Microsoft Windows XP Professional Logo
Trace8147 Posted on May 06, 2011
Answered by a Fixya Expert

Trustworthy Expert Solutions

At Fixya.com, our trusted experts are meticulously vetted and possess extensive experience in their respective fields. Backed by a community of knowledgeable professionals, our platform ensures that the solutions provided are thoroughly researched and validated.

View Our Top Experts

I have a "Backdoor.Tidserve!inf virus on my

2 Answers

Nash delos Santos

Level 2:

An expert who has achieved level 2 by getting 100 points

All-Star:

An expert that got 10 achievements.

MVP:

An expert that got 5 achievements.

Sergeant:

An expert that has over 500 points.

  • Expert 172 Answers
  • Posted on May 06, 2011
Nash delos Santos
Expert
Level 2:

An expert who has achieved level 2 by getting 100 points

All-Star:

An expert that got 10 achievements.

MVP:

An expert that got 5 achievements.

Sergeant:

An expert that has over 500 points.

Joined: May 03, 2011
Answers
172
Questions
0
Helped
53987
Points
536

Try the following steps:

1. Download Malwarebytes and install
2. When finished, Run it and let it update its definition to the latest one. Internet connection is needed during this point.
3. When update is finished. Click on Scan. This should take sometime.
4. Click on Show Results.
5. Click on Remove/Clean.

If you can't install Malwarebytes, it maybe that virus is blocking it. If such is the case, restart your machine and boot into safe mode. Follow the above steps in Safe Mode.

Hope it helps.

Matthew deSilva

Level 3:

An expert who has achieved level 3 by getting 1000 points

All-Star:

An expert that got 10 achievements.

MVP:

An expert that got 5 achievements.

Master:

An expert who has achieved Level 3.

  • Master 375 Answers
  • Posted on May 06, 2011
Matthew deSilva
Master
Level 3:

An expert who has achieved level 3 by getting 1000 points

All-Star:

An expert that got 10 achievements.

MVP:

An expert that got 5 achievements.

Master:

An expert who has achieved Level 3.

Joined: May 02, 2011
Answers
375
Questions
0
Helped
64161
Points
1156

If you have access to another pc, try connecting your drive as a secondary drive and then scan with antivirus and antispyware software, it could be that the virus itself is blocking the antivirus from deleting it.

Ad

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

tip

How to remove Autorun.inf

Here are some typical malware which can install autorun.inf.exe file to your computer and give your computer a critical strike.
Autorun.inf virus contains three execute files which are kavo.exe, ntdelect.com and autorun.inf. All of them are hidden files. You cannot find the by showing hidden files. The only way to find them is to use DOS command.

Not all user have computer savvy. I was suffered from this virus a lot. Success got rid of it using RegTool and want to share it with you.

To remove Autorun.inf

Tools you need RegTool and AVG anti-virus.

Also here is an easy way to remove Autorun.inf manually!

click Start>Run>enter “CMD” them you will see and command window. In the command prompt, you can search for any exe.files. First we can disable “read only” and “hidden” attributes.
Enter the word in prompt.
Check C drive: key in dir c:\/a/w
2 then
attrib -s -h -r c:\autorun.inf
attrib -s -h -r c:\ ntdelect.com
You can use the same way to disable attributes of other drive such like D, E, etc.
3 OK, everything is done, we can now remove these two files.
For C drive, you can enter
del c:\autorun.inf
del c:\ntdelect.com

The same to D drive
How about kavo.exe? You need to repeat step1 and step 2 to disable attributes.
The delete command is different with them.
attrib -s -h -r c:\windows\system32\kavo.exe
del c:\windows\system32\kavo.exe

last thing you should do:
Open registry editor by entering Regedit.
Go to HKEY_LOCAL-MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Remove Kavo value.

on Jun 01, 2010 • Computers & Internet
1helpful
1answer

I am using a Transcend 8GB USB Pend Driver. when i scanned it, it showed me that, find "rahulvirusprotection.vbe". Hence i delete it immediately. After deleting the virus, i tried to access the...

It is virus which uses autorun feature of the removable devices such as USB Pen Drive. These type of viruses usually have two files. (a) autorun.inf and (b) the executable (.exe) or script file. Some Antivirus programs delete the exe file but the autorun files remains. In your case, the exe file (rahul's virus protection.vbe) has been removed but the autorun entry is there, which is run everytime you try to access your pen drive. First, plug-in the drive and DONT OPEN IT. Open 'My Computer' , right click the pen drive and choose explore. (This would by-pass the autorun feature).

Download Flash Disinfector and save it to your desktop. Double-click Flash Disinfector.exe to run it and follow any prompts that may appear. The utility may ask you to insert your flash drive. Please do so and allow the utility to clean up those drives as well. Wait until it has finished scanning and then exit the program.
Reboot your computer when done.

(Flash_Disinfector will remove any autorun.inf files, create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection)


Let me know if any further clarification/ assistance is required.

Good Luck!
Appreciate generously, if the solution could have been of any help!
CreativeTECH
0helpful
1answer

My computer seems to be infected by the Backdoor, Tidse virus. I have Norton/Symantec anti-virus. Every time I start up the computer, Symantec tells me that a restart is required. Then I restart & it...

Your best bet is to reimage the machine. Even if you get rid of the virus you also get rid of the file(s) it infected. That means those files are no longer available to run and they typically are critical system files. Viruses will hide and then repopulate if you don't completely format and put a clean image on the system. Because you probably don't want to loose all of your data you will want to back it up. Here is another problem because some of that data could be infected as well. I recommend removing the hard drive and use another computer that has a good anti-virus system, backing up your data to another device. Be sure to check your email files because they can bring a virus into your system. Chasing a virus can be frustrating and ultimately unsuccessful. Bite the bullet and give yourself a clean system.
0helpful
1answer

Any file or document from word or excel.I have tried with other flash drive but same problem applied.

you may have a virus which is possibly resident on your flash drive.
Lately virus have been attacking flash drives and being spread to computer.
look in your drive for autorun.ini autorun.inf desktop.ini
if your see these files your infected and will need to take steps to get rid of the virus.
do a search for "flash drive virus" in gogole and see what comes up
1helpful
1answer

Funny UST scandal!!!

How to remove the virus:
first download taskiller in here or here and install it to your computer because you can’t use task manager to terminate the virus(the virus automatically close task manager).

run taskiller and left click it on the system tray(the one with a skull icon)
click processes
to close the virus, select process and click yes to the question

(process to close)

  1. killer.exe
  2. lsass.exe
  3. smss.exe
note: close only file that have the same icon of Funny UST Scandal.avi.exe
CMD STEPS
  1. now, click “start” then “run”
  2. type “cmd” without quotes
  3. type “cd\” without quotes
  4. type “attrib -h -s smss.exe” without quotes
  5. type “attrib -h -s autorun.inf” without quotes
  6. type “start c:” without quotes (a new window will open)
  7. select smss.exe, autorun.inf, Funny UST Scandal.avi.exe and delete it
If theres any drive or a partition type “d:” in command prompt without quotes “d” is the drive letter then repeat the CMD STEPS number 4-7 above…….
  • now type this on the command prompt “cd windows” without quotes.
  • type “attrib -h -s smss.exe” (without quotes)
  • type “start c:\windows” (without quotes)
  • delete the file smss.exe
  • now, goto c:\documents and settings\all users\startmenu\programs\startup
  • delete lsass.exe
click “start” then “run”
type “regedit” without quotes then delete the registry entries above….

“VIRUS REMOVE”
Or just simply download this UST VIRUS REMOVER (not tested)
0helpful
1answer

Funny scandal ust.avi.exe...virus problem

How to remove this virus:

-first download taskiller in http://www.rsdsoft.com/task_killer
and install it to your computer because you cant use taskmanager to terminate the virus(the virus automatically close taskmanager).

-run taskiller and left click it on the system tray(the one with a skull icon)

-click processes

-to close the virus, select process and click yes to the question

(process to close)
1.killer.exe
2.lsass.exe
3.smss.exe

note: close only file that have the same icon of Funny UST Scandal.avi.exe


CMD STEPS
1-now, click "start" then "run"
2-type "cmd" without quotes
3-type "cd\" without quotes
4-type "attrib -h -s smss.exe" without quotes
5-type "attrib -h -s autorun.inf" without quotes
6-type "start c:" without quotes(a new window will open)
7-select smss.exe,autorun.inf,Funny UST Scandal.avi.exe and delete it

-if theres any drive or a partition type "d:" in command prompt without quotes
"d" is the drive letter then repeat the CMD STEPS number 4-7 above.......

-now type this on the command prompt "cd windows" without quotes(na naman!)
-type "attrib -h -s smss.exe" without quotes(uli)
-type "start c:\windows" without quotes(hay naku!)
-delete the file smss.exe
-now, goto c:\documents and settings\all users\startmenu\programs\startup
-delete lsass.exe

-click "start" then "run"
-type "regedit" without quotes then delete the registry entries above....

Hope this helps!

Brad Nelson
0helpful
3answers

Funny UST scandle.avi (Virus)

I done research on this but not tested to my computer ..just try this remover created in philippines . this the link: http://www.geocities.com/six519/Remover.zip may this help.
0helpful
2answers

UST Scandal.avi.exe

1. Start Notepad
2. Copy the following text. (note: Everything in between the square brackets should be in one line)

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"



3. Save the file with a name (anything) like DisableAutoRun.reg (The extension .reg is the important part)
4. Double Click your newly created registry file. Choose yes or continue to the warning that will appear.


But what if you are already infected with the virus? There are several programs on the internet that you can download. Here are some of those programs that can be helpful:

Taga Lipa Are Remover (or Noob Killer) by Leerz (<--click to download)

else


first download taskiller in http://www.rsdsoft.com/task_killer/index... and install it to
your computer because you cant use taskmanager to terminate the virus(the virus automatically close taskmanager).

-run taskiller and left click it on the system tray(the one with a skull icon)

-click processes

-to close the virus, select process and click yes to the question

(process to close)
1.killer.exe
2.lsass.exe
3.smss.exe

note: close only file that have the same icon of Funny UST Scandal.avi.exe


CMD STEPS
1-now, click "start" then "run"
2-type "cmd" without quotes
3-type "cd\" without quotes
4-type "attrib -h -s smss.exe" without quotes
5-type "attrib -h -s autorun.inf" without quotes
6-type "start c:" without quotes(a new window will open)
7-select smss.exe,autorun.inf,Funny UST Scandal.avi.exe and delete it

-if theres any drive or a partition type "d:" in command prompt without quotes
"d" is the drive letter then repeat the CMD STEPS number 4-7 above.......

-now type this on the command prompt "cd windows" without quotes(na naman!)
-type "attrib -h -s smss.exe" without quotes(uli)
-type "start c:\windows" without quotes(hay naku!)
-delete the file smss.exe
-now, goto c:\documents and settings\all users\startmenu\programs\startup
-delete lsass.exe

-click "start" then "run"
-type "regedit" without quotes then delete the registry entries above....

-thats all


(* from support forume)



0helpful
3answers

Virus from ym

try using bitdefender anti virus. it removes most of the viruses with no strings attached
Not finding what you are looking for?

111 views

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

Grand Canyon Tech
Grand Canyon Tech

Level 3 Expert

3867 Answers

k24674

Level 3 Expert

8093 Answers

Brad Brown

Level 3 Expert

19187 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...