Suspisious file

Discussion in 'Malware Help (A Specialist Will Reply)' started by Elvy, Dec 25, 2010.

  1. Elvy

    Elvy Private E-2

    I have had some kind of Trojen dropper or something on my computer. My ESET nod 32 has been preventing it from getting any further but it was still messing with me. I used TDSSKiller to remove it and my computer seems to be working normal now. But I still have this file the TDSSKiller detected but I have no idea if it is good or bad.
    C:\WINDOWS\system32\Drivers\sptd.sys - copied to quarantine
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    A driver relating to Daemon Tools.
     
  3. Elvy

    Elvy Private E-2

    alright thanks.
     
  4. Elvy

    Elvy Private E-2

    There is actually still I problem that I just noticed. My cd rom will not load any cds. And deamon tools will not load any .iso files. It shows that they are present when I restart my comp but it show no files on the cd and when I eject the cd and put it back it, it does not show up at all.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a problem for the Malware Forum. Please post in the Software Forum for issues with software and the Hardware Forum for hardware problems. Since you quarantined the driver for Daemon Tools, it is not going to work. Either restore the file, or reinstall Daemon Tools.

    I will move this thread to the Software Forum for now since that is a better starting place.
     
  6. Elvy

    Elvy Private E-2

    If it is a hardware problem then it is also a malware problem. Because it didn't start doing this until after the stupid trojen virus showed up. I have reinstalled deamon tools already and reinstalled the cd-rom drivers, and it is still doing the same thing. And I have tried disabling the cd-rom restarting the computer and then enabling it again. Still does nothing.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still does not mean that the problem that is present now is due to any remaining malware. Residual effects from malware could always be significant and they cannot always be fixed just by hunting down malware. We will try a cleaning process, but you may have to do a system restore or repair to fix your problems. You could just be suffering the effects of using Daemon Tools and breaking it after quarantining its driver. Daemon Tools does intercept processes related to the CD drive. And also note that it almost never uninstalls properly.

    So if you really suspect malware and because your problem began after you fix something with TDSSkiller then attach your logs from TDSSkiller (See: HOW TO: Attach Items To Your Post )

    Also work thru the below cleaning procedure. I will move this back to the Malware Forum so that we can work on the cleaning process and logs.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
    Last edited: Dec 27, 2010
  8. Elvy

    Elvy Private E-2

    Uploaded the TDSSKiller log.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    TDSSkiller found and attempted to fix an infection in a driver for your graphics card. The other item that was quarantined was for Daemon Tools and as stated, this could have affected the behaviour of your CD drive. You need to continue with the rest of my instructions so I can see if anything else remains.
     
  10. Elvy

    Elvy Private E-2

    SUPERAntiSpyware found nothing.
    Combo fix gave me a blue screen that said Bad_Pool_Header.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some additional malware was found and removed but nothing that would seem to relate to your CD drive issues. The only additional thing I see to do is delete the below file and then reboot.

    C:\WINDOWS\Tasks\Qfttqf.job

    Then if still having problems with your CD drive, post in the Hardware Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds