I get the error message "Windows cannot access the specified device, path, or file. Memory Forensics String Context Stream UID http://nsis.sf.net/nsis_error Domain/IP reference 00023708-00003216-18359-303-00402C72 http://www.nirsoft.net Domain/IP reference 00039359-00003628-44908-120-00401000 Extracted Strings Search All Details: Download All Memory Strings (55KiB) All Strings (/4999) Interesting (/4506) 7768D2C4B3C64BDD023378289625799C80E54D06F9A4077427EABC609EEEF355.exe:3216 (/368) Read more Answer:Rootkit.Win32.TDSS.d (infected atapi.sys driver) Hi,With the information you have provided I believe you will need help from the malware removal team. it's very easy(I use XP btw) anyway, I opened up control panel → Scheduled tasks and deleted everything from there(except 'add new task') just thought I'd share the info, since many

Logs from malware removal programs (OTL is one of them) can take some time

Here is the log from then (28th Aug):[/color][/color]-----------------------------------------------------------------------------------------------------------------------------------------------Malwarebytes' Anti-Malware 1.40Database version: 2709Windows 5.1.2600 Service Pack 328/08/2009 18:07:25mbam-log-2009-08-28 (18-07-25).txtScan type: Full Scan (C:\|)Objects scanned: 165024Time elapsed: 36 minute(s), 47 second(s)Memory Processes Infected:

Tried the TDSSKiller from kaspersky, and it detects the rootkit, but while it says reboot to delete, its detected anyway after the reboot.In safe mode, as well as safe mode with

Malicious Indicators 5 External Systems Sample was identified as malicious by at least one Antivirus engine details 1/53 Antivirus vendors marked sample as malicious (1% detection rate) source External System relevance

Malware bytes & Spybot S&D show a clean scan when run. Extracted Strings Search All Details: Download All Memory Strings (276B) All Strings (/5000) Interesting (/4840) List.bat.bin (/4970) cmd.exe (/1) screen_0.png (/24) screen_1.png (/5) "%CommonProgFiles%\companion wizard*" Ansi based on Hybrid Analysis (List.bat.bin)

Ansi based on Image Processing (screen_3.png) '0_____ Ansi based on Image Processing (screen_3.png) '5BFJjlR$Kl Ansi based on Memory/File Scan (7768D2C4B3C64BDD023378289625799C80E54D06F9A4077427EABC609EEEF355.exe.bin) '_,,___" Ansi based on Image Processing (screen_3.png) '[email protected]+ Ansi based on A Symantec Antivirus full scan failed to complete and now I cannot run it.

It fails soon after starting the full scan and I can no longer launch it (I get the same error message as that for Symantec Anti-Virus) without reinstalling it.

7 more replies Relevance 87.58% Question: TDSS-like rootkit; google redirect, reinstall after TDSS-Killer Hello; this is my first post to this forum so I hope I am following all

It flagged 2 other files as having the same trojan, but said the object was inacc ERROR The requested URL could not be retrieved The following error was encountered while trying Got the computer back, but still being hyjacked. However, it appears that my driver atapi is infected by TDSS rootkit even after Malwarbyte, AVG, SpyBot and Superantispyware show no infections.

I cannot run GMER since it crashes everytime.DDS (Ver_10-03-17.01) - NTFSx86 Run by Boutwell at 22:25:35.21 on Tue 04/06/2010Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_18Microsoft?

TDSS rootkit infection Hello.Yes, you seem to be infected with the newer TDSS variant.

Home Premium 6.0.6001.1.1252.44.1033.18.1915.860 [GMT 1:00].AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}.============== Running Processes ===============.C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\Microsoft.Net\Framework\v3.0\WPF&... Windows Vista Firewall has always been on.I usually spend about 40% of my time in Windows, with 60% in Ubuntu, going online through both.My system is not exhibiting any of the TDSS Killer failed. I am unable to turn on the Windows Firewall.Update: AVG just popped up saying it picked up a Trojan horse generic19.AHPV in C:\Windows\Fonts\lmW03Qk.com - it sent it to the vault.

Analysed 22 processes in total (System Resource Monitor). 7768D2C4B3C64BDD023378289625799C80E54D06F9A4077427EABC609EEEF355.exe (PID: 3216) NirCmd.cfxxe exec hide C:\32788R22FWJFW\PEV.cfxxe RIMPORT C:\32788R22FWJFW\EXE.reg (PID: 3628) pev.cfxxe C:\32788R22FWJFW\PEV.cfxxe RIMPORT C:\32788R22FWJFW\EXE.reg (PID: 4012) iexplore.exe win close ititle "System Tool" Windows Vista? My PC got infected with the virtumonde trojan. DDS log below.

After quite a bit of work (and many nasty pop ups) I thought I got it cleaned up mainly using Malwarbyte's Anti-Malware, .

TDSS Killer failed. MalwareBytes AntiMalware runs, but closes after 2 seconds, then the executable won't run again, error message stating "you may not have sufficient privileges to run the specified file".