Rootkit.TDSS. How to remove? (Uninstall guide)

removal by Linas Kiguolis - -   Also known as TDSS, TDL3, Alureon | Type: Malware
12

Rootkit.TDSS, TDL3 or Alureon [Microsoft] is a malware designed to hide the existence of any process on the infected machine in order to perform malicious and dangerous actions. TDSS may also replace essential system executable files, which may then be used to hide processes and files installed by the attackers. Rootkit.TDSS is installed without user's permission through the use of trojan viruses, whereas trojan virus can download and install additional malware, adware or even rogue anti-spyware applications. This virus may also infect MBR sector, which is executed prior windows boot. Rootkit.TDSS removal can be complicated, but it is essential. When your computer is infected with TDSS rootkit you may encounter the following symptoms:

  • Google (Bing, Yahoo) search result links will be redirected to various misleading sites that promote rogue products or display bogus advertisements.
  • Security related websites will be blocked.
  • You won't be able to launch legitimate anti-malware or anti-virus applications.
  • You may find that web pages load slower.

Please use TDSS virus remover and remove it as soon as possible after detection. First of all, download TDSSKiller. This tool was created to remove rootkits that belong to numerous malware families, including TDSS. Run TDSSKiller and press the button Start scan for the utility to start scanning. The scan won't take long, only a few minutes. After the scan, it will list maliciius files. Suspicous objects should be skipped and malicious, high risk objects should be deleted. After clicking Next, the utility applies selected actions and outputs the result. Select the correct option and click Continue. A reboot might require after disinfection, so just click Reboot. Now, your computer should be TDSS rookit free. You can download TDSS remover to remove associated malware from the system.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Rootkit.TDSS you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Rootkit.TDSS. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

More information about this program can be found in Reimage review.
Rootkit.TDSS snapshot
Rootkit.TDSS

Rootkit.TDSS manual removal:

Kill processes:
RkLYLyoM.exe

podmena.exe

file.exe

~.exe

7-v3av.exe

csrssc.exe

72631899.exe

1776260179.exe

ucxmykkc.exe



Delete registry values:
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices_VOIDd.sys

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices_VOID[random]

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesUACd.sys

Unregister DLLs:
UACyylfjdaa.dll

TDSSnrsr.dll

tdssserf.dll

TDSSriqp.dll

TDSSciou.dll

TDSSoexh.dll

Delete files:
_VOIDd.sys

_VOID[random].sys

UAC[random].sys

UACyylfjdaa.dll

TDSSnrsr.dll

TDSSmaxt.sys

tdssserf.dll

TDSSriqp.dll

TDSSciou.dll

TDSSoexh.dll

tdidrv2.sys

RkLYLyoM.exe

podmena.exe

tdssserv.sys

file.exe

~.exe

7-v3av.exe

csrssc.exe

72631899.exe

1776260179.exe

ucxmykkc.exe



Delete directories:
C:WINDOWS_VOID[random]

About the author

Linas Kiguolis
Linas Kiguolis - Expert in social media

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

More information about the author


  • uk

    one of the hardest to remove parasites

  • Aimee

    I have this virus on my computer. TDSSKiller did not find it despite running it several times.
    OI have also run, Spybot search & Destroy, Paretologic Health Check up, Norton Scan, Ccleaner, Spyzooka, malware antimalware and many others. None can seem to find this virus anywhere. What else can I try?

  • Alex

    Aimee, as microsoft suggest – the best way if you got rootkit – it reinstall the whole system.
    But be careful, last TDSS(Alureon) modified MBR record on a HDD so you can reinstall from hidden partition that parasite again, so the best choice before reinstallation – it burn light weight Linux distro like “Puppy linux” (I prefer old version 4.x) andwhen it loaded you will see on HDD files that explained in manual removal and delete them.(Dont scare about Linux, it feels the same as windows but much much faster).
    After that step check google for “rescue anvirus cd” almost all popular one have ISO version, that load Linux OS from CD (so TDSS dont have choice to activate itself) and run full scan.
    After that you can reinstall WIndows and when you done – make favor for yourself, create separate restricted account, put password on administrator account and always work only from restricted account.