01-20-2012 02:37 PM
NOTE: For MaxSS (SST.*) Norton is detecting this infection as "Boot.Tidserv" and giving the link to FixTDSS. The progam can't fix this.
Quads
02-27-2012 07:23 PM
I definitely know that Norton can't detect or even clean these hard to find&remove rootkits and bootbots, so I used the following to get rid of most of them successfully: TDSSKiller by Kaspersky, Malwarebytes, and Emsisoft Antimalware. I had to use a laptop to download those free malware scanners b/c the fake antivirus known as XP Home Security 2012 had infected my pc. TDSSKiller cleaned those that were not detectable by Norton's antirootkit that had given me those annoying popups that showed up everytime I started my computer and when I tried going to a website on Internet Explorer 8. Then I had to look for instructions on how to reinstall Netbt service on Windows, since the netbt.sys file in the system32 folder had a rootkit on it and it was removed by TDSSKiller.
02-27-2012 08:51 PM
Oh, I almost forgot to tell you that TDSSKiller has to be used more than once to actually find all those Tidserv rootkits and if you do lose internet connection like I have, then use another computer to connect and then google this, "How to reinstall NetBT Service on Windows XP."
02-28-2012 12:36 PM
NOTE: This thread is for instructions to remove the MaxSS partition detected as Boot.Tidserv, Please ignore the above posts by Momoboro. None of his tools he used are successful. Let alone the fact:-
a) Sounds like he is not talking about MaxSS.
b) No details of what was actually detected.
c) Now no Internet Connection for what ever reason, let alone the next users problem file might not be say "netbt.sys" or it's a problem with the I.P. Stack.
d) Sounds more like Max++
Quads
02-28-2012 08:14 PM
um, anyone found this website? http://en.kioskea.net/faq/18862-rootkit-boot-sst
02-28-2012
08:59 PM
- last edited on
02-29-2012
12:40 AM
by
Preetha_G
also try GMER’s mbr.exe: http://w ww2.gmer.net/mbr/mbr.exe
[Edit: Removed the direct link to the executable to conform with Participation Guidelines and Terms of Service ]
02-29-2012 03:49 AM - edited 02-29-2012 04:12 AM
I don't need to know about other websites or tools, I can infect my system with MaxSS when I want I have the dropper / installers. Also it did or does not infect a driver at all, But instead the partition has to be removed and the flag made sure is set correctly.
A least 2 or 3 people have use my instructions with success with their own threads and a) TDSSkiller does not fix the problem of the partition.
Loads of others unknown (by the amount of views) may have also used my instructions.
Problems occuring with TDSSkiller and what is or looks like MaxSS, after running TDSSkiller
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
Attention! C:\WINDOWS\system32\Drivers\afd.sys is missing.
Attention! C:\WINDOWS\system32\Drivers\netbt.sys is missing.
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
Attention! C:\WINDOWS\system32\Drivers\ipsec.sys is missing.
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
And
", I have a laptop that was infected. I had removed pretty much everything that was found but was still getting a kdcom.dll BSOD every hour or so while windows 7 x64 was running. I found that the machine had the rootkit.boot.sst.b infection and attempted to remove it with TDSSKILLER. Afterwards it would not fully boot no matter of Normal modem or Safe Mode. It stops on the 0x7B error every time.
Had a 0.03GB boot patition.
Quads
02-29-2012 02:05 PM - edited 02-29-2012 03:05 PM
Will Norton have an antirootkit/recovery option for mbr rootkits even when the computer can't boot up? I already know that Live CDs and Partition managers are good methods to remove the MaxSS/Pihar/TDL4, but is there another way? Also, when Windows 8 comes out, it's going to have a UEFI secure boot feature to get rid of these kinds of rootkits.
02-29-2012 11:48 PM
With all due respect momoboro ..........
momoboro wrote:Will Norton have an antirootkit/recovery option for mbr rootkits even when the computer can't boot up? I already know that Live CDs and Partition managers are good methods to remove the MaxSS/Pihar/TDL4, but is there another way? Also, when Windows 8 comes out, it's going to have a UEFI secure boot feature to get rid of these kinds of rootkits.
As you must be aware ....we have had the Developer preview...the Windows 8 newest preview was only released moments ago .....and Microsoft plainly tell us that major changes may be implemented before final RTM of Windows 8 ...
So lets' keep an open mind on just what may make it to the Final release candidate ...No one really knows yet ![]()
Windows7 SP1....Norton NIS 2012 ...4Gb RAM ..Momentus XT SolidState HybridHD
Docendo discimus ( Teach in order to learn)
03-02-2012 03:52 PM
There is already a Windows 8 Root/Boot kit created
Quads
