Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32.TDSS.rtk and XP Deluxe Protector (Help Plz)


  • Please log in to reply

#1
hatemalware101

hatemalware101

    New Member

  • Member
  • Pip
  • 2 posts
I am getting popups for XP Deluxe Protector..done scans with avg/norton/spybot/ and other stuff during my search...spybot found Win32.TDSS.rtk and unable to remove. All antiviruses and firewalls have been disabled (lol big surprise NOT) Have read many posts here and did the Combofix scan here is the log. ( oh and did the recovery thing with combofix)
Also I should add that the xp deluxe protector is in its own folder/file... its just a folder with the .exe in it and when u try to delete tells me that I either don't have the disk space or its being used (um...duh..its always running) I would really like to get this thing out...Having to buy a new OS is not fun :) and hubbys retarded and never went and picked my install disks back up (ROFL don't ask).
Neways plz let me know what I need to do from here
Thanks :)
Ps I can't uninstall either avg or norton ..they r both stuck (dunno if that has to do with what is goin on or not)


ComboFix 09-05-30.04 - Heather 05/31/2009 5:22.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1677 [GMT -5:00]
Running from: c:\documents and settings\Heather\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.
2009-05-30 19:52 . 2009-05-30 19:52 -------- d-----w- c:\program files\SGPSA
2009-05-30 19:52 . 2009-05-30 19:52 -------- d-----w- c:\documents and settings\Heather\XP Deluxe Protector
2009-05-30 05:40 . 2009-05-30 05:40 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-05-30 05:20 . 2009-05-30 05:20 29184 ----a-w- c:\windows\system32\iehostcx32.dll
2009-05-29 20:28 . 2009-05-29 20:28 -------- d-----w- c:\program files\Fast Browser Search
2009-05-28 22:23 . 2009-05-28 22:23 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-05-19 14:21 . 2009-05-08 14:03 2051864 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-05-19 14:21 . 2009-05-08 14:03 354584 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-05-19 14:21 . 2009-05-08 14:03 424472 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll
2009-05-19 14:21 . 2009-05-08 14:03 177432 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll
2009-05-19 14:21 . 2009-05-08 14:03 3288344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-05-19 14:21 . 2009-05-08 14:03 312088 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglngx.dll
2009-05-19 14:21 . 2009-05-08 14:03 486168 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe
2009-05-19 14:19 . 2009-05-08 14:00 755992 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-05-19 14:19 . 2009-05-08 14:00 1437464 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-16 14:19 . 2009-05-08 14:03 3399960 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-05-16 14:19 . 2009-05-08 14:03 2302232 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-05-03 01:07 . 2009-05-03 01:07 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-05-02 10:40 . 2009-05-02 10:40 -------- d-sh--w- c:\documents and settings\Heather\IECompatCache
2009-05-02 10:39 . 2009-05-02 10:39 -------- d-sh--w- c:\documents and settings\Heather\PrivacIE
2009-05-02 10:37 . 2009-05-02 10:37 -------- d-sh--w- c:\documents and settings\Heather\IETldCache
2009-05-02 10:30 . 2009-05-02 10:30 -------- d-----w- c:\windows\ie8updates
2009-05-02 10:29 . 2009-02-28 04:55 105984 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-05-02 10:28 . 2009-05-02 10:29 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-31 09:58 . 2005-07-05 21:24 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-31 09:48 . 2008-01-15 20:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-31 09:33 . 2008-07-23 18:32 -------- d-----w- c:\documents and settings\Heather\Application Data\StumbleUpon
2009-05-31 08:24 . 2008-05-15 20:23 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-31 08:16 . 2006-12-13 02:35 -------- d-----w- c:\program files\Norton Internet Security
2009-05-30 20:46 . 2008-01-15 20:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-30 19:52 . 2007-12-31 21:59 -------- d-----w- c:\program files\World of Warcraft
2009-04-21 04:51 . 2008-07-23 18:32 -------- d-----w- c:\program files\StumbleUpon
2009-04-14 22:05 . 2006-01-02 23:04 -------- d-----w- c:\program files\Diablo II
2009-03-08 09:34 . 2006-06-23 17:33 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2002-09-03 13:00 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2002-09-03 13:00 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2002-09-03 13:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2002-09-03 13:00 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2002-09-03 13:00 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2002-09-03 13:00 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2002-09-03 13:00 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2002-09-03 13:00 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2002-09-03 13:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2002-09-03 13:00 284160 ----a-w- c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-12-01 4662776]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-05 3022848]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Diablo II\\Diablo II.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"11042:TCP"= 11042:TCP:vent
"11402:TCP"= 11402:TCP:vent
"6881:TCP"= 6881:TCP:blizzard downloader
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [4/12/2009 1:19 PM 120168]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tattoodle.com?tid={D157F405-70AF-4f30-A963-2D350EDEDC7C}&v=12
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-31 05:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-329068152-1979792683-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-329068152-1979792683-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4008)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-05-31 5:27
ComboFix-quarantined-files.txt 2009-05-31 10:26
ComboFix2.txt 2009-05-31 10:02
Pre-Run: 40,633,593,856 bytes free
Post-Run: 40,622,612,480 bytes free
144 --- E O F --- 2009-05-13 08:02
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Download The Avenger by Swandog46 from
http://swandog46.gee...r2/download.php
* Unzip/extract it to a folder on your desktop.
* Double click on avenger.exe to run The Avenger.
* Click OK.
* Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
* Copy all of the text between the stars to the clipboard by highlighting it and then pressing Ctrl+C.

*******************************************************
Folders to delete:
c:\program files\SGPSA
c:\documents and settings\Heather\XP Deluxe Protector

Drivers to delete:
tdsserv
tdssmhct

******************************************************
* In the avenger window, click the Paste Script from Clipboard icon, Image button.
* :!: Make sure that what appears in Avenger matches exactly what you were asked to Copy/Paste from the Code box above.
* Click the Execute button.
* You will be asked Are you sure you want to execute the current script?.
* Click Yes.
* You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
* Click Yes.
* Your PC will now be rebooted.
* Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
* If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.
* After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt). I would like to see the log in your next post.

Run SDFix per the instructions:

http://www.bleepingc...opic131299.html

When you download and run sdfix your antivirus should be paused or stopped. McAfee especially will remove critical files and keep it from running.

Hopefully it will run without a problem so you should be able to start in the middle of the page where it says

SDFix Instructions:

I'd like this log.

Run:

Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:

http://www.malwarebytes.org/mbam.php

SAVE Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.


Download but do not yet run ComboFix
:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Rename this file -- (call it george.exe ) to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Doubleclick on george to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.

Re-activate your protection programs at this time :!:

Reboot now, please :!:

Post Back (copy/paste the .txt files, do not use attachments)
After following the above, post back with:

1. Avenger log

2. SDFix log

1. Rooter log

2.Contents of C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

3. Contents of C:\Combofix.txt;


Ron
PS If you can't get to the download sites, have a friend download the files and put them on a CD. Don't use a USB drive unless it's never been on your PC and you can leave it in until we finish. Copy the tools to your desktop and then proceed as above.
  • 0

#3
hatemalware101

hatemalware101

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Ty I will get that stuff done this evening..just to insure I didnt' miss nething.
Some how last night i did get that xp protector out...ahead of u on the malbyte program installed it last night and ran it..it got rid of 2 trojans the first scan and another 3 the second and zero the third YAY...but I will go thru ur instructions to just insure i got everything..and the combofix i have is the new one i downloaded the night i posted my help thread.
Right now one issue is Norton snuck back in on the puter (don't ask i don't know hubby did something) i tried to uninstall...get it out..now its messed up to the point IE would crash everytime u tried to open it..i was able to use msn to get IE8 downloaded and installed ...now we can use IE but only with NO add-ons enabled...Norton phishing program or something has just messed that up...don't know if that can be fixed now or not..no system restore will work..i'll take that over the trojans and malware.
At least the boogers r out that i know of..I will post the logs for u this evening when i run everything.
and ty for getting back to me.
Ps i use avg antivirus..so far in my yrs its been one of the lesser evil antivirus..i won't use norton nor mcafee.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP