Computing.Net > Forums > Security and Virus > Removing TDSS virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Removing TDSS virus

Reply to Message Icon

Name: Bamu
Date: February 16, 2009 at 19:30:09 Pacific
OS: Microsoft Windows XP Professional
CPU/Ram: 2.599 GHz / 1021 MB
Product: Intel / D845glva
Subcategory: Viruses
Comment:

Close to a month ago, I downloaded a torrent and opened the contents. I'm pretty sure now that Symantec AntiVirus popped up with a message warning me, but I didn't really absorb it and chose not to heed whatever it was saying, closing it. Shortly afterwards I noticed that my google results were redirecting to suspicious locations, so I scanned the computer with Symantec, and sure enough, it came up with tdss files.

I performed full scans a couple of times, each time having the antivirus clean, delete or move what it could; after the second or third time the google results stopped redirecting and my computer seemed to operate fine. But I distinctly remember that for a couple of files, it asked to reboot and still could not perform any requested actions. I meant to post on these forums then, but I kept procrastinating until now. Meanwhile, Symantec has stopped asking for reboots but does prompt me to download some updates and check if quarantined items can be cleaned or deleted now. So far no luck with that. And, I just checked: Symantec's AntiVirus SFV tells me the 52 files it recorded in the history are missing now (log is below).

My question is, have I done enough to remove any threat, or should I be doing more? I looked at some previous cases on these forums and it seemed like getting rid of the virus was a long, involved and individualized process, so I wanted to confirm.

Symantec AntiVirus SFV log:
QuickSFV v2.36
Risk
Downloader
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv
Backdoor.Tidserv!inf
Downloader
Bloodhound.Exploit.213
Trojan Horse
Backdoor.Tidserv
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv
Backdoor.Tidserv!inf
Backdoor.Tidserv
Backdoor.Tidserv!inf
Backdoor.Tidserv
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Downloader
Backdoor.Tidserv!inf
Downloader
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Packed.Generic.200
Packed.Generic.200
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Trojan Horse
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Trojan Horse
Trojan Horse
Backdoor.Tidserv
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
Packed.Generic.200
Trojan Horse
Trojan Horse
Backdoor.Tidserv!inf
Backdoor.Tidserv
Backdoor.Tidserv!inf
Backdoor.Tidserv!inf
52 files checked
There were 52 missing files



Sponsored Link
Ads by Google

Response Number 1
Name: jabuck
Date: February 16, 2009 at 19:36:35 Pacific
Reply:

I think you are still infected.

Depending opun the variant of the google redirect malware this may temporaryily help with the redirects:

Click on Start, click Run, and then type devmgmt.msc and click OK
On the View menu click on Show hidden devices
Browse to Non-Plug and Play Drivers and click the + sign to the left, you should see something like TDSSserv.sys in that list.
Highlight that driver and right click on it and select DISABLE - NOT uninstall.
Now RESTART your computer.

Please download Malwarebytes' Anti-Malware from one of these sites:

MalwareBytes1

MalwareBytes2

Rename the setup file, mbam-setup.exe, before you download it. To do that once the "enter name of file to save to" box appears as the download begins in the filename box rename mbam-setup.exe to tool.exe> click save.

1. Double Click tool.exe to install the application.
2. Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
3. If an update is found, it will download and install the latest version.
4. Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient.
5. When the scan is complete, click OK, then Show Results to view the results.
6. Make sure that everything found is checked, and click Remove Selected.
7. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
8. The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
9. Copy&Paste the entire report in your next reply.


If Malwarebytes installed but will not run navigate to this folder:

C:\Programs Files\Malwarebytes' AntiMalware

Rename all the .exe files in the MAlwarebytes' Anti-Malware folder and try to run it again.

Please download and install the latest version of HijackThis v2.0.2:


Download the "HijackThis" Installer from this link:
Hijack This

Rename the setup file, HJTInstall.exe, before you download it. To do that once the "enter name of file to save to" box appears as the download begins in the filename box rename HJTInstall.exe to tools.exe> click save.
1. Save " tools.exe" to your desktop.
2. Double click on tools.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


0

Response Number 2
Name: james88
Date: February 16, 2009 at 20:02:25 Pacific
Reply:

TDSS is a trojan that is also known as TDSS SERV or Trojan.Backdoor.Tid Serv. ok heres a manual removal guide for removing the TDSS
http://darfuns.com/remove-trojan-td...


0

Response Number 3
Name: Bamu
Date: February 17, 2009 at 20:41:39 Pacific
Reply:

I tried following the steps to deal with the redirect (even though it stopped a long time ago after I used Symantec), but couldn't find TDSSserv.sys or anything similar.

I downloaded Malware but couldn't find the way to rename it before, so I just renamed the setup file after it finished downloading. I also renamed the folder to tool.. not sure if that accomplished anything.

In any case I did the quick scan and it detected a couple of misnomers. Since it asked for a reboot I decided to delay posting the log which popped up. However, during the reboot process I got a black screen that said something like, "Invalid system disk. Please correct and press any button to continue". I do have a slave drive, if that's relevant; I can get it switched with the primary drive for me if it's needed. Meanwhile I can't access the computer as I keep on getting that message even if I restart (I'm using another computer to post this). What should I do?


0

Response Number 4
Name: jabuck
Date: February 18, 2009 at 14:30:00 Pacific
Reply:

Switch it with the primary drive and see if it will boot.


0

Response Number 5
Name: Qwazin
Date: February 22, 2009 at 09:44:07 Pacific
Reply:

Hello, I belive I have a similar problem with my computer. My Norton Antivirus discovered this naughty little virus called "packed.generic.200", and shortly after I got some trojans and crap aswell. Now I keep getting redirected on the internet, aswell as having all internet advertisement replaced with adds for viagra pills.

I would appriciate any help I can get.


0

Related Posts

See More



Response Number 6
Name: jabuck
Date: February 22, 2009 at 10:08:34 Pacific
Reply:

Qwazin, please start a thread of your own and we will try to help. Just state the problem as you did here, do not post any logs yet please.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Removing TDSS virus

I have removed the virus!! www.computing.net/answers/security/i-have-removed-the-virus-/683.html

remove AntiEXE virus www.computing.net/answers/security/remove-antiexe-virus-/22431.html

WORM_DELF.FKZ. remove this virus www.computing.net/answers/security/wormdelffkz-remove-this-virus/23562.html