Infection Resolving Team

Re: Security Team

No Airbot, the virus is very smart and wont allow any malware or spyware programs(exc comodo) to show on the screen. The weird part is when i go to task manager, click on processes, it is right there. It just wont show on the screen
Bem
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

I was just talking to someone here at work. She has the same virus.

They should start educating people when they sell PC's. She had no idea that she was dealing with a virus. As soon as she said she's getting pop-ups telling her that she has 32 viruses, I knew exactly what it was (thanks to this forum!).
 

My Computer

System One

  • Manufacturer/Model
    H/P dv7 Notebook PC
    CPU
    Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
    Motherboard
    Compal ID 30F4 Version 99.67
    Memory
    4.096
    Graphics card(s)
    NVidia GeForce 9600M GT
    Screen Resolution
    1440x900
    Hard Drives
    WDC WD3200BVET-60ZTC0 ATA DEVICE
    Mouse
    Synaptics PS/2 Port TouchPad HID-compliant mouse
    Keyboard
    IBM ENHANCED (101 or 102) keyboard

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal Crucial CT256MX100SSD1 256GB SSD, Seagate ST2000DM001-1CH1 2TB, External (USB3) Seagate Backup+ Hub BK SCSI Disk 8TB 2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs) NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel
Re: Security Team

Thanks you all very much for the info. In the end, i called my teacher and i offered the two optitions and she actually wanted me to do a PC restore.
Thanks everyone
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

Thanks you all very much for the info. In the end, i called my teacher and i offered the two optitions and she actually wanted me to do a PC restore.
Thanks everyone
Ben

That's probably the easiest and best option. That's what I told my co-worker to do. Back up anything you want to save and wipe the slate clean.

I'm buying my daughter a laptop for Christmas, I already told her that before she gets it we're going to sit down and go over ways to keep her computer safe and working well.
 

My Computer

System One

  • Manufacturer/Model
    H/P dv7 Notebook PC
    CPU
    Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
    Motherboard
    Compal ID 30F4 Version 99.67
    Memory
    4.096
    Graphics card(s)
    NVidia GeForce 9600M GT
    Screen Resolution
    1440x900
    Hard Drives
    WDC WD3200BVET-60ZTC0 ATA DEVICE
    Mouse
    Synaptics PS/2 Port TouchPad HID-compliant mouse
    Keyboard
    IBM ENHANCED (101 or 102) keyboard
Re: Security Team

IESVG is the Adobe SVG plugin for IE
Adobe is the Flash Player plugin

SYMCHECKUPSTUB.EXE usually is associated with Symantec Corporation; Norton PC Checkup Stub Application

Your program is showing these as potentially unsafe although they pose no malicious risk.

TDSSBRSR.DLL is part of a trojan that hijacks browsers in order to produce popup advertisements from known badsites and also has rootkit functionality in order to hide itself as a system driver.




How to remove TDSSBRSR.DLL
Author:TDSSBRSR.DLL Hits: UpdateTime:2008-10-20 9:36:39
TDSSBRSR.DLL removal

TDSSBRSR.DLL and detail of TDSSBRSR.DLL:
TDSSBRSR.DLL description :The filename TDSSBRSR.DLL was last seen on 10.19.2008, and it is considered unsafe. This threat is associated with the malware group rootkit.agent. Threat name rootkit.agent Filename [System32Root]\tdssbrsr.dll Filesize Unknown Last seen 10.19.2008 Status Known to RemoveIT Pro as unsafe. This file can perform following behavior. - Usualy created by unsafe process. - Registered as a Dynamic Link Library File. - Usualy have random filename and refers to many versions of a dynamic link library. - Can be injected/attached to the legitimate Windows process such as explorer.exe or other.

TDSSBRSR.DLL remove instruction
1. Temporarily Disable System Restore, Reboot computer in SafeMode;
2. Locate TDSSBRSR.DLL virus files and uninstall TDSSBRSR.DLL files program. Follow the screen step-by-step screen instructions to complete uninstallation of TDSSBRSR.DLL.
3. Delete/Modify any values added to the registry related with TDSSBRSR.DLL,Exit registry editor and restart the computer;
4.Clean/delete all TDSSBRSR.DLLinfected file(s):TDSSBRSR.DLL and related,or rename TDSSBRSR.DLL virus files;
5.Please delete all your IE temp files with TDSSBRSR.DLL manually,run a whole scan with antivirus program ;

How to remove TDSSBRSR.DLL|Virus Com

The other DLL's are derivatives of the above and should be deleted the same way.
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Mouse
    Targus
    Keyboard
    Microsoft
    Internet Speed
    1500kbs
    Other Info
    Self built.
Re: Security Team

Hi Ben

The TDSS infection is a rootkit infection and can be nasty. It installs at root level and roams about undetected by most AV's and scanners. It is dangerous and incorrect to assume that because the rootkit has been removed the computer is now secure.

TDSS can be removed by the use of special tools under guidance, I myself have helped users remove this infection. Even though you mention that you have done a system rollback, if you are having problems, or feel things are not right I would advise that you post in a dedicated security forum that is ASAP affiliated where someone with experience on removing such infections can advise you further.

Regards
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    2.53 Celery Stick
    Memory
    2Gb
    Graphics card(s)
    Onboard
    Sound Card
    Onboard
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1280*1024
    Hard Drives
    320Gb Western Digital
    Case
    Dell Standard
    Internet Speed
    20Mb
Re: Security Team

thanks sjb007 but i am all set. The rollback restores the computer to the exact format as when i got it out of the box. Everything is all set.

And i am very sure that i have very helpful people on this site.
Thanks very much for the info as well

Also Thanks very very much barman and Norm.
Very helpful info.
See, even i have problems with viruses. Im no where near an expert(clearly), but i do try my hardest and solve a lot of problems.

Thanks again.
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

Hey everyone,
My uncle is on the board of security for Blue Cross Blue Shield. He is amazing with the security aspect of computers. I was talking to him about the TDSS trojan and he was telling me a couple things. I was so mad at myself for one thing imperticular that i didnt think of.

When someone gets infected with that type of trojan, once it is detected, it will jump off of that file, go to another, and use that one.

My uncle told me that i should have unchecked the system restore optition when something like this comes up

I was like why would i do that it would ruin any chance for recovery if the trojan were to screw anything up.

The system restore holds a copy of what your computer files, ect look like. If the trojan goes around to different files, even if i find it on the normal section of my HD, i still will have it in the system restore files.

I was so upset with my self when i had found this out. So i know now that i will have to disable that feature when you have a virus like that.

Darn o well ill know for next time something happens.

Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

My take on that would be that you only disable it when you know you have a clean machine, that is when you get rid of the old restore points and set a new one.

At least then if you screw up while trying to clean the machine at least you can still get into it even if it's dirty, then you can try the clean up again.
 

My Computer

System One

  • Operating System
    Windows 10 Home
    Manufacturer/Model
    HP Envy x360 Convertible 15-bq0xx
    CPU
    AMD A9 Stoney Ridge Technology
    Motherboard
    HP 8312 (Socket FP4)
    Memory
    8.00GB Dual-Channel Unknown (?-0-0-0)
    Graphics card(s)
    Generic PnP Monitor (1920x1080@60Hz) 512MB ATI AMD Radeon R5
    Sound Card
    AMD High Definition Audio Device Realtek High Definition Aud
    Monitor(s) Displays
    Generic PnP Monitor on AMD Radeon R5 Graphics
    Screen Resolution
    1920 x 1080
    Hard Drives
    119GB SanDisk SD8SN8U-128G-1006 (SSD) 931GB Hitachi HGST HTS721010A9E630 (SATA
    Mouse
    Microsoft Optical Wheel Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    62.86Mbps down 18.19Mbps up
    Other Info
    EPSON78D0CF (XP-332 335 Series) (Default Printer)
Re: Security Team

Hey Ben, I had never actually realised that a virus would still be in my restore files - how did I miss that!? :eek:

Thanks for the tip :)
 

My Computer

System One

  • Manufacturer/Model
    Hewlett Packard
    CPU
    3.40Ghz / 2.20Gz Duo Core
    Memory
    2GB / 3GB
    Hard Drives
    160 GB / 160 GB
Re: Security Team

Good point Joan,
I guess that makes sense.

and i know how you feel Fmjc,
I was like wow how did i miss that
aSDFASDFSADFASDF
haha
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

Good point Joan,
I guess that makes sense.

and i know how you feel Fmjc,
I was like wow how did i miss that
aSDFASDFSADFASDF
haha

Well, you learn something new every day :)
 

My Computer

System One

  • Manufacturer/Model
    Hewlett Packard
    CPU
    3.40Ghz / 2.20Gz Duo Core
    Memory
    2GB / 3GB
    Hard Drives
    160 GB / 160 GB
Re: Security Team

Exactly,
We might have an incoming help needed. Someone just posted about the Trojian Vanderboild.
They need help
Lets help them out.
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

Where is the post Ben?
 

My Computer

System One

  • Manufacturer/Model
    Hewlett Packard
    CPU
    3.40Ghz / 2.20Gz Duo Core
    Memory
    2GB / 3GB
    Hard Drives
    160 GB / 160 GB
Re: Security Team

it is in the security section on the site. I told the person that they should come and post here but im not sure if they are going to. I was just giving you peoplke a heads up incase they do
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

Hey everyone 100 replies on this forum and a ton more to go!

Thanks and congrats to alll members!!!
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Re: Security Team

I'd say any of the good free ones. Avast Home Edition, Avira, Comodo, AVG. Some good paid versions...Eset NOD 32, Kapersky.
 

My Computer

System One

  • Manufacturer/Model
    Airbot 2.0
    CPU
    Core i7 920 (D0) @ 4Ghz, 26c idle- 65c full load on air
    Motherboard
    Asus P6X58D Premium -Sata 6Gb/s - USB 3.0
    Memory
    12GB Corsair Dominator -CMD12GX3M6A1600C8
    Graphics card(s)
    EVGA Nvidia GTX 480 -Fermi
    Sound Card
    ASUS Xonar D2X
    Monitor(s) Displays
    LG 24" Flatron W2453V-PF Full HD 1080p 2ms response time
    Screen Resolution
    1920x1080@60hz
    Hard Drives
    1 OCZ Vertex2 180GB SSD 1 TB Samsung Spinpoint F1 7200RPM 32MB cache 2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS) Pioneer DVD Burner DVR-S18M
    PSU
    Corsair HX1000W
    Case
    Cooler Master HAF 932
    Cooling
    Case Fans -3 230mm, 1 140mm/CPU - Tuniq Tower 120 Extreme
    Mouse
    Logitech Wireless MK700
    Keyboard
    Logitech Wireless MK700
    Internet Speed
    100 MBPS DL 30.17Mbps UL 0.98Mbps
    Other Info
    Windows 7 Processor-7.7 RAM- 7.9 Graphics-7.9 Gaming Graphics- 7.9 HDD- 7.8 W.E.I final score= 7.7 Windows Vista=5.9
Re: Security Team

Most likly Comodo or Avir AV, they are both in brinks free software list. For Paid, either

Norton Internet Security 2009 :D


ESET Smart Security :D
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Mouse
    Logitech EX100 Combo
    Keyboard
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Back
Top