Scan for tracking cookies Terminate memory threats before quarantining Quote We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs. RaidMax Smilodon Gaming Case | Gigabyte Z77X-UD5H M/B | Intel Core i5 3570K @ 3.4GHz | 8GB Corsair RAM | Nvidia GTX550 Ti 1GB GDDR5 | Corsair 800w PSU Register for FREE >>here<< | If we have helped you, please consider a donation >>here<< SAS | MBAM | WinPatrol | Avira | ERUNT | Nvidia Drivers http://i285.photobucket.com/albums/ll57/mjsmileys/userbarnew4sec.gif
canes1711 Posted March 23, 2009 Author Posted March 23, 2009 Still not working It still isn't working. I did the ATF Cleaner, but I still can't get the SUPER Spyware to work. And the cleaner did something weird so that ESPN and other websites don't show up like normal. Quote
Match Posted March 23, 2009 Posted March 23, 2009 Hi Canes. you have to download in safe mode and then run the programs in normal widows is this what you are trying to do? or are you trying to run them in safe mode? Quote
canes1711 Posted March 23, 2009 Author Posted March 23, 2009 I tried that, but it still isn't working. When I try to download the Malware Bytes, it will download off of a site, but it won't "run" after the .exe is downloaded. When I try the SUPERanti-spyware, it will download the .exe, but it has an error when I try to run it. I appreciate the help. Quote
canes1711 Posted March 23, 2009 Author Posted March 23, 2009 Also, the TDSS.aru doesn't show up in the processes when I hit ctrl-alt-del. Quote
Match Posted March 23, 2009 Posted March 23, 2009 are you running any other antivirus/spyware programs at the same time? if so disable them first then try the disinfection procedure. I appreciate the help. Sorry this is not going as planned but bare with us and we will get there :) Quote
canes1711 Posted March 23, 2009 Author Posted March 23, 2009 That's fine. I'll try it again while turning them off. Quote
Tootech Posted March 23, 2009 Posted March 23, 2009 but it won't "run" after the .exe is downloaded If that doesn't work, try renaming the Malwarebytes download to something like m.exe, and run the renamed file. Quote
canes1711 Posted March 23, 2009 Author Posted March 23, 2009 Ok, MalwareBytes is now downloaded, but when I try to run the actual program (in normal mode), it just won't start. It won't get to the scanning part. Quote
canes1711 Posted March 24, 2009 Author Posted March 24, 2009 Okay, it is now running. I went to How to remove trojan TDSSserv (TDSSserv.sys), clbdriver.sys and seneka.sys | My Anti Spyware and apparently I had the TDSSserv trojan, which blocked the MalwareBytes. I followed the instructions, and now, Malware is running. Quote
canes1711 Posted March 24, 2009 Author Posted March 24, 2009 Okay, I've been through the spyware scans, and I'm running them through a second quick scan to make sure they get everything. Then, I'll do the virus scan, but it seems to be working. I notice my internet is running much faster. Also, this error comes up saying quickset.exe is not running properly or at all. Should I get some sort of Registry Fixer, and if so, which one? Quote
canes1711 Posted March 24, 2009 Author Posted March 24, 2009 Okay, when I got to the Start > Run for the Cleanmgr, it asks for the drive, which I assume is C. And then it starts to calculate how much space can be saved, at which point I hit cancel. Is that what it's supposed to do? Quote
RandyL Posted March 24, 2009 Posted March 24, 2009 canes under no circumstance run any type of registry fixer or registry cleaner of any sort. Run the rest of the scans as suggested. quickset.exe is a process belonging to Dell computers which allows you to access power management diagnostics and settings. It probably isn't needed to be run at startup and can be disabled via the icon in the system tray. If you want it you should be able to download it from the Dell site and reinstall it. I fail to see how Cleanmgr relates to this issue but yes that is what it is supposed to do. Finish with the issues at hand like the scans before moving on to unrelated issues like cleaning your temp files. Wishing you luck. Quote We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.Get help with computer problems. Join Free PC Help here Donations are welcome. Read Here
canes1711 Posted March 24, 2009 Author Posted March 24, 2009 Fair enough. Thanks for all the help. Everything is running much, much smoother now. Quick Question -- I have Ad-Aware, MalwareBytes, and Super Anti-Spyware. Should I get rid of any of them? Which should I keep? Quote
maynardvdm Posted March 24, 2009 Posted March 24, 2009 Hi Keep Super Anti-Spyware and Malwarebytes and run them once a week. Quote We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs. RaidMax Smilodon Gaming Case | Gigabyte Z77X-UD5H M/B | Intel Core i5 3570K @ 3.4GHz | 8GB Corsair RAM | Nvidia GTX550 Ti 1GB GDDR5 | Corsair 800w PSU Register for FREE >>here<< | If we have helped you, please consider a donation >>here<< SAS | MBAM | WinPatrol | Avira | ERUNT | Nvidia Drivers http://i285.photobucket.com/albums/ll57/mjsmileys/userbarnew4sec.gif
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.