I recently started getting detection alerts talking about trojan.gen.2 being block a few days ago. The next day I looked in my history and I had 79 attempts by trojan.gen.2 I guess to attack. I get these messages almost every couple of minutes. Then today, I get an alert talking about Tidserv Activity 2 and needed manual removal. I have followed all of the instructions around the web and nothing can detect anything. I ran a complete system scan while in safe mode and it detected 32 threats but shortly after my computer just shuts off. What steps should I take from here?
Hi and Welcome!! My name isJeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users: These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———-
Please download DDS from one of the following links and save it to your desktop.
Double click DDS icon to run the tool (may take up to 3 minutes to run)
When done, DDS.txt will open.
After a few moments, attach.txt will open in a second window.
Save both reports to your desktop.
—————————————————
Post the contents of the DDS.txt report in your next reply
Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-
GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image] Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.
———-
In your next reply please post the logs created by DDS and GMER.
I have attached the attachment., gmer, and dds files for your reviewing. Pasted below is the contents of the DDS file. Question about the GMER.exe scan You said to uncheck IAT/EAT, Drives/Partitions other than C: Drive, and Show All. On the one that I did a scan with the only boxes that are able to be adjusted were the Services, Registry, Files, C:\, and ADS. The others are greyed out.
Go ahead and run the following for me please:
Please download aswMBR to your desktop.
Right click and Run as Administrator the aswMBR icon to run it.
Click the Scan button to start scan.
When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image] Click the image to enlarge it
———-
Download Combofix from either of the links below, and save it to your desktop. Link 1 Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt for further review.
I disable my norton security suite firewall and antivirus but the program is still detecting that they are still active. Also, I cannot directly save it to my desktop because something to do with the risk of the file. My only option is to run the program and then move it to my desktop from my Downloads folder.
It completed the report and deleted the files and folders and restarted. It said it was preparing logs and then a alert poped up saying c:\ Program Files\TOSHIBA\TPHM17PCHWMsg.exe Illegal operation attempted on a registry key that has been marked for deletion. I left it alone for about an hour and ComboFix still says its preparing logs.
Hi cory t,
Go ahead and just reboot your system and that should take care of it. You MAY have to reboot twice but it won't be a problem. Then look in your C:\ drive and find ComboFix.txt and then post that log into your next reply.
Also, ComboFix made a program I use for work unable to be opened. I located this, "2011-10-20 18:03:18 . 2011-03-08 15:47:11 43 —-a-w- C:\TOSSetup.batin" in the ComboFix history text doc. This program is safe.
I located this, "2011-10-20 18:03:18 . 2011-03-08 15:47:11 43 —-a-w- C:\TOSSetup.batin" in the ComboFix history text doc. This program is safe.
This was not removed. It is showing where it has been created in the past 3 months.
The ComboFix log looks incomplete. Make sure that you copied all correctly. If that was all there was please re-run ComboFix and post that log into your next reply.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI