Results 1 to 2 of 2

Thread: Removal of win32.TDSS.rtk

  1. #1
    Junior Member
    Join Date
    Mar 2009
    Posts
    1

    Default Removal of win32.TDSS.rtk

    Hi,

    I run Spybot every day as part of my PC wellness program. Thursday morning, Spybot alerted me to the presence of the win32.TDSS.rtk trojan.

    1. Spybot wasn't able to remove it.
    2. The subdirectory referenced in all of the messages stated it was under my user appdata/roaming/twain32
    3. I ran Spybot as part of the reboot (I immediately rebooted). Spybot said it wasn't able to remove the trojan.
    4. I rebooted in Safe mode and ran Spybot. It said it was able to remove the trojan.

    Friday's Spybot scan came back with the same win32.TDSS.rtk trojan. I did the following:
    1) ran Spybot on reboot - unable to remove the trojan
    2) ran Spybot under Safe mode, it removed the trojan
    3) ran Spybot after normal reboot, it detected the trojan
    4) ran Spybot under Safe mode, it removed the trojan
    5) ran Spybot after normal reboot, it detected the trojan

    At this point I started searching for solutions without any success.

    Do you have any suggestions?

    Thank...
    So it appears to be in a driver or something that's loaded

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hello jwhatter

    Please see this next

    Please follow the instructions in the above thread and then start a fresh topic with the logs required.

    Regards.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •