This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Backdoor.Tidserv.I!inf

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

I dont get redirects I get win patrol warning all the time. - do you still get them?
I get a blank window titled Mirar unistall but nothing happens - will deal with that later
I have malware bytes on my computor already it OK to use that one - yes that is fine just update it please
I also have adobe professional 6.0.1 do I need to lose that aswell - if you don't use it then yes, if you use it then make sure you use the reader to open pdf files
In add remove programs Mirar has no size listed ? - might not be there anymore we will deal with that soon

gringo
Everything seems to be working OK Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/05/2010 6:28:36 PM mbam-log-2010-05-01 (18-28-36).txt Scan type: Quick scan Objects scanned: 121860 Time elapsed: 6 minute(s), 24 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, May 2, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, May 02, 2010 00:04:18 Records in database: 4027430 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 86254 Threats found: 5 Infected objects found: 13 Suspicious objects found: 0 Scan duration: 01:45:30 File name / Threat / Threats count C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\BASH\Clone\BHC1B.tmp Infected: Trojan-Downloader.Win32.Agent.dgzj 1 C:\Documents and Settings\User\Local Settings\Application Data\Identities\{12F96E70-0131-4552-96AE-FF60D3A0F15B}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan.Win32.Small.acdp 1 C:\Program Files\Adobe\Premiere 6.5\Plug-ins\fl-boost.prm Infected: Trojan.Win32.Buzus.dfws 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP1\A0002013.old Infected: Rootkit.Win32.TDSS.ap 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP1\A0004013.old Infected: Rootkit.Win32.TDSS.ap 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP2\A0005024.old Infected: Rootkit.Win32.TDSS.ap 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP2\A0008054.old Infected: Rootkit.Win32.TDSS.ap 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP2\A0008087.old Infected: Rootkit.Win32.TDSS.ap 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP5\A0008396.old Infected: Rootkit.Win32.TDSS.ap 1 C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP6\A0008429.old Infected: Rootkit.Win32.TDSS.ap 1 C:\WINDOWS\system32\drivers\rasacd.old Infected: Rootkit.Win32.TDSS.ap 1 E:\Music\morning of earth.wma Infected: Trojan-Downloader.WMA.Wimad.y 1 E:\programs\Premiere 6.5\Plug-ins\fl-boost.prm Infected: Trojan.Win32.Buzus.dfws 1 Selected area has been scanned.
Hello Blackdogs

Delete files

Open Notepad.
Copy this in the Notepad-file:

@ECHO OFF
IF EXIST log.txt DEL log.txt
ECHO Deleting files>>log.txt
FOR %%g in (
"C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\BASH\Clone\BHC1B.tmp" 
"C:\Program Files\Adobe\Premiere 6.5\Plug-ins\fl-boost.prm"
"C:\WINDOWS\system32\drivers\rasacd.old"
"E:\Music\morning of earth.wma"
"E:\programs\Premiere 6.5\Plug-ins\fl-boost.prm") DO (
IF EXIST %%g (
ATTRIB -r -s -h %%g
DEL %%g
IF EXIST %%g (
ECHO %%g not deleted>>log.txt
) ELSE (
ECHO %%g deleted>>log.txt)
) ELSE (
ECHO %%g not found>>log.txt))
START NOTEPAD.EXE log.txt

Go to File - Save as…
Fill in the next values:
Location: Desktop
File name: del.bat
File type: All files (*.*).
Now, click Save.
Doubleclick del.bat.
Post the contents of the logfile that opens in your next reply.

Gringo
Deleting files "C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\BASH\Clone\BHC1B.tmp" not deleted "C:\Program Files\Adobe\Premiere 6.5\Plug-ins\fl-boost.prm" deleted "C:\WINDOWS\system32\drivers\rasacd.old" deleted "E:\Music\morning of earth.wma" deleted "E:\programs\Premiere 6.5\Plug-ins\fl-boost.prm" deleted
Hello

I would like you to boot into safe mode and run del.bat again

Boot into Safe Mode

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.


gringo
Safe mode Deleting files "C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\BASH\Clone\BHC1B.tmp" deleted "C:\Program Files\Adobe\Premiere 6.5\Plug-ins\fl-boost.prm" not found "C:\WINDOWS\system32\drivers\rasacd.old" not found "E:\Music\morning of earth.wma" not found "E:\programs\Premiere 6.5\Plug-ins\fl-boost.prm" not found
Hello

Click Start >> Run and then type the following in the run box
maxlook -cleanup

(don't worry if it says it can't be found just move to next stage)

Please download maxlook, saving the file to your desktop.
Double click maxlook.exe to run it. Note - you must run it only once!

1.Restart your computer.
2.Before Windows loads, you will be prompted to choose which Operating System to start.
3.Use the up and down arrow key to select Microsoft Windows Recovery Console
4.You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
5.At the C:\Windows prompt, type the following bolded entries, and press 'Enter' (note the spaces):
batch look.bat
🖼Click to load external image (Posted Image)

You will see 1 file copied many times then return to the x:\windows> prompt.
Type Exit to restart your computer then logon in normal mode.

Click Start >> Run and then type the following in the run box

maxlook -sig

(note the space before the - sign)
It will produce looklog.txt on the desktop and open it.
Please post the results here.

Gringo
Run from C:\Documents and Settings\User\Desktop\maxlook.exe on Tue 04/05/2010 at  7:59:04.15

——— maxlook unsigned files ———

c:\windows\maxdriver\aspi32.sys:
	Verified:	Unsigned
	File date:	8:05 AM 17/07/2002
	Publisher:	Adaptec
	Description:	ASPI for WIN32 Kernel Driver
	Product:	Adaptec's ASPI Layer
	Version:	4.71 (0002)
	File version:	4.71 (0002) built by: WinDDK
c:\windows\maxdriver\imagedrv.sys:
	Verified:	Unsigned
	File date:	5:37 PM 2/03/2004
	Publisher:	Ahead Software AG
	Description:	NERO IMAGEDRIVE SCSI miniport
	Product:	Nero ImageDrive
	Version:	2.27.0.0
	File version:	2.27.0.0 built by: WinDDK
c:\windows\maxdriver\imagesrv.sys:
	Verified:	Unsigned
	File date:	5:37 PM 2/03/2004
	Publisher:	Ahead Software AG
	Description:	Nero Image Server
	Product:	Nero ImageDrive
	Version:	2.27.0.0
	File version:	2.27.0.0 built by: WinDDK
c:\windows\maxdriver\ScFBPNT2.sys:
	Verified:	Unsigned
	File date:	12:00 AM 21/05/1999
	Publisher:	n/a
	Description:	n/a
	Product:	n/a
	Version:	n/a
	File version:	n/a
c:\windows\maxdriver\StMp3Rec.sys:
	Verified:	Unsigned
	File date:	11:31 AM 16/03/2005
	Publisher:	Generic
	Description:	Generic MP3 Player USB Driver
	Product:	Generic MP3 Player
	Version:	250, 1, 5, 1
	File version:	1, 521, 0, 139

——— system32\drivers unsigned files ———

c:\windows\system32\drivers\aspi32.sys:
	Verified:	Unsigned
	File date:	8:05 AM 17/07/2002
	Publisher:	Adaptec
	Description:	ASPI for WIN32 Kernel Driver
	Product:	Adaptec's ASPI Layer
	Version:	4.71 (0002)
	File version:	4.71 (0002) built by: WinDDK
c:\windows\system32\drivers\imagedrv.sys:
	Verified:	Unsigned
	File date:	5:37 PM 2/03/2004
	Publisher:	Ahead Software AG
	Description:	NERO IMAGEDRIVE SCSI miniport
	Product:	Nero ImageDrive
	Version:	2.27.0.0
	File version:	2.27.0.0 built by: WinDDK
c:\windows\system32\drivers\imagesrv.sys:
	Verified:	Unsigned
	File date:	5:37 PM 2/03/2004
	Publisher:	Ahead Software AG
	Description:	Nero Image Server
	Product:	Nero ImageDrive
	Version:	2.27.0.0
	File version:	2.27.0.0 built by: WinDDK
c:\windows\system32\drivers\ScFBPNT2.sys:
	Verified:	Unsigned
	File date:	12:00 AM 21/05/1999
	Publisher:	n/a
	Description:	n/a
	Product:	n/a
	Version:	n/a
	File version:	n/a
c:\windows\system32\drivers\StMp3Rec.sys:
	Verified:	Unsigned
	File date:	11:31 AM 16/03/2005
	Publisher:	Generic
	Description:	Generic MP3 Player USB Driver
	Product:	Generic MP3 Player
	Version:	250, 1, 5, 1
	File version:	1, 521, 0, 139
Hello

SystemLook:

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:filefind
ScFBPNT2.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

gringo
SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 10:58 on 04/05/2010 by User (Administrator - Elevation successful) ========== filefind ========== Searching for "ScFBPNT2.sys" C:\WINDOWS\maxdriver\ScFBPNT2.sys –a— 15488 bytes [01:32 08/03/2009] [14:00 20/05/1999] 50B724C9D03111245DF270BC3F49F04D C:\WINDOWS\system32\drivers\ScFBPNT2.sys –a— 15488 bytes [01:32 08/03/2009] [14:00 20/05/1999] 50B724C9D03111245DF270BC3F49F04D -=End Of File=-
Hello

I don't think that is the correct file please look for this one

SystemLook:

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:filefind
monfilt.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

gringo
SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 14:47 on 04/05/2010 by User (Administrator - Elevation successful) ========== filefind ========== Searching for "monfilt.sys" C:\WINDOWS\maxdriver\monfilt.sys –a— 1389056 bytes [04:15 19/01/2009] [06:12 14/02/2008] 9FA7207D1B1ADEAD88AE8EED9CDBBAA5 C:\WINDOWS\system32\drivers\monfilt.sys -ra— 1389056 bytes [04:15 19/01/2009] [06:12 14/02/2008] 9FA7207D1B1ADEAD88AE8EED9CDBBAA5 -=End Of File=-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI