Symanec Protection Suites

 View Only
  • 1.  Trojan.Gen.2 followed by Tidserv Activity 2

    Posted Oct 20, 2011 11:59 PM

    I recently started getting detection alerts talking about trojan.gen.2 being block a few days ago. The next day I looked in my history and I had 79 attempts by trojan.gen.2 I guess to attack. I get these messages almost every couple of minutes. Then today, I get an alert talking about Tidserv Activity 2 and needed manual removal. I have followed all of the instructions around the web and nothing can detect anything. I ran a complete system scan while in safe mode and it detected 32 threats but shortly after my computer just shuts off. What steps should I take from here?



  • 2.  RE: Trojan.Gen.2 followed by Tidserv Activity 2

    Broadcom Employee
    Posted Oct 21, 2011 12:57 AM


  • 3.  RE: Trojan.Gen.2 followed by Tidserv Activity 2

    Posted Oct 21, 2011 10:11 AM

    Hi Cory,

     

    I would start with downloading the latest Rapid Release definitions, then boot into safe mode and running a Disk Cleanup (right-click the C drive, Properties, Disk Cleanup) - that will delete all the files that are in these temporary locations, as well as IE's temporary files, etc. Perform another full system scan in safe mode.

    If that fails to detect and remove the threats, there are some useful tools that are provided by Symantec for help with finding those hard to detect threats.

    1. The Power Eraser Tool eliminates deeply embedded and difficult to remove threats that traditional virus scanning doesn't always detect.

    2. The SERT (Symantec Endpoint Recovery Tool)is useful in situations where computers are too heavily infected for the Symantec Endpoint Protection client installed upon them to clean effectively.

     

    3. The Load point Analysis Tool generates a detailed report of the programs loaded on your system. It is helpful in listing common loadpoints where threats can live.

     

     

    Rapid Release Virus Definitions –

    http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=rr

     

    Power Eraser tool –

    http://security.symantec.com/nbrt/npe.asp?lcid=1033&origin=default

     

    How To Use the Symantec Endpoint Recovery Tool with the Latest Virus Definitions –http://www.symantec.com/business/support/index?page=content&id=TECH131732&locale=en_US

     

    Support Tool with Power Eraser Tool included –

    http://www.symantec.com/business/support/index?page=content&id=TECH105414&locale=en_US

    How to use the Load Point Analysis within the Symantec Support Tool to help locate suspicious files http://www.symantec.com/business/support/index?page=content&id=TECH141402

    If you are unable to remove the threat(s) from your systems, please submit the suspected files to Symantec for analysis. New signatures will be created and included in future definition sets for detection.

    http://www.symantec.com/business/security_response/submitsamples.jsp

     

    Keep us posted.

    Best,

    Thomas