Home / Spyware Encyclopedia / Rootkit.TDSS << Back

Recommendation to Automatically remove Rootkit.TDSS


Our products can remove Rootkit.TDSS and thousands of other Virus and Spyware automatically and instantly.

Rootkit.TDSS Details


  • Category Rootkit
  • Discovered 5/14/2009 4:01:39 PM
  • Modified 9/5/2024 12:13:03 PM
  • Threat Level Critical
  • Category Description
    A Rootkit is a collection of tools (programs) that enable administrator-level (root) access to a computer or computer network. A Rootkit may consist of spyware and other programs that: monitor traffic and keystrokes; create a "backdoor" into the system for the hacker's use; alter log files; attack other machines on the network; and alter existing system tools to escape detection. They are usually hidden and difficult to clean as they ingranulate deeply within the Registry and system files.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
baiduc.dll 151552Syons.Fae2.0.0.07392d782b8106dc26ab7fb6d63e1d92a 
baiduc.dll 163840Syons.Fae2.0.0.023b25817c5dd167a0b3441088bd9309f 
baiduc.dll 159744Hello Loons.Fad2.0.0.01375d320536a20a2b1b8402d384c416e 
IETimber.dll 193912????????1.0.0.136c56c0f69df06f8184d3ef0b96b907c 
IAPro.exe 1286656 1.0.1.809349790722815e3fab3a3c839e42ddaeb 
IAPro.exe 1319424 1.0.1.801c0ed71f5b9e515d1d04db00377a9ca2f 
IAPro.exe 1319424 1.0.1.800e76337a0b2cd7b93c5a1aca9ca7700ca 
42713bcc.exe 31744  fded68a6159d31c70fbd39629dde9d6b 
6A100BCA.EXE 30720  fcdaa9f763ca24548eb5021fa322d75b 
6909EE42.EXE 27648  fb5e27155081cf18ca8b7b2fbbea06c8 

The following Registry Entries were created:
..\Software\Classes\globalview\(Default)
..\Software\Microsoft\Windows\CurrentVersion\Run\\"systemguard"\"%DAS.AU.LS%\Temp\5FF1782F.EXE"
..\Software\Microsoft\Windows\CurrentVersion\Uninstall\intav_is1\(Default)
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Internet Antivirus Pro"\"%PF%\\Internet Antivirus Pro\IAPro.exe" /s "
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.EXE\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsnetsvr.EXE\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\naPrdMgr.EXE\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.EXE\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.EXE\(Default)
..\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.EXE\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware