This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tidserv Activity 2 [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi redmax1,

Please delete the following files:
C:\Documents and Settings\Larry.MAX\My Documents\Larry's stuff\runit.exe
C:\Documents and Settings\Larry.MAX\My Documents\My Download Files\media.player.codec.pack.v3.9.6.setup.exe
C:\Documents and Settings\Larry.MAX\My Documents\My Download Files\screen savers\libertyUSA.exe
C:\Documents and Settings\Larry.MAX\My Documents\My Download Files\Unlocker\unlocker1.9.0.exe

===================================================

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
===================================================

I'd like you to run ESET again and post the log after completing the above two steps.
Hey Noodletech, I never realized what a project it was to clean an infected computer…wow! I'm glad you know what you are doing….Thanks again I have deleted these files: Please delete the following files: C:\Documents and Settings\Larry.MAX\My Documents\Larry's stuff\runit.exe C:\Documents and Settings\Larry.MAX\My Documents\My Download Files\media.player.codec.pack.v3.9.6.setup.exe C:\Documents and Settings\Larry.MAX\My Documents\My Download Files\screen savers\libertyUSA.exe C:\Documents and Settings\Larry.MAX\My Documents\My Download Files\Unlocker\unlocker1.9.0.exe Can you tell me why I had to? They have been in my computer for years except for unlocker which I installed about maybe 4 months ago. I am using the media player codec pack in windows media player. It was recomended by friends who use it also. Should I tell them to get rid of it? i ran TFC and it rebooted and ESET is almost finished (I hope) I am running it with the delete files box unchecked as before. I will send you the file as soon as it is finished ESET seems to have stalled for quite a while now. Says scanning in progress…step 3 out of 4…..Target-Operating memory…..progress bar says 100% and the scan time has stopped.
Hi redmax1, My pleasure :). Regarding those files, I figured you already installed them, so it wouldn't hurt to delete the setup files. The reason they came up in the ESET scan is because they come bundled with third party software that might fall under the category of adware. Although you are given the option of choosing whether or not to install this third party software, ESET detects it as malware anyways. If you and your friends have been using the software for years without problem, I would say continue to do so and don't worry about it. Is ESET still stalled?
Hi noodleTech, Maybe it did finish here is the file. Do you want me to still run ESET again? How late are you working tonight…I am Eastern standard time C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\serial.sys.vir Win32/Sirefef.DA trojan C:\System Volume Information\_restore{084BB1E7-1D40-4DED-BEDE-3F8FD6106370}\RP3\A0000565.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000001.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000008.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000010.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000011.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000012.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000013.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000021.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000022.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000033.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000039.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000040.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000042.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000043.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000044.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000173.exe Win32/CokeGift trojan C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000174.EXE probably a variant of Win32/Agent.JGNPZLZ trojan C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000194.exe probably a variant of Win32/Hoax.Agent.CEFEVMK application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000195.exe probably a variant of Win32/Agent.LTSZKUS trojan C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000207.EXE Win32/Adware.SaveNow application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000211.EXE a variant of Win32/Adware.WhenUSave application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000212.exe Win32/Adware.NdotNet application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000213.exe Win32/Adware.SuperBar application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000214.EXE multiple threats C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000218.exe Win32/Adware.TimeSink application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000230.exe probably a variant of Win32/Agent.BRDLGXM trojan C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000247.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000255.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000258.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000483.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000493.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000496.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000501.ini Win32/Adware.Virtumonde.NEO application C:\System Volume Information\_restore{C5AA0ED0-812D-49C2-ACC1-D5F9F9793EC1}\RP1\A0000508.ini Win32/Adware.Virtumonde.NEO application
Hi redmax1,

Perfect, that is exactly what I needed to see. No need to run it again. Your system appears to be free of malware :). I will probably be up until 1 AM PST so if you have any questions, feel free to post them. Don't forget to reenable your antivirus software.

Please delete DDS, aswMBR, TDSSKiller, and SystemLook from your desktop.

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

Updates
  • It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware.
  • It's a good idea to have Windows Update automatically download and install updates as they become available.
  • FileHippo Update Checker is a great tool that will tell you which of your third party applications need to be updated.
Run Anti-Virus Software
  • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.
  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.
  • When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
  • Once complete, remember to re-engage your resident security before going online.
Passwords
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection.
  • Refer to this Microsoft article
    Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.
Spyware Protection
  • This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?
Additional Software
  • To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.
  • Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any further questions? 


**Please respond one more time to confirm your problem is resolved so I can close this thread.
Hey NoodleTech,

I can't thank you enough for all your time and trouble. My computer is my connection to the outside word. I am totally disabled and depend on my computer for everything. This computer is 10 yrs. old in a few weeks and I built it from scratch before my accident in 2005. I should get a new computer but I don't want one off the shelf and I am unable to build it myself anymore so I just keep upgrading and maintaining this one. Ity is a comforting thought to know people like you exist and are there when needed Thanks again and what a great job you did and WhattheTech's url is in my address book for future use(Hopefull I won't need it)

redmax1 :notworthy:
:thumbup: :clap: :woot:

ps: My local file has changed. Where are my list of cookies and websites visited now???


Have a great holiday
redmax1, My pleasure :). It is people like you that make this sort of work worthwhile. I totally understand you not wanting to buy an off the shelf computer. I've been building my own for the past 10 years and have never looked back :D. I wish you the best and maybe I'll see you around the forums again! Regards, NoodleTech
I'm sorry…the temporary internet files folder where cookies and things are stored. I went into folder options and clicked show hidden files but that didn't work. Maybe I need to reboot my computer for that to work. I like to delete cookies and things that don't get deleted through regular file cleaning

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI