Severity scale  
  (85/100)

Rootkit.TDSS. How to Remove? (Uninstall Guide)

removal by - -   Also known as TDSS, TDL3, Alureon | Type: Malware
12

Rootkit.TDSS, TDL3 or Alureon [Microsoft] is a malware designed to hide the existence of any process on the infected machine in order to perform malicious and dangerous actions. TDSS may also replace essential system executable files, which may then be used to hide processes and files installed by the attackers. Rootkit.TDSS is installed without user's permission through the use of trojan viruses, whereas trojan virus can download and install additional malware, adware or even rogue anti-spyware applications. This virus may also infect MBR sector, which is executed prior windows boot. Rootkit.TDSS removal can be complicated, but it is essential. When your computer is infected with TDSS rootkit you may encounter the following symptoms:

  • Google (Bing, Yahoo) search result links will be redirected to various misleading sites that promote rogue products or display bogus advertisements.
  • Security related websites will be blocked.
  • You won't be able to launch legitimate anti-malware or anti-virus applications.
  • You may find that web pages load slower.

Please use TDSS virus remover and remove it as soon as possible after detection. First of all, download TDSSKiller. This tool was created to remove rootkits that belong to numerous malware families, including TDSS. Run TDSSKiller and press the button Start scan for the utility to start scanning. The scan won't take long, only a few minutes. After the scan, it will list maliciius files. Suspicous objects should be skipped and malicious, high risk objects should be deleted. After clicking Next, the utility applies selected actions and outputs the result. Select the correct option and click Continue. A reboot might require after disinfection, so just click Reboot. Now, your computer should be TDSS rookit free. You can download TDSS remover to remove associated malware from the system.

Rootkit.TDSS properties:
• Hides from the user
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Rootkit.TDSS. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Rootkit.TDSS. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2012-01-04 06:17)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-01-04 06:17)
Hitman Pro
Webroot SecureAnywhere AntiVirus
Rootkit.TDSS screenshot
Rootkit.TDSS snapshot

Rootkit.TDSS manual removal

Kill processes:
RkLYLyoM.exe
podmena.exe
file.exe
~.exe
7-v3av.exe
csrssc.exe
72631899.exe
1776260179.exe
ucxmykkc.exe

Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOID[random]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys
Unregister DLLs:
UACyylfjdaa.dll
TDSSnrsr.dll
tdssserf.dll
TDSSriqp.dll
TDSSciou.dll
TDSSoexh.dll

Delete files:
_VOIDd.sys
_VOID[random].sys
UAC[random].sys
UACyylfjdaa.dll
TDSSnrsr.dll
TDSSmaxt.sys
tdssserf.dll
TDSSriqp.dll
TDSSciou.dll
TDSSoexh.dll
tdidrv2.sys
RkLYLyoM.exe
podmena.exe
tdssserv.sys
file.exe
~.exe
7-v3av.exe
csrssc.exe
72631899.exe
1776260179.exe
ucxmykkc.exe

Delete directories:
C:\WINDOWS\_VOID[random]\

Geolocation of Rootkit.TDSS

Map reveals the prevalence of Rootkit.TDSS. Countries and regions that have been affected the most are: United States.

Information updated:

Comments on Rootkit.TDSS

0
0
Alex
Aimee, as microsoft suggest - the best way if you got rootkit - it reinstall the whole system.
But be careful, last TDSS(Alureon) modified MBR record on a HDD so you can reinstall from hidden partition that parasite again, so the best choice before reinstallation - it burn light weight Linux distro like "Puppy linux" (I prefer old version 4.x) andwhen it loaded you will see on HDD files that explained in manual removal and delete them.(Dont scare about Linux, it feels the same as windows but much much faster).
After that step check google for "rescue anvirus cd" almost all popular one have ISO version, that load Linux OS from CD (so TDSS dont have choice to activate itself) and run full scan.
After that you can reinstall WIndows and when you done - make favor for yourself, create separate restricted account, put password on administrator account and always work only from restricted account.
0
0
Aimee
I have this virus on my computer. TDSSKiller did not find it despite running it several times.
OI have also run, Spybot search & Destroy, Paretologic Health Check up, Norton Scan, Ccleaner, Spyzooka, malware antimalware and many others. None can seem to find this virus anywhere. What else can I try?
0
0
uk
one of the hardest to remove parasites

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)