<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Norton 360 and Boot.tidserv nightmare ! in Norton 360</title>
    <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629767#M63736</link>
    <description>&lt;p&gt;As long as you have the right partition that you removed, you still after have to go into Norton's history and clear the unresolved threats list.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;That's because Norton still has the detected listing in the unresolved threats list, due to the fact Norton didn't remove the detection but another program was used instead (Gparted) to do the job.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; aswmbr and gmer  is not required, expect by people who are trying anything and everything. For MaxSS there are now instructions on how to use Gparted for MaxSS on this forum.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
    <pubDate>Sun, 08 Jan 2012 20:03:35 GMT</pubDate>
    <dc:creator>Quads</dc:creator>
    <dc:date>2012-01-08T20:03:35Z</dc:date>
    <item>
      <title>Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628677#M63610</link>
      <description>&lt;p&gt;Hi there,&lt;/p&gt;&lt;p&gt; I am experiencing a nightmare with this rootkit, I have done tons of tests but cannot get rid of it,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The pc is a HP Desktop Pavilion  1209 with Windows XP Home 1gb ram.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The system boots normally' then after 3,4 minutes tha hard drive starts again to work a lot and comes up with the attached screen contained in this set:&lt;br&gt;&lt;a target="_blank" href="https://picasaweb.google.com/109175126296685887586/MBRBOOTVIRUS?authuser=0&amp;amp;feat=directlink"&gt;https://picasaweb.google.com/109175126296685887586/MBRBOOTVIRUS?authuser=0&amp;amp;feat=directlink&lt;/a&gt;&lt;br&gt; I choose the option to cure within the combo box and the problem seems fixed, only till next boot actually.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Here is only a small part of all tests that I recall:&lt;br&gt;&lt;br&gt;&amp;gt;NPE&lt;br&gt;&amp;gt;NPE boot disk&lt;/p&gt;&lt;p&gt;&amp;gt;karpersky removal tool&lt;/p&gt;&lt;p&gt;&amp;gt;bit defender removal tool&lt;br&gt;&amp;gt;TDSSKiller&lt;/p&gt;&lt;p&gt;&amp;gt;g-data rescue live cd&lt;/p&gt;&lt;p&gt;&amp;gt;bitdefender rootkit new tool&lt;/p&gt;&lt;p&gt;&amp;gt;bitdefender recue live cd&lt;/p&gt;&lt;p&gt;&amp;gt;karsperky rescue live cd  &lt;/p&gt;&lt;p&gt;&amp;gt;combofix&lt;/p&gt;&lt;p&gt;&amp;gt;gmer&lt;/p&gt;&lt;p&gt;&amp;gt;mbr.exe&lt;/p&gt;&lt;p&gt;&amp;gt;hitman pro second opinion&lt;/p&gt;&lt;p&gt;---&lt;/p&gt;&lt;p&gt;Lately I also booted from cd and hit the 'R' and successfully run the commands:  'fixboot' and 'fixmbr'.&lt;/p&gt;&lt;p&gt;---&lt;/p&gt;&lt;p&gt;Also, tried enabling and disabling the Windows restore point function&lt;/p&gt;&lt;p&gt;---&lt;/p&gt;&lt;p&gt;Gparted showes a hidden partition, I deleted that but no luck, still the dreadfull Norton notice.&lt;/p&gt;&lt;p&gt;---&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am quite desperate, Hope someone can help, I would seriously need to avoid the zerofilling of hard disk and reinstalling everything.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please en-light me :-)&lt;/p&gt;&lt;p&gt;Thank you&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Ferrux&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 07 Jan 2012 00:18:30 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628677#M63610</guid>
      <dc:creator>ferrux</dc:creator>
      <dc:date>2012-01-07T00:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628855#M63637</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt;I forgot to mention that I also run&lt;br&gt;&lt;br&gt;Malwarebytes and Superantispyware&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;no luck :-(&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The Beast is still alive !&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jan 2012 09:56:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628855#M63637</guid>
      <dc:creator>ferrux</dc:creator>
      <dc:date>2012-01-07T09:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628867#M63640</link>
      <description>&lt;p&gt;&amp;quot;Gparted showes a hidden partition, I deleted that but no luck, still the dreadfull Norton notice.&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;As long as you have the right partition that you removed, you still after have to go into Norton's history and clear the unresolved threats list.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 07 Jan 2012 11:48:07 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628867#M63640</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-01-07T11:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628901#M63649</link>
      <description>Thank you for email&lt;br&gt;do you think that could be a false positive ?&lt;br&gt;&lt;br&gt;Ferrux</description>
      <pubDate>Sat, 07 Jan 2012 13:34:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628901#M63649</guid>
      <dc:creator>ferrux</dc:creator>
      <dc:date>2012-01-07T13:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628907#M63650</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt;how can I do that ?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thank you :-)&lt;/p&gt;</description>
      <pubDate>Sat, 07 Jan 2012 14:13:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/628907#M63650</guid>
      <dc:creator>ferrux</dc:creator>
      <dc:date>2012-01-07T14:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629685#M63727</link>
      <description>&lt;p&gt;It is no false message but you can remove it manually.&lt;/p&gt;&lt;p&gt;In my case i had the BootTidserv virus. It made a small extra hidden partition and made it the default boot device.&lt;/p&gt;&lt;p&gt;I used a linux live cd with parted magic and moved  the default boot device tag to the windows partition.&lt;/p&gt;&lt;p&gt;Now boot from your windows XP install CD.&lt;/p&gt;&lt;p&gt;Choose R to repair windows.&lt;/p&gt;&lt;p&gt;At the command line use fixmbr to repair your boot record.&lt;/p&gt;&lt;p&gt;Now windows should be save to use.&lt;/p&gt;&lt;p&gt;Use aswmbr and gmer to remove the rest of the rootkit.&lt;/p&gt;&lt;p&gt;After all was working i used parted magic once more to remove the hidden partition with the virus.&lt;/p&gt;</description>
      <pubDate>Sun, 08 Jan 2012 16:29:54 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629685#M63727</guid>
      <dc:creator>arno50</dc:creator>
      <dc:date>2012-01-08T16:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629767#M63736</link>
      <description>&lt;p&gt;As long as you have the right partition that you removed, you still after have to go into Norton's history and clear the unresolved threats list.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;That's because Norton still has the detected listing in the unresolved threats list, due to the fact Norton didn't remove the detection but another program was used instead (Gparted) to do the job.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; aswmbr and gmer  is not required, expect by people who are trying anything and everything. For MaxSS there are now instructions on how to use Gparted for MaxSS on this forum.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 08 Jan 2012 20:03:35 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629767#M63736</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-01-08T20:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629785#M63737</link>
      <description>&lt;p&gt;Quads you are probably right in your advise.&lt;/p&gt;&lt;p&gt;In this forum I am classified as a beginner but my first encounter was frodo lives and have learned a lot since then.&lt;/p&gt;&lt;p&gt;There are two reasons why you should use those two tools:&lt;/p&gt;&lt;p&gt;1) fixing the mbr with fixmbr is not always sufficient with a non standard mbr and the threat may still be there.&lt;/p&gt;&lt;p&gt;2) you have to clear up all the mess, if you do not you could get an instable system or wrong information when you get infected a second time.&lt;/p&gt;</description>
      <pubDate>Sun, 08 Jan 2012 20:47:16 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629785#M63737</guid>
      <dc:creator>arno50</dc:creator>
      <dc:date>2012-01-08T20:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629795#M63740</link>
      <description>&lt;p&gt;Hi there&lt;/p&gt;&lt;p&gt;cleaning the unresolved threat in the Norton' history the problem seems fixed.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The system seems to work with no more apparent problems, however I am sure some dormient or leftovers are still in the pc, for instance I tried to :&lt;br&gt;&lt;br&gt;Right click My computer &amp;gt;Hardware&amp;gt;Device Manager&lt;/p&gt;&lt;p&gt;In Device Manager clicked  view&amp;gt;Show hidden devices&lt;/p&gt;&lt;p&gt;In Non-plug and play drivers I saw and disabled TDSS.sys driver&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Rebooting the pc got crazy, it war continuosly restarting the pc even in safe mode, I have&lt;/p&gt;&lt;p&gt;to reboot with last know good configuration.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I am attachin some screen shots ( it is a zip renamed to txt), sorry there are not in english but are readable, hope so.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Do you recall some possible action from this screens, please do not say reformat :-) since the pc now is usable.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thank you&lt;/p&gt;&lt;p&gt;best regards.&lt;/p&gt;&lt;p&gt;Ferrux&lt;/p&gt;</description>
      <pubDate>Sun, 08 Jan 2012 21:05:22 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629795#M63740</guid>
      <dc:creator>ferrux</dc:creator>
      <dc:date>2012-01-08T21:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629903#M63755</link>
      <description>&lt;p&gt;&lt;font color="#FF0000"&gt;&lt;strong&gt;&amp;quot;cleaning the unresolved threat in the Norton' history the problem seems fixed.&amp;quot;&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;That is good, nothing else is detected then don't bother looking and screwing around, makes things a deep hole sometimes.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Right click My computer &amp;gt;Hardware&amp;gt;Device Manager&lt;/p&gt;&lt;p&gt;In Device Manager clicked  view&amp;gt;Show hidden devices&lt;/p&gt;&lt;p&gt;In Non-plug and play drivers I saw and disabled TDSS.sys driver&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Don't bother with that as Norton, Malwarebytes Combofix can delete the files for OLD TDL1 and 2 files if they arethe malware versions.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;How old, see &lt;a target="_blank" href="http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/td-p/46674"&gt;http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/td-p/46674&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 09 Jan 2012 00:09:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629903#M63755</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-01-09T00:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629907#M63756</link>
      <description>&lt;p&gt;Looked at the screenshots, leave it alone, the driver you are looking at is legit, belongs to FixTDSS (Symantec)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 09 Jan 2012 00:18:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/629907#M63756</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-01-09T00:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/630095#M63774</link>
      <description>&lt;p&gt;Hi  Quads&lt;/p&gt;&lt;p&gt;thank you for your email, infact when I tried to deactivate / unable the driver the system got crazy&lt;/p&gt;&lt;p&gt;and was restarting and booting to the infinite :-)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;So that driver is the cure from the antivirus ? Is that correct ?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thank you, very much, indeed .-)&lt;/p&gt;&lt;p&gt;Fx&lt;/p&gt;</description>
      <pubDate>Mon, 09 Jan 2012 08:15:28 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/630095#M63774</guid>
      <dc:creator>ferrux</dc:creator>
      <dc:date>2012-01-09T08:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/666535#M67167</link>
      <description>Ran Norton tool, tdsskiller found no threat, updated norton, re-scanned, threat still there. help!</description>
      <pubDate>Wed, 22 Feb 2012 12:21:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/666535#M67167</guid>
      <dc:creator>CristianMéfiant</dc:creator>
      <dc:date>2012-02-22T12:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Norton 360 and Boot.tidserv nightmare !</title>
      <link>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/666877#M67215</link>
      <description>&lt;p&gt;Norton Tool  (FixTDSS) = no detection.&lt;/p&gt;&lt;p&gt;TDSSkiller                       = no detection.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;hmmmm  Norton detects MaxSS as Boot.Tidserv, which is actually another partition.  Like this thread &lt;a href="http://community.norton.com/t5/Norton-Internet-Security-Norton/BOOT-Tidserv/td-p/610864" target="_blank"&gt;http://community.norton.com/t5/Norton-Internet-Security-Norton/BOOT-Tidserv/td-p/610864&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Wed, 22 Feb 2012 22:33:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Norton-360-and-Boot-tidserv-nightmare/m-p/666877#M67215</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2012-02-22T22:33:53Z</dc:date>
    </item>
  </channel>
</rss>

