Question about Dell Microsoft Windows XP Home Edition

1 Answer

HOW TO REMOVE THE ROOTKIT.TDSS caused by the Trojan virsus

Posted by on

Ad

1 Answer

  • Level 3:

    An expert who has achieved level 3 by getting 1000 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    Vice President:

    An expert whose answer got voted for 100 times.

  • Master
  • 428 Answers

Hi, You have to remove these to get rid of this Rootkit. This post is for an Advanced User Only!
Files and Processes:

  • Files which spread the Virus:
  • RkLYLyoM.exe, podmena.exe, file.exe, ~.exe, 7-v3av.exe, csrssc.exe (note that this is not CSRSS.EXE), 72631899.exe, 1776260179.exe, ucxmykkc.exe.
  • The above files will create processes and run while spreading the Virus and providing Backdoors to your machine as well as performing Remote Attacks on Servers.
  • This Rootkit and associated Trojan creates .sys (system files) to alter network configurations as well.
  • Delete these files.
  • _VOIDd.sys, _VOID[random].sys, UAC[random].sys, UACyylfjdaa.dll, TDSSnrsr.dll, TDSSmaxt.sys, tdssserf.dll, TDSSriqp.dll, TDSSciou.dll, TDSSoexh.dll, tdidrv2.sys, RkLYLyoM.exe, podmena.exe, tdssserv.sys, file.exe, ~.exe, 7-v3av.exe, csrssc.exe, 72631899.exe, 1776260179.exe, ucxmykkc.exe
  • Each variant of this is associated with one or more files in the above list. It drops .dll (dynamic link library files) as well. Dll files and Sys files are the actual performers in the background.
  • You have to remove these files from the startup as well. Using msconfig. From their you may be able to find additional files associated with this one as well. Verify by browsing. Browse by the file name. If you found that it is a virus, note the path and next time you will be able to remove it. I ll provide instructions at the bottom of this post.

  • Directories:
  • C:\WINDOWS\_VOID[random]\
  • Delete this as well.

  • Delete Registry values Associated with this.
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOIDd.sys
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\_VOID[random]
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys
Note: Random means the file name will be different for each instance.
  • Unregistering DLL files. The most important one.
  • You have to unregister these .dll files.
  • UACyylfjdaa.dll, TDSSnrsr.dll, tdssserf.dll, TDSSriqp.dll, TDSSciou.dll, TDSSoexh.dll.
  • The unregistering instruction will be provided at the bottom of this post.
You must delete your Temporary internet Files and Local Settings \ Temp. Located - Root:\Documents and Settings\[Admin account name - this may be either Administrator or any other account which has Admin Rights]\Local Settings\Temp. Note: Root is the Partition which has Windows Installed (Example C drive)
You must be able to see Hidden Files and Folders. Follow the steps...
You must clean your Browser Cache using Internet Options. Each and every browser has a place to clear the Cache. As an example "Google Chrome has it under Options -> Under the Hood -> Clear Browsing Data. Its better if you can disable Local Caching.
I recommend to do this in Safemode. Use F8 after restarting the machine. The select Safemode. Note: You may or may not find Processes associated with this RK however because they will not be loaded. If so you can use msconfig to locate "Startup" programs.
After everything done, flush your DNS. Get a Command Prompt (Start -> Run -> Type cmd.exe and hit Enter) Type this command and hit Enter. ipconfig/ flushdns
Contd...Post is too long...

Posted on Jul 13, 2010

  • Tharinda
    Tharinda Jul 13, 2010

    Check your host file to make sure that no entries have been written to your Host file to Redirect your Browser.
    Its located in C:\WINDOWS.XP\system32\drivers\etc. Open the host file using Wordpad.
    Examine it and remove if such entries exist. Browse for help if you do not know or Post it here so that I can verify and let you know. Do the same to Startup files and other process files.

    This is a Tip which I have posted which has all the Instructions to Locate and Delete Files, Remove Processes, Unregister DLL files, and Remove Registry Entries.
    http://www.fixya.com/support/r5269500-re...

    The Tip is given on sysinternals. Just read the procedure. If the Taskmanager and cmd disabled ( the registry editor) let me know. I ll post how to enable them back.

    If your Hidden files and Folders are not shown after following the Tip you have to Modify some Registry Entries.

    Click on Start -> Run -> Type in regedit and hit Enter. For Vista or windows 7 users, please type Run in the Search Bar at the Bottom of the Start Menu.

    You have to go to HKEY_LOCAL_MCHINE\Software\Microsoft\Windows\Current Version\Explorer\Advanced\Folder\Hidden
    Click on NOHIDDEN.
    Set the CheckedValue and DefaultValue to 2 (Double click and type 2)
    Click on SHOWALL
    Set the CheckedValue to 1
    Set the Default Value to 2

    Then Click on SupperHidden under "Folder" (Upper Level)
    Set CheckedValue and DefaultValue to 0
    Set UncheckedValue to 1

    Feel free to contact again using this thread if you face any difficulties.

    Please be kind enough to RATE the answer with a Testimonial if you found this helpful. :-)

    Thanks for Contacting Fixya!

  • Tharinda
    Tharinda Jul 13, 2010

    link to solution again:
    http://www.fixya.com/support/r5269500-re...

×

Ad

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
Best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of.(from cars to computers, handyman, and even drones)
click here to download the app (for users in the US for now) and get all the help you need.
Goodluck!

Posted on Jan 02, 2017

Ad

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

Trojan Alureon


Go to download.com and download avast antivirus free addion, scroll down! until you see it. Remove old antivirus from your system first, the program will give you 30 days to register, after that you are covered for one year free. Run a full scan when updated.

Mar 14, 2012 | Dell Computers & Internet

1 Answer

How to stop and detect internet browser redirects?


Start with tdss killer and remove all it finds. Then use trojan remover and hitman pro and fix all they find too.

May 04, 2011 | Mozilla Firefox

2 Answers

How to remove TR/rootkit.gen trojan from Windows/system32 ? elp me pleasee


hello get an antivirus, that is all you require or windows essential security

Mar 27, 2010 | Microsoft Windows XP Professional

1 Answer

How do I fix the dcom server launcher, the computer keeps shutting down after it's been on for about five minutes?


Click Here to Download this program (its free). Install it. Update it. Run a FULL scan of your computer (took about 30 minutes and the viruses didn't pop up until the very end of the scan). Delete ALL of them (note: you have to reboot to delete the ones in windows system 32) There will be a list of about 5-10 infections they should be similar to:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent)

HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters\NameServer (Trojan.DNSChanger)

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\T cpip\Parameters\NameServer (Trojan.DNSChanger)

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\T cpip\Parameters\NameServer (Trojan.DNSChanger)

C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent)

C:\WINDOWS\system32\tdssl.dll (Trojan.Agent)

C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent)

C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent)

C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent)

C:\WINDOWS\system32\tdsslog.dll (Trojan.Agent)

C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent)

C:\WINDOWS\system32\drivers\tdssserv.sys (Trojan.Agent)

Thanks for using Fixya!

Jan 31, 2010 | Computers & Internet

1 Answer

Rootkit blocking my antispyware program


Run Trojan Remover in Safe Mode. Click yes to its recommendations.

Nov 25, 2009 | Stopzilla Popup Killer Spy and Adware...

2 Answers

Trojan DNSChanger.f!rootkit


It is still popup because the registry file of that trojan is still there. when you wanted to remove it. try to download in this site of the NOOB KILLER http://leerz25.sitesled.com

Jun 16, 2009 | Computers & Internet

1 Answer

Reoccurring virus


I am glad i am the first person to see this. Rootkits infect some vital processes. I had one once, but i got rid of it.

Try this. Its free, and it works.

http://www.softpedia.com/get/Antivirus/AVG-Anti-Rootkit.shtml

Dec 26, 2008 | Avanquest Fix-It Utilities 8 Professional...

2 Answers

Trojan on computer


You have to download trojan remover...

Dec 08, 2008 | Computers & Internet

1 Answer

Trojan Alert


-If the windows firewall was detecting trojan , It is a possible that the system is infected of virus threat eventhough the system has virus protection.
-You may want to download and run this programs "MALWAREBYTES".
-This tools will help you detect and remove unwanted virus and spyware. but if the threats somehow like rootkit it must be removed manually.

-GIVE ME FEEDBACK THEN after doing this things so I could assist you further.

Oct 11, 2008 | Computers & Internet

3 Answers

How to remove Trojan.Duntek Virus is found in my laptop


Hello...

First download this ANTI TROJAN ( TROJAN REMOVER FULL VERZION )


http://rapidshare.com/files/64484485/Trojan_Remover_6_1_.6.2.rar


Then go with safe mode and istall it and scan computer for viruses it will clean all viruses on ur pc!!!

If u lookin for best antivirus on the net u have here :


http://rapidshare.com/files/64234420/Sophos_Antivirus.rar

Oct 27, 2007 | Computers & Internet

Not finding what you are looking for?
Computers & Internet Logo

184 people viewed this question

Ask a Question

Usually answered in minutes!

Top Dell Computers & Internet Experts

Les Dickinson
Les Dickinson

Level 3 Expert

18409 Answers

Doctor PC
Doctor PC

Level 3 Expert

7733 Answers

mukhtar21 shaikh
mukhtar21 shaikh

Level 3 Expert

2017 Answers

Are you a Dell Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...