ChiefsPlanet

ChiefsPlanet (https://www.chiefsplanet.com/BB/index.php)
-   Media Center (https://www.chiefsplanet.com/BB/forumdisplay.php?f=2)
-   -   Computers The Official Malware/Antivirus Thread - Need help or general advice? Read this first! (https://www.chiefsplanet.com/BB/showthread.php?t=232173)

QuikSsurfer 04-03-2012 12:14 PM

Quote:

Originally Posted by ChiefsandO'sfan (Post 8514259)
I just had BOOT.TIDSERV lost everything how do i get it back? windows 7

What do you mean you lost everything?

ShowtimeSBMVP 04-03-2012 12:47 PM

Quote:

Originally Posted by QuikSsurfer (Post 8515086)
What do you mean you lost everything?

All my pics and games are gone. All my files say empty. It wont even let me have a wallpaper it say's access denied.

Fish 04-03-2012 12:56 PM

Quote:

Originally Posted by ChiefsandO'sfan (Post 8514259)
I just had BOOT.TIDSERV lost everything how do i get it back? windows 7

That one is really nasty. Depending on the infection, you might not get any files back. But you can try.

Download and run TDSSKiller from here: http://support.kaspersky.com/faq/?qid=208283363

You might have to boot to Safe Mode to run it. You should also run scans from your virus scanner and Malwarebytes as well.

ShowtimeSBMVP 04-03-2012 12:56 PM

infected by SMARTHDD or SYSTEM CHECK rogue

Download

http://download.bleepingcomputer.com/grinler/unhide.exe

Run the UNHIDE tool,it should restore your hidden files


This seemed to work starting to get them back now.

ShowtimeSBMVP 04-03-2012 12:57 PM

Quote:

Originally Posted by KC Fish (Post 8515157)
That one is really nasty. Depending on the infection, you might not get any files back. But you can try.

Download and run TDSSKiller from here: http://support.kaspersky.com/faq/?qid=208283363

You might have to boot to Safe Mode to run it. You should also run scans from your virus scanner and Malwarebytes as well.

I agree man did all that seems to be gone. This crap was nasty.

ShowtimeSBMVP 04-03-2012 01:02 PM

Click on startmenu and type

cmd

right click on it and select run as administrator,now run these commands one by one and press ENTER after each command

diskpart

select disk=0

select partition=4

delete partition override


Now restart the PC ,if norton shows boot.tidserv,allow it to fix it,you should get a successful message

good luck


Doing this help out alot with BOOT.TIDSERV

QuikSsurfer 04-03-2012 01:17 PM

Quote:

Originally Posted by ChiefsandO'sfan (Post 8515176)
Click on startmenu and type

cmd

right click on it and select run as administrator,now run these commands one by one and press ENTER after each command

diskpart

select disk=0

select partition=4

delete partition override


Now restart the PC ,if norton shows boot.tidserv,allow it to fix it,you should get a successful message

good luck


Doing this help out alot with BOOT.TIDSERV

Good good.. I was just about to have you take a screen shot of your disk management screen for this very reason.

chasedude 04-05-2012 09:27 AM

You Apple people think you're safer than the rest of us eh? 1/2 million systems hit with malware, most in US.

http://www.bbc.co.uk/news/science-environment-17623422

Fish 04-05-2012 10:02 AM

Quote:

Originally Posted by chasedude (Post 8519562)
You Apple people think you're safer than the rest of us eh? 1/2 million systems hit with malware, most in US.

http://www.bbc.co.uk/news/science-environment-17623422

Ahhh... another "Macs get viruses too!" scare.

LMAO... and conveniently the only source for this is a small virus program vendor who doesn't bother explaining how he calculated those numbers. What a strange coincidence that the source informing us of this is also trying to sell us a product to fix it...

Anyway.. This is a little deceiving...

To get infected with this, a user must download a 3rd party application, provide administrator credentials, and actually install the application. So that's technically not malware, that's considered downloading a program that you don't know, and manually installing a program you don't know even after an "Are you sure?" admin confirmation. Anyone dumb enough to do that, on any OS platform, shouldn't have admin credentials in the first place and deserves a lesson in computer responsibility.

chasedude 04-05-2012 10:22 AM

Quote:

Originally Posted by KC Fish (Post 8519656)
Ahhh... another "Macs get viruses too!" scare.

LMAO... and conveniently the only source for this is a small virus program vendor who doesn't bother explaining how he calculated those numbers. What a strange coincidence that the source informing us of this is also trying to sell us a product to fix it...

Anyway.. This is a little deceiving...

To get infected with this, a user must download a 3rd party application, provide administrator credentials, and actually install the application. So that's technically not malware, that's considered downloading a program that you don't know, and manually installing a program you don't know even after an "Are you sure?" admin confirmation. Anyone dumb enough to do that, on any OS platform, shouldn't have admin credentials in the first place and deserves a lesson in computer responsibility.


I agree being an informed user would prevent this from installing on their system. Yet the number of the uninformed usually outweighs intelligent users.

My main point I was trying to get across is no OS is safe anymore. Apple users thought they were bullet proof because most malware/trojans are meant for the more popular Windows system.

I just hooked up avast on my mobile and it's caught a couple hidden in some apps I wanted to try.

Fish 04-05-2012 10:47 AM

Quote:

Originally Posted by chasedude (Post 8519708)
I agree being an informed user would prevent this from installing on their system. Yet the number of the uninformed usually outweighs intelligent users.

My main point I was trying to get across is no OS is safe anymore. Apple users thought they were bullet proof because most malware/trojans are meant for the more popular Windows system.

I just hooked up avast on my mobile and it's caught a couple hidden in some apps I wanted to try.

Well... most malware/trojans are written for Windows. Because it's infinitely easier to execute malicious code that doesn't require any user input. "Drive by" infection is still not possible with OS X. Which does provide OS X with a much greater resistance to infection, and makes antivirus programs for Mac pretty much unnecessary. The last few versions of OS X actually have malware protection built in to the OS, which most people don't realize. And OS X is much better at sandboxing everything you run to prevent infection, memory leaks, permission issues, etc. I completely agree that no OS is bullet proof. But OS X should still be considered one of the safest options available.

I could write a program in about 5 minutes, that could completely destroy an OS X install. But it would also require the user to authenticate as admin to install, no different than the "malware" above. I don't think that makes me a hax0r though, and I wouldn't consider OS X to be vulnerable because the program I wrote could harm it if it were installed. Because that's just common sense. No virus or malware protection is going to protect against irresponsible stupidity like that.

bevischief 04-06-2012 08:21 AM

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:14:01 AM, on 4/6/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\HiJack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsearcher.com
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.5.0\PriceGongIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files\Funmoods\funmoods\1.5.11.16\bh\funmoods.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files\Funmoods\funmoods\1.5.11.16\funmoodsTlbr.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe

--
End of file - 6494 bytes

Does this look right?

QuikSsurfer 04-06-2012 10:02 AM

Quote:

Originally Posted by bevischief (Post 8521320)

Does this look right?

Looks clean minus the "PriceGong" and "funmoods" crap.

what's going on?

chasedude 04-06-2012 11:02 AM

Quote:

Originally Posted by QuikSsurfer (Post 8521503)
Looks clean minus the "PriceGong" and "funmoods" crap.

what's going on?

I agree with QuikSurfer, posting the log to hijackthis.de finds both what he mentioned questionable.

Buck 05-25-2012 10:23 PM

I'm having a hell of a time with something redirecting me on clicked links from google searches. I can't find it with anything.


All times are GMT -6. The time now is 06:01 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.