Also, if you still have difficulties after following the comments above, try downloading ComboFix to another machine, then into a USB memory stick (or equivalent). Rename it and then connect it to the infected machine.
Main Topics
Browse All TopicsAd-aware AE reports win32 trojan tdss, says it fixed it and requires a reboot.
After reboot it is still there.
Downloaded combofix.exe but after double clicking nothing happens.
Any idea how to fix this?
Rolf
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hey Install AVG ROOTKIT http://www.softpedia.com/g
and run the scan....this will sure help you :)
as advised above Combofix should be able handle this infection, if this did not work for some reason, I found the below method posted on Malwarebytes forum straightforward and effecient at cleaning this particular infection, the idea is to allow the user to remove the main rootkit component using a tool like RootRepeal , then allow Malwarebytes antimalware to clean the leftovers, this routine has proven the only way to go when running Combofix is not possible,e.g. Vista problems or Windows 2003 server ,etc..
http://www.malwarebytes.o
Note:
Hi rolfg :... well i have faced that TDSS trojan problem on my computer..
I have malwarebytes also installed on my computer..but it doesn't remove the virus completly..as soon as you reboot your computer the virus will com again...so that is why i have given the perfect solution of installing AVG ROOTKIT...which completly removed that virus.. from the computer ...
For AVG ROOTKIT go here http://www.softpedia.com/g
That's good, and you'll see that the ComboFix log has several "Other Deletions" of infection(s).
Although perhaps not a problem, you may well have some Spyware remaining .. for example, this entry>>
c:\program files\Lx_cats
It's in the "Find3M Report". Assume you are running a Lexmark product?
Details>http://homerun-netw
You could try downloading, then updating Malwarebytes' Anti-Malware (already suggested by Admin3k):
http://www.malwarebytes.or
Superantispyware:
http://www.superantispywar
There's also a-squared Free:
http://www.emsisoft.com/en
Have quickly studied the remainder of the Combo log & it may well be okay .. have to logoff for the night ... perhaps IndiGenus would like to comment more .. if not, i'll be around at first light ..
There are some things that should still be dealt with here. The sysaudio.sys infection is covered nicely by Miekiemoes in her blog.
http://miekiemoes.blo
T
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------
File::
C
Registry:
[HKEY_LOC
"aux2"=-
[HKLM\~\se
"135:
"500
"5
"5002:TCP"
"5003:TC
"5004:
"500
"5
"5007:TCP"
"5008:TC
"5009:
"501
"5
"5012:TCP"
"5013:TC
"5014:
"501
"5
"5017:TCP"
"5018:TC
"5019:
"502
--
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
5. After reboot, (in case it asks to reboot), please upload the following reports/logs.
-Combofix.txt
Once again it appears clean, at least the sysaudio.sys infection seems to be gone, but maybe Indigenus will have further comments.
When you have finally finished with ComboFix, you can uninstall it as follows >
Start > Run > then type "ComboFix /u" (with no quotes, and space between x and / )
Then hit enter. This will uninstall ComboFix, reset your clock settings, re-hide system hidden files, re-hide the file extensions and reset System Restore.
Business Accounts
Answer for Membership
by: IndiGenusPosted on 2009-07-28 at 18:09:56ID: 24966527
Delete the version of combofix you have now, then renaming combofix to combo-fix.exe, before downloading it. Try again and that should allow it to run. Attach the log, there may be more.