Author Topic: help system restore.dll file infected by win32:worm  (Read 4555 times)

0 Members and 1 Guest are viewing this topic.

gh.ankit

  • Guest
help system restore.dll file infected by win32:worm
« on: January 10, 2009, 09:47:43 AM »
guys i am in a great trouble a virus has blocked system restore function in xp pro sp2 and has infected C:/ drive i am having the following problems:

1. i am unable to do a system restore by any software nor by windows default ..

2. i am unable to fix my root drive c:/ errors by properties>tools>chek disk for error

3.every time i run ccleaner or avast root kit and error message pops up  at the bottom and  shows that these files are corrupt.

4. i did a boot time scan with avast home edition it found those files as infected :

C:/Windows/System32/driver/msqpdxoyotptts [Infected by Win32:Root sec ]

C:/Windows/System32/driver/msqpdxmyktevxesys [Infected by Win32:Root sec ]

C:/Windows/System32/msqpdxdwtjncrqdl [Infected by Win32:fasesc

and sysrestore.dll file infected by win32:worm


avast home edition 4 is not able to fix this problem it is showing error
 
i even tried with avast rootkit scanner but it gives error -"c:drive could not be opened"


help guys i am unable to fix this problem and even cannot restore the sysytem if any critical fault happens

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: help system restore.dll file infected by win32:worm
« Reply #1 on: January 10, 2009, 04:51:10 PM »
what is your filesystem? have you tried some 3rd party apps to fix possible bugs on your HDD?

Win32 Virut Helper

  • Guest
Re: help system restore.dll file infected by win32:worm
« Reply #2 on: January 12, 2009, 09:22:45 PM »
System restore will not help you.

And yes it did do this to me. Read my How to removes Win32.Virut this should be very helpful in your case.

Offline essexboy

  • Malware removal instructor
  • Avast √úberevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help system restore.dll file infected by win32:worm
« Reply #3 on: January 12, 2009, 09:26:32 PM »
This third party ap will clear the malware as this is one of the latest variants of the TDSS rootkit

Download Combofix from any of the links below. You must rename it before saving it.  Save it to your desktop.

Link 1
Link 2
Link 3





--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.