Endpoint Protection

 View Only
Expand all | Collapse all

RDPENCDD.sys (Backdoor.Tidserv!inf)

  • 1.  RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 19, 2010 09:20 AM

    Hi,

    Everytime i start my computer(windows vista) , i see a notification from symatec endpoint antivirus saying that there are some threats found, when i click on the message i see the following,



    even after restarting as the message starts i see the same pop up again. When i click on Details, i see this:



    I selected the following from action: clean, put into quarantine, delete but none of them worked. I tried to locate the rpencdd.sys but there is only a dll and no sys file. I tried scanning with malware but even that did not work.

    Can some one please help about what i should do to get rid of this risk

    Thanks



  • 2.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 19, 2010 10:01 AM


  • 3.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 19, 2010 12:34 PM


  • 4.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 22, 2010 01:58 AM
    Did you run the  removal tools , suggested by Prachand above? Are you still getting these detections, and remediation unsucessful? If yes, then you may have to open a ticket with support, I think...


  • 5.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 22, 2010 10:17 AM
    This is a SYS file ( driver file )
    So its most probably a rootkit and you wont be able to find this file without using rootkits tools.
    This file will not get deleted normally
    Once you can try scanning the machine in Safe mode..as 3rd party drivers dont load in safe mode and it can get detected.

    I would suggest you to use Icesword1.2 or GMER and remove this file using it.

    Check this article for rootkits and tools useful in removing it
    https://www-secure.symantec.com/connect/articles/rootkit-intruder-living-your-kernel


  • 6.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 22, 2010 10:25 AM
    I had a customer  with the  same detection, and remediation status was unsuccessful....came out as an un repairable threat....

    You may have to replace the file from another  computer...


  • 7.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 22, 2010 03:40 PM
    Can you try a scan in safe mode?  

    Note, there is some trickery if it's still a "feature" where SEP will say something like "do you want to start the SEP services?"  Clicking no is what you want to do when in safe mode.


  • 8.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 22, 2010 05:33 PM
    Safemode has never worked for me with this rootkit, mainly because it's a critical system driver which Windows always has locked. I've found that replacing it with a known good file using BartPE does the trick. This one is a real pain to say the least.


  • 9.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 23, 2010 01:18 AM
    Then why not the SERT disc then?  This is the bootable ISO available on fileconnect


  • 10.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 23, 2010 01:42 AM
    SERT is used when your  computer  would not  boot at  all...and  is used to scan with the  current  definitions,at those  situations. Over here, this  is not the  case...

    Have you  installed ru6 mp1?


  • 11.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 23, 2010 07:43 AM
    The problem is this rootkit completely replaces the valid .sys file so even if it is cleaned, deleted, whatever, Windows still needs the file to function correctly. It needs to be completely replaced with a valid one so there will be more manual intervention than just running a scan. At least that is what I have found with the few clients I've had.


  • 12.  RE: RDPENCDD.sys (Backdoor.Tidserv!inf)

    Posted Aug 24, 2010 01:35 PM
    SERT is also useful when the system is infected with a rootkit so you can boot from the CD and not load any malware.  The SERT disk along with current defs should identify the malware and hopefully remove it.  I don't think it is only for use when the system is not bootable.

    This from Symantec tech support "The Symantec Endpoint Recovery Tool is an image that you can burn on a disc, which you can use to scan and remove malware from client computers. You use this tool for the computers that are too infected for Symantec  Endpoint Protection to clean effectively."  Full details are located at:

    https://www-secure.symantec.com/connect/videos/symantec-endpoint-recovery-tool-sert