Virus/Malware infections backdoor.Tidserv.I!inf , Murlo , GASF etc

Posted 02 September 2010 - 03:14 PM

Would be grateful for help in removing viruses/malware from my PC.
Approx. 1 week before I changed from norton internet security 2009 to 2010 I received a number of popup adverts, didn't think much about it at the time, I just deleted quickly, however as I look back now I realise I fell for a Microsoft window claiming virus infection etc I downloaded the exe. file but did not open the file once downloaded which is when I woke up and realised it was not from Microsofts website I deleted the file from my computer (sorry did not take down the name), I do not know if downloading the exe file would infect my pc as I did not open it, but assume backdoor.Tidserv.I!inf coursed the popups in the 1st place.

On installing Norton internet security 2010 the Sonar protection detected backdoor.tidserv.I!inf and asked for manual removal, which did not work, looked on their site and it said to disable restore points and manual remove in safe mode which again did not work. In Norton security history noticed Norton was blocking loads of attacks at medium severity, a few every minute when online, so googled how to remove this from my PC. Don't get angry with me PC helpers but I ran Combofix (now see it is advised not to do so without expert help), + Malwarebytes. But anyway this has greatly reduced attack rate but when I start my PC up am still getting around 7 medium level notices from Norton 3 various descriptions 'Unauthorized access blocked (open process Token) and (access process data) and (Duplicate object)' . When online I get the odd 1 or 2 medium level notices, an additional norton message to above 'Unauthorized access blocked (send terminate message to window).

Have also run Spywaredoctor which has dected Murlo,
And Stopzilla! has detected the following:
'Rogue' internetSecurity2010 file location rnpatch70.exe$$rnpatch70.exe AND internetSecurity2010 file rnpatch72.exe$$rnpatch72.exe (don't know if these are to do with the fact that norton was also running).
'Trojan' GASF , location c:\system volume information\_restore{d8696f73-2d76-412a-a981-4300c43ef86f}\rp10\a0003086.exe
'Trojan' W32.RemoteHack12 (x10 times connected with basically same document)
'Trojan' Gen Downloader.1 , location c:\documents and settings\hp_owner\desktop\20100819-019-v5i32.exe
'Spyware' lpv4mons located registry key hklm\software\Windows\CurrentVersion\controlPanel\load
'Hijacker' System Policies.DisableRegistryTools
'Adware' Cognac , location c:\system volume information\_restore{d8696f73-2d76-412a-a981-4300c43ef86f}\rp10\a0003082.exe
As I do not have a licence for these 2 anitvirus programs have not removed them.

Thank you any help you can give, have attached log files.

Posted 11 September 2010 - 06:59 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process. Please also continue to work with me until I give you the all clear. Even if your computer appears to act better, you may still be infected.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.

Once we start working together, please reply back within 3 days or this thread may be closed so we can help others who are waiting.

We need to create an OTL report,
  • Please download OTL from this link.
  • Save it to your desktop.
  • Double click on the icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Under the Custom Scan box paste this in:

    drivers32 /all
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\*.sys /90
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\*. /mp /s
    %systemroot%\*. /mp /s

  • Click the Quick Scan button.
  • The scan should take a few minutes.
  • Please copy and paste both logs in your reply.

In your reply, please post both OTL logs

Posted 14 September 2010 - 08:28 AM

Thank you for your reply, Current status is as above, I do not know if what I did removed backdoor.Tidserv.I!inf, in addition - Norton internet security 2010 recent updates may have removed it but I still have this virus in my history of unresolved security risks. Still getting the few medium Norton level attacks in my recent history as dscribed above.
Please find attached the 2 OTL logs a requested.
Thank you Ed

Posted 14 September 2010 - 05:47 PM

Hello, EdEd.
Tidserv is a backdoor rootkit.

Backdoor Warning
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you do decide to proceed, please continue with the fix below.

Registry Cleaner Warning

I also see that you have a Ccleaner installed. It is a great tool that I use. However, be careful of the registry cleaning functionality (versus file cleaning), Here at BC, we do not recommend using registry cleaners as they don't speed up your computer and they can do more harm than good if they remove a legitimate entry. If you do use it, make sure to use a tool like ERUNT to back up your registry first. Merely backing it up yourself via regedit wont' help you if you can't boot up as a result!

See here for more information:

Viewpoint (foistware) Warning"

Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This changed from what we know in 2006 read this article:


I suggest you remove the program now. Click on start > run > and then paste the following into the "open" field: appwiz.cpl and press OK. From within Add or Remove Programs uninstall the following if they exist: Viewpoint, Viewpoint Manager, Viewpoint Media Player.

Trusted Zone Warning

Having trusted sites may not be a good idea. The reason why I say it's not a good idea is because the security settings for the internet is not extremely high and once you put a site in your trusted zone, basically almost anymore or thing, including hackers or other malicious software have full access to that site which can lead to hijacking that site and may even have access to your computer. Are you sure you trust a site to that degree?

It is recommended NOT to have ANY sites in your Trusted Zone unless the site requires it to function properly and you trust it very well. Other than that, it is not necessary for you to add any sites into the trusted zone. If you're not sure, and/or you do not need these in your trusted zone to facilitate access or you did not knowingly permit this access yourself, then please remove those sites from your trusted zone.

They can be accessed in Internet Explorer via Tools>>Internet Options>>Security>>Trusted Zone>>Sites. Remove if there are any there.

Step 1

I see you have Stopzilla installed. This is of debatable quality; see Web of Trust here:

I recommend you uninstall it.

Step 2

Please post C:\Combofix.txt

Step 3

Scan With RKUnHooker
  • Please Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.

Copy the entire contents of the report and paste it in a reply here.

Note** you may get this warning it is ok, just ignore

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

Step 4

Please download MBRCheck by ad_13 and save it to your desktop.

Double-click to run. A window will pop up. If it says 'non-standard' or 'infected' MBR code detected, please type 3 for Exit for now and press Enter.

It will save a logfile on your desktop that starts with MBR, then has the date, etc. Please copy and paste the contents of that log in your reply.


Posted 16 September 2010 - 10:08 AM

When you say reformat and reinstall of the OS, I assume that is returning my computer to it's 'as bought' state using the system recovery section of my hard drive, is that correct? if so I think I will use that method if it will give the best clean result. Is there anything I should know before I go ahead, I have got my HP basic instructions for carrying that out. I see alternatively you say running various virus detection softwares etc would not guarantee that it will be 100% secure afterwards, does full system recovery give a 100% secure result, I guess there is risk from reinstalling my document files (which I need to do), please advise
On a minor point just wondered if there is anyway I can backup my Favourites list in explorer.
I would appreciate any other advise before I carry out the system recovery, not sure if it's age being from 2005 would course any problems when it comes to software updates.

Thank you

Posted 16 September 2010 - 06:32 PM

Yes, reimaging from the recovery partition counts as a reinstall of the OS. Backup your files first. To minimize chance of reinfection, don't back up windows system files (*.SYS, *.DLL, or anything in C:\windows) and don't' back up programs (*.EXE, *.PIF, *.SCR, *.COM, *.BAT, etc.). Reinstall programs from scratch. Only backup documents & media, the rest can be replaced. When you put them on a backup media (e.g. external HD), make sure to hold down SHIFT before, during and after plugging it in to a clean computer until Windows tells you your hardware is installed and ready to use. That will disable autorun and minimize any malware jumping over to the clean computer. Then, update your antivirus and scan the external drive; then update and scan it with MBAM or SAS as well.

The age shouldn't matter, except you would need a lot of updates from Windows Update, so make sure to do that. If the restore doesn't have secuirty software, don't forget to install 1 antivirus (Avast or AntiVir are good free ones), 1 antispyware (MBAM or SAS) and enable the firewall or use a third party one before doing much on the clean install.

Now...you can never be 100% sure any computer is safe. What if a developer wrote a virus so good it didn't impact system performance and wasn't detectable? Would you ever know? Would we? So, the second you plug that computer into the internet, it could be infected and that's a risk we all take by accessing the internet. I can guarantee you that you would start from a secure state.

By backing up your favorites list, do you mean in Internet Explorer? You can import/export favorites. See here:

Here's some reading for other questions you may have about reformating and security.

Here's a good article on how to reformat:
When Should I Format, How Should I Reinstall

Also, to protect yourself against malware and reduce your chance of reinfection in the future, I strongly recommend to have a look at following links (giving some advice and tips):

Posted 21 September 2010 - 06:36 PM

