Tech ARP Forums

Go Back   Tech ARP Forums > Software Discussion > General Software
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

General Software This is the forum for general discussions about software.

Reply
 
LinkBack Thread Tools
Old 25th Nov 2008, 11:41 AM   #1 (permalink)
Super Active
 
Zenphic's Avatar
 
Join Date: 23 Apr 2006
Location: Quebec, Canada
Posts: 1,098
Reputation: 467
Zenphic is a glorious beacon of lightZenphic is a glorious beacon of lightZenphic is a glorious beacon of lightZenphic is a glorious beacon of lightZenphic is a glorious beacon of light
Rep Power: 9
Default omg, !@#$*^ trojan!

Seriously, this hasn't been my week. I booted my PC this morning and I got a warning from Avira Antivir that it detected a trojan. It was located under System32 and it was called TDSSntlv.dl and caused problems like not being able to run some software and bluescreens...

Whenever I tried deleting/quarantining/ignoring/denying access, a new warning would pop up moments later with the same problem.

I navigated to System32 and I tried to look for the file itself, thinking that maybe Avira wasn't deleting it properly. I made sure that Explorer was set to show all files and, omg, I couldn't see it! Ran a full virus scan with Antivir and it didn't pick anything up. I ran other spyware software and they didn't pick anything up or would crash whenever I tried running it in safeboot.

Finally, got frustrated and pulled out the HDD, put it into an enclosure and got my laptop to scan it. I explored the HDD and I could finally see the TDSSntlv.dl file. Running the scan right now and it picked up a few TDSS***.dll files. Hopefully it fixed it...
__________________
E2160 @ 1.8Ghz (0.95V) | XFX 650i Ultra | 2x1GB Crucial Ballistix DDR2-800 | Gigabyte GeForce 6600 | Hitachi Desktar T7K250 250GB | CM Mystique 632 | 2x Noctua NF-S12 800RPM | CM RPP 550W
Zenphic is offline   Reply With Quote
SPONSOR

Old 25th Nov 2008, 11:53 AM   #2 (permalink)
Getting there
 
Join Date: 6 Oct 2008
Location: Brunei earth
Posts: 158
Reputation: 0
starboykb is an unknown quantity at this point
Rep Power: 2
Default

you should tried using Combofix to do the cleaning and see if it helps.
starboykb is offline   Reply With Quote
Old 25th Nov 2008, 12:04 PM   #3 (permalink)
"Little" Devil
 
PsYkHoTiK's Avatar
 
Join Date: 8 Apr 2004
Location: On the "throne"
Posts: 14,661
Reputation: 4442
PsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond repute
Rep Power: 64
Default

Make sure your System restore is turned off before you clean/scan.
__________________
Intel SLAPL 4.3GHz @ 1.35v : 2x2GB OCZ Platinum DDR2 1066 : Asus P5K Premium : WD RE3 250GB x2 RAID 0 : 3ware 9650SE-2LP : G92 8800GTS 512mb 820MHz Core : XFi Platinum : Silverstone OP650 : Silverstone TJ-07 : Dtek FuZion CPU : Swiftech MCW60 : MCP655 : Thermochill PA120.3 w Scythe Ultra Kaze
CPU-Z: SLAPL : SLA9U : FX-55 : DDR 600 : VX
www.techarp.com
PsYkHoTiK's Meanderings
PsYkHoTiK is online now   Reply With Quote
Old 25th Nov 2008, 01:06 PM   #4 (permalink)
Super Active
 
lee_what2004's Avatar
 
Join Date: 28 Dec 2007
Location: Melaka
Posts: 1,313
Reputation: 1106
lee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud of
Rep Power: 14
Default

sysinternal task manager to kill the process
and hijackthis to diagnose
and unlocker to delete
__________________
Once a wise-man said :
Chapter 1: Don't ever compare if you want to stay constant.....
Chapter 2: Whatever you have done in the internet, you will never get away from it...
Chapter 3:To be continued after I thought another one
lee_what2004 is online now   Reply With Quote
Old 25th Nov 2008, 01:59 PM   #5 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 27,884
Reputation: 4630
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 81
Default

Taking out the HDD and connect it to another PC is the best way to clean it.
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Old 25th Nov 2008, 09:15 PM   #6 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 32,299
Reputation: 3574
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 75
Default

Quote:
Originally Posted by Chai View Post
Taking out the HDD and connect it to another PC is the best way to clean it.
Yeah, that's actually much easier than cleaning the drive using the same system.
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 25th Nov 2008, 10:11 PM   #7 (permalink)
Active
 
Join Date: 29 Nov 2006
Posts: 599
Reputation: 11
karhoe is on a distinguished road
Rep Power: 3
Default

Did you set the option to 'show system protected files?'
__________________
My Blog
SPM Timetable 2009
karhoe is offline   Reply With Quote
Old 25th Nov 2008, 10:43 PM   #8 (permalink)
Super Active
 
lee_what2004's Avatar
 
Join Date: 28 Dec 2007
Location: Melaka
Posts: 1,313
Reputation: 1106
lee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud oflee_what2004 has much to be proud of
Rep Power: 14
Default

Quote:
Originally Posted by Adrian Wong View Post
Yeah, that's actually much easier than cleaning the drive using the same system.
that's applicable only if you got spare system to do it
__________________
Once a wise-man said :
Chapter 1: Don't ever compare if you want to stay constant.....
Chapter 2: Whatever you have done in the internet, you will never get away from it...
Chapter 3:To be continued after I thought another one
lee_what2004 is online now   Reply With Quote
Old 25th Nov 2008, 11:08 PM   #9 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 32,299
Reputation: 3574
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 75
Default

Quote:
Originally Posted by lee_what2004 View Post
that's applicable only if you got spare system to do it
That's true... or well, a friend who has a computer.
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 26th Nov 2008, 01:20 AM   #10 (permalink)
Administrator
 
Chai's Avatar
 
Join Date: 6 Oct 2002
Location: Maranello
Posts: 27,884
Reputation: 4630
Chai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond reputeChai has a reputation beyond repute
Rep Power: 81
Default

I think most people have more than 1 PC at home now.
__________________
Chai (Contributor & Forum Admin)
http://www.techarp.com/
Chai is offline   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +8. The time now is 01:39 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2009 Tech ARP. All rights reserved.