Rootkit.TDSS: what it is and how to remove it

Rootkit.TDSS, TDL3, or Alureon is a malicious program designed to hide the existence of any process on the infected machine in order to perform malicious and dangerous actions. The main purpose of the rootkit is to intercept user web traffic and steal sensitive data such as credit card details, banking credentials, logins, social security numbers, and much more.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like Rootkit.TDSS usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Rootkit.TDSS yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Screenshot of Rootkit.TDSS: rootkit tdss
Rootkit.TDSS as our 2021 report showed it.

Rootkit.TDSS: summary

NameRootkit.TDSS
TypeRootkit, bootkit
First detection2007; no Microsoft detection name is known for this name
FunctionIntercepts user traffic and collects a variety of personally-identifiable and sensitive information
DistributionNot recorded in the old report
DamageNot recorded in the old report
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 4 more facts
SymptomsAn unknown program in Installed apps
EvidenceOne write-up by a security site; details still limited
First seen6 May 2021
Facts checked7 October 2026

What Rootkit.TDSS does on an infected PC

From our report of May 2021 · not reviewed since

Rootkit.TDSS - malware that deeply infects Windows system files to operate

Rootkit.TDSS, TDL3, or Alureon is a malicious program designed to hide the existence of any process on the infected machine in order to perform malicious and dangerous actions.

The main purpose of the rootkit is to intercept user web traffic and steal sensitive data such as credit card details, banking credentials, logins, social security numbers, and much more.

The virus may also replace essential system executable files, which may then be used to hide processes and files installed by the attackers. It can also cause several Blue Screen of death crashes when operational.

Rootkit.TDSS is installed without the user's permission through the use of trojan viruses, whereas Trojan virus can download and install additional malware, adware, or even rogue anti-spyware applications.

This virus may also infect the MBR sector, which is executed prior to Windows boot. The removal of malware can be complicated, but it is essential.

When your computer is infected with a TDSS rootkit, you may encounter the following symptoms:

It goes without saying that you should not tolerate the presence of this threat on your Windows machine. Keep in mind that it can record very private personal data, eventually providing access to your online banking or other personal accounts.

It would not be surprising that you would lose money at any time, become a victim of future phishing campaigns, or even suffer from identity theft. Therefore, follow the detailed instructions we provide below in order to remove all the malicious files and components of this rootkit.

  • Google (Bing, Yahoo) search result links will be redirected to various misleading sites that promote rogue products or display bogus advertisements.
  • Security related websites will be blocked.
  • Frequent BSOD errors
  • You won't be able to launch legitimate anti-malware or anti-virus applications.
  • You may find that web pages load slower.
Screenshot of Rootkit.TDSS: rootkit tdss
Rootkit.TDSS in our 2021 report.

From our report of May 2021 · not reviewed since

More from our earlier report on Rootkit.TDSS

  • The virus might be very difficult to remove due to its extensive persistence mechanisms.
  • Use robust anti-malware tools to get rid of it in Safe Mode if required

How to remove Rootkit.TDSS

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like Rootkit.TDSS add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after Rootkit.TDSS, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of Rootkit.TDSS that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Rootkit.TDSS can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Manual removal using Safe Mode

Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.

Step 1. Access Safe Mode with Networking

Manual malware removal should be best performed in the Safe Mode environment.

Windows 7 / Vista / XP

  1. Click Start > Shutdown > Restart > OK.
  2. When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  3. Select Safe Mode with Networking from the list.Windows 7/XP

Windows 10 / Windows 8

  1. Right-click on Start button and select Settings.
    Settings
  2. Scroll down to pick Update & Security.
    Update and security
  3. On the left side of the window, pick Recovery.
  4. Now scroll down to find Advanced Startup section.
  5. Click Restart now.
    Reboot
  6. Select Troubleshoot.Choose an option
  7. Go to Advanced options.Advanced options
  8. Select Startup Settings.Startup settings
  9. Press Restart.
  10. Now press 5 or click 5) Enable Safe Mode with Networking.Enable safe mode

Step 2. Shut down suspicious processes

Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Click on More details.
    Open task manager
  3. Scroll down to Background processes section, and look for anything suspicious.
  4. Right-click and select Open file location.
    Open file location
  5. Go back to the process, right-click and pick End Task.
    End task
  6. Delete the contents of the malicious folder.

Step 3. Check program Startup

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Go to Startup tab.
  3. Right-click on the suspicious program and pick Disable.
    Startup

Step 4. Delete virus files

Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:

  1. Type in Disk Cleanup in Windows search and press Enter.
    Disk cleanup
  2. Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
  3. Scroll through the Files to delete list and select the following: Temporary Internet Files
    Downloads
    Recycle Bin
    Temporary files
  4. Pick Clean up system files.
    Delete temp files
  5. You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter): %AppData%
    %LocalAppData%
    %ProgramData%
    %WinDir%

After you are finished, reboot the PC in normal mode.

From our report of May 2021 · not reviewed since

Virus removal instructions

Please use TDSS virus remover and remove it as soon as possible after detection.

First of all, download TDSSKiller.

This tool was created to remove rootkits that belong to numerous hard-to-remove malware families. Run the program and press the Start scan button for the utility to start the scan process. The scan won't take long - only a few minutes.

After the scan, it will list malicious files. Suspicious objects should be skipped, and malicious, high-risk objects should be deleted. After clicking Next, the utility applies selected actions and outputs the result. Select the correct option and click Continue.

A reboot might require after disinfection, so just click Reboot. Now, your computer should be TDSS rootkit free. Note that additional malware could be hiding on your PC. If for some reason, you are unable to use the provided scanner, you should access Safe Mode with Networking and perform a full system scan.

Additionally, scanning the device with or another reputable security software can help ensure that no malicious components are left on your machine. Don't forget to clean your web browsers and fix registries - you can use for the job.

After removal: passwords, accounts and prevention

Your passwords after Rootkit.TDSS

Removing Rootkit.TDSS does not undo what it may already have sent out while the PC showed rootkit.TDSS in the list of installed apps.

Treat saved browser passwords and logged-in sessions on this PC as known to the attacker.

From another device, change the e-mail password first and end all its sessions. Then do the same for the bank, PayPal, Microsoft, Google and Apple accounts. Stolen session cookies keep working after a password change until you sign out everywhere.

Move crypto to a new wallet created on a clean device. A step-by-step order for every kind of account is in our guide to account security after an infection.

Stream videos without limitations, no matter where you are

There are multiple parties that could find out almost anything about you by checking your online activity.

While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.

Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.

Data backups are important - recover your lost files

Ransomware is one of the biggest threats to personal data.

Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.

While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.

Questions about Rootkit.TDSS

Can I safely uninstall Rootkit.TDSS?

If you did not install Rootkit.TDSS yourself and it is not part of your hardware or a program you rely on, yes. Uninstalling an unwanted program does not harm Windows. Before you do, search the exact name and publisher to be sure it is not a driver tool, a printer utility or a game launcher with an odd name.

Then remove it from Settings, Apps, Installed apps. Ignore any offers or warnings in its uninstaller about losing protection or performance. Afterwards check Startup apps and your browsers for leftovers, and restart once to confirm that it does not reinstall itself.

How do I stop programs like Rootkit.TDSS from being installed again?

Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.

Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped Rootkit.TDSS before it reached the app list.

Why can't I find Rootkit.TDSS in antivirus databases?

Because it is new or because it is listed under a different name. Antivirus companies name threats after the family they belong to, and a program that appears as Rootkit.TDSS on your PC may carry a generic or unrelated label in their databases.

Many new samples are first detected only by behaviour, without a family name. What you saw, rootkit.TDSS in the list of installed apps, is enough to act on:

  • end the program
  • remove its startup entry
  • run a Microsoft Defender offline scan
  • secure your accounts

A detection name from a scan is worth noting for later.

My antivirus was on. How did a trojan get past it?

Antivirus programs see a file only when it is written or run, and criminals test each new build against popular scanners before release. Detection catches up within hours or days, which is often after the first victims ran it.

Archives with passwords, installers that fetch the malware later, and scripts run through PowerShell make the job harder. That is why behaviour such as downloading cracks or pasting commands matters more than any setting. Keep Windows and Defender updated, and turn on Reputation-based protection in App & browser control.

I found AnyDesk or ScreenConnect that I did not install. Is that Rootkit.TDSS?

Not necessarily Rootkit.TDSS, but it is a warning sign. These are legitimate remote support tools, and criminals use them as ready-made backdoors, especially after tech support scams or fake invoice calls.

If you did not install it and no one you trust set it up, uninstall it, change passwords from a clean device and check your bank account. If someone connected to your PC through it, follow the steps for remote access trojans and consider a Windows reset. Installed apps sorted by date shows when it appeared.

Can I keep using the PC while Rootkit.TDSS is on it?

Not for anything that matters. As long as the program behind rootkit.TDSS in the list of installed apps runs, it can see what you type and what the browser stores, and it may download more malware. Disconnect the PC from the internet while you remove it, and do your banking, e-mail and password changes from another device.

Once the offline scan finds nothing and the sign does not return after a few restarts, normal use is fine. If the scan keeps finding new items, or you cannot remove the startup entry, a reset of Windows is the safer choice.

How do I know if my PC has Rootkit.TDSS?

Often you do not, which is the point of a trojan. Possible signs are an antivirus alert naming Rootkit.TDSS or a generic trojan detection, unknown programs or scheduled tasks, processes with random names in Task Manager, browser extensions you did not add, security settings turned off, slower performance, or account alerts about logins from unknown places.

The reliable check is a full scan followed by Microsoft Defender's offline scan. If you recently ran a crack, a fake installer or a command a website told you to paste, scan even without symptoms.

Should I report Rootkit.TDSS?

Report it if you lost money, if accounts were taken over, if you are a business, or if the trojan came through a scam call. A police or national cybercrime report gives you a reference number for your bank and insurer and helps link cases.

You do not need to report a trojan that antivirus blocked before it ran. Before reporting, write down the dates, the detection name, file names and any messages or transactions linked to the attack; screenshots of antivirus alerts are useful evidence. The country list is in the report section above.

Should I check my other computers too?

Yes, it takes little time and removes doubt. Rootkit.TDSS itself usually stays on one PC, but the download that carried it may have been copied to other computers, shared drives may hold the same installer, and an attacker who had access could have tried saved passwords on other devices.

Run a full scan on every Windows PC in the home or office, check shared folders for the original download, and change Wi-Fi and router passwords if they were stored on the infected machine.

Will Fortect remove Rootkit.TDSS?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Rootkit.TDSS, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Questions and experiences: Rootkit.TDSS

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year