|
#11
|
|||
|
|||
|
Quote:
Good luck and keep us posted. Have you tried renaming TDSS to something like explorer.exe? I have put it in the startup folder on occasion and sometimes it will run as the oprating sytem is loading......hopefully before it gets blocked.
__________________
Harold ACS Alternative Computer Solutions |
|
#12
|
|||
|
|||
|
Glad I'm not the only one that noticed that. I had 4 calls today about the same stupid virus. SMART HDD. Luckily it is easy to remove and clean up after but jeez it was odd.
|
|
#13
|
|||
|
|||
|
The absolute best approach IMO is to boot to a WinPE build and run TDSSKiller from within WinPE. Configure it to only scan Boot Sectors and TDSS File System.
__________________
-Steve Born a technician, though always willing to learn and improve. :) Managing Editor, DigitalChumps.com Senior Editor, Notebookcheck Owner/Sole Proprieter, Triple-S Computers |
|
#14
|
|||
|
|||
|
I've yet to see a redirect combofix didn't kill.
|
|
#15
|
||||
|
||||
|
I would have to agree, it's been about the same for me.
|
|
#16
|
||||
|
||||
|
I've seen it fail to clean some in the past...and this one is added to the list...redirects still happening even after running combfix.
Will see what happens Monday...hopefully MWB or SAS will have updated definitions to deal with this new variant.
__________________
Resident "Geek on a Harley" doing IT in Southeast Connecticut http://www.dynamic-alliance.com/ https://www.facebook.com/YeOldeStonecat |
|
#17
|
||||
|
|
||||
|
have you tried hitmanpro it has found redirects in the past for me
|
|
#18
|
|||
|
|||
|
I've been seeing alot more lately when in the same situation its a rootkit hidden in an small partition tacked on to the end of the drive that is set to hidden and boot last one was only 1 meg large. Used partition magic to delete grow the main drive over the now unused space and set the boot flag on the right partition. After this all the tools that wouldn't run work just fine. Hope this might help.
|
|
#19
|
|||
|
|||
|
Quote:
You can also use partitioning software to do it though and then set the System Reserved partition as Active (if it's Windows 7). You have to be careful not to end up here however: http://triplescomputers.com/blog/?p=81
__________________
-Steve Born a technician, though always willing to learn and improve. :) Managing Editor, DigitalChumps.com Senior Editor, Notebookcheck Owner/Sole Proprieter, Triple-S Computers |
|
#20
|
|||
|
|||
|
Quote:
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|