Computing.Net > Forums > Security and Virus > Removing Trojan.TDSS

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Removing Trojan.TDSS

Reply to Message Icon

Name: noir98
Date: August 30, 2009 at 01:15:05 Pacific
OS: Windows XP SP3
Product: Lenovo Thinkpad t61
Subcategory: Viruses
Tags: windows xp, Virus, trojan
Comment:

Hi, I just scanned my laptop with
Malwarebytes and it found a couple of Trojans
and it told me it was necessary to restart in
order to completely remove them. After it
restarted I scanned it again and it found one
remaining Trojan (Trojan.TDSS) and I had to
restart again. I rescanned and restarted about
5 times but Malwarebytes keeps finding it. I
also scanned with Spybot Search and Destroy
but it didn't find anything after the second
search. So I want to know how to remove this
last Trojan.



Sponsored Link
Ads by Google

Response Number 1
Name: Jack Frost46
Date: August 30, 2009 at 14:01:44 Pacific
Reply:

Try this goto device manager >> view >> show hidden >> and scroll to TDSSserver.sys or anything that starts TDSS and disable , DO not delete as it will put it's self back on again , then re-scan with MBAM .


0

Response Number 2
Name: noir98
Date: August 30, 2009 at 19:13:56 Pacific
Reply:

I tried that but I don't see anything that starts with TDSS. There's a yellow exclamation point next to something that says Parport though does that mean anything? I tried to remove it manually from the Registry (its called SKYNETalxjnawv) but it just keeps saying "unable to delete all specified values".

I downloaded CCleaner to clean out my registry but Malwarebytes is still detecting the Trojan. I am at a complete lost at what to do and its's been 3 days since I've had it.


0

Response Number 3
Name: noir98
Date: August 30, 2009 at 23:31:21 Pacific
Reply:

@ Hertinas

I went to the site but when I click on the links it doesn't open them.


0

Response Number 4
Name: Jack Frost46
Date: August 31, 2009 at 04:21:56 Pacific
Reply:

OK try this d\l Process Explorer open and look for a process called skynet , right click it and kill process then scan again with Malwarebyte's Antimalware , and let us know how you got on .

http://majorgeeks.com/Process_Explo...


0

Response Number 5
Name: Jack Frost46
Date: August 31, 2009 at 10:59:26 Pacific
Reply:

Hello noir98 , Update I have just dealt with another case of SKYNET on another forum , A change of AV to Avast free did the trick .


http://www.avast.com/eng/avast_4_ho...

Good luck


0

Related Posts

See More



Response Number 6
Name: noir98
Date: August 31, 2009 at 14:05:29 Pacific
Reply:

I looked for the Skynet file in the Process Explorer but it wasn't there. I downloaded Avast last night and scanned my laptop. It found 2 infected file and suggested moving them to the chest which is what I did. I scanned with mbam again and it found the virus again but instead of being called "Trojan.TDSS" it said "Rookit.TDSS" but it is still has the same file name. Mbam still
cannot remove it though. Avast wasn't running properly so I deleted it and redownloaded it. I am currently scanning so I will let you know if I was able to remove the virus.


0

Response Number 7
Name: noir98
Date: August 31, 2009 at 15:55:01 Pacific
Reply:

I scanned with Avast twice and it hasn't found anything but Malwarebytes is still finding the rookit.


0

Response Number 8
Name: Jack Frost46
Date: August 31, 2009 at 17:20:17 Pacific
Reply:

Well this a different problem , Try the easy ways first .

http://www.sophos.com/products/free...

Or this fully working evaluation copy ,

http://greatis.com/unhackme/downloa...

As I say there is the hard way but give these a try first and after that run MBAM again and post the log here .

..........


0

Response Number 9
Name: Jack Frost46
Date: August 31, 2009 at 17:34:58 Pacific
Reply:

I forgot to mention with Avast you can schedule a boot time scan this will scan the system before it actually loads , Dealing with the malware before it wakes up so to speak .
You'll find this in options .


0

Response Number 10
Name: noir98
Date: August 31, 2009 at 19:38:06 Pacific
Reply:

Thank you very much for all your help! I think my laptop is fixed now. I just scanned with Malwarebytes and it finally came out clean. If I have any more problems I'll be sure to ask. Thanks again.


0

Response Number 11
Name: Jack Frost46
Date: September 1, 2009 at 02:48:47 Pacific
Reply:

Thank you for getting back to us , your feed back will help others .


0

Sponsored Link
Ads by Google
Reply to Message Icon





Use following form to reply to current message:

Login or Register to Reply
LoginRegister


Sponsored links

Ads by Google


Results for: Removing Trojan.TDSS

Help Removing: Trojan Agent Tdss www.computing.net/answers/security/help-removing-trojan-agent-tdss/24321.html

Trojan.tdss problems, cant get rid of it! www.computing.net/answers/security/trojantdss-problems-cant-get-rid-of-it/26961.html

System infected: trojan-agent-tdss www.computing.net/answers/security/system-infected-trojanagenttdss/24318.html