We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Virus Stops Me From Running Anti-Virus Software

1246

Comments

  • wordsearch
    wordsearch Posts: 90 Forumite
    The logfile that malware found;

    Malwarebytes' Anti-Malware 1.30
    Database version: 1306
    Windows 5.1.2600 Service Pack 2

    31/03/2009 16:38:19
    mbam-log-2009-03-31 (16-38-12).txt

    Scan type: Quick Scan
    Objects scanned: 64074
    Time elapsed: 20 minute(s), 52 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 7

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> No action taken.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nuviwitiko (Trojan.Agent) -> No action taken.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\TDSSakao.log (Trojan.TDSS) -> No action taken.
    C:\WINDOWS\system32\TDSSdxgp.dll (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\TDSSkrxx.dll (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\TDSSnpur.dll (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\TDSSoitu.dll (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\TDSSyoqu.dll (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\drivers\TDSSmxfe.sys (Rootkit.Agent) -> No action taken.



    I assume I should delete all of those? Last time you were specific on JUST SCAN DON'T TOUCH lol :)
  • boyse7en
    boyse7en Posts: 883 Forumite
    Sorry, I can't offer much help, but this sounds exactly the same as I got on my computer a couple of months ago (despite running AVG and Spybot S&D). It won't let you get anything that is on a list of AV suppliers (you just get an advertising screen instead)

    After I tried booting into Safe Mode and doing a repair of Windows it wouldn't let me boot up at all (got to screen offering the options of safe mode, safe with networking, standard, etc. and would just go black screen for any option)

    Never did get it working. In the end I bought a new Hard drive and reinstalled all the programs, then slaved my old HD to copy across the data. Then formatted the old HD to ensure that the virus was gone and I now use it as a backup drive
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    wordsearch. They ALL say "No action taken." at the end. Did you remove and delete them? if not then please do so

    In fact, you ran QUICK scan. I would HIGHLY recommend a FULL scan before continuing
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    wordsearch wrote: »



    I assume I should delete all of those? Last time you were specific on JUST SCAN DON'T TOUCH lol :)

    Just read this ~ i was refering to HIJACK THIS only when I said that :p

    yes ~ remove the lot
    :idea:
  • wordsearch
    wordsearch Posts: 90 Forumite
    aliEnRIK wrote: »
    wordsearch. They ALL say "No action taken." at the end. Did you remove and delete them? if not then please do so

    In fact, you ran QUICK scan. I would HIGHLY recommend a FULL scan before continuing

    Not yet, I was waiting on your reply as last time you were specific on not doing anything that came up! LOL and for all I know deleting them could have made them worse. Deleting right now.

    The full scan actually wouldn't work. It froze after about 15 minutes both times. But once these are deleted I will try that again. Also the Windows File Protection appears to be working - although we'll see at the end I suppose!
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    With a bit of luck you will hopefully be able to download a few things now (if just in SAFE MODE WITH NETWORKING)

    Priorities at this stage are UPDATING malwarebytes (be it through the program or through that link I posted on page 1) and running HIJACK THIS in normal mode
    :idea:
  • wordsearch
    wordsearch Posts: 90 Forumite
    I think I'm crazy but on the malware link you gave on the first place (which I can actally load! Hoorah!) I can't actually see a link anywhere to download it? It says below and I have clicked around randomly just in case haha but I can't seem to find one. And of course, actually clicking on malware on the side won't load.

    Thank you very very much for all your help by the way! I am going to have to go through and thank everyone of your posts, haha.
  • gaming_guy
    gaming_guy Posts: 6,128 Forumite
    1,000 Posts Combo Breaker
    wordsearch wrote: »
    I think I'm crazy but on the malware link you gave on the first place (which I can actally load! Hoorah!) I can't actually see a link anywhere to download it? It says below and I have clicked around randomly just in case haha but I can't seem to find one. And of course, actually clicking on malware on the side won't load.

    Thank you very very much for all your help by the way! I am going to have to go through and thank everyone of your posts, haha.
    there should be a green button on the page saying Download

    anyway, here is the file you need from that page:

    http://www.gt500.org/malwarebytes/mbam-rules.exe
  • wordsearch
    wordsearch Posts: 90 Forumite
    Ooh! Hijack This actually worked this time! This is bizarre to me that it is seeming to allow one new program at a time, haha.

    http://docs.google.com/Doc?id=ddtsxmfr_78ffqb79hb

    That's the log. It, uh, means nothing to me ;)
  • wordsearch
    wordsearch Posts: 90 Forumite
    gaming_guy wrote: »
    there should be a green button on the page saying Download

    anyway, here is the file you need from that page:

    http://www.gt500.org/malwarebytes/mbam-rules.exe

    Thanks, that worked that time. But now Malware Bytes won't work as it says that it does not support the newest update. Obviously all the normal download sites aren't working so I will go searching for an odd site that has it!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.2K Banking & Borrowing
  • 254.3K Reduce Debt & Boost Income
  • 455.3K Spending & Discounts
  • 247.2K Work, Benefits & Business
  • 603.8K Mortgages, Homes & Bills
  • 178.4K Life & Family
  • 261.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.