Reply
Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Boot.tidserv

When you open the disk management and have it open press the "print screen key on the keyboard.

Then you can use a program like MS Paint and use the Paste command.

 

The other way to confirm is yo download and run Listparts

 

http://www.bleepingcomputer.com/download/listparts/  download your os bit type, and tick lis bcd

 

Quads

Contributor
KenCheppaikode
Posts: 44
Registered: ‎06-09-2012

Re: Boot.tidserv

Ah, OK, for some reason Paint wasn't coming up, but I did it in Photoshop. 

 

screenshot.jpg

 

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Boot.tidserv

OK

 

Partition (Unknown) (3)  3MB              BAD

Partition  (Presario C:)   104.46GB    GOOD   (Working Partition)        Don't Delete

Partition  (Presario_RP) 7.30 GB       GOOD  (the recovery partition)   Don't Delete

 

Go to the message here with the screenshots http://community.norton.com/t5/Tech-Outpost/Rootkit-Boot-SST-b-is-NOT-coming-off-PLEASE-help/m-p/614...

 

Read the post as many times as you like and maybe even print them out so you can use them as you are using the Program /CD.

Be very carefu to do every step and make double sure you don't delete the wrong partition (only the 3MB one is to go) and make sure the flag is set correctly.

 

Quads

Contributor
KenCheppaikode
Posts: 44
Registered: ‎06-09-2012

Re: Boot.tidserv

Great, did this this morning, and it seems to have worked just fine! Thanks for all your help!

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Boot.tidserv

Do you want to make sure the rest of the system is clean??

 

Quads

Contributor
KenCheppaikode
Posts: 44
Registered: ‎06-09-2012

Re: Boot.tidserv

Yes, that would probably be helpful!

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Boot.tidserv

Please read carefully and Slowly

 

 Please scan with ESET next 


I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Attach the resulting log in your next reply


If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it. 

 

Quads

Contributor
KenCheppaikode
Posts: 44
Registered: ‎06-09-2012

Re: Boot.tidserv

Hey there - thanks, I did that. It did in fact detect another threat, which is in the attached log.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Boot.tidserv

I won't be back on the forum for up to 24 hours.

 

Quads

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Boot.tidserv

Have you still got Spybot S&D installed??

 

Quads