Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Support > TDSS Trojan

Reply
Thread Tools

TDSS Trojan

 
 
Scott269
Guest
Posts: n/a
 
      11-01-2008
Ok, so my father, ugh, running XP Home Edition, recently clicked
"Remove" on a "Do you want to remove spyware from your computer??"
popup and was infected with xp-antispyware 2009. *groan* .

Anyways, I got him Malwarebytes Anti-Malware installed and scanned and
removed the nasty stuff. Only problem is one was left, Trojan-TDSS.
I tried the usual stuff of boooting into SafeMode and running the
scanner there and it again found it and claimed to remove it but it
came right back. I did a registry search and found a couple instances
of it in a registry directory called TDSSSYS.SYS and proceeded to
delete them. But, after every reboot they came back and Malwarebytes
continued to find the trojan and "remove" it without actually fully
removing it. Seems to block me from doing a system restore also, I
gave that a try and after selecting the date and clicking Next,
nothing happens, it just sits there. I'm not near the computer right
now so I can't post a HijackThis log at the moment. Any suggestions
on something that will remove this bastard?
 
Reply With Quote
 
 
 
 
chuckcar
Guest
Posts: n/a
 
      11-01-2008
Scott269 <> wrote in
news:05ad70bc-ac6e-4bdc-baa3-:

> Ok, so my father, ugh, running XP Home Edition, recently clicked
> "Remove" on a "Do you want to remove spyware from your computer??"
> popup and was infected with xp-antispyware 2009. *groan* .
>
> Anyways, I got him Malwarebytes Anti-Malware installed and scanned and
> removed the nasty stuff. Only problem is one was left, Trojan-TDSS.
> I tried the usual stuff of boooting into SafeMode and running the
> scanner there and it again found it and claimed to remove it but it
> came right back. I did a registry search and found a couple instances
> of it in a registry directory called TDSSSYS.SYS and proceeded to
> delete them. But, after every reboot they came back and Malwarebytes
> continued to find the trojan and "remove" it without actually fully
> removing it. Seems to block me from doing a system restore also, I
> gave that a try and after selecting the date and clicking Next,
> nothing happens, it just sits there. I'm not near the computer right
> now so I can't post a HijackThis log at the moment. Any suggestions
> on something that will remove this bastard?
>

Searching for the fix on Symantec's website. A *lot* of malware has to be
removed in an *exact* manner. Most likely you missed a registry hook and
it "repaired" itself on reboot.

--
(setq (chuck nil) car(chuck) )
 
Reply With Quote
 
 
 
 
Pennywise@DerryMaine.Gov
Guest
Posts: n/a
 
      11-01-2008
Scott269 <> wrote:

> I did a registry search and found a couple instances
>of it in a registry directory called TDSSSYS.SYS and proceeded to
>delete them. But, after every reboot they came back and Malwarebytes
>continued to find the trojan and "remove" it without actually fully
>removing it.


Your deleting the child not the parent program.
Use hijackthis

Go here http://hijackthis.de/en download
http://download.hijackthis.eu/HJTInstall.exe

No need to install, just run it; Scan, save log, copy then, paste the
log file into http://hijackthis.de/en click analyze. Google first of
course, but Red should be deleted and yellow researched.

And whatever it is could be in your restore points. so turn restore
off.

Also you can find your problem with Process Explorer, by double
clicking on the program, read it's image, delete it's source.
http://technet.microsoft.com/en-us/s.../bb896653.aspx

Autoruns is also good for just turning off malware, instead of
removing it, found from the same site as Process Explorer

--

Octopus wreaks havoc
http://tinyurl.com/5a879m
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Removing Trojan TDSS.sys or TidServ backdoor dfinc Cisco 2 08-06-2009 04:03 AM
Re: Trojan Agent TDSS Tommy McClure Computer Support 0 10-23-2008 08:56 PM
Re: Trojan Agent TDSS Pennywise@DerryMaine.Gov Computer Support 0 10-23-2008 06:15 PM
Re: Trojan Agent TDSS Tommy McClure Computer Support 1 10-23-2008 04:18 PM
New trojan spam tells you where to download trojan as "MS beta antispy" Joel Rubin Computer Support 2 03-07-2005 02:26 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57