6 Replies Latest reply: Jan 29, 2009 7:59 PM by ryoma10 RSS

    How to remove TDSSserv registries

      Hi

      My laptop was infected by TDSSserv.sys rootkit . I cleaned it with the help of superantispyware and malwarebites. also i have mannually removed the tdssserv .sys from my device list.
      But still after cleaning using boht of them i am still seeing 5 registries in of TDSSserv in the detection in superantispyware.Malewarebutes gives no infections.

      Is my computer still infected with this TDSSserv?
      If not then how do i remove these registries completely from my machine.

      Also after cleaning this rootkit i am facing a problem when my comp is starting up i am seeing a small white box in right hand bottom corner above the start up panel ,with a symbol ( similar to picure not available symbol)..Also i am not able to see any symbols and smilies in my messenger window ( gtalk in my case)

      Can any one please help me out and suggest me what i should do to rectify the problems


      Following is the log from a superantispyware.I ran only registry sand memory sacn as form complete scan too gettign the same result.

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 01/26/2009 at 11:41 PM

      Application Version : 4.15.1000

      Core Rules Database Version : 3729
      Trace Rules Database Version: 1699

      Scan type : Custom Scan
      Total Scan Time : 00:05:57

      Memory items scanned : 622
      Memory threats detected : 0
      Registry items scanned : 7353
      Registry threats detected : 5
      File items scanned : 0
      File threats detected : 0

      Rootkit.TDSServ
      HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys
      HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#start
      HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#type
      HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#imagepath
      HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#group
        • 1. RE: How to remove TDSSserv registries
          paullotion
          Hello,

          Click start> run> type regedit

          Then click on

          HKLM
          +
          SYSTEM
          +
          CurrentControlSet
          +
          Services

          Locate TDSSserv.sys and right click on it

          Select delete from drop down menu.
          • 2. RE: How to remove TDSSserv registries
            Hi
            I did try that .but it says cannot delete TDSSserv.sys , error while deleting key .
            I dont know why this is happening

            Also not only any messnger window but also my intenet explorer is affected adn does not show any picture. in fact when i open google home page , then cant see the google mono instead of that it shows a symbol of picture not available type ( a small rectangular pic )

            below is my malwarebytes log as well as full system scan log of superantispyware

            Malwarebytes' Anti-Malware 1.33
            Database version: 1701
            Windows 5.1.2600 Service Pack 3

            1/27/2009 11:25:58 PM
            mbam-log-2009-01-27 (23-25-58).txt

            Scan type: Full Scan (C:\|)
            Objects scanned: 287393
            Time elapsed: 2 hour(s), 32 minute(s), 56 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 0
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 0

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            (No malicious items detected)

            Registry Values Infected:
            (No malicious items detected)

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            (No malicious items detected)

            -------------------------------------------------------------------
            SUPERAntiSpyware Scan Log
            http://www.superantispyware.com

            Generated 01/28/2009 at 02:28 AM

            Application Version : 4.15.1000

            Core Rules Database Version : 3732
            Trace Rules Database Version: 1702

            Scan type : Complete Scan
            Total Scan Time : 00:50:25

            Memory items scanned : 593
            Memory threats detected : 0
            Registry items scanned : 7351
            Registry threats detected : 5
            File items scanned : 29101
            File threats detected : 3

            Adware.Tracking Cookie
            C:\Documents and Settings\Ansh\Cookies\ansh@adbrite[2].txt
            C:\Documents and Settings\Ansh\Cookies\ansh@clickbank[1].txt
            C:\Documents and Settings\Ansh\Cookies\ansh@doubleclick[1].txt

            Rootkit.TDSServ
            HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys
            HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#start
            HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#type
            HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#imagepath
            HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#group
            • 3. hi..can you pls try this one..
              Click start-->run--> type devmgmt.msc then click on ok

              On the upper part of the device manager, click on VIEW then select show hidden devices.

              Click on "NON PLUG AND PLAY DRIVERS /DEVICES.

              Then, right click TDSSserv.sys and disable it.

              .Then try deleting it again on the directions given by paullotion..
              • 4. RE: hi..can you pls try this one..
                Hi
                I did done that, but on reading on some forum i actually instead of disabling it, uninstalled it as whenever i was trying to disable that it was giving an error that it cant be disabled.
                Is that something i done wrong ?
                currently under device management no TDSSserv.sys is coming

                thanks
                • 5. RE: hi..can you pls try this one..
                  Vinod R


                  Get to that location on the REGEDIT ( start --->run and then type Regedit)

                  on the key( the folder like entity on the left pane)
                  right click and select permissions then add EVERYONE and give full control to that keys alone
                  then scan after you have changed permissions
                  • 6. RE: hi..can you pls try this one..
                    Hi
                    thanks for ur advice
                    i tried that and then scanned .so now after removing those registries in next scan they are not coming in superantispyware.

                    But when i checked my registries using regedit
                    and searched for TDSS i can still see a registry

                    HKEY_LOCAL_MACHINES\SYSTEM\ControlSet003\Services\TDSSserv.sys


                    and i am not able to delete it by delete command .Its giving error that it cant be deleted.


                    Please guide me .


                    Thanks