Help with Boot.Tidserv

Discussion in 'Malware Help (A Specialist Will Reply)' started by cheetah, Jan 28, 2011.

  1. cheetah

    cheetah Private E-2

    Followed Malware removal procedures and attached logs.

    I've also ran TDSSKiller and FixTDSS.

    Your help would be greatly appreciated.

    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the following logs:
    TDSSKiller log
    C:\MGLogs.zip
     
  3. cheetah

    cheetah Private E-2

    Attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, one of the TDSSKiller logs embedded in the MGLogs.zip shows you had a TDS infection so let's make sure it did cure it.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Then tell me what malware issues you are still having, if any.
     
  5. cheetah

    cheetah Private E-2

    Here you go and thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this drive ( you have 3 listed ):
    931 GB \\.\PhysicalDrive2 Unknown MBR code
     
  7. cheetah

    cheetah Private E-2

    Not sure which one it is, but found this.

    Disk 0 has 2 partitions;
    Vista 32 os & Storage

    Disk 1 is just storage

    Disk 2 has 2 partitions;
    Vista 64 os & Storage

    I dual boot. Having issue in 64. Norton warning comes up with 3 boot.tidserv issues
     
  8. cheetah

    cheetah Private E-2

    Disk 0 is 1/2 gig

    Disk 1 80 gig

    Disk 2 is 1 gig
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you attach the Norton log so I can see what it is complaining about?
     
  10. cheetah

    cheetah Private E-2

    Here's what Norton says:

    Master Boot record infection;
    Drive 0x82 removal fail
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both physical drive 0 and 1 are fine. I am assuming that drive 2 is your external storage drive?

    What malware issues are you having?
     
  12. cheetah

    cheetah Private E-2

    Can only find Recenthistory.mcf file, but unable to upload it's too big. Is there another file?
     
  13. cheetah

    cheetah Private E-2

    The only issue is the Norton Antivirus warning pops up on occasion. It started with only 2 warnings of boot.tidserv now it's three.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you wanting to upload? Both your drives have the proper MBR's. As I asked, what malware issues are you having?

    Sorry, you were posting as was I.

    Re-run TDSKiller and attach the new log.
     
  15. cheetah

    cheetah Private E-2

    should I run it from safe mode?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, run it in normal mode. And tell me exactly what Norton is saying now. Is it complaining about each hard drive's MBR?
     
  17. cheetah

    cheetah Private E-2

    Computer restarted and immediately Norton showed warning. Norton log attached and TDSS Killer
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, TDSSKiller is reporting drive 0 as infected. Let's re-run MBRCheck and see if it did cure it.
     
  19. cheetah

    cheetah Private E-2

    When I ran TDSS K, it said

    Malicious objects
    Root Kit.Win32.TDSS.tdl4
    Physical drive
    Name: \HardDisk0
     
  20. cheetah

    cheetah Private E-2

    mbr log attached
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still giving the same report.

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 2 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  22. cheetah

    cheetah Private E-2

    Thanks for you help.
     
  23. cheetah

    cheetah Private E-2

    files attached
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Vista install disc?
     
  25. cheetah

    cheetah Private E-2

    yes i do
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am confused as one log reports your C drive as physical drive 1 and the other log reports it as physical drive 2.

    Let's try doing this:

    First boot into the bios and change the boot order to make the cd drive the first boot device. Insert the disc and reboot.
    For fixing the boot issues:
    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER. Note the space after exe and /

    Remove the disc and reboot. Then re-run MBRCheck and attach the new log.
     
  27. cheetah

    cheetah Private E-2

    will do
     
  28. cheetah

    cheetah Private E-2

    Here you go.
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try it one more time:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 1 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  30. cheetah

    cheetah Private E-2

    Both attached. Thanks.
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You entered 2 as your choice and I wanted you to enter 1 as the choice. Please try it again and select physical drive 1.
     
  32. cheetah

    cheetah Private E-2

    Sorry. Tried uploading mbrfix.txt, but says I have already uploaded file in this thread. I renamed it same issue.
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Back when I had you go into the Recovery Environmnent, did you select your C: drive ( the disc that is 931 GB)?
     
  34. cheetah

    cheetah Private E-2

    It gave me 2 options to fix. 1 drive was vista32 and the other was vista64. The Vista64 drive is the 1 gig drive and that's the one I chose.
     
  35. cheetah

    cheetah Private E-2

    I pulled up what Norton says:

    Master boot record infection: Drive 0x82
    Remove Failed.

    By any chance is that drive 0?
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't have a 1gig drive. You have what I suspect is a 1T drive, an 80gig drive and a 500gig drive. Your C: drive ( and your E: drive ) is the 1T drive ( 931gig's).
     
  37. cheetah

    cheetah Private E-2

    I don't feel so smart right now. I actually should know better.

    c (vista64): drive is 1 T

    Vista 32 is 500 gig
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So which did you choose when you were in the Recovery Environment?
     
  39. cheetah

    cheetah Private E-2

    c: drive (64) with e: drive together is 1 t

    D: drive is 80 gig

    H: (32) and I: drive is 500 gig
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you choose the 1T drive when in the Recovery Environment???
     
  41. cheetah

    cheetah Private E-2

    When I choose repair the next screen gave me two options:

    Vista 32

    Vista 64

    I selected Vista 64
     
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And at the command prompt you typed:
    Bootrec.exe /fixmbr ? with the space?
     
  43. cheetah

    cheetah Private E-2

    Bootrec.exe /fixmbr is what I typed.

    I think is said repair made or something like that.
     
  44. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am stumped. I have asked the other malware fighters for some input on this issue. Hopefully we will come up with a solution for you. The fixmbr should have worked. What manufacturer is this system? Dell? HP? Other?
     
  45. cheetah

    cheetah Private E-2

    Other. Purchased in pieces and put together.

    Just re-ran vista install and repaired the mbr.

    When os loaded Norton came up with same warning?

    Sorry for all the trouble, but greatly appreciate the time you have spent with me.
     
  46. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, I don't know why the MBR repair is not working. Hang in there and we will try to figure this out. I have asked Chaslang to look at this issue with me and hopefully he will have some input. ;)
     
  47. cheetah

    cheetah Private E-2

    Thanks again for all your hard work on this. I really appreciate the time you've spent helping me.
     
  48. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please don't think I have forgotten about you. We are still trying to figure out what is wrong. ;)
     
  49. cheetah

    cheetah Private E-2

    No issues. I understand. I'm just glad someone much smarter than me is working on it.
     
  50. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do this as a final try. I want you to unplug the other two drives (shut down the computer first). Pull the power plug on both drives except the 931gb drive. Do not replug them in until I tell you to.

    Then with only the C: drive ( 931gb ) plugged in, boot into the Recovery Environment again and enter the command prompt and again type in:
    Bootrec.exe /fixmbr

    Hit enter and when done remove the disc and reboot to Windows. Now re-run MBRCheck as well as the C:\MGtools\GetLogs.bat file and attach the new logs.

    If this doesn't work, we may be stuck with having to do a complete reformat and clean install. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds