<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: rootkit.tdsserv/fake &#8211; A Very Annoying RootKit</title> <atom:link href="http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/feed/" rel="self" type="application/rss+xml" /><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/</link> <description>Antivirus Reviews For 2011 / 2012, Tools and How To&#039;s</description> <lastBuildDate>Tue, 07 Feb 2012 03:52:00 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: David</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-1611</link> <dc:creator>David</dc:creator> <pubDate>Mon, 15 Dec 2008 20:48:52 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-1611</guid> <description>In device manager, select &quot;show hidden devices&quot; under view.  The TDSServ &#039;driver&#039; hides in the Non Plug &amp; Play location.
Good luck!</description> <content:encoded><![CDATA[<p>In device manager, select &#8220;show hidden devices&#8221; under view.  The TDSServ &#8216;driver&#8217; hides in the Non Plug &amp; Play location.<br
/> Good luck!</p> ]]></content:encoded> </item> <item><title>By: Thor</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-1597</link> <dc:creator>Thor</dc:creator> <pubDate>Mon, 15 Dec 2008 17:36:34 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-1597</guid> <description>What was the name of the hidden PNP device?  I am working on the exact same problem, now.  Thanks</description> <content:encoded><![CDATA[<p>What was the name of the hidden PNP device?  I am working on the exact same problem, now.  Thanks</p> ]]></content:encoded> </item> <item><title>By: David</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-1479</link> <dc:creator>David</dc:creator> <pubDate>Thu, 04 Dec 2008 08:46:55 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-1479</guid> <description>Ok, I have finally quashed this one.
GMER wouldn&#039;t complete without crashing (got stuck on the protected registry entries)To summarise:  I was running AVG 8, and it couldn&#039;t see any issues.
MalwareBytes Anti-Malware found and removed a lot of issues in the registry and took out a lot of the TDSS*.sys files dotted around the drive.
SuperAntiSpyware was used afterwards, and took the count down to 17 registry items which kept recurring on bootup.At this point nothing was being fixed any further.  I found a hidden device driver under PNP devices, and deleted it and booted into safe mode, which allowed me to see and delete a few more TDSS files from System32 and System32/Drivers directories.After this, I deleted a lot of TDSS entries in the registry but it didn&#039;t help - the ones I needed to kill were hidden and protected.Eventually I tried Combifix (I think it&#039;s the right name?) which took out a protected registry entry on reboot, and then SAS cleared out the remaining ones.So far, it&#039;s reporting as being clean in SAS and GMER (works again now), in both safe and normal mode.</description> <content:encoded><![CDATA[<p>Ok, I have finally quashed this one.<br
/> GMER wouldn&#8217;t complete without crashing (got stuck on the protected registry entries)</p><p>To summarise:  I was running AVG 8, and it couldn&#8217;t see any issues.<br
/> MalwareBytes Anti-Malware found and removed a lot of issues in the registry and took out a lot of the TDSS*.sys files dotted around the drive.<br
/> SuperAntiSpyware was used afterwards, and took the count down to 17 registry items which kept recurring on bootup.</p><p>At this point nothing was being fixed any further.  I found a hidden device driver under PNP devices, and deleted it and booted into safe mode, which allowed me to see and delete a few more TDSS files from System32 and System32/Drivers directories.</p><p>After this, I deleted a lot of TDSS entries in the registry but it didn&#8217;t help &#8211; the ones I needed to kill were hidden and protected.</p><p>Eventually I tried Combifix (I think it&#8217;s the right name?) which took out a protected registry entry on reboot, and then SAS cleared out the remaining ones.</p><p>So far, it&#8217;s reporting as being clean in SAS and GMER (works again now), in both safe and normal mode.</p> ]]></content:encoded> </item> <item><title>By: malwarekilla</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-1477</link> <dc:creator>malwarekilla</dc:creator> <pubDate>Thu, 04 Dec 2008 02:00:15 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-1477</guid> <description>@David - you can try GMER (but that hasn&#039;t been working for lately).A bootable anti-malware disc is about the only way to get rid of it (besides GMER if it works).</description> <content:encoded><![CDATA[<p>@David &#8211; you can try GMER (but that hasn&#8217;t been working for lately).</p><p>A bootable anti-malware disc is about the only way to get rid of it (besides GMER if it works).</p> ]]></content:encoded> </item> <item><title>By: David</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-1476</link> <dc:creator>David</dc:creator> <pubDate>Thu, 04 Dec 2008 01:56:12 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-1476</guid> <description>I have been struggling with this all morning.  It slipped straight past AVG 8 (which now doesn&#039;t even work), and have been trying to remove it with SuperAntiSpyware and MalwareBytes Anti-Malware.To get those programs to work I had to rename the .exe files, as I think they were being blocked.MalwareBytes claims the infection has gone, however SuperAntiSpyware has just found 17 more items.</description> <content:encoded><![CDATA[<p>I have been struggling with this all morning.  It slipped straight past AVG 8 (which now doesn&#8217;t even work), and have been trying to remove it with SuperAntiSpyware and MalwareBytes Anti-Malware.</p><p>To get those programs to work I had to rename the .exe files, as I think they were being blocked.</p><p>MalwareBytes claims the infection has gone, however SuperAntiSpyware has just found 17 more items.</p> ]]></content:encoded> </item> <item><title>By: Michel</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-878</link> <dc:creator>Michel</dc:creator> <pubDate>Wed, 29 Oct 2008 08:03:13 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-878</guid> <description>Detects hijackers
search-and-destroyis amazing software which detected, blocked and removed hijackers, Rootkits .The speed of my pc has also increased.  It was really a blessing for me. You too go for it….it’s amazing</description> <content:encoded><![CDATA[<p>Detects hijackers<br
/> search-and-destroyis amazing software which detected, blocked and removed hijackers, Rootkits .The speed of my pc has also increased.  It was really a blessing for me. You too go for it….it’s amazing</p> ]]></content:encoded> </item> <item><title>By: malwarekilla</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-568</link> <dc:creator>malwarekilla</dc:creator> <pubDate>Tue, 07 Oct 2008 13:48:43 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-568</guid> <description>@alan - I did try, however it won&#039;t install unless i deselect the toolbar for ie.@Drpcfixit  - Yeah, I figured MBAM would at least see it, however it didn&#039;t.@VJ - It seams like everyone detects it as long as I&#039;m in a bootable env (which nullifies the hidden rootkit)@AV-Guy - I&#039;m trying to fit A-Squard in this month.  I use this app everyweek from a bootable env</description> <content:encoded><![CDATA[<p>@alan &#8211; I did try, however it won&#8217;t install unless i deselect the toolbar for ie.</p><p>@Drpcfixit  &#8211; Yeah, I figured MBAM would at least see it, however it didn&#8217;t.</p><p>@VJ &#8211; It seams like everyone detects it as long as I&#8217;m in a bootable env (which nullifies the hidden rootkit)</p><p>@AV-Guy &#8211; I&#8217;m trying to fit A-Squard in this month.  I use this app everyweek from a bootable env</p> ]]></content:encoded> </item> <item><title>By: Jonte</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-559</link> <dc:creator>Jonte</dc:creator> <pubDate>Mon, 06 Oct 2008 13:25:52 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-559</guid> <description>About the F-Secure review, why did´nt you test in safe mode?
Other Antivirus you should test: Norman, AVG Antivirus ( Test Again) Sophos.</description> <content:encoded><![CDATA[<p>About the F-Secure review, why did´nt you test in safe mode?<br
/> Other Antivirus you should test: Norman, AVG Antivirus ( Test Again) Sophos.</p> ]]></content:encoded> </item> <item><title>By: AV-Guy</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-556</link> <dc:creator>AV-Guy</dc:creator> <pubDate>Mon, 06 Oct 2008 06:22:10 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-556</guid> <description>Hi Matt. Still enjoying the reviews, sorry about F-Secure =) I think other good programs you could test are A2 Squared free and/or the Antimalware (w/ the Ikarus Engine) which is available for a 30 day trial. I have always heard that these programs have great detection but are known for high false positives, but I have seen very little on how these products actually remove the malware. I think a review of one of these products by Emsisoft would be very informative.</description> <content:encoded><![CDATA[<p>Hi Matt. Still enjoying the reviews, sorry about F-Secure =) I think other good programs you could test are A2 Squared free and/or the Antimalware (w/ the Ikarus Engine) which is available for a 30 day trial. I have always heard that these programs have great detection but are known for high false positives, but I have seen very little on how these products actually remove the malware. I think a review of one of these products by Emsisoft would be very informative.</p> ]]></content:encoded> </item> <item><title>By: Jonas</title><link>http://remove-malware.com/malware/rootkits/rootkittdsservfake-a-very-annoying-rootkit/#comment-553</link> <dc:creator>Jonas</dc:creator> <pubDate>Sun, 05 Oct 2008 16:09:18 +0000</pubDate> <guid
isPermaLink="false">http://remove-malware.com/?p=386#comment-553</guid> <description>Yess, it would be nice if you could test AVG again, maby they have fixed the problem, or test like Alan say =)</description> <content:encoded><![CDATA[<p>Yess, it would be nice if you could test AVG again, maby they have fixed the problem, or test like Alan say =)</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 26/36 queries in 0.014 seconds using disk: basic
Object Caching 592/604 objects using disk: basic

Served from: remove-malware.com @ 2012-02-11 21:08:45 -->
