Wednesday, June 2, 2010

Technique to remove HTTPS Tidserv Request

Introduction about Tidserv Trojan

“HTTPS Tidserv Request” or “HTTPS Tidserv Request 2”is a mark which detects your antivirus. It indicates that your computer is infected with a Tidserv trojan. Tidserv (TDSS) trojan fix onto your computer through a vulnerabilities in an already installed applications (mostly in InternetExplorer, Java and Adobe Acrobat reader) or with the help of a rogue antispyware programs. This trojan is very dangerous and uses rootkit-specific techniques designed to hide the program presence in the system.

When installed, Tidserv trojan creates a hidden driver and hidden service to run automatically when Windows loads. While is running, the trojan can hijack Internet Explorer, redirect search results in Google, Yahoo, MSN to non related sites, block most of antivirus and antispyware programs from running, block an access to security websites, disable Windows Task Manager, Windows Security Center and Registry editor, and much more.

Steps to remove Tidserv Trojan

1. Download TDSSKiller by Kaspersky Antivirus Lab and unzip to your desktop.
2. Open TDSSKiller folder. Right click to tdsskiller and select rename. Type a new name (123myapp, for example). Press Enter. Double click the TDSSKiller icon to start scanning Windows registry for TDSS trojan.
3. When TDSSKiller will prompt you to press “Y”, type Y and press Enter. Your computer will be rebooted.
4. Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.
5. Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.
6. MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.
7. As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu.
8. Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer for Tidserv (TDSS) trojan. This procedure can take some time, so please be patient.
9. When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below.
10. Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove Tidserv (TDSS) trojan. MalwareBytes Anti-malware will now remove all of associated Tidserv (TDSS) trojan files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

After this Tidserv Trojan will be permanently remove from computer.

No comments: