Reply
Visitor
sykesy69
Posts: 6
Registered: ‎09-19-2009
Accepted Solution

NIS 09 Neither Scan will start

Hi,

 

I thinking this may have something to do with either a virus or malware, but I try to start a Full or Quick Scan and they just hang and scan no files, then I can't even quit the program.

 

I've a Full Scan in Safe Mode but it doesn't find anything.  In normal mode I've had "a.exe" not working properly messages, which I've found out is a trojan and every 4 hours Backdoor.Tidservis blocked.

 

If somebody could help me clear this up would be much appreciated, hoping I don't have to take to drastic measures and format C:\

Stu Rootkit Eradicator
Rootkit Eradicator
Stu
Posts: 5,210
Registered: ‎04-08-2008

Re: NIS 09 Neither Scan will start

Sounds like a nasty rootkit.

What version are you exactly running?

"All that we are is the result of what we have thought"
delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: NIS 09 Neither Scan will start

[ Edited ]

The user will not be able to update, uninstall, or reinstall a new version over top of a rootkit. Malwarebytes will not run, nor will SAS.

 

 

Syskesy69:

 

We might as well find out exactly which rootkit is being identified as Backdoor.tidsrv

 

Please run a SysProt log for us so we can check your system for rootkit activity. You will need to disable Norton auto-protect while you run the scan.

Once it is downloaded to your desktop, right click on the SysProt icon, go to properties, and click unblock and apply.

Choose log, check all the boxes except show hidden objects only and scan.

You will be able to post the log here using the "add attachments" link just below the orange post button.

http://homepages.slingshot.co.nz/~crutches/SysProt

 

Message Edited by delphinium on 09-20-2009 05:49 AM
Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Visitor
sykesy69
Posts: 6
Registered: ‎09-19-2009

Re: NIS 09 Neither Scan will start

[ Edited ]

Sorry...

 

All Drives or just Root Drive???

 

Root Scan attached...

Message Edited by sykesy69 on 09-19-2009 11:18 AM
delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: NIS 09 Neither Scan will start

Root drive is fine, I think.  gasfky rootkit.  Nasty.   Please do not do anything else for the time being.
Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Visitor
sykesy69
Posts: 6
Registered: ‎09-19-2009

Re: NIS 09 Neither Scan will start

Do you mean in terms of trying to treat the root kit or don't open any other programs at all???
delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: NIS 09 Neither Scan will start

The rootkit makes your system unstable, and may cause other problems.  Rootkits also download other malware.  Definitely do not do anything to try to remove it, or we may not be able to assist you afterwards.  If you need the machine to communicate, so be it.
Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Visitor
sykesy69
Posts: 6
Registered: ‎09-19-2009

Re: NIS 09 Neither Scan will start

Ok, I'll boot my other partition and await further instructions...
delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: NIS 09 Neither Scan will start

Hi sykesy69:

 

I'm just checking in to let you know that you haven't been forgotten.  This is a fairly new rootkit infection and is a bit more difficult to resolve.  There are two other users with a similar infection, being worked on.  As those are resolved, it will also help with yours.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: NIS 09 Neither Scan will start

Hi

 

I have sent you a Personal Message, look for the Yellow envelope near the upper right hand side

 

Quads