Very useful video. I had TDL4@MBR on my main home computer. AVG free and Malewarebytes did not find it. GMER found it, but when trying to remove I got BSOD. Kaspersky TDSSkiller got it and now I have my computer back!
But what do I now do with the half dozen thumbdrives that have "setup50045.fon, setup50045.lnk, autorun.inf, myporno.avi.lnk, pornmovs.lnk" on them? How do I clean them up???
TDL4 will rewrite the Default MBR code....this has to replaced with a standard MBR using a repair disk or MBRCheck....It is to be noted that Dell has a different MBR code and it will be dangerous to replace the code since if replaced the Access to recovery will be lost...u will have to fix it with DSRFix....tdsskiller wil cure the The rootkit on the computer but it may fail in some conditions...so dell users have two options...either a factory restore through the DSR or to hav contd infectn
My g/f had this on her Sony VAIO laptop and the virus disabled .exe files, so TDSSKiller wouldn't run!!!
In the end, the only way to run it was by putting it on a Memory Stick from a clean computer, CHANGE ITS NAME!! (To K.com or anything really), insert the memory stick into the infected comp and RUN IT FROM THAT LOCATION.
This was the ONLY way i could get this amazing tool to do its job.
(There's a reg file called FixNCR.reg which will change the .exe corruption back too)
I spent some time online trying different options to remove this annoying virus from my PC without success. TDSS Killer found and removed it straight away. Thanks very much.
you will see that this is the reason that you still have the virus after using fixmbr, because you did not use the proper syntax. you can find the proper syntax by typing "map" in the recovery console prompt before using your fixboot and fixmbr commands
you have used the wrong syntax for fixmbr. the proper use is fixmbr \device\harddisk\partition where the first hard drive is "harddisk0" and so on, and where the first partition is "partition0" and so on. you do not just type fixmbr. that does absolutely nothing really... first partition on the first hard drive would be as follows: fixmbr \device\harddisk0\partition0 every partition has an mbr, so it is necessary to fix every mbr, not just one...
Brian Krebs of Krebs on Security dot com has a great blog post today "Who’s Behind the TDSS Botnet?" showing some amazing research he's conducted in an effort to out the TDSS author. Based on the target's actions since Krebs posted the article, it appears that Krebs is on the right track. The target immediately started trying to shutdown all of his Internet accounts, including his Live Journal and YouTube accounts. Unfortunately for the Target, Fizot, Krebs saved screenshots of everything.
MSE finds this virus on my PC. HitmanPro, TDSS Killer, GMER.exe, Malwarebytes and Spybot S&D all do not find this virus. MBRCheck.exe tells me I have standard MBR. Do I still have it or not? MSE would find it and 'remove' it but it kept coming back on reboot. However, I have no effects of the virus. I don't get redirected, I can still open antivirus applications/websites etc.
Oh and by the way does Malwarebytes and Microsoft Essentials work against this virus? cuz that's what I've used for viruses before, so if those aren't as good as the ones you mentioned on the video let me know please...I appreciate your help thanks.
does using the boot up cd for windows xp procedure you did delete the information you have on your hard drive?...I'm looking into doing a different procedure where I'm buying an adapter for sata/ide/pata hdd to usb connection to use on a different computer and use the antivirus there to get rid of the virus and then put the hdd back on my pc, idk if that will work...and unfortunately my pc didn't come with a boot up cd, so Idk where to buy a windows xp booting cd, any recommendations?
Great video. Just one question--is it best to have the four scanning tools you mentioned already downloaded to your harddrive before any trouble is noticed?
If I'm infected and got the black screen in the beginning of the video, can I use the system repair disc that I made in the "Backup and Restore" section in Windows 7? I don't have a Windows CD.
Cool video, Thanks. Can you look at this new malware that bleeping computer wrote about. it uninstalls your current antivirus program. When it is done uninstalling your antivirus software it will reboot back into normal Windows mode and display alerts that appear to be from your security software so that you think it is still installed and working properly. Security researcher Xylitol recently wrote an article about the new malware.
I had TDL3 a few years ago infecting atapi.sys and no tool could remove it... but format c: and DriveImageXML saved me :P
m4dn3ss999 1 month ago
Excellent video! tdl4 is HELL to get rid of; great, brief, solution!!
MrT6bill 1 month ago
Very useful video. I had TDL4@MBR on my main home computer. AVG free and Malewarebytes did not find it. GMER found it, but when trying to remove I got BSOD. Kaspersky TDSSkiller got it and now I have my computer back!
But what do I now do with the half dozen thumbdrives that have "setup50045.fon, setup50045.lnk, autorun.inf, myporno.avi.lnk, pornmovs.lnk" on them? How do I clean them up???
chuckmerja 1 month ago
Great Tutorial. Thanks
Th3AngestK1d 2 months ago
thank u
virolo89 2 months ago
u save my computer this its awsome
virolo89 2 months ago
Hi Brian,
Once again you saved my laptop, you never fail.
Thank you
dmaher2007 3 months ago
My sis' laptop had this and a simple scan with tdss killer fixed everything up. Thanks a bunch!
xLan7 3 months ago
Hi!
TDL4 will rewrite the Default MBR code....this has to replaced with a standard MBR using a repair disk or MBRCheck....It is to be noted that Dell has a different MBR code and it will be dangerous to replace the code since if replaced the Access to recovery will be lost...u will have to fix it with DSRFix....tdsskiller wil cure the The rootkit on the computer but it may fail in some conditions...so dell users have two options...either a factory restore through the DSR or to hav contd infectn
12345shre 4 months ago
This has been flagged as spam show
My g/f had this on her Sony VAIO laptop and the virus disabled .exe files, so TDSSKiller wouldn't run!!!
In the end, the only way to run it was by putting it on a Memory Stick from a clean computer, CHANGE ITS NAME!! (To K.com or anything really), insert the memory stick into the infected comp and RUN IT FROM THAT LOCATION.
This was the ONLY way i could get this amazing tool to do its job.
(There's a reg file called FixNCR.reg which will change the .exe corruption back too)
GuyMagicFingers 4 months ago
Касперский что своё говно и зарубеж толкает? я в шоке)
360Gradusov 4 months ago
I spent some time online trying different options to remove this annoying virus from my PC without success. TDSS Killer found and removed it straight away. Thanks very much.
jkingi161168 5 months ago
@jkingi161168 Your welcome glad i could help.
Britec09 5 months ago
you will see that this is the reason that you still have the virus after using fixmbr, because you did not use the proper syntax. you can find the proper syntax by typing "map" in the recovery console prompt before using your fixboot and fixmbr commands
getoffwithitalready 5 months ago
you have used the wrong syntax for fixmbr. the proper use is fixmbr \device\harddisk\partition where the first hard drive is "harddisk0" and so on, and where the first partition is "partition0" and so on. you do not just type fixmbr. that does absolutely nothing really... first partition on the first hard drive would be as follows: fixmbr \device\harddisk0\partition0 every partition has an mbr, so it is necessary to fix every mbr, not just one...
getoffwithitalready 5 months ago
another great vid
wtbm123 5 months ago
Brian Krebs of Krebs on Security dot com has a great blog post today "Who’s Behind the TDSS Botnet?" showing some amazing research he's conducted in an effort to out the TDSS author. Based on the target's actions since Krebs posted the article, it appears that Krebs is on the right track. The target immediately started trying to shutdown all of his Internet accounts, including his Live Journal and YouTube accounts. Unfortunately for the Target, Fizot, Krebs saved screenshots of everything.
BigMurano 5 months ago
I've used all these programs and only once it was found, but now no program finds it or any variants. Idk what to do now..
BakuhatsuShojo 5 months ago
top man, worked 1st time using the bitdefender option.... thanx thanx & THANX again.... ;)
rainbow2010rainbow1 5 months ago
MSE finds this virus on my PC. HitmanPro, TDSS Killer, GMER.exe, Malwarebytes and Spybot S&D all do not find this virus. MBRCheck.exe tells me I have standard MBR. Do I still have it or not? MSE would find it and 'remove' it but it kept coming back on reboot. However, I have no effects of the virus. I don't get redirected, I can still open antivirus applications/websites etc.
dominiccss 5 months ago
Oh and by the way does Malwarebytes and Microsoft Essentials work against this virus? cuz that's what I've used for viruses before, so if those aren't as good as the ones you mentioned on the video let me know please...I appreciate your help thanks.
ferrodriguez10 6 months ago
does using the boot up cd for windows xp procedure you did delete the information you have on your hard drive?...I'm looking into doing a different procedure where I'm buying an adapter for sata/ide/pata hdd to usb connection to use on a different computer and use the antivirus there to get rid of the virus and then put the hdd back on my pc, idk if that will work...and unfortunately my pc didn't come with a boot up cd, so Idk where to buy a windows xp booting cd, any recommendations?
ferrodriguez10 6 months ago
are you able to run any tools(tdsskiller,etc.) before running fixboot and fixmbr?
mike91342 6 months ago
@mike91342 you might get a chance to scan with tools if you know you have the infection, but black screen happened when I rebooted.
Britec09 6 months ago
Great video. Just one question--is it best to have the four scanning tools you mentioned already downloaded to your harddrive before any trouble is noticed?
wns67 6 months ago
@wns67 it wont hurt
Britec09 6 months ago
Britech, you are simply one of the best...I thank you for your videos !!
IcaroChacal 6 months ago
@IcaroChacal thanks alot for your kind words
Britec09 6 months ago
people like britech have become rare so it seams ..great service! thank you A+
great tutor site
lllraverslll 6 months ago
@lllraverslll Thanks
Britec09 6 months ago
In enjoyed the Video! Especially the RootKits and RamsomWare!
mooselexus 6 months ago
Bang on as usual Brian. A lot of people don't realize that doing this sort of thing is very time consuming. Much appreciated :-)
smallpebble7 6 months ago
@smallpebble7 Your welcome mate.
Britec09 6 months ago
Thanks Brian. Another great video.
mitchman5155 6 months ago
are these all free tools
hardcore4d4 6 months ago
@hardcore4d4 Yes they are all FREE
Britec09 6 months ago 2
Awesome thanks Brian.
Zendukai 6 months ago
Thank you for such an excellent post
erkamalmander 6 months ago
Great tutorial as always - Thanks Brian..
OmenX13 6 months ago
Excellent Information....Ill be sure to send people your way.
Energy321com 6 months ago
Excellent video Brian, You sure taught me some new methods of removing these nasty things. Cheers.
MrXidus 6 months ago
If I'm infected and got the black screen in the beginning of the video, can I use the system repair disc that I made in the "Backup and Restore" section in Windows 7? I don't have a Windows CD.
hahacify 6 months ago
@hahacify If you made a Backup copy on a Disc...then you should be able to do a restore of the system... yes
Britec09 6 months ago
Cool video, Thanks. Can you look at this new malware that bleeping computer wrote about. it uninstalls your current antivirus program. When it is done uninstalling your antivirus software it will reboot back into normal Windows mode and display alerts that appear to be from your security software so that you think it is still installed and working properly. Security researcher Xylitol recently wrote an article about the new malware.
yodabadass 6 months ago
@yodabadass yeah thats the Trojan.FakeAV.LVT virus I will see if i can get a copy and do a video on it.
Britec09 6 months ago
Another well explained vid, you do save us all from the nasty stuff on the net. Takes time to do this and we all thank you two thumbs up.
shammon1 6 months ago 7
@shammon1 Thanks mate... and your right it does take time, it did not work out how I wanted, but it was ok.
Britec09 6 months ago
Does the recovery console need to be pre-installed?
Kurio71 6 months ago
@Kurio71 you use a windows cd
Britec09 6 months ago
Another great tutorial Brian. More porn huh. lol
capman911 6 months ago