We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Serious Virus Blocking My Virus Checkers

Options
24

Comments

  • Post a hijack this log

    Click here to download HijackThis.
    Save HJTInstall.exe to your Desktop.
    Double click on the HJTInstall.exe icon to start the program.
    By default it will install to C:\Program Files\Trend Micro\HijackThis
    After the final dialogue box it will launch HijackThis.

    Click on the scan button. It will scan and then ask you to save the log.
    Save the log, and post me it in your next reply.
  • anno1664
    anno1664 Posts: 108 Forumite
    I ran Dr Web Cure It and this is the report I got

    tdssserv.sys;c:\windows\system32\drivers;BackDoor.Tdss.14;Deleted.;RegUBP2b-user1.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;A0020880.reg;C:\System Volume Information\_restore{642D9D69-2210-4F79-98A6-DFC7A8DAA7A6}\RP243;Trojan.StartPage.1505;Deleted.;A0022155.reg;C:\System Volume Information\_restore{642D9D69-2210-4F79-98A6-DFC7A8DAA7A6}\RP266;Trojan.StartPage.1505;Deleted.;A0022547.reg;C:\System Volume Information\_restore{642D9D69-2210-4F79-98A6-DFC7A8DAA7A6}\RP281;Trojan.StartPage.1505;Deleted.;flash.inf;C:\WINDOWS\Downloaded Program Files;Trojan.DownLoader.3634;Deleted.;tdssl.dll;C:\WINDOWS\system32;BackDoor.Tdss.7;Deleted.;tdsslog.dll;C:\WINDOWS\system32;Trojan.Sespy.13;Deleted.;tdssserf.dll;C:\WINDOWS\system32;Trojan.Fakealert.1304;Deleted.;TDSS4753.tmp;C:\WINDOWS\Temp;BackDoor.Tdss.14;Deleted.;

    I can now connect to avg and other virus sites, so it seems to have done the trick. But I have a couple of questions

    1. What caused the problem
    2. What do I now do with Dr web cure it that is on my pc. Do I leave it or delete it
    3. Can I now carry out scans with AVG, Spybot and Ad-aware, and if so in what order

    Finally a big thank you to all for some excellent advice, it is well appreciated
    £2008 in 2008 Member No. 689 : £962.29 to go
    Feb - £200 March - £90.30 April - £76 May - £141.43 June - £82 - July - £101.28 - Sept £304 :DOct - Hair Paste £20.70 USB Hub Mouse Mat £10
  • Your choice on Dr Web - it's free and if you decide to run it again it will ask to update anyway.

    I would run malware bytes just to see what it picks up.

    Malware Bytes

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
    • On the Scanner tab:
      • Make sure the "Perform Quick Scan" option is selected.
      • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.
    • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report in your next reply and exit MBAM.
    Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.
  • anno1664
    anno1664 Posts: 108 Forumite
    I ran MalawareBytes and the following is the report generated

    Malwarebytes' Anti-Malware 1.28
    Database version: 1258
    Windows 5.1.2600 Service Pack 3
    11/10/2008 22:29:18
    mbam-log-2008-10-11 (22-29-18).txt
    Scan type: Quick Scan
    Objects scanned: 50695
    Time elapsed: 13 minute(s), 25 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 12
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 13
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_CLASSES_ROOT\Interface\!!8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb} (Adware.EGDAccess) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\!!093f9cf8-0de1-491c-95d5-5ec257bd4ca3} (Adware.EGDAccess) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\!!1eb17d1c-141d-4d9d-91cb-24d99215851d} (Adware.EGDAccess) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\RX ToolBar (Adware.RXToolbar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" /s) Good: ("%1" /S) -> Quarantined and deleted successfully.
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    C:\WINDOWS\system32\ustart.exe (Adware.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\_005105_.tmp.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\_005136_.tmp.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tdssserf1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Downloaded Program Files\dtc32.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
    C:\WINDOWS\Downloaded Program Files\netia32.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
    C:\WINDOWS\tmlpcert2005 (Adware.EGDAccess) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mswbm32.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\TDSSerrors.log (Trojan.TDSS) -> Quarantined and deleted successfully.

    From the two reports I have now posted can you see what my problem was.
    Also why did AVG, Spybot, Ad-Aware and CC cleaner not pick any of it up
    £2008 in 2008 Member No. 689 : £962.29 to go
    Feb - £200 March - £90.30 April - £76 May - £141.43 June - £82 - July - £101.28 - Sept £304 :DOct - Hair Paste £20.70 USB Hub Mouse Mat £10
  • anno1664
    anno1664 Posts: 108 Forumite
    After all the troubles I have had, I would like to thank everyone for the time and effort they took in sorting out my problems. Thank you

    I do though have one final question for you all:

    I now have loaded on my PC

    1. AVG antivirus
    2. SpyBot Search & Destroy
    3. Ad-Aware
    4. CC Cleaner
    5. Dr.Web CureIt
    6. Malware Bytes Anti Malware

    Which ones should I keep
    Which, if any should I delete
    How often should I run what is kept
    £2008 in 2008 Member No. 689 : £962.29 to go
    Feb - £200 March - £90.30 April - £76 May - £141.43 June - £82 - July - £101.28 - Sept £304 :DOct - Hair Paste £20.70 USB Hub Mouse Mat £10
  • Because you have TDS...entries It may be worth running SDFix to ensure you have got rid of everything.

    Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

    Please download SDFix by AndyManchesta and save it to your desktop.
    When using this tool, you must use the Administrator's account or an account with "Administrative rights"
    • Double click SDFix.exe and it will extract the files to %systemdrive%
    • (this is the drive that contains the Windows Directory, typically C:\SDFix).
    • DO NOT use it just yet.
    Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Open the SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Copy and paste the contents of the results file Report.txt in your next replyalong with a new HijackThis log.
    -- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
    Please go to Start Menu > Run > and copy/paste the following line:
    %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
    Press Ok and then run SDFix again.

    -- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
    %systemdrive%\SDFix\apps\FixPath.exe /Q
    Reboot and then run SDFix again.

    -- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
    %SystemRoot%\system32\cmd.exe


    In answer to your question I do not know what the cause was.
  • anno1664
    anno1664 Posts: 108 Forumite
    The report from SDFix is too long to post here?

    But can someone please answer the following
    I now have loaded on my PC

    1. AVG antivirus
    2. SpyBot Search & Destroy
    3. Ad-Aware
    4. CC Cleaner
    5. Dr.Web CureIt
    6. Malware Bytes Anti Malware
    7. SDFix

    Which ones should I keep
    Which, if any should I delete
    How often should I run what is kept
    £2008 in 2008 Member No. 689 : £962.29 to go
    Feb - £200 March - £90.30 April - £76 May - £141.43 June - £82 - July - £101.28 - Sept £304 :DOct - Hair Paste £20.70 USB Hub Mouse Mat £10
  • There is nothing wrong with having multiple anti spyware/malware software on your computer as it gives you more protection. It is only recommended to have 1 anti-virus software however, which you have with AVG :)

    I would run a full scan weekly and a quick scan daily at the very least.
  • Browntoa
    Browntoa Posts: 49,602 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    post the log in sections for us
    Ex forum ambassador

    Long term forum member
  • anno1664 wrote: »
    The report from SDFix is too long to post here?

    But can someone please answer the following
    I now have loaded on my PC

    1. AVG antivirus
    2. SpyBot Search & Destroy
    3. Ad-Aware
    4. CC Cleaner
    5. Dr.Web CureIt
    6. Malware Bytes Anti Malware
    7. SDFix

    Which ones should I keep
    Which, if any should I delete
    How often should I run what is kept

    They can all remain on your computer. I would however, once you are clean, remove 3 and 7. That is my own opinion and other would disagree. Run weekly if you want.

    The SDFix log - can you post it in two?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.