Backdoor.TDSS |
|
|
Danger level:
8
8
Type: Trojan
Common infection symptoms:
- Shows commercial adverts
- Normal system programs crash immediatelly
- System crashes
- Cant change my homepage
- Slow Computer
How to manually remove Backdoor.TDSS
Files associated with Backdoor.TDSS infection:
TDSScfub.dll
TDSSnrsr.dll
TDSSmaxt.sys
TDSSriqp.dll
TDSSoeqh.dll
TDSSfpmp.dll
TDSSnrse.dll
TDSSciou.dll
TDSScfgb.dll
TDSSmhxt.sys
TDSSliqp.dll
TDSSmhct.sys
TDSSosvn.dat
install[1].exe
ati8quxx.sys
setupapi.dll
~tmpa.exe
bnmio.exe
bd3q0qix.exe
vamsoft.exe
iii[1].exe
load[1].exe
winafoe.exe
ParisHilton[1].exe
winkfmc.exe
TckBX673.exe
card[1].exe
ert51791.exe
AdwarePro.exe
AdwarePro_Setup[1].exe
SSEngine.dll
StartApp.exe
1[1].exe
sysguardn.exe
free_scan.exe
ntos.exe
usp10.dll
Omahonafazeq.dll
new23[1].exe
gr[2].exe
adv111[1].exe
new26[1].exe
281681216.exe
SetupAntivirusXP[1].exe
ieupdates.exe
28823330.exe
Test.exe
loader[1].exe
Hyves_Browser.exe
Hyves_Browser_Instalation.exe
i386si.sys
duzfajdjnnyxethwo.dll
fwanqtvosgmeh.dll
9179499.exe
1462403437.exe
uxeqipuzimocin.dll
cvucujahoza.dll
oqarib.dll
winlogin.exe
AntivirusXP.exe
vvunbwrhxa.exe
imod3.dll
file.exe
winlogon.exe
UACd.sys
svchost.exe
tdssadw.dll
hapldpbpoz.dll
ytasfwkoslyqdk.dll
googletoolbar_download.exe
gasfkyfpcrnmxg.dll
gasfkydovvwqoh.dll
ktk57D9.tmp.exe
wow64main.exe
wscsvc32.exe
TDSSnrsr.dll
TDSSmaxt.sys
TDSSriqp.dll
TDSSoeqh.dll
TDSSfpmp.dll
TDSSnrse.dll
TDSSciou.dll
TDSScfgb.dll
TDSSmhxt.sys
TDSSliqp.dll
TDSSmhct.sys
TDSSosvn.dat
install[1].exe
ati8quxx.sys
setupapi.dll
~tmpa.exe
bnmio.exe
bd3q0qix.exe
vamsoft.exe
iii[1].exe
load[1].exe
winafoe.exe
ParisHilton[1].exe
winkfmc.exe
TckBX673.exe
card[1].exe
ert51791.exe
AdwarePro.exe
AdwarePro_Setup[1].exe
SSEngine.dll
StartApp.exe
1[1].exe
sysguardn.exe
free_scan.exe
ntos.exe
usp10.dll
Omahonafazeq.dll
new23[1].exe
gr[2].exe
adv111[1].exe
new26[1].exe
281681216.exe
SetupAntivirusXP[1].exe
ieupdates.exe
28823330.exe
Test.exe
loader[1].exe
Hyves_Browser.exe
Hyves_Browser_Instalation.exe
i386si.sys
duzfajdjnnyxethwo.dll
fwanqtvosgmeh.dll
9179499.exe
1462403437.exe
uxeqipuzimocin.dll
cvucujahoza.dll
oqarib.dll
winlogin.exe
AntivirusXP.exe
vvunbwrhxa.exe
imod3.dll
file.exe
winlogon.exe
UACd.sys
svchost.exe
tdssadw.dll
hapldpbpoz.dll
ytasfwkoslyqdk.dll
googletoolbar_download.exe
gasfkyfpcrnmxg.dll
gasfkydovvwqoh.dll
ktk57D9.tmp.exe
wow64main.exe
wscsvc32.exe
Backdoor.TDSS DLL's to remove:
TDSScfub.dll
TDSSnrsr.dll
TDSSriqp.dll
TDSSoeqh.dll
TDSSfpmp.dll
TDSSnrse.dll
TDSSciou.dll
TDSScfgb.dll
TDSSliqp.dll
setupapi.dll
SSEngine.dll
usp10.dll
Omahonafazeq.dll
duzfajdjnnyxethwo.dll
fwanqtvosgmeh.dll
uxeqipuzimocin.dll
cvucujahoza.dll
oqarib.dll
imod3.dll
tdssadw.dll
hapldpbpoz.dll
ytasfwkoslyqdk.dll
gasfkyfpcrnmxg.dll
gasfkydovvwqoh.dll
TDSSnrsr.dll
TDSSriqp.dll
TDSSoeqh.dll
TDSSfpmp.dll
TDSSnrse.dll
TDSSciou.dll
TDSScfgb.dll
TDSSliqp.dll
setupapi.dll
SSEngine.dll
usp10.dll
Omahonafazeq.dll
duzfajdjnnyxethwo.dll
fwanqtvosgmeh.dll
uxeqipuzimocin.dll
cvucujahoza.dll
oqarib.dll
imod3.dll
tdssadw.dll
hapldpbpoz.dll
ytasfwkoslyqdk.dll
gasfkyfpcrnmxg.dll
gasfkydovvwqoh.dll
Backdoor.TDSS processes to kill:
install[1].exe
~tmpa.exe
bnmio.exe
bd3q0qix.exe
vamsoft.exe
iii[1].exe
load[1].exe
winafoe.exe
ParisHilton[1].exe
winkfmc.exe
TckBX673.exe
card[1].exe
ert51791.exe
AdwarePro.exe
AdwarePro_Setup[1].exe
StartApp.exe
1[1].exe
sysguardn.exe
free_scan.exe
ntos.exe
new23[1].exe
gr[2].exe
adv111[1].exe
new26[1].exe
281681216.exe
SetupAntivirusXP[1].exe
ieupdates.exe
28823330.exe
Test.exe
loader[1].exe
Hyves_Browser.exe
Hyves_Browser_Instalation.exe
9179499.exe
1462403437.exe
winlogin.exe
AntivirusXP.exe
vvunbwrhxa.exe
file.exe
winlogon.exe
svchost.exe
googletoolbar_download.exe
ktk57D9.tmp.exe
wow64main.exe
wscsvc32.exe
~tmpa.exe
bnmio.exe
bd3q0qix.exe
vamsoft.exe
iii[1].exe
load[1].exe
winafoe.exe
ParisHilton[1].exe
winkfmc.exe
TckBX673.exe
card[1].exe
ert51791.exe
AdwarePro.exe
AdwarePro_Setup[1].exe
StartApp.exe
1[1].exe
sysguardn.exe
free_scan.exe
ntos.exe
new23[1].exe
gr[2].exe
adv111[1].exe
new26[1].exe
281681216.exe
SetupAntivirusXP[1].exe
ieupdates.exe
28823330.exe
Test.exe
loader[1].exe
Hyves_Browser.exe
Hyves_Browser_Instalation.exe
9179499.exe
1462403437.exe
winlogin.exe
AntivirusXP.exe
vvunbwrhxa.exe
file.exe
winlogon.exe
svchost.exe
googletoolbar_download.exe
ktk57D9.tmp.exe
wow64main.exe
wscsvc32.exe
Remove Backdoor.TDSS registry entries:
TDSS
Microsoft\Windows NT\CurrentVersion\tdssdata
Microsoft\Windows\CurrentVersion\Run\kxva
Microsoft\Windows\CurrentVersion\Uninstall\AdwarePro
Microsoft\Windows\CurrentVersion\Run\AdwareProMFCT
Adware Pro
Microsoft\Windows\CurrentVersion\App Paths\AdwarePro.exe
Microsoft\Windows\CurrentVersion\Run\sysguardn
Microsoft\Windows\CurrentVersion\Run\Mmexofumutokara
Microsoft\Windows\CurrentVersion\Run\281681216
AntivirusXP
Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntivirusXP
Microsoft\Windows\CurrentVersion\Uninstall\Hyves Browser
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bbe160c6-8bd8-4ac6-2473-08baeca009ec}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDAA8EDA-5EBE-B4C8-8205-5C732F6F815E}
MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusXP.exe
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ loader
RUNNING PROGRAM\winlogon.exe
RUNNING PROGRAM\Explorer.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinsysMon
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ktk57D9.tmp.exe
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ wow64main.exe
RUNNING PROGRAM\wscsvc32.exe
Microsoft\Windows NT\CurrentVersion\tdssdata
Microsoft\Windows\CurrentVersion\Run\kxva
Microsoft\Windows\CurrentVersion\Uninstall\AdwarePro
Microsoft\Windows\CurrentVersion\Run\AdwareProMFCT
Adware Pro
Microsoft\Windows\CurrentVersion\App Paths\AdwarePro.exe
Microsoft\Windows\CurrentVersion\Run\sysguardn
Microsoft\Windows\CurrentVersion\Run\Mmexofumutokara
Microsoft\Windows\CurrentVersion\Run\281681216
AntivirusXP
Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntivirusXP
Microsoft\Windows\CurrentVersion\Uninstall\Hyves Browser
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bbe160c6-8bd8-4ac6-2473-08baeca009ec}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDAA8EDA-5EBE-B4C8-8205-5C732F6F815E}
MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AntivirusXP.exe
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ loader
RUNNING PROGRAM\winlogon.exe
RUNNING PROGRAM\Explorer.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinsysMon
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ktk57D9.tmp.exe
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ wow64main.exe
RUNNING PROGRAM\wscsvc32.exe

Post comment — WE NEED YOUR OPINION!