Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Help removing Trojan Tdss

  • Please log in to reply
1 reply to this topic

#1 JuturnaVII


  • Members
  • 1 posts
  • Local time:07:52 AM

Posted 31 July 2009 - 09:01 PM

Hello! Recently, my computer has been slower and the links on google are being redirected to lame sites (i haven't checked if they are being redirects on other sites like yahoo or bing). I scanned my computer with Avast and it detected a virus on my computer and asked to reboot so it can do a special scan on startup. Then, avast deleted all the bad files and stuff.

However, my computer was still infected with a virus! My pages were still being redirected to other sites AND the virus blocks anti virus programs from opening. So i tried scanning with malwarebytes (after changing the name of the exe cause it kept gettin blocked) and it detected a bunch of other bad stuff. It had me reboot, it deleted the viruses, and i STILL had the same problem. So i scanned with Ad aware, and it found just win32TrojanTdss, and i had to reboot again. While startin up, the virus was deleted. My computer began running better than before the avast scan and i could hardly notice it was slower.

But, on an occasion, my pages are getting redirected AND my antiviruses are still gettin blocked. I scanned with Ad aware again and the same virus was detected! I cant get rid of it! I'd appreciate it SOOOO much if someone can help me! pleaseee :[

one more detail.. i used to have b.exe in my processes (not before i had the viruses) and i occasionally received errors about it not working because of not being able to access data or something and it must be terminated (i can hardly remember what it said). i read all over the internet that it was a virus, so i deleted it from docs and settings>localsettins>temp>b.exe but deleting it had no positive or negative affect on my computer, besides getting rid of the errors.

BC AdBot (Login to Remove)


#2 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • Gender:Male
  • Local time:06:52 AM

Posted 31 July 2009 - 09:09 PM

Hello and welcome to Bleeping Computer.

Please subscribe to your topic so that you will be notified as soon as I post a reply, instead of you having to check the topic all of the time. This will allow you to get an email notification when I reply.

To subscribe, go to your topic, and at the top right hand corner by your first post, click the Options button and then click Track this topic. The bullet the immediate notification bubble. Then press submit.

I am so sorry but I have bad news:

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identity Theft, Internet Fraud, and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.

Edited by Computer Pro, 31 July 2009 - 09:10 PM.

Computer Pro

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users