Recurring virus – Backdoor.Tidser!kmem [Solved]
11 min read
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
- Click the Scan button to start scan.
- If you are asked to update the Avast Virus database please allow it to do so.
- When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
Please download TDSSKiller
- Double click TDSSKiller.exe
- When the window opens, click on Change Parameters
- Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
- click OK
- Press Start Scan
- Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
items. - Attach the log in your next reply
- A copy of the log will be saved automatically to the root of the drive (typically C:\)
Please double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator".
- Click the Scan button to start scan.
- When scan finishes, press the Fix Button. Once the Fix is done, press the Save Log button and save the log to your desktop. You need to reboot your computer when its done before you do anything else, then post the log that will be on your desktop.
[external image: Posted Image]
Click the image to enlarge it
Good job!
Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-
Run OTL.exe
- Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL
:Services
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q=
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.7.2.0
[2012/10/06 18:26:22 | 000,000,000 | —D | M] (Vuze Remote Community Toolbar) – C:\Documents and Settings\Phil\Application Data\Mozilla\Firefox\Profiles\lr8lp7pc.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
O1 - Hosts: 159.148.86.201 static.ak.fbcdn.net
O1 - Hosts: 98.137.80.34 mail.yimg.com
O1 - Hosts: 98.137.80.49 l.yimg.com
O1 - Hosts: 159.148.86.207 static1.meetupstatic.com
O1 - Hosts: 159.148.86.207 static2.meetupstatic.com
O1 - Hosts: 77.67.20.25 static.poptropica.com
O1 - Hosts: 159.148.86.207 edge.quantserve.com
O1 - Hosts: 77.67.29.169 b.scorecardresearch.com
O1 - Hosts: 159.148.86.207 ia.media-imdb.com
O1 - Hosts: 159.148.86.207 i.i.com.com
O1 - Hosts: 216.239.116.49 adlog.com.com
O1 - Hosts: 77.67.20.43 graphics.alt.com
O1 - Hosts: 159.148.86.207 resources.news.com.au
O1 - Hosts: 159.148.86.207 resources0.news.com.au
O1 - Hosts: 159.148.86.201 resources1.news.com.au
O1 - Hosts: 159.148.86.207 resources2.news.com.au
O1 - Hosts: 159.148.86.207 resources3.news.com.au
O1 - Hosts: 159.148.86.201 sops.news.com.au
O1 - Hosts: 159.148.86.207 www.dailytelegraph.com.au
O1 - Hosts: 159.148.86.207 shared.live.com
O1 - Hosts: 159.148.86.207 js.wlxrs.com
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://l.yimg.com/jh/games/web_games/popca…aploader_v6.cab (PopCapLoader Object)
O33 - MountPoints2\{66958fee-4929-11df-8502-00221597c95d}\Shell - "" = AutoRun
O33 - MountPoints2\{66958fee-4929-11df-8502-00221597c95d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{be8f24e5-4a41-11dd-876a-005056c00008}\Shell\AutoRun\command - "" = slacker.synclauncher.exe
O33 - MountPoints2\{be8f24e5-4a41-11dd-876a-005056c00008}\Shell\slacker\command - "" = slacker.synclauncher.exe
O33 - MountPoints2\{cedc36a0-0ea4-11e2-b348-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{cedc36a0-0ea4-11e2-b348-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cedc36a0-0ea4-11e2-b348-806d6172696f}\Shell\AutoRun\command - "" = D:\Setup.exe – [2006/02/08 17:49:31 | 000,417,792 | R— | M] (Hewlett-Packard)
O33 - MountPoints2\{e649170c-f50e-11de-9128-005056c00008}\Shell\AutoRun\command - "" = slacker.synclauncher.exe
O33 - MountPoints2\{e649170c-f50e-11de-9128-005056c00008}\Shell\slacker\command - "" = slacker.synclauncher.exe
[2012/10/08 15:55:44 | 000,000,000 | —D | C] – C:\Program Files\Bing Bar Installer
[2012/10/06 14:21:31 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\PriceGong
[2012/10/06 10:57:18 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Conduit
[2012/10/06 10:56:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ConduitEngine
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\*.tmp files -> C:\*.tmp -> ]
[27 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[2012/10/07 09:50:04 | 000,005,632 | —- | M] () – C:\Documents and Settings\Phil\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/05 21:18:17 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2009/01/02 19:00:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2012/10/07 00:36:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Phil\Application Data\Azureus
:Files
ipconfig /flushdns /c
:Commands
[emptytemp]
[resethosts]
[start explorer]
[Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Post the logs made by OTL and then let me know how your system is running.
During the "Run Fix" I received an error that a file couldn't be deleted.
The file "10092012_072720.txt" is the log generated during the "Run Fix"
The file "OTL.txt" is the log from the post fix scan
Cheers
Phil
I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.
Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-
Clear Java Cache
See this page for instructions on how to clear java's cache.
Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
- Under Temporary Internet Files, click the Delete Files button.
- There are three options in the window to clear the cache - Leave ALL 3 Checked
- Downloaded Applets
Downloaded Applications
Other Files
- Downloaded Applets
- Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. - Click OK to leave the Java Control Panel.
Please download Malwarebytes Anti-Malware to your desktop.
- Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan as shown below.
[external image: Posted Image]
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
The log can also be found here:
Windows 2000 & Windows XP:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs
Windows Vista & Win7:
C:\Users\\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
———-
ESET Online Scanner
Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
- Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activex control to install
- Click Start
- Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
- Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
- Click Scan
- Wait for the scan to finish
- When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
- Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
- Close the ESET online scan, and let me know how things are now.
Run OTL.exe
- Copy/paste the following text written inside of the quote box into the Custom Scans/Fixes box located at the bottom of OTL
:Services
:Files
C:\Documents and Settings\Phil\Application Data\Mozilla\Firefox\Profiles\lr8lp7pc.default\user.js
C:\Documents and Settings\Phil\My Documents\Downloads\Adaware_Installer.exe
C:\Documents and Settings\phil.AUSTINE.000\My Documents\Downloads\winamp5581_full_emusic-7plus_en-us.exe
C:\Software\utilities\iso\Magic ISO Maker v5.3+keygen\keygen.exe
ipconfig /flushdns /c
:Commands
[emptytemp]
[resethosts]
[clearallrestorepoints]
[start explorer]
[Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Post the new OTL logs and let me know if you are having any more malware related problems.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI