<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Seneka Rootkit with TDSServ in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/54618#M28677</link>
    <description>&lt;p&gt;There's a new version of the Seneka rootkit out - it doesn't seem to be hiding in the &amp;quot;non-plug and play&amp;quot; drivers section anymore. (I've killed the Seneka / TDSServ rootkit described by Quads a few weeks ago.)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Symantec endpoint protection catches it...sort of. It finds&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Trojan.Vundo&amp;quot; (Deleted but restart required)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Backdoor.Tidserv!inf&amp;quot; Unable to do anything because a process or server is using it - the file was seneka4cbd.tmp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Trojan.Adclicker&amp;quot; deleted&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Downloader.MisleadApp&amp;quot; deleted.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;So, after a restart, it can't find any sign of Backdoor.Tidserv!inf or any new trojans. In fact, the system seems fine. Except...if you try to go to symantec or any other security-related websites, it's unable to connect. (Tracert shows that the system is just trying to talk to 127.0.0.1 instead of going to the actual websites.) So, this is the same thing that Seneka/TDSServ did, but Quads' steps no longer apply. Any thoughts?&lt;/p&gt;</description>
    <pubDate>Fri, 02 Jan 2009 23:08:13 GMT</pubDate>
    <dc:creator>mmetzger</dc:creator>
    <dc:date>2009-01-02T23:08:13Z</dc:date>
    <item>
      <title>Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46674#M23740</link>
      <description>&lt;p&gt;Hi Guys&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The file with the name &amp;nbsp;&lt;span class="Apple-style-span"&gt;TDSServ is used by more than one Malware under different names, The one that seems to be doing the rounds at the moment is the Variation that has&amp;nbsp;the Seneka Rootkit, Can also enter on the back of &amp;quot;AntiVirus 2009&amp;quot;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This seems to be the order of removal for this nasty piece of work. The drivers are in use&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;1. You have to disable the drivers, Reboot, then Remove. By doing this,&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Go to the &amp;quot;Control Panel&amp;quot; click on &amp;quot;System&lt;/p&gt;&lt;p&gt;Click on the &amp;quot;Hardware&amp;quot; tab. &amp;nbsp;&lt;/p&gt;&lt;p&gt;Click on &amp;quot;Device Manager&amp;quot; to open it&lt;br /&gt;Click 'View' &amp;nbsp;in the menu and select 'Show Hidden Devices'&lt;br /&gt;Expand the 'Non-Plug and Play' Drivers category&lt;br /&gt;(If you find them, You can tell me), Right-click and 'Disable' &amp;quot;clbdriver.sys&amp;quot;, &lt;span class="Apple-style-span"&gt;&amp;quot;&lt;span class="Apple-style-span"&gt;msqpdxserv.sys&amp;quot;, &lt;/span&gt;&lt;/span&gt;&amp;quot;tdsserv.sys&amp;quot; (or tdssxyz.sys where xyz.sys are random characters), and/or &amp;quot;seneka.sys&amp;quot;&lt;/p&gt;&lt;p&gt;Restart computer to Safe Mode&lt;br /&gt;After restart, go back to Device Manager and right-click 'Uninstall' for the above drivers&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Then Use the latest Version of &amp;quot;SDfix&amp;quot;, Instructions&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;How to use SDFix:&lt;/strong&gt;&lt;br /&gt;1. Download SDFix and save to your Desktop.&lt;br /&gt;2. Install SDFix: double-click on the SDFix. If a &amp;ldquo;Security Warning window opens&amp;rdquo;, click on the Run button.&lt;br /&gt;3. Follow the prompts.&lt;br /&gt;4. Reboot your PC in to Safe mode.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;- Restart your computer&lt;br /&gt;- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.&lt;br /&gt;- Instead of Windows loading as normal, a menu should appear&lt;br /&gt;- Select the first option, to run Windows in Safe Mode.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;5. Click Start -&amp;gt; Run,type the following text in type box:&amp;nbsp;C:\SDFix\RunThis.bat&lt;br /&gt;6. Press Enter or OK button.&lt;br /&gt;7. When the tool is finished, it will produce a report for you.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Notes:&lt;/strong&gt;&lt;br /&gt;If this error message is displayed when running SDFix:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;The command prompt has been disabled by your administrator. Press any key to continue . . .&lt;/em&gt;&lt;br /&gt;Please goto Start Menu &amp;gt; Run &amp;gt; then copy and paste the following line: %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg&lt;br /&gt;Press OK then run SDFix again&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;If the Command Prompt window flashes on then off again on XP or Windows2000&lt;/p&gt;&lt;blockquote&gt;Please goto Start Menu &amp;gt; Run &amp;gt; then copy and paste the following line: %systemdrive%\SDFix\apps\FixPath.exe /Q Reboot and then run SDFix again&lt;/blockquote&gt;&lt;blockquote&gt;&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;Then apparently the SAS pre-release will remove the ruminants &amp;nbsp;&lt;a href="http://www.superantispyware.com/prerelease.html" target="_blank"&gt;http://www.superantispyware.com/prerelease.html&lt;/a&gt;&lt;/blockquote&gt;&lt;blockquote&gt;Try that for the guys that are getting infected with this form that's doing the rounds.&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;Quads&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;&amp;nbsp;&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;&amp;nbsp;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Quads on &lt;/span&gt;&lt;span class="local-date"&gt;12-07-2008&lt;/span&gt;&lt;span class="local-time"&gt; 08:51 AM&lt;/span&gt;&lt;/div&gt;&lt;div class="message-edit-history"&gt;&lt;strong&gt;&lt;font size="1" color="#ff0000"&gt;[edit: edit at Quads request.]&lt;/font&gt;&lt;/strong&gt; &lt;br /&gt;&lt;/div&gt;&lt;div class='message-edit-history'&gt;&lt;span class='edit-author'&gt;Message Edited by Allen_K on &lt;/span&gt;&lt;span class='local-date'&gt; 12-11-2008&lt;/span&gt;&lt;span class='local-time'&gt; 08:11 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Thu, 11 Dec 2008 14:11:19 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46674#M23740</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-11T14:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46675#M23741</link>
      <description>&lt;p&gt;Hi Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Great info!Great work!Well done! &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;TrDo.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;PS: Two Questions:&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1)Why Pre-release SAS? The normal free edition (&lt;font size="2"&gt;4.22.1014 )&lt;/font&gt; will not do it?&lt;/p&gt;&lt;p&gt;2) SDFix from Andy Manchesta, and download from My Anti Spyware?&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by TrDo on &lt;/span&gt;&lt;span class="local-date"&gt;12-06-2008&lt;/span&gt;&lt;span class="local-time"&gt; 11:04 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sat, 06 Dec 2008 21:04:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46675#M23741</guid>
      <dc:creator>TrDo</dc:creator>
      <dc:date>2008-12-06T21:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46681#M23747</link>
      <description>&lt;p&gt;Nice Research Quads!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I hope I never have to refer to it, but I'm going to bookmark this one.&lt;/p&gt;</description>
      <pubDate>Sat, 06 Dec 2008 20:57:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46681#M23747</guid>
      <dc:creator>Phil_D</dc:creator>
      <dc:date>2008-12-06T20:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46699#M23761</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;TrDo wrote:&lt;br&gt;&lt;p&gt;Hi Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Great info!Great work!Well done! &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;TrDo.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;u&gt;PS: Two Questions:&lt;/u&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;1)Why Pre-release SAS? The normal free edition (&lt;font size="2"&gt;4.22.1014 )&lt;/font&gt; will not do it?&lt;/p&gt;&lt;p&gt;2) SDFix from Andy Manchesta, and download from My Anti Spyware?&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by TrDo on &lt;/span&gt;&lt;span class="local-date"&gt;12-06-2008&lt;/span&gt;&lt;span class="local-time"&gt; 11:04 PM&lt;/span&gt;&lt;/div&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;blockquote&gt; 1. People are reporting the normal version of SAS is not doing the job at removing. &lt;/blockquote&gt;&lt;blockquote&gt;2. Yes, from here &lt;a target="_blank" href="http://downloads.andymanchesta.com/RemovalTools/SDFix_ReadMe.htm"&gt;http://downloads.andymanchesta.com/RemovalTools/SDFix_ReadMe.htm&lt;/a&gt;&lt;/blockquote&gt;&lt;blockquote&gt;    or as you say here &lt;a target="_blank" href="http://www.myantispyware.com/free-programs/"&gt;http://www.myantispyware.com/free-programs/&lt;/a&gt;&lt;/blockquote&gt;&lt;blockquote&gt;Quads &lt;/blockquote&gt;&lt;blockquote&gt; &lt;/blockquote&gt;&lt;blockquote&gt; &lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 06 Dec 2008 21:51:07 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46699#M23761</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-06T21:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46700#M23762</link>
      <description>...you posted this because Norton is incapable of detecting this?</description>
      <pubDate>Sat, 06 Dec 2008 21:51:57 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46700#M23762</guid>
      <dc:creator>Tech0utsider</dc:creator>
      <dc:date>2008-12-06T21:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46708#M23766</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;Tech0utsider wrote:&lt;br&gt;...you posted this because Norton is incapable of detecting this?&lt;hr&gt;&lt;/blockquote&gt;&lt;blockquote&gt;I posted it to help people. I have I think had 5 Posters saying Norton Detects (which ever variant) but manual removal is required. Then they can't find the files or can't delete the file. Due to probably in use, or locked.&lt;/blockquote&gt;&lt;blockquote&gt; Quads &lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 06 Dec 2008 22:24:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46708#M23766</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-06T22:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46711#M23769</link>
      <description>&lt;p&gt;Hi Quads,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Thanks for the reply.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;TrDo.&lt;/p&gt;</description>
      <pubDate>Sat, 06 Dec 2008 22:31:26 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46711#M23769</guid>
      <dc:creator>TrDo</dc:creator>
      <dc:date>2008-12-06T22:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46735#M23779</link>
      <description>&lt;p&gt;This thread brings me to ask a question for the Symantec guys: if Early Load is enabled in NIS/NAV, are Norton's services and drivers loaded early enough to detect and remove rootkits like these before they hide themselves into the seclusion of Non Plug and Play Driver section?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;And what about those rootkits that hook the network drivers and ntfs.sys to hide themselves completely, and that run in kernel mode exclusively (like the Srizbi botnet rootkit)?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Is NIS effective against those?&lt;/p&gt;</description>
      <pubDate>Sun, 07 Dec 2008 00:24:36 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46735#M23779</guid>
      <dc:creator>TomiRed</dc:creator>
      <dc:date>2008-12-07T00:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46748#M23788</link>
      <description>&lt;p&gt;Kind of disappointed in NIS/NAV right now, however NIS/NAV08 were the highest rated, &amp;quot;++&amp;quot; in terms of rootkit detection and cleaning.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;av-test.org&lt;/p&gt;</description>
      <pubDate>Sun, 07 Dec 2008 01:27:31 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46748#M23788</guid>
      <dc:creator>Tech0utsider</dc:creator>
      <dc:date>2008-12-07T01:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46752#M23791</link>
      <description>&lt;p&gt;Hey guys &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I did this tread to help the people with this type of infection NOT to start on about Norton or other Security software not removing, It is not only Norton having trouble with removing this Malware, People with this nasty piece of work on their system say others can't remove either.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Quads on &lt;/span&gt;&lt;span class="local-date"&gt;12-07-2008&lt;/span&gt;&lt;span class="local-time"&gt; 01:59 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 07 Dec 2008 01:59:39 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46752#M23791</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-07T01:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46786#M23816</link>
      <description>&lt;p&gt;Can you PM me the link to the infected file, or more specfically the Seneka Rootkit?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have enough CPU cycles to spare =)&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Tech0utsider on &lt;/span&gt;&lt;span class="local-date"&gt;12-07-2008&lt;/span&gt;&lt;span class="local-time"&gt; 12:50 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sun, 07 Dec 2008 05:50:04 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/46786#M23816</guid>
      <dc:creator>Tech0utsider</dc:creator>
      <dc:date>2008-12-07T05:50:04Z</dc:date>
    </item>
    <item>
      <title>Worked for me with Tidserv!inf</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/47298#M24154</link>
      <description>&lt;p&gt;&lt;font size="3" face="comic sans ms,sans-serif"&gt;Thanks Quads!!!!&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Comic Sans MS"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Comic Sans MS"&gt;I am a novice at dealing with viruses, but found your instructions easy to follow.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Comic Sans MS"&gt;Followed them to the letter and deleted the virus.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Comic Sans MS"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Comic Sans MS"&gt;I will know where to go next time I need help.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Comic Sans MS"&gt;&lt;br&gt;Jen&lt;/font&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 09 Dec 2008 05:27:41 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/47298#M24154</guid>
      <dc:creator>limejen</dc:creator>
      <dc:date>2008-12-09T05:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Worked for me with Tidserv!inf</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/47300#M24156</link>
      <description>&lt;p&gt;That's good&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Tue, 09 Dec 2008 05:29:08 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/47300#M24156</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-09T05:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48232#M24723</link>
      <description>Hi, I am following your guide. However in the 'Non-Plug and Play' Drivers category, I cant find any of the devices you've listed, but I have found msqpdxserv.sys. Should I just uninstall that?</description>
      <pubDate>Thu, 11 Dec 2008 06:22:13 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48232#M24723</guid>
      <dc:creator>Julz</dc:creator>
      <dc:date>2008-12-11T06:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48234#M24724</link>
      <description>Great work Quads. Good to see your passion to help out the people around the forum</description>
      <pubDate>Thu, 11 Dec 2008 06:28:29 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48234#M24724</guid>
      <dc:creator>Stu</dc:creator>
      <dc:date>2008-12-11T06:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48244#M24733</link>
      <description>&lt;p&gt;Hi Julz&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;&lt;span class="Apple-style-span"&gt;msqpdxserv.sys&amp;quot; indeed belongs to &lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;W32.Tidns,and is in the TDSS family ( Norton detects as Tidsserv!inf), It spreads by removable drives &lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt; (flash Drive etc) This bug also redirects your browser.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please use the instuctions in the first post as you were doing, Disable  &lt;span class="Apple-style-span"&gt;msqpdxserv.sys, reboot, Uninstall .......................... SDfix instuctions, then the 3rd at the Bottom SuperAntispyware Free Prerelease....................................&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You can report back after all that. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;p&gt;  &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 11 Dec 2008 06:43:16 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48244#M24733</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-11T06:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48246#M24735</link>
      <description>&lt;p&gt;Hi Stu&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It's actually enjoyable helping people, and sometimes more research and tinkering is needed than other times,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;But then again you are the Guru, so you must be the same.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Thu, 11 Dec 2008 06:46:05 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48246#M24735</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-11T06:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48247#M24736</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;Quads wrote:&lt;br&gt;&lt;p&gt;Hi Stu&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It's actually enjoyable helping people, and sometimes more research and tinkering is needed than other times,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;But then again you are the Guru, so you must be the same.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;Please don't tell anyone ;)&lt;/p&gt;</description>
      <pubDate>Thu, 11 Dec 2008 06:47:52 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/48247#M24736</guid>
      <dc:creator>Stu</dc:creator>
      <dc:date>2008-12-11T06:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/49424#M25511</link>
      <description>&lt;p&gt;Hi&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Part of the TDSServ (which variant?? and how much of it?? for the change) has been added to SuperAntispywares definitions as,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Rootkit.TDSServ/Fake&amp;quot;  &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Also whether you have to still do any of the steps in the first post, don't know.  &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;Quads &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 15 Dec 2008 05:14:35 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/49424#M25511</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2008-12-15T05:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Seneka Rootkit with TDSServ</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/54618#M28677</link>
      <description>&lt;p&gt;There's a new version of the Seneka rootkit out - it doesn't seem to be hiding in the &amp;quot;non-plug and play&amp;quot; drivers section anymore. (I've killed the Seneka / TDSServ rootkit described by Quads a few weeks ago.)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Symantec endpoint protection catches it...sort of. It finds&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Trojan.Vundo&amp;quot; (Deleted but restart required)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Backdoor.Tidserv!inf&amp;quot; Unable to do anything because a process or server is using it - the file was seneka4cbd.tmp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Trojan.Adclicker&amp;quot; deleted&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;Downloader.MisleadApp&amp;quot; deleted.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;So, after a restart, it can't find any sign of Backdoor.Tidserv!inf or any new trojans. In fact, the system seems fine. Except...if you try to go to symantec or any other security-related websites, it's unable to connect. (Tracert shows that the system is just trying to talk to 127.0.0.1 instead of going to the actual websites.) So, this is the same thing that Seneka/TDSServ did, but Quads' steps no longer apply. Any thoughts?&lt;/p&gt;</description>
      <pubDate>Fri, 02 Jan 2009 23:08:13 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Seneka-Rootkit-with-TDSServ/m-p/54618#M28677</guid>
      <dc:creator>mmetzger</dc:creator>
      <dc:date>2009-01-02T23:08:13Z</dc:date>
    </item>
  </channel>
</rss>

