We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

possible virus backdoor tidserve!inf!

Options
Hello

I am very non-techie and am hoping someone can help me here.
I recently forwarded an e-mail fat lady calendar to a friend and he tells me that he got the above virus on his computer. A real techie person identified it and took some time to remove it for him.
I am on windows XP with the free version of AVG for protection. I have carried out searches on my files for backdoor etc and nothing comes up. I am not experiencing any problems myself but I didn't get any warning etc when I opened the e-mail. I have carried out scans and deleted temp files/ cookies etc.
Before I go scaring everyone else I sent it to, can anyone tell me how to find out for sure if I have the virus?

Thank you
«134

Comments

  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Download this http://www.malwarebytes.org/mbam.php then install it then run a quick scan and remove everything it finds after post the logfile back here. I recommend using Avira AntiVir instead of AVG http://www.filehippo.com/download_antivir/
  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Upload the file onto here to see if its infected http://www.virustotal.com/
  • oxters
    oxters Posts: 456 Forumite
    Part of the Furniture Combo Breaker
    manythanks for the advice. Is that free software or do I have to pay for it?
  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Both Avira and Malwarebytes are completely free :D.
  • oxters
    oxters Posts: 456 Forumite
    Part of the Furniture Combo Breaker
    Both Avira and Malwarebytes are completely free :D.
    Sorry to be such a dummy, but the link gives me this:

    Activating the full version unlocks realtime protection, scheduled scanning, and scheduled updating. It is a one time fee of $24.95.
    try.jpg buy.jpg

    Do I just click on download and I get the free version please?
  • thomas01155
    thomas01155 Posts: 2,382 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Yup you just press download ^.^ the paid version just unlocks some extra things but you don't need those.
  • Marty_J
    Marty_J Posts: 6,594 Forumite
    Almost every day, someone who uses AVG is on here saying they have a virus. It really is pretty bad. I wish Martin would stop recommending it to people.
  • Browntoa
    Browntoa Posts: 49,602 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    you cannot allow for people foolishly clicking on Links and downloading stuff, see just as many threads on here with Nortons etc on here , not only AVG
    Ex forum ambassador

    Long term forum member
  • oxters
    oxters Posts: 456 Forumite
    Part of the Furniture Combo Breaker
    after post the logfile back here.

    Did you mean me to do this?

    Malwarebytes' Anti-Malware 1.32
    Database version: 1625
    Windows 5.1.2600 Service Pack 3
    06/01/2009 21:25:28
    mbam-log-2009-01-06 (21-25-28).txt
    Scan type: Quick Scan
    Objects scanned: 54363
    Time elapsed: 10 minute(s), 5 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\!!9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    C:\WINDOWS\system32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.

    I have deleted the infected files but none of them said "backdoor tidserve!inf!
    Is it safe to assume I don't have it?
  • oxters
    oxters Posts: 456 Forumite
    Part of the Furniture Combo Breaker
    Browntoa wrote: »
    you cannot allow for people foolishly clicking on Links and downloading stuff, see just as many threads on here with Nortons etc on here , not only AVG

    But I didn't click on a link, I just opened the e-mail, read the content and forwarded it to some friends, one of whom alleges he got the virus from it!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.