How to Disable ‘tdssserv.sys’ Trojan Identified With Update Failure and Redirected Searches
1.
4. Restart your computer
5. Confirm 'TDSSserv.sys' is disabled. Repeat Step 1-3. Cancel to exit.
6. Begin or resume UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions
Key Symptoms: (any of the following)
Procedural Steps- applying software updates does not work
- Google searches /Yahoo searches are redirected
- AntiVirus / AntiMalware programs are just 'spinning'
- often associated with Antivirus XP 2008, Antivirus XP 2009
- Ability to complete the UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions
- Ability to update your protection programs: Antivirus, AntiMalware, Rootkit, etc.
1.
- Start->Run-> Devmgmt.msc ->ok
- On the toolbar, Click on View -> "Show hidden devices"
- Scroll down and locate Non-plug and Play Drivers
- Click the + sign to expand
- Search for “TDSSserv.sys”
- More exploits: clbdriver.sys, oUltraf, seneka.sys,
- Right click on it, and select “Disable”
4. Restart your computer
5. Confirm 'TDSSserv.sys' is disabled. Repeat Step 1-3. Cancel to exit.
6. Begin or resume UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions
Aknowledgement: Mike, humble PC users everywhere
Technical Details:
Technical Details:
- Common Names: gogoogle, goyahoo
- O20 - AppInit_DLLs: karna.dat is apparent in HJT log
- Detected in various scanning programs:
- C:\WINDOWS\system32\wini10894.exe
- C:\WINDOWS\brastk.exe
- C:\WINDOWS\system32\brastk.exe
- C:\WINDOWS\karna.dat
- C:\WINDOWS\system32\karna.dat
- TDSSserv.sys
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | brastk
- all software updates redirected to 127.0.0.1 (your own computer) so they won't update.
Modification History
2.2 Add more service names
2.1 Modify title
1.1 Source material from Kimsland
1.2 This is pretty much my limit for addressing technical details for rooting out the infection
2.1 Modify title
1.1 Source material from Kimsland
1.2 This is pretty much my limit for addressing technical details for rooting out the infection