Reply
Visitor
kiwifrost4
Posts: 3
Registered: ‎09-20-2011

Tidserv Activity 2 - threat pop-ups but not found?

I have been getting bombarded with pop-ups saying "Threat requiring manual removal detected: System Infected: Tidserv Activity 2". Following the manual removal instructions did not work - downloaded FixTDSS.exe, it reported no infected files found, no action taken.

 

I have also looked on various forums for advice, and have run full system scans in safe mode with both Norton and Malwarebytes, neither of which show any infected files. I have also followed instructions to remove files by viewing my "hidden" non-plug and play drivers, nothing titled "TDSS" shows up there.

 

This is getting really frustrating - on my history I am seeing an intrusion attempt approx. every 20 minutes. At the same time I have started seeing "80000032.@ (Trojan.Gen.2) detected by Auto-Protect,Blocked,Resolved - No Action Required" every 20 minutes or so as well.

 

I need help. Nothing seems to be found by scanning, yet something is going on. Can someone please help me remove this junk and restore my sanity?

 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Tidserv Activity 2 - threat pop-ups but not found?

You can try TDSSKiller, here:

 

http://support.kaspersky.com/faq/?qid=208280684

 

New variants of the rootkit come out all the time and it becomes increasingly difficult finding apps to safely remove it.  If TDSSKiller also can't find it, you will need to visit one of these free malware removal forums where they can use more advanced tools, track it down, and help you get rid of it.  Bleeping may have a longer wait time as they are very busy.

 

www.bleepingcomputer.com

http://www.geekstogo.com/forum/

http://www.cybertechhelp.com/forums/

http://forums.whatthetech.com/

http://support.emsisoft.com/forum/6-help-my-pc-is-infected/

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Symantec Employee
jithinpk
Posts: 35
Registered: ‎09-07-2011

Re: Tidserv Activity 2 - threat pop-ups but not found?

Hi kiwifrost4 ,

 

You can try the steps in link http://www.symantec.com/security_response/writeup.jsp?docid=2010-090608-3309-99 and I think the issue will get fixed

 

Regards,

 

Jithin 

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Tidserv Activity 2 - threat pop-ups but not found?

Both FixTDSS (stand alone)  and TDSSkiller should be able to detect and cure the infected Driver or Boot Sector.  TDSSkiller has been updated this month.

 

Quads

Visitor
kiwifrost4
Posts: 3
Registered: ‎09-20-2011

Re: Tidserv Activity 2 - threat pop-ups but not found?

That is the first step I tried, as that is what the pop-up box tells me to do. Unfortunately this does not seem to work in my case.

 

Also, since my PC came with Vista pre-installed, I do not have a CD-ROM if any re-installation / manual repair needed to occur.

Visitor
kiwifrost4
Posts: 3
Registered: ‎09-20-2011

Re: Tidserv Activity 2 - threat pop-ups but not found?

Quads - thanks for the info. I ran TDSS rootkit removing tool (I believe this is the version #) 2.5.23.0. Is that the latest version? Downloaded from kaspersky.com. Scan (took only 24 seconds, is that right? Seems awfully quick) found no objects.

 

Could this possibly be a false positive? If so, how do you check? Let me know if you need to see a copy of the TDSS results, if that helps in any way.

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Tidserv Activity 2 - threat pop-ups but not found?

It is very unlikely to be a false positive.  If the tools given are not working, then you will need to get assistance using more advanced tools at the forums, linked above.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Tidserv Activity 2 - threat pop-ups but not found?

I am trying to figure out myself if it's something new enough, like the TDSS (Tidserv) I have for 2 days ago, or the likes of TDSS and Zeroaccess are getting so close to each other.

Due to your detection for 80...........@ (Trojan.Gen2), Zeroaccess has the files as @80.......... the "@" is placed in a different place for the file name.

 

Quads

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Tidserv Activity 2 - threat pop-ups but not found?

NOTE: this is infomation, but please stay with the other forum(s) you have posted logs for as those forum(s) for malware removal are protected so that only people trained with those tools can reply to help a user remove malware and not every Tom, Dick and Harry.

 

It appears even though Norton is correctly doing it's job in Intrusion Prevention blocking access to the network for the C&C Server on the web, it it's just the detection name that seems wrong so instead of the popup saying  "Threat requiring manual removal detected: System Infected: Tidserv Activity 2".  it should read  "Threat requiring manual removal detected: System Infected: Zeroaccess Activity *".   as after doing some digging and some information on this thread it is somewhat likley that It's not Tidserv but Zeroaccess.

 

1. FixTDSS and TDSSKiller comeback clean, no detection

2. The Norton detection of  "80000032.@ (Trojan.Gen.2) detected by Auto-Protect,Blocked,Resolved - No Action Required" which is connect to a variant(s) of Zeroaccess the Trojan.Gen.2 is a usually a detection for a object that is newish and is not yet added to a group.

 

One test

 

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\@

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\bckfg.tmp

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\cfg.ini

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\Desktop.ini

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\keywords

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\kwrd.dll

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\L\[RANDOM CHARACTERS]

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\lsflt7.ver

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\U\00000001.@

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\U\00000002.@

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\U\80000000.@

C:\windows\$NtUninstallKB[NUMBERS]$\[NUMBERS]\U\80000032.@  (Detected as Trojan.Gen 2???)

 

The "@" is at the correct end 

 

There are 2 programs that can get this cured but I suggest using the programs under supervision on the other forums as it's a critical OS file that needs to be cured /disinfected and even the folder in the list above does not like to be deleted or can't be deleted easily in Windows and the folder actually shows in Explorer as being empty when it's not.

 

Zaccessdetect.jpg

 

I have 3 more samples to try that I received this morning.

 

Quads

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Tidserv Activity 2 - threat pop-ups but not found?

Here is a GMER log attached, it's not complete but still shows Zeroaccess. Not all areas are scanned if you do GMER hits the Tripware and closes then the user is not able to use it.

 

I did find a flaw in Zeroaccess, usually if the infection is in full flight programs like MBAM, GMER, SAS, Combofix etc. hits the tripware and close................................  I found that there is a time when Zeroaccess is not fully functioning (Tripwire not active??) so those program can now run.

 

Newer Zeroaccess variants to come may be different of course.

 

Quads