6/4/2011
I just edited my 4/14/2011 description. I had you trying to download updates in safe mode.
4/30/2011
When your system is clean, I like to turn off Super Anti-Spyware. It is usually worthwhile to update and run Malwarebytes once a month.
The above rootkit instructions are for a bad infection. If your system is not crippled, but just limping, then you may just want to run Malwarebytes.
If you choose to install AVG Free as your anti-virus, then I prefer to install the minimal configuration. Let me know if I need to describe this better. - Mike
General Root Kit and Bad Infection Procedures
Offline and in Safe Mode
Run Kaspersky TDSS Root Kit Killer
Run rkill.com, then install and run Super Anti-Spyware (without updates)
Reboot to normal mode, run rkill.com, install updates for Super Anti-Spyware.
Reboot to safe mode, run rkill.com, run Super Anti-Spyware.
Reboot to safe mode and run all again.
Make sure to run rkill.com after every reboot, until you are finished cleaning.
When all is clean you will probably need to re-install your virus killer and reset things like Homepage and wallpaper.
http://support.kaspersky.com/downloads/utils/tdsskiller.exe
http://download.cnet.com/RKill/3000-8022_4-11464676.html
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
When your system is clean, I like to turn off Super Anti-Spyware.
The above rootkit instructions are for a bad infection. If your system is not crippled, but just limping, then you may just want to run Super Anti-Spyware.
If you choose to install AVG Free as your anti-virus, then I prefer to install the minimal configuration. Let me know if I need to describe this better. - Mike
7/27/2012
I removed Malwarebytes from the above procedures
I am told that Super Anti-Spyware is good enough to use by itself, so you do not need to use Malwarebytes anymore. This seems to be working for me, but I have not encountered any serious infections since I have quit using Malwarebytes.
How I killed tdss.c mem rootkit - 4/14/2011
Offline and in Safe Mode
Run Kaspersky TDSS Root Kit Killer
Run rkill.com, then run Malwarebytes and Super Anti-Spyware (both without updates)
Reboot to normal mode, run rkill.com, install updates for Malwarebytes and Super Anti-Spyware.
Reboot to safe mode, run rkill.com, run Malwarebytes and Super Anti-Spyware.
Reboot to safe mode and run all again.
Make sure to run rkill.com after every reboot, until you are finished cleaning.
When all is clean you will probably need to re-install your virus killer and reset things like Homepage and wallpaper.