This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tidserv Problems [Solved]

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Levijudah,

My pleasure :) How's the computer running now? Any outstanding issues?

I'd like for you to run aswMBR once more and post the log.

I'd also like for you to run ESET Online Scanner.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Here are the logs NoodleTech aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software Run date: 2012-01-29 09:29:36 —————————– 09:29:36.167 OS Version: Windows 6.0.6002 Service Pack 2 09:29:36.167 Number of processors: 2 586 0x1706 09:29:36.167 ComputerName: PHILBLOW-PC UserName: philblow 09:29:37.025 Initialize success 09:29:40.228 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-1 09:29:40.228 Disk 0 Vendor: ST3250310AS 3.ADA Size: 238418MB BusType: 3 09:29:40.275 Disk 0 MBR read successfully 09:29:40.275 Disk 0 MBR scan 09:29:40.275 Disk 0 Windows VISTA default MBR code 09:29:40.275 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63 09:29:40.290 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238362 MB offset 112640 09:29:40.306 Disk 0 scanning sectors +488278016 09:29:40.368 Disk 0 scanning C:\Windows\system32\drivers 09:29:44.877 Service scanning 09:29:46.452 Modules scanning 09:29:50.993 Disk 0 trace - called modules: 09:29:51.024 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 09:29:51.024 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x854ea3d8] 09:29:51.024 3 CLASSPNP.SYS[8afa58b3] -> nt!IofCallDriver -> [0x852dc918] 09:29:51.024 5 acpi.sys[806956bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-1[0x852b8b98] 09:29:51.024 Scan finished successfully 09:29:58.512 Disk 0 MBR has been saved successfully to "C:\Users\philblow\Desktop\MBR.dat" 09:29:58.528 The log file has been saved successfully to "C:\Users\philblow\Desktop\aswMBR.txt" ESETSCAN LOG: C:\Documents and Settings\philblow\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\402b2b-4b557aab multiple threats C:\Documents and Settings\philblow\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\348ded37-54b65970 Java/Agent.EA trojan C:\Documents and Settings\philblow\Downloads\cnet2_AutoUnpack444_exe.exe a variant of Win32/InstallCore.D application C:\Qoobox\Quarantine\[4]-Submit_2012-01-28_02.12.22.zip a variant of Win32/Rootkit.Kryptik.HA trojan C:\Users\philblow\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\402b2b-4b557aab multiple threats C:\Users\philblow\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\348ded37-54b65970 Java/Agent.EA trojan C:\Users\philblow\Downloads\cnet2_AutoUnpack444_exe.exe a variant of Win32/InstallCore.D application Operating memory multiple threats
Hi Levijudah,

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
===================================================

Please run Malwarebytes' Anti-Malware.
  • Click the Update tab, then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Next, click Scanner, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
I will get on that as soon as I get home tonight…I really want this over with, I am buying MS Office finally and want to install it like yesterday, but I'm assuming that wouldn't be a smart thing to do while trying to clean this thing out. Am I right in that assumption?
Hi Levijudah, I know you do :). We should be done after you complete these steps. Then we can clean up the tools we used and get you back up and running. It would be best to wait until after you complete the last set of steps before installing Office. We can clean up the tools we used afterwards.
Ok Noodletech,,,sorry for the delay, but I've done what you said! Here's the log.. Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.02.01 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 philblow :: PHILBLOW-PC [administrator] Protection: Enabled 2/1/2012 9:59:00 PM mbam-log-2012-02-01 (21-59-00).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 212231 Time elapsed: 12 minute(s), 3 second(s) Memory Processes Detected: 1 c:\users\philblow\appdata\local\temp:winupd.exe (Trojan.Agent) -> 1904 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winupd (Trojan.Agent) -> Data: C:\Users\philblow\AppData\Local\Temp:winupd.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 c:\users\philblow\appdata\local\temp:winupd.exe (Trojan.Agent) -> Delete on reboot. (end)
Hi Levijudah,

Everything looks good! Let's remove the tools we used and you'll be good to go.

Please delete DDS, aswMBR, and TDSSKiller from your desktop.

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

Updates
  • It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware.
  • It's a good idea to have Windows Update automatically download and install updates as they become available.
  • Secunia Online Software Inspector is a great tool that will tell you which of your applications are outdated and vulnerable to attack.
Run Anti-Virus Software
  • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.
  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.
  • When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
  • Once complete, remember to re-engage your resident security before going online.
Passwords
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection.
  • Refer to this Microsoft article
    Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.
Spyware Protection
  • This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?
Additional Software
  • To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.
  • Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any further questions? 

**Please respond one more time to confirm your problem is resolved so I can close this thread.
Thank you so much! I really appreciate your help!! One thing though, when I tried to remove Combofix it stated that it was not found.
Hi Levijudah,

It is my pleasure :). Ok, let's give this a shot.

  • Download OTC from the following mirror and save it to your desktop.
  • Double click on [external image: Posted Image]
  • Push the large "Cleanup" button.
  • Allow your system to reboot.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI