my symantec antivirus program reports that my computer is infected with a virus named Backdoor.Tidservlinf which it cannot remove or quarantine. it is located at C:\Documents and Settings\david\Local Settings\Temp\tds.tmp which i do not know how to access. other programs that i have used either freeze up or do not find it. since i am not sure what this virus does, i am reluctant to do anything on the computer until it is removed. i could really use some help! thank you.

Let's make sure you have hidden files visible.

Show hidden files
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

Delete C:\Documents and Settings\david\Local Settings\Temp\tds.tmp file if found.

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop and post them back here.

thanks for your help. first, i misnamed the virus file, it is:

C:\Documents and Settings\david\Local Settings\Temp\tds147.tmp

i followed your instructions, found the file, but when i tried to delete the file the computer said : cannot delete tds147: access is denied. i looked at the properties of the file and i cannot find anything that says that it is write protected. i did not go any further since the deletion step was unsuccessful. please let me know what to do next. thanks again.

Please run DDS and post back its reports. We'll deal the problematic file later :santa:

i do not know how to disable script blockers if they exist. also, i disabled my sytem restore when i was trying to delete the virus by myself (before contacting spybot), and since i was unsuccessful i left it disabled. i ran dds and am copying the logs. thanks.

DDS (Version 1.0)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 8/2/2004 10:42:28 PM
System Uptime: 12/17/2008 11:38:34 AM (1 hours ago)

Motherboard: Dell Computer Corp. | | 0C2425
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2790/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 34 GiB total, 20.906 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Ad-Aware 2007
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9
Banctec Service Agreement
Broadcom Management Programs
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
Dell Support Center (Support Software)
Filmmakers and Financing, 4e
Help and Support Customization
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Image Zone 4.7
HP Product Assistant
HP PSC & OfficeJet 4.7
HP Software Update
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Extreme Graphics Driver
Internet Explorer Default Page
iPod for Windows 2006-03-23
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 8
J2SE Runtime Environment 5.0 Update 9
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
Kodak EasyShare software
LiveUpdate 1.80 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Small Business
Microsoft Picture It! Express 9
Microsoft Picture It! Library 9
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Modem Event Monitor
Modem Helper
Modem On Hold
Mozilla Firefox (
MSN Connection Center
MSN Encarta Plus Support Files
MSN Messenger 6.2
MSN Money Investment Toolbox
MSN Money Investment Toolbox Beta
MSN Music Assistant
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch® Jukebox
OpenOffice.org 2.4
SanDisk TransferMate
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Skype™ 3.5
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
StreetSmart Pro
Symantec AntiVirus Client
TextBridge Pro 9.0
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Verizon Online
Verizon Online Support Center
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WordPerfect Office 12

==== Event Viewer Messages From Past Week ========

12/12/2008 12:26:49 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
12/15/2008 1:18:58 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
12/15/2008 1:18:58 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

==== End Of File ===========================

Please re-enable system restore. Even infected system restore point is better than no point at all.

You have way too old Firefox version installed there. Uninstall it and get the latest one here.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 11.
  • Scroll down to where it says
    The J2SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the
    button to the right.
  • Select Windows on platform combobox and check the box that says:
    Accept License Agreement. Click continue.
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe to install the newest version. Note: Uncheck MSN toolbar option if you don't want to install it.

Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here. Post back its report.

We need to execute an OTMoveIt3 script
  1. Please download OTMoveIt3 by OldTimer and save it to your desktop.
  2. Double click theOTMoveIt3 icon on your desktop.
  3. Paste the following code under the Paste Fix Here area. Do not include the word
    C:\Documents and Settings\david\Local Settings\Temp\tds.tmp
  4. Push the large MoveIt button.
  5. OTMI3 may ask to reboot the machine. Please do so if asked.
  6. Copy/Paste the contents under the Results line here in your next reply with a fresh hjt log.
  7. If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

i made a typo when i originally wrote the name of the virus file. the correct name is:

C:\Documents and Settings\david\Local Settings\Temp\tds147.tmp

i assume that is the name i should paste. thanks.

i am running the kaspersky online scanner. it mostly came up as indicated in the screenshot, except that when i pressed settings, the correct settings came up, but the save option never came on. i assumed that the settings that came up were what was in fact set and i am running the scan. if there is a problem with anything that i did, please let me know. thanks

i have run the kaspersky scan and am pasting in the results. i have not yet done OTMoveIt3. i am not quite sure what this does so i will wait until you clarify the file name. should i just copy the instruction to a word document, alter it, and paste? thanks again for your help.

Wednesday, December 17, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version:
Program database last update: Wednesday, December 17, 2008 17:31:21
Records in database: 1469879

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:

Scan statistics:
Files scanned: 88623
Threat name: 3
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 02:12:33

File name / Threat name / Threats count
C:\Documents and Settings\david\Local Settings\Temp\tds147.tmp Infected: Trojan.Win32.Patched.dw 1
C:\Program Files\Common Files\Verizon Online\SFP\vzbb.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.b 1
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\newgetposted[1].htm Infected: Trojan-Downloader.JS.Agent.cnn 1

The selected area was scanned.

Yes, that file has to be removed. However, lets take the chance and add other bad findings to the script :santa:

C:\Documents and Settings\david\Local Settings\Temp\tds147.tmp
C:\Program Files\Common Files\Verizon Online\SFP\vzbb.dll
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\newgetposted[1].htm

i followed your instructions and will paste the results. does otmoveit delete the bad files? thanks.

========== FILES ==========
File move failed. C:\Documents and Settings\david\Local Settings\Temp\tds147.tmp scheduled to be moved on reboot.
C:\Program Files\Common Files\Verizon Online\SFP\vzbb.dll unregistered successfully.
C:\Program Files\Common Files\Verizon Online\SFP\vzbb.dll moved successfully.
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\newgetposted[1].htm moved successfully.

OTMoveIt3 by OldTimer - Version log created on 12182008_110103

Files moved on Reboot...
C:\Documents and Settings\david\Local Settings\Temp\tds147.tmp moved successfully.

yes i did reboot which is indicated at the bottom of the otmoveit log with the heading "Files moved on Reboot...". i did a search and the tds147.tmp file seems to have been moved to

C:\_OTMoveIt\MovedFiles\12182008_110103\Documents and Settings\david\Local Settings\Temp\tds147.tmp

should i now try to delete the file? also, at the bottom of web pages, as the spybot page i am now working on, i often get "Done, but with errors on the page". is this related to the malware? can i get rid of these errors? thanks
Probably some javascript related errors. Not malware related and I wouldn't be worried :santa:

We shall now uninstall OTMoveIT3. That will take away those moved objects too.

  • Double-click OTMoveIt3.exe.
  • Click the CleanUp! button.
  • Select Yes when the
    Begin cleanup Process?
    prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.

Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet, please allow it to do so.

How's the system running now? Are you still getting alerts of infections?

thank you so much for your help. the system seems to run much better and symantec finds no infections. any suggestions on how to improve my security situation would be appreciated. thanks again.:)
Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis

We need to re hide system files. To do so, please follow the steps below:
  1. Double-click My Computer.
  2. Click the Tools menu, and then click Folder Options.
  3. Click the View tab.
  4. Put a check by
    Hide file extensions for known file types.
  5. Under the
    Hidden files
    folder, select
    Show hidden files and folders.
  6. Check
    Hide protected operating system files.
  7. Click Apply, and then click OK.


IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

  • Download Spybot
    Spybot is a scanner like adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and pretection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
    To see how to set this up as well as more spybot features, see here
    Spybot can be downloaded at this location
  • Download SpywareBlaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
    kill bits
    in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
    You can download SpywareBlaster here here
    SpywareBlaster tutorial
  • hosts file:
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    1. [*]Click the start button (at the lower left hand corner of your screen) [*]Click run [*]In the dialog box, type services.msc [*]hit enter, then locate dns client [*]Highlight it, then double-click it. [*]On the dropdown box, change the setting from automatic to manual. [*]Click ok
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!).

Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Once again, please post and tell me how things are going with your system... problems etc.

Happy Holidays,
Blade :santa:

i do have one thing that is bothering me about the system (but i am not convinced that it is malware). my outlook express program, which i never use, spontaneously turns on (twice in the last week or so) and tries to send messages. at first i thought it was nothing, but something similiar happened on a computer that i often transfer data to with a memory stick. i don't know what i am doing to cause these things to happen. anyway, other than that the system seems fine.

i set the new restore point and protected operating system files to be hidden. can you explain what other hidden files are and why i want to see them. also, my internet explorer security options were almost exactly as you describe except navigate sub-frames across different domains is set at disable. i don't understand what this does.

i would like to download spybot, i know it is a very good system, but i thought that there was a conflict between my ad-watch program and the spybot tea timer (both real time protection).

thanks again for all your help. david :)
i do have one thing that is bothering me about the system (but i am not convinced that it is malware). my outlook express program, which i never use, spontaneously turns on (twice in the last week or so) and tries to send messages. at first i thought it was nothing, but something similiar happened on a computer that i often transfer data to with a memory stick. i don't know what i am doing to cause these things to happen. anyway, other than that the system seems fine.
Has this happened after cleaning operation was finished?

i set the new restore point and protected operating system files to be hidden. can you explain what other hidden files are and why i want to see them.
Sometimes malware uses hidden files and in order to delete those files have to be visible. System files are normally hidden to ensure those are not deleted by accident.

also, my internet explorer security options were almost exactly as you describe except navigate sub-frames across different domains is set at disable. i don't understand what this does.
That's ok. You may have that option disabled as well.

i would like to download spybot, i know it is a very good system, but i thought that there was a conflict between my ad-watch program and the spybot tea timer (both real time protection).
You don't have to enable TeaTimer :santa:

as to question one, yes it happened once before (which actually prompted me to run symantec and find Backdoor.Tidserv!inf) and once after. ok to the rest of the comments. thanks again.:)

So, if it's still happening it's better we run one more tool.

Please visit this webpage for download links, and instructions for running ComboFix tool:


Please ensure you read this guide carefully and install the Recovery Console for XP home edition first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

New HijackThis log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.