BSoD caused by FixTDSS.exe/boot.tidserv

Hopefully I'm posting this in the correct area. If not, please move it to where it is most appropriate(EDIT: I apologize greatly for posting this in the wrong forum. If a moderator/admin would be so kind as to move this to the "Other Norton Products" section or an otherwise better suiting subforum, please do.)

 

Recently my computer became infected with the Boot.Tidserv rootkit(or bootkit, whatever you want to call it). It caused no real issues on loading my windows vista(64-bit) OS. However, the known issues it DID cause were a redirection of Google links and a more and more frequent BSoD while my computer was idle(Note: this is not my current issue.)

 

As the BSoD became more and more frequent(began happening maybe once every few days, to once a day, to multiple times in a day randomly), it became more of a bother and definitely needed to be fixed soon. This morning, I did more research on how I could actually fix it and came upon multiple solutions, of which I used FixTDSS.exe as was recommended not only by the Norton site, but also multiple other replies on threads related to the Boot.Tidserv infection.

 

After running the FixTDSS.exe, it showed that the infection laid within my MBR, and I proceeded to cure the issue(I cannot remember the exact wording of the program, but I basically just continued through the prompts). I was asked to fix my MBR, which I did. Upon restarting my computer, I now cannot load Normal Mode in Windows Vista as it will BSoD directly before the Windows Login screen comes up. It shows the GUI boot screen, my screen goes black for a moment(it always did this), then you can see the mouse load for just a moment. This is where the BSoD occurs.

I get the error code 0x1000007E. 

 

I can boot into safe mode(with networking/cmd) and it loads perfectly fine, however, normal mode does not. I've since made multiple attempts to rewrite my MBR. I used MBRChecker.exe that was recommended from other sites and "successfully" rewrote my MBR. But,  I'm currently at a standstill as it still goes straight into the BSoD as it did before.

 

What else can I attempt to do? Simple Google searches have stopped providing me with possible solutions. I can get any information off my system if needed with whatever programs. And, as far as I can tell, through scanning countless times with FixTDSS.exe again, NBRT, along with TDSSKiller.exe(which never showed any infections to begin with - but that may have been due to still having protected system files hidden, but they are being shown now and it picks up nothing), the infection has been disposed of. So, that shouldn't be the issue. I cannot think of any more solutions myself and, as I said, I cannot find anymore information on what may be causing this to begin with.

 

I do have this computer dual-booted with Ubuntu, however that has never caused any problems so far, and I can still load into it perfectly fine.

 

I'm mainly trying to fix this problem without having to reinstall my entire Vista OS. The "repair" disk I have has no cmd option with the DOS commands and ONLY has options to completely reinstall the OS. Through past experience, this also rewrites my ubuntu partition without any real warning - it completely wipes the disk.

 

So, with all that said... What now?

Removing malware from a machine can be an incredibly complex business.  Norton products normally recognize and warn about Tidserv infections, but removal can put some critical system files at risk, as might happen with any product designed to remove infections.

 

We don't know what Norton product you are running, or if it identified the infection.  We don't actually know, without some identification, or scan results if you had a Tidserv or zeroaccess infection.  We don't know what was causing the original BSOD's or redirects and many other things can cause the same symptoms.

 

The best thing to do now is visit the experts at one of these free malware removal forums to see if they can find out what the problem is and help you fix it.

 

www.bleepingcomputer.com

http://www.geekstogo.com/forum/

http://www.cybertechhelp.com/forums/

http://forums.whatthetech.com/

http://support.emsisoft.com/forum/6-help-my-pc-is-infected/ 

It was a Boot.Tidserv infection. I've already specified this.

 

I was running Norton 360 V5. Upon starting my computer it prompted me every time that it had detected "Boot.Tidserv" and asked me to rescan, which always brought the same result up each time.

 

I ran the norton product FixTDSS.exe which has now lead me unable to start my windows vista normally without safe mode.

 

 

EDIT: Also, the NBRT also identified the only problem on my computer as Boot.Tidserv. Other antivirus software either did not pick it up or claimed it to be a rootkit, which, correct me if I'm wrong, but is the origin of Boot.Tidserv before it infects the MBR. These have since been removed.

 

I'm looking for a fix to my BSoD. Not the infection that I've already resolved.

 

The Infection has not what we in the correct circles call resolved due to the fact that something is not able to load in Normal mode causing the BSOD, but does not get loaded (or attempted to load) in Safe Mode so the Startup process is fine.

 

System Restore to days or weeks before the known infection appeared may work. Or using the other forums swapping the system hive over.

 

Quads

Thank you for the additional info.  You didn't actually mention what was identifying the Boot.Tidserv.  The BSOD is still unknown as it was ther prior to the removal, so the actual infection may not have been the cause.  If you don't have a list of the errors as well as the parameters, try running Nirsoft Bluescreenview.  It reads Windows dump files and may provide enough information on what is causing the crash to fix it.  The download is near the bottom of the page.  

 

http://www.nirsoft.net/utils/blue_screen_view.html 

 

This thread may also be of interest as you have a dual-boot system.  Ubuntu makes changes to the boot that may affect both drives, and you may have inadvertently changed that when you fixed the MBR.

 

http://community.norton.com/t5/Tech-Outpost/introduce-me-a-boot-manager/m-p/572944/message-uid/572944/highlight/true#U572944

 

Your thread may be moved by the Mods to the N360 forum.  A link will be left here so that you can find it.