31
Re: ANOTHER TDSS SUFFERER on Tue Apr 13, 2010 12:04 pm
DragonMaster Jay
Site Owner

The px***.sys files are legitimate. After further investigation, they are required for Windows to boot.
We can go with a reformat and reinstall, to help rid the infection and replace all of the system files lost.
Or, those px***.sys files will have to be found on the OS disc or at a remote location and replaced.
See the problem you were having, in which I discovered immediately, was that TDSS was making a backup each time it re-infected your computer. Once it was removed, it then restored the infection from its backup. Rootkits have primary system control, in which they can manipulate infections and hide them from existence.
TDSS is used by hackers to gain full system access in order to launch attacks across the internet or cause the system to be manipulated to generate income for the malware writer.
My plan was to find where the backup was, then delete that and the infection at the same time.
Also, could be that your system was infected by a newer variant of Virut, which is a file-patching virus that infects core system files with malware, and attempts to take control of your computer.
We can go with a reformat and reinstall, to help rid the infection and replace all of the system files lost.
Or, those px***.sys files will have to be found on the OS disc or at a remote location and replaced.
See the problem you were having, in which I discovered immediately, was that TDSS was making a backup each time it re-infected your computer. Once it was removed, it then restored the infection from its backup. Rootkits have primary system control, in which they can manipulate infections and hide them from existence.
TDSS is used by hackers to gain full system access in order to launch attacks across the internet or cause the system to be manipulated to generate income for the malware writer.
My plan was to find where the backup was, then delete that and the infection at the same time.
Also, could be that your system was infected by a newer variant of Virut, which is a file-patching virus that infects core system files with malware, and attempts to take control of your computer.
..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner

Kaspersky Anti-Virus 2012: Click HereContribute/donate to our site















