Solved! Use TSZDOO.PIF (Rootkit TDSS) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

TSZDOO.PIF – Rootkit TDSS removal

File MD5 Virus Alias
TSZDOO.PIF ade1b7325ef1cdf9b40d9b7fbd93561f Rootkit TDSS
TSZDOO.PIF ade1b7325ef1cdf9b40d9b7fbd93561f Trojan Exception.gen.101
TSZDOO.PIF ade1b7325ef1cdf9b40d9b7fbd93561f Trojan Artemis
TSZDOO.PIF ade1b7325ef1cdf9b40d9b7fbd93561f Trojan Generic
TSZDOO.PIF ade1b7325ef1cdf9b40d9b7fbd93561f Trojan Agent

TSZDOO.PIF size: 24064 bytes
TSZDOO.PIF hash: ADE1B7325EF1CDF9B40D9B7FBD93561F

Created files:

%WinDir%\tszdoo.pif

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Jbjghcdef Hijkfgdfglmno Qrs\Type: 10010000
HKLM\System\CurrentControlSet\Services\Jbjghcdef Hijkfgdfglmno Qrs\Start: 02000000
HKLM\System\CurrentControlSet\Services\Jbjghcdef Hijkfgdfglmno Qrs\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Jbjghcdef Hijkfgdfglmno Qrs\DisplayName: Abcdefdff Hijklmnfgdfgdfo Qgdfgrstuvwx Abcd
HKLM\System\CurrentControlSet\Services\Jbjghcdef Hijkfgdfglmno Qrs\ImagePath: %WinDir%\tszdoo.pif
HKLM\System\CurrentControlSet\Services\Jbjghcdef Hijkfgdfglmno Qrs\Description: Abcdefsdfsfsdfgh Jklmnopqr Tuvwxya Cdefgfgdfhij dfgLmn

Detected by UnHackMe:

TSZDOO.PIF
Default location: %WinDir%\TSZDOO.PIF

Dropper information:
MD5: ade1b7325ef1cdf9b40d9b7fbd93561f
File size: 24064 bytes

Leave a Reply