HTTP Tidserv Request 2

We recommend the following steps to help protect and verify the integrity of the computer:• Run the Backdoor.Tidserv removal tool.• Update your product definitions and perform a full system scan.• Identify

scan completed successfullyhidden files: 0**************************************************************************Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.netdevice: opened successfullyuser: MBR read successfullycalled modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x896D0AC8]<< kernel: MBR read successfullydetected MBR rootkit hooks:\Driver\Disk

Click Yes to allow ComboFix to continue scanning for malware.When the tool is finished, it will produce a report for you.

Additional References Backdoor.Tidserv Removal Tool Blogs relating to Backdoor.Tidserv Backdoor.Tidserv

Eventually they stayed and since then I haven't had any notifications about Tidserv or anything. Infections the inject, patch or overwrite legit files to do with Windows and Windows needs, its not a good idea to use NPE, that's anything from TDL3 /TDL4 to Ramnit.

Please include the report in your next post:C:\ComboFix.txt"information and logs"In your next post I need the followingLog From Combofixlet me know of any problems you may have hadHow is the computer I have two concerns while I am working on this.

Second, when I ran TDSSKiller it said that atapi.sys was infected and would be cured on reboot. First, Download TDSSKiller and save it to your Desktop.

