tds won't start

Discussion in 'Trojan Defence Suite' started by squirrel, Dec 14, 2004.

Thread Status:
Not open for further replies.
  1. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    hi
    i need some help my pc (winxp) had some serious problems with trojans and my tds refuses to run i reinstalled it put new radius and tryed to run it but nothing happened, managed to clean pc by loading tds from another pc and now it's clean (i hope so) but tds still won't run on my pc. even tryed running it in safe mode but it's the same. when i run tds it gets into memory but i can't see it. can anyone help me please :doubt:
     
  2. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi squirrel, Is your TDS a licensed version or the trial? If a trial it may have run out of time.
    If yours is a licensed version did you have Execution Protection (EP) running before you had these Trojans, as to re-install EP must be uninstalled first.
    Try uninstalling TDS now and delete it's folder, reboot, then disable your other programs especially your AV resident parts, then try re-installing again.
    Make sure your keyfile is put back into the TDS main folder if you have a license. Reboot

    HTH Pilli
     
  3. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    hi Pilli thanks for helping me, but still no changes i have trial version but it worked so far. if it's out of time then how come when i start program i can see it in processes over task manager and as a running aplication. if its out of time it shouldn't apear there, or should it?
     
  4. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Hi there, not sure. How long did you have TDS? It is a 30 days version, after that it can't be used anymore.
    If it did run fine all time, you should have had a kind message thanking you for evaluating the software and now it's time to register to keep protected.
    So you could of course register and put in the keyfile and see if it all works fine again with that.
     
  5. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    hi Jooske, the thing is that i get no message,nothing, my pc just ignores when i start tds only thing it does is that tds runs in background cause i can see it in processes and aplication in task manager, but can't get it's interface and make it scan.
     
  6. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi squirrel, Do you have TDS to automatically start? Or do you start it manually after boot up?

    If you start TDS3 automatically then I suggest that you kill the process in task manager and try and start it manually then change the settings to manuakl start.

    If this does not succeed then try running TDS3 in safe mode and then change the setting to run manually - reboot into normal mode and see if it then works.

    HTH Pilli
     
  7. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    Hi Pilli, i always start tds manually. i also tried to start tds in safe mode but same happenes like in normal mode tds goes to processes and aplication in task manager like it's running but i can't see it's interface and start scan.
     
  8. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    From the TDS FAQ's
    Why can't I get TDS-3 to restore itself from the System Tray?
    One of the few things that keeps our programmers awake at nights, this strange problem can be fixed by going into: MS-Windows..|..Start..|..Settings..|..Control Panel..|..Display and changing to SMALL FONTS. Alternatively, you can use the TDS Mini Control Window instead of having TDS-3 minimise to the system tray. This is available from: Configuration..|..Startup..|..Minimise TDS To.

    For a full list of FAQs go here:
    http://tds.diamondcs.com.au/index.php?page=tds-faq#17

    HTH Pilli :)
     
  9. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    but the thing is that tds doesn't even show up in system tray i tried to run it from task manager but just won't work. i saw forum and went through it but can't find solution.
     
  10. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    If you say you had trojans and TDS now won't start or run then it is possible that something is blocking it

    In this case please post a HIjackthis log and I will look at it and see if you have one of the security application killer trojans running

    go to here and download 'Hijack This!'. double click on the file and it will self extract to C:\program files\hijackthis.
    Go to that folder then doubleclick the Hijackthis.exe
    Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log.
    Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.
    It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required,
    so do NOT fix anything yet.
    Someone here will be happy to help you analyze the results.
     
  11. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    hi dvk thanks for helping me,heres log of hijackthis

    Logfile of HijackThis v1.99.0
    Scan saved at 22:05:35, on 16.12.2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\eDonkey2000\eDonkey2000.exe
    C:\Program Files\NetLimiter\NetLimiter.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Program Files\eMule\emule.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\WinMX\WinMX.exe
    C:\Program Files\eMule+\eMule.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\MXMoni128Eb\MXMoniE.exe
    C:\Program Files\Ghrone\Ghrone 0.271\Ghrone.exe
    C:\Program Files\Messenger Plus! 3\MsgPlus.exe
    C:\Program Files\GetRight\getright.exe
    C:\Program Files\GetRight\getright.exe
    C:\Program Files\ARPR\arpr.exe
    C:\Program Files\HijackThis\HijackThis.exe

    O1 - Hosts: netscape.com
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
    O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
    O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
    O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
    O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
    O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: *.crazywinnings.com
    O15 - Trusted Zone: *.iframedollars.biz
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.iframedollars.biz (HKLM)
    O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    O15 - Trusted Zone: *.windupdates.com (HKLM)
    O15 - Trusted IP range: 69.50.161.82
    O15 - Trusted IP range: (HKLM)
    O23 - Service: avast! iAVS4 Control Service - Unknown - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  12. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    It's not showing what I thought it would but you do have some problems

    Running any P2P program is a risk, but having 3 running is extreme danger in my book and all the O15 entries allow anything from those site to download anything to your computer. We ahve noticed recently that some of those entries accompany a rootkit that we think has a security application killer in it so the best way to proceed is to run HJT again but this time in safe mode and we'll see if what I think is there will show in safe mode

    when we see that then we might be able to find a cure
     
  13. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    this is a log made in safe mode


    Logfile of HijackThis v1.99.0
    Scan saved at 22:51:46, on 16.12.2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HijackThis\HijackThis.exe

    O1 - Hosts: netscape.com
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
    O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
    O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
    O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
    O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
    O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
    O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O15 - Trusted Zone: *.crazywinnings.com
    O15 - Trusted Zone: *.iframedollars.biz
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.iframedollars.biz (HKLM)
    O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    O15 - Trusted Zone: *.windupdates.com (HKLM)
    O15 - Trusted IP range: 69.50.161.82
    O15 - Trusted IP range: (HKLM)
    O23 - Service: avast! iAVS4 Control Service - Unknown - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  14. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    Nothing showing there either so I don't know why TDS won't start unless it thinks the 30 day trial is up for some reason

    But let's clear up the few problems that are showing

    Run hijackthis, tick these entries listed below and ONLY these entries, double check to make sure, then make sure all browser & email windows are closed and press fix checked

    O1 - Hosts: netscape.com
    O15 - Trusted Zone: *.crazywinnings.com
    O15 - Trusted Zone: *.iframedollars.biz
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.iframedollars.biz (HKLM)
    O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    O15 - Trusted Zone: *.windupdates.com (HKLM)
    O15 - Trusted IP range: 69.50.161.82
    O15 - Trusted IP range: (HKLM)
     
  15. squirrel

    squirrel Registered Member

    Joined:
    Dec 14, 2004
    Posts:
    8
    thanks so much for your help i fixed those enteries you told me to. just don't get why is tds in processes and i can't see its interface i see it in task manager like its working normally so don't think it's expired jet.
     
  16. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi squirrel, Can you please uninstall TDS3 completely, If your trial version is faulty please re download from the DCS website and try re-installing.

    If your version has run out of time purchase a license.

    Thanks. Pilli
     
Thread Status:
Not open for further replies.