• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove TDSS, Backdoor.Tidserv, Alureon trojan/rootkit

Myantispyware team November 5, 2008    

TDSS trojan also known as Backdoor.Tidserv [PCTools], Backdoor.Tidserv.I!inf [Symantec], Rootkit.Win32.TDSS.y [Kaspersky Lab], Patched-SYSFile.a [McAfee], Mal/TDSSRt-A [Sophos], Virus:Win32/Alureon.F [Microsoft] is very dangerous. It installs onto your computer through a vulnerability in an already installed programs (mostly in InternetExplorer) or with the help of a rogue antispyware programs. Trojan TDSS uses rootkit-specific techniques designed to hide the software presence in the system. It is practically not detected by standard means Windows, you will not find its files on the disk, as well as writing about it in the Windows registry.

When installed, it will be configured to start automatically when Windows starts. While is running, TDSS (Backdoor.Tidserv, Alureon) trojan may:

  • display a lot of popups and fake security alerts
  • hijack Internet Explorer
  • redirect search results in Google, Yahoo, MSN to non related sites
  • block an access to security websites
  • disable Windows Task Manager, Windows Security Center and Registry editor

What is more, TDSS, Backdoor.Tidserv, Alureon trojan blocks the ability to run a lot of antivirus and antispyware programs, including Malwarebytes Anti-Malware. Also it is usually installed in conjunction with a rogue antispyware programs.

If your computer is infected with the trojan, then use these removal instructions below, which will remove TDSS, Backdoor.Tidserv, Alureon trojan and any associated malware for free.

Symptoms in a RootRepeal Log

Hidden Services
——————-
Service Name: H8SRTd.sys
Image Path: C:\WINDOWS\system32\drivers\H8SRTnfvywoxwtx.sys
Service Name: _VOIDd.sys
Image PathC:\WINDOWS\system32\drivers\_VOIDaabmetnqbf.sys

Use the following instructions to remove TDSS, Backdoor.Tidserv, Alureon trojan.

1. Use TDSSKiler by Kaspersky lab to detect and remove a rootkit.
2. Use Malwarebytes Anti-malware to remove TDSS, Backdoor.Tidserv, Alureon rootkits associated malware.

1. Use TDSSKiler by Kaspersky lab to detect and remove the TDSS rootkit.

Download TDSSKiller from th link above.

TDSSKiller download link.

Right click to it and select Extract all. Follow the prompts.

Open TDSSKiller folder. Double click the TDSSKiller icon to run it. You will a screen like below.

tdsskiller main menu

Click Start scan button to start scanning and disinfection process. Once the process is complete, your computer will be rebooted.

2. Use Malwarebytes Anti-malware to remove TDSS, Backdoor.Tidserv, Alureon rootkits associated malware.

Download MalwareBytes Anti-malware from the following link.

MalwareBytes Anti-malware download link.

Close all programs and Windows on your computer. Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

mbam scanning

Click Scan Now button. It will start scanning your computer for TDSS, Backdoor.Tidserv, Alureon infection associated malware. This procedure can take some time, so please be patient.

When the scan is complete you will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

mbam removes operatingsystemerror

Make sure that everything is checked, and click Remove Selected for start TDSS, Backdoor.Tidserv, Alureon associated malware removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

TDSS, Backdoor.Tidserv, Alureon trojan creates the following files:

C:\Windows\System32\TDSS[RANDOM CHARACTERS].tmp
C:\Windows\System32\drivers\TDSS[RANDOM CHARACTERS].sys
C:\Windows\System32\TDSS[RANDOM CHARACTERS].sys
C:\Windows\System32\TDSS[RANDOM CHARACTERS].dat
C:\Windows\System32\TDSS[RANDOM CHARACTERS].log
C:\Windows\System32\TDSSserv.sys
C:\Windows\System32\TDSSerrors.log
C:\Windows\System32\TDSSservers.dat
C:\Windows\System32\TDSSl.dll
C:\Windows\System32\TDSSlog.
C:\Windows\System32\TDSSmain.dll
C:\Windows\System32\TDSSinit.dll
C:\Windows\System32\TDSSlog.dll
C:\Windows\System32\TDSSadw.dll
C:\Windows\System32\TDSSpopup.dll

TDSS, Backdoor.Tidserv, Alureon trojan creates the following registry keys and values

HKEY_LOCAL_MACHINE\SOFTWARE\TDSSserv
HKEY_LOCAL_MACHINE\SOFTWARE\TDSSserv\connections
HKEY_LOCAL_MACHINE\SOFTWARE\TDSSserv\disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\TDSSserv\injector
HKEY_LOCAL_MACHINE\SOFTWARE\TDSSserv\versions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sys

Rootkit Trojan Tutorials - HowTo
AlureonBackdoor.Tidservtdss

 Previous Post

How to remove Antivirus Pro 2009

Next Post 

How to remove Ultra Antivirus

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

169 Comments

  1. Anand
    ― June 22, 2009 - 3:11 pm  Reply

    Thank you very much. What a step by step explanation. It is of great help.

  2. sergio
    ― August 23, 2009 - 12:35 pm  Reply

    it didnt work for me when i tried the 1st step of right clicking properties of my computer it keeps showing C:\WINDOWS\system32\rundll32.exe and it does the same thing when i try to click an option in my control pannell plz help

  3. Patrik
    ― August 23, 2009 - 9:36 pm  Reply

    sergio, skip first step.

  4. Sean
    ― December 9, 2009 - 3:49 am  Reply

    Hi guys! firstlyjust got to say a big thank you and what a great site. I just removed that dreaded Google installer, I thought I was looking at a format and software re-build, keep up the great work, Sean

  5. john
    ― January 16, 2010 - 7:28 am  Reply

    thanks a lot for the instructions, works for me…

  6. Anjelica
    ― February 10, 2010 - 2:53 pm  Reply

    Dude, I’ve had this freaking virus for MONTHS, and neither McAffe nor AVG could get rid of it. Just found these instructions, and now it’s gone. THANKS MAN!

  7. TJ
    ― March 8, 2010 - 1:23 pm  Reply

    Thanks man! You’re instructions are a life saver.

  8. Marike
    ― March 17, 2010 - 5:02 pm  Reply

    Thank you so much!

    After I figured out how to remove Antivirus XP 2010, I still could not update my Malwarebytes and all the other antivirus programs. The TDSSkiller worked and now I can update, scan, and be rid of these POS!

  9. Faith Fulcher
    ― March 21, 2010 - 11:50 am  Reply

    Hi it is telling me that the cure has failed – what do i do now. I have windows 7

  10. Patrik
    ― March 21, 2010 - 11:54 am  Reply

    Try run TDSSKiller once again, if it does not help, then open a new topic in our Spyware removal forum.

  11. Jack
    ― March 25, 2010 - 5:26 am  Reply

    Patrik, you are awesome! I think that program you recommended took care of it. It found some infected file and then after reboot, I did another scan (it didn’t come up with anything). My computer still moves rather slow but at least, I am no longer getting the Tidserv warnings from Norton anymore and I can visit websites again that were blocked before (not to mention the svchost.exe spikes are gone). Thank you very much again for being one of the good guys and sharing your knowledge with us. This site will be the first one I recommend to anyone else I know who has any problems in the future.

  12. Dave D.
    ― March 25, 2010 - 9:05 am  Reply

    ~{Backdoor.Tidserv!inf}~ TDSSkiller nailed it.
    Just wanted to say thank you! I have been chasing this bug for about two weeks. After trying numerous programs that got rid of, or contained portions of it – this wiped it out very quickly. I was able to connect to windows update and use windows defender, both of which virus disabled. Thank you for the easy to follow instructions….. {Dave}

  13. Dave F (NZ)
    ― March 29, 2010 - 7:30 am  Reply

    Thanks – been trying to suss this out for 2 nights. Removal tool worked beautifully. Thank you!

  14. E
    ― April 2, 2010 - 5:54 pm  Reply

    Thank you! Thank you! Thank you! This is the only thing that worked. Hoping it’s gone for good

  15. dabeachmon
    ― April 3, 2010 - 9:10 pm  Reply

    ive gone about trying to get the rootkits removed, but every program including these steps always end with “program not compatible with x64 bit operating systems..” any idea where to find a compatable and comparable fix?

  16. Patrik
    ― April 4, 2010 - 8:53 am  Reply

    dabeachmon, you have tried run Malwarebytes ?

  17. tonganboi
    ― April 11, 2010 - 12:40 am  Reply

    A total of about 15 minutes…now my cpu is back! Thanks.

  18. Tia
    ― April 14, 2010 - 5:51 am  Reply

    Help, please! I can’t download TDSSkiller, and my computer restarts when I want to run Malwarebytes’ Anti-Malware! Also, avast! seems to be turned off, and I can’t turn it on!

  19. Patrik
    ― April 14, 2010 - 8:51 am  Reply

    Tia, try Safe mode with networking to download TDSSKiller. Also you can use another PC to download this file and move it using flash or cd disk to your computer.

  20. MJ
    ― April 14, 2010 - 10:08 pm  Reply

    If I follow these directions will this nasty virus/trojan or whatever it is stop redirecting me to other websites every time I type something in and click on a link on any search engine I get on?? Please seriously I’ve had this problem since the following Sunday and the website redirects are very annoying!!!

  21. Patrik
    ― April 15, 2010 - 8:30 am  Reply

    MJ, yes looks like your computer is infected with TDSS troja, then TDSSKiller should fix your problem.

  22. Sam
    ― April 17, 2010 - 7:42 pm  Reply

    I can’t download the TDSS Killer, even whilst in Safe Mode with Networking. Noticed I could download on another PC and transfer. Would I have to download the TDSS Killer even then? Or could I go straight to Malwarebytes?

  23. Patrik
    ― April 18, 2010 - 9:20 am  Reply

    Sam, try run Malwarebytes. If it`s blocked, then you need use TDSSKiller.

  24. Nick
    ― May 13, 2010 - 8:32 am  Reply

    Will this same removal process work with the virus: Win32/Alureon.H ? slightly different to the F version.
    It does the same thing as in: search results redirects to non related sites etc. Thanks for your feedback in advance.

  25. Patrik
    ― May 15, 2010 - 7:29 am  Reply

    Nick, yes try the instructions.

  26. catguy
    ― May 31, 2010 - 12:37 pm  Reply

    My AVAST 5 found today some kind of template attached to mbam.exe and put in in quarantine the file , i want to know about this kind of shell exploit found by avast…..ty very much!

  27. Patrik
    ― June 1, 2010 - 7:36 am  Reply

    catguy, probably your computer infected with a virus like virut. Scan your computer with Kaspersky online scanner.

  28. Jabberwocky
    ― June 15, 2010 - 1:49 pm  Reply

    I think this is exactly what I need, but the program refused to run with my x64 processor. I have Windows 7, intel core i3. I NEED HELP!

  29. Patrik
    ― June 16, 2010 - 9:54 am  Reply

    Jabberwocky, start a new topic in our Spyware removal forum. I will check your PC.

  30. Nae
    ― June 16, 2010 - 9:00 pm  Reply

    I was having a problem for 2 wks trying to remove the trojan. I tried everything on the web. This was the only progrm that worked.

« Previous 1 … 3 4 5 6 Next »

Leave a Reply Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
Malwarebytes won’t install, run or update – How to fix it
search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024
How to reset Google Chrome settings to default
How to remove pop-up ads [Chrome, Firefox, IE, Opera, Edge]

Recent Guides

How to remove Antivirus Pro 2009
How to remove Trojan-Keylogger.WIN32.Fung (fake Windows Security Alert)
How to remove Personal Defender 2009
How to remove WinDefender 2009
Removal instructions for Real Antivirus

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.