A rootkit for Windows systems is a program that penetrates into the system and intercepts the system functions (Windows API). It can effectively hide its presence by intercepting and modifying low-level API functions. Kaspersky Lab has developed the TDSSKiller utility that allows removing rootkits. Moreover it can hide the presence of particular processes, folders, files and registry keys.
Some rootkits install its own drivers and services in the system (they also remain “invisible”).
TDSS rootkit hides by infecting a low level system driver, most notably atapi.sys, iastor.sys or vmscsi.sys.
Kaspersky Lab has developed the TDSSKiller utility that allows removing rootkits.
- The utility supports 32-bit and 64-bit operation systems.
- The utility can be run in Normal Mode and Safe Mode.
It detects and removes the following malware
- malware family Rootkit.Win32.TDSS;
How to disinfect a compromised system
- Download the TDSSKiller.zip archive and extract it into a folder on the infected (or possibly infected) computer with an archiver (WinZip, for example);
- Run the TDSSKiller.exe file;
- Wait until the scanning and disinfection completes. A reboot might require after the disinfection has been completed.
Download : Kaspersky TDSSKiller 126.96.36.199