read and run me didnt work until tdserv.sys deleted (see post 175235)

Discussion in 'Malware Help (A Specialist Will Reply)' started by bobdog, Dec 19, 2008.

  1. bobdog

    bobdog Private E-2

    I either downloaded something nasty on a vid, or it happened when my mcafee loaded but didnt enable on-access scan (a known xp issue) and I didnt notice and accidentally left the comp connected for 2-3 days that way.

    INTERNET: yahoo, etc ran, but all links redirected and malware help sites blocked.

    SAS: error, must close

    SAS ALT boot: ran, found a c:\combofix\creg.dat that I allowed

    SSAD: server name or address could not be resolved

    MB: DOA, click not acknowleged

    CF: didnt bother.


    Then I found the post on tdsserv.sys in the non-P&P drivers, deleted it and the net and the malware tools worked.

    A Combofix file was caught by McAfee, I dont think it was deleted.
    CF started running as soon as I did the drag and drop, they need to update their instructions..also disable the AV software sooner.
     

    Attached Files:

  2. bobdog

    bobdog Private E-2

    Eh..I'm looking for my MGTools.zip file and haven't found it yet..but did find these...

    WinTDSSrtk.zip
    WinTDSSrtk1.zip
    WinTDSSrtk2.zip
    WinTDSSrtk3.zip
    WinTDSSrtk4.zip
    WinTDSSrtk5.zip
    WinTDSSrtk6.zip
     
  3. bobdog

    bobdog Private E-2

    my attachments aren't visible:confused
     
  4. bobdog

    bobdog Private E-2

    mgtools.zip not found, going to re-run it
     
  5. bobdog

    bobdog Private E-2

    Here's the log, I may have skipped running mg. *shrug* Life with a hyperactive, insomniac, adorable and thoroughly evil two year old little girl

    Thank God the twelve year old cat still has good reflexes....
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience.

    Kes13!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) If you haven't already, please disable the Guest account in User accounts.

    2) Please go to Add or Remove programs and uninstall the following softwares:

    • Ad-Aware 2007 <-- old and ineffective
    • Java(TM) 6 Update 10

    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user') <--- Please be aware that this isn't malware. It relates to Dr Watson which is a program error debugger for Windows, but there is no need for it to be running at start-up so include it in our fix.


    After clicking Fix exit HJT.



    4) Could you please get this file winhelp.ini.vir into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to Start > Run and paste in the following:


    5) Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    6) Now Run Ccleaner!

    7) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger or combofix

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  8. bobdog

    bobdog Private E-2

    confused?

    1) If you haven't already, please disable the Guest account in User accounts.

    2) Please go to Add or Remove programs and uninstall the following softwares:
    • Ad-Aware 2007 <-- old and ineffective
    • Java(TM) 6 Update 10

    ---Done

    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user') <--- Please be aware that this isn't malware. It relates to Dr Watson which is a program error debugger for Windows, but there is no need for it to be running at start-up so include it in our fix.


    After clicking Fix exit HJT.

    --- Sorry, but the version of MGTools I have has no MGTools\analyse.exe , it only supplies log files and displays no fix command. I ran it twice to verify this. Instructions I have for MGTools are as follows:
    Instructions for all other Windows Users:
    • run the MGTools.exe program by double clicking on it.
    o It will create a folder named MGTools in the root folder of the hard disk where Windows is installed ( typically C:\MGTools ).
    o It will also automatically extract a bunch of files into this folder.
    o It will the automatically start running three batch ( .bat files are batch programs ) programs in that folder.
    o It will sequentially run GetRunKey.bat, ShowNew.bat, and GetUnKey.bat and then will also run a file named analyse.exe which is a copy of HijackThis.. Each of these programs will create logs respectively named runkeys.txt, newfiles.txt and GetUnKey.txt. You will notice a command prompt window open and messages will appear in this window. This window will close when the scans are complete for all Win 2K and XP users. Win 9x and ME users will have to close this window manually but only when the scans complete.
    o You may see a popup window with a license agreement for TrendMicro HijackThis. Make sure you click the I Accept button.
    o If you see HijackThis open and/or a log from HijackThis open in notepad, just close HijackThis and the notepad window.
    o These log files while be placed in the root folder of your Windows drive. The log file will also automatically be put into a ZIP file named MGlogs.zip which you will be uploading as an attachment to your message in the forum. Unlike older versions of the programs, no popups of the logs will appear when they finish running during this initial installation. At a later time, running any of the individual batch files will still cause the logs to automatically pop up.
    o Continue on to the General Information section below.
    ---If this is different download than MGTools, please provide a link.

    Also: 7) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger or combofix

    Do you also want me to run ComboFix again? Not mentioned above.

    :waveHappy New Year! (I fell asleep getting my dau to bed & missed it all:zzz:p)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: confused?

    Yes it does, and I can see it here as indicated by your logs:

    The MGTools Folder is sat in your C Drive:

    MGTools directory on C drive.jpg

    And analyse.exe is found upon double clicking/opening the MGTools directory as shown below:

    HJT.jpg



    No, we don't need to re run Combofix.

    What I would be interested to see is the following from my step #4:

    Could you please get this file winhelp.ini.vir into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to Start > Run and paste in the following:





    And a very Happy New Year to you too bobdog :)
     
  10. bobdog

    bobdog Private E-2

    Here you go and thanks! Hopefully this will be done with it, the comp seems to be running ok.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) I see the following software in your Add or Remove programs list:

    • Groowe Search Toolbar v2.0

    Did you knowingly install this?


    2) Now we need to restore a file:


    Please use windows explorer to navigate to the following bold file:

    C:\Qoobox\Quarantine\C\WINDOWS\winhelp.ini.vir

    Ensure that you right click and rename it to dis-include the .vir extension.
    Then move it back to it's original location of: C\WINDOWS

    3) Now goto this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run the new MGTools.exe and attach the MGlogs.zip that it will generate into your next reply.
     
  12. bobdog

    bobdog Private E-2

    The groowe toolbar is there intentionally.

    Thanks Again,

    Here y'go:
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to ensure you followed my step #2 in post #11 before completing the below. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. bobdog

    bobdog Private E-2

    Hooray!

    Winhelp.ini was replaced, I forgot to mention that in my post.

    Thanks again, you guys rock!

    (I work at a library and probably refer a couple dozen ppl a week to this site)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're most welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds