Packed.Generic.200 (globalroot) or Tidserv!inf, TDSS, Tidserv.G...................

Hi Try this sequence for these infections, (Malware) although there may be a very new one that if following the renaming etc. etc. it still doesn't work, I am reasonably busy with the NZ legal system at the moment, so here goes,

 

Hijackthis does NOT show this malware group.

 

as they are progressing = in general harder and harder to remove.

 

1. See if renaming the install package works to install, MBAM and/or SAS then rename it's .exe file after install to run, update, and then do full scans, sometimes the full scan in Safe Mode First.  work?? Please remember to update the Defintions after the install and renaming of the Programs .exe file.

 

2. Downloading  A -Squared USB free scan from Flash Drive (if USB ports are not affected) or you can unzip to a desktop folder and run from in the folder, to update, then run a "Deep Scan". After the scan only select the items that relate to the above infections, or deselect the others. Work??

Why deselect non related entries, so A-Squared does not remove them just the ones you want??  Well the other detected entries may be false positives, or in the case of "Virut",  A-Squared DELETES the file with Virut, even if it is a system OS file like "explorer.exe" etc. which is a NO NO, causes a broken Windows.  Where as Norton "FIX"s the file so that Virut is removed from "explorer.exe" but leaves the OS file. 

 

3. Combofix, last resort, as it can cause problems, to the OS,  and if happened to be infected with "W32.Virut.CF" Combofix won't work.  Also don't move the mouse cursor inside the box when Combofix is scanning as it could cause freezing. Should work.

 

4. After removal, by any of the above programs, Norton may still say and remind the infection is still there as other programs have been  used to remove the Malware instead, The listing is still here by in the "Unresolved" list.   This is were the "FIX" for the "Qbackup" folder is to be used.

 

Quads (hmmm wonder if qbackup" was named after me LOL short for "q(uads)backup).  

 


THE FIX:
It is not necesary to erase the complete Qbackup folder, neither you need to boot in safe mode also.QBackup folder (Quarantine Backup) is used by Norton AntiVirus component to store backup recoveries of repaired and removed threats when you fix/remove threats during the scan. It may also contain information about threats detected and retains the remediated data in your computer itself. It will be automatically recreated by Norton program when you run scan next time.
So to FIX this problem. Just open NIS2009 history,  GO to "unresolved security risk" Press "Remove*" the item failed to remove, wait for the "failed to remove" status, this will update the "*.qbi" file which have the history of the unresolved items. Then go to NIS2009 settings, go to "miscellaneous setting" and disable the Norton Product Tamper Protection under Miscellanious Settings. Then open your windows explorer and go to
  "C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\QBackup"
and erase your most recently (updated, newly)  "*.QBI" file. The asteric it a long number as "{DDAB4332-ED04-4898-9C20-D231FDC4B0C5}.qbi" it will be a small file 1-10 KB. Only deleted this file. Close Windows explorer, go to NIS2009 reactived the  Norton Product Tamper Protection under Miscellanious Settings and you can enter to the HISTORY and you will find it is empty (clear).
Hope this will help to not erase the hole (complete) "Qbackup folder".
BEST REGARDS (SALU2 PARA LA RAZA)
TUFE (aka JC.WILCOX or SABROSO)

Quads

 

Message Edited by Quads on 05-20-2009 04:43 PM