CNET Editors' review
Rootkits burrow into the roots of your Windows operating system, hiding and intercepting Windows API functions, often modifying them for their own purposes, which are seldom benign. TDSSKiller by Kaspersky Labs can find and remove rootkits, either in Normal Mode or Safe Mode. It targets malware where it lurks, including boot records.
We extracted and ran TDSSKiller, which immediately found an available update. Kaspersky strongly advised downloading the update before we scanned our system; we strongly agreed. This involved downloading and extracting a completely new copy of this compact, portable app, but that probably took less time than most ordinary updates. The tool's interface is about as simple as they come: one big Scan button, plus buttons to Change Parameters, view a Report, and Close the program. But the interface also describes what TDSSKiller targets, including a variety of known rootkits as well as rootkit-like anomalies, among them Sinowal, Stoned, Whistler, Trop, Cmoser, Pihar, and others, with new threats added by updates. We clicked Start Scan. TDSSKiller scanned 445 objects in our system in 13 seconds and found zero threats. That's what we expected it to find, but it's still a relief to see a clean report. We clicked Change Parameters, which let us select or deselect both Services and drivers and Boot sector for scanning (both are selected by default). The program only offers two more options: Verify file digital signatures and Detect TDLFS file system. A button lets you quickly restore the default settings.
Even though TDSSKiller found no malware to remove from our system, it generated a detailed report of every step of the recent operation. While we're glad we didn't need Kaspersky TDSSKiller, we don't doubt its ability to find what it claims it can, in part because we've had good experiences with other free utilities from Kaspersky Labs, but also because it's worked well for users who need it to clean up their systems. We're just glad it's available, and happy to run it on our supposedly clean system, even if only to prove it's clean. Come to think of it, that may be the best reason of all.
Kaspersky TDSSKiller - Detect and remove rootkit malware on your PC - Download Video Previews:Publisher's Description
From Kaspersky Lab:
A rootkit is a program or a program kit that hides the presence of malware in the system. A rootkit for Windows systems is a program that penetrates into the system and intercepts the system functions (Windows API). It can effectively hide its presence by intercepting and modifying low-level API functions. Moreover it can hide the presence of particular processes, folders, files and registry keys. Some rootkits install its own drivers and services in the system (they also remain "invisible").
Kaspersky Lab has developed the TDSSKiller utility that allows removing rootkits. The utility can be run in Normal Mode and Safe Mode. It detects and removes the following malware: malware family Rootkit.Win32.TDSS; bootkits; rootkits.
More Products to Consider
- Detect and quickly remove malicious threats to your computer.Download
Installed
Smart Install - Search your hard disk and Registry for threats to your security...Download
Installed
Smart Install - Detect and remove spyware, malware, rootkits, trojans, hijacker...Download
Installed
Smart Install - Detect and remove rootkits on your PC.Download
Installed
Smart Install - Detect presence of the TDL rootkit in your system.Download
Installed
Smart Install - Rescue your computer from viruses and malware.Download
Installed
Smart Install - Protect your personal home computer from malware attacks.Download
Installed
Smart Install - Protect your PC against the latest viruses and spyware.Download
Installed
Smart Install - Protect your computer from viruses and malicious programs.Download
Installed
Smart Install - Rescue your computer from viruses and malware.Download
Installed
Smart Install - Clean infected computers with a collection of repair tools.Download
Installed
Smart Install - Provide secure, anonymous, and private browsing on Wi-Fi hotspo...Download
Installed
Smart Install - Protect your Windows PC from online threats.Download
Installed
Smart Install - Detect and eliminate viruses, get free protection for home user...Download
Installed
Smart Install - Kill running malware processes that stop the use of normal anti...Download
This download is served from an external site
closeNOTICE: This link will open a connection to a third-party site. CNET cannot ensure the security of software that is hosted on external sites.
Sponsored Products
Installed
Smart Install - Download and exchange files safely, enjoy games and Web surfing...Download
Installed
Smart Install - Get the latest antivirus updates.Download
Installed
Smart Install - Scan for spyware and remove it from your computer.Download
Installed
Smart Install - Get updated virus pattern files.Download
Installed
Smart Install - Record and view every keystroke typed on keyboard.Download
Installed
Smart Install - Update Norton virus definitions and antivirus products.Download
Installed
Smart Install - Secure your connection to public Wi-Fi networks with premium VP...Download
Installed
Smart Install - Check your system for Windows vulnerabilities.Download
Installed
Smart Install - Perform various PC maintenance or malware removal tasks with on...Download
Installed
Smart Install
-
All versions:
4.6 starsout of 18 votes
-
Current version:
4.0 starsout of 1 votes
-
My rating:
Write review
Results 1-1 of 1
-
"False positives, probably, rendered my PC unusable."
Version: Kaspersky TDSSKiller 2.8.17
Pros
Characters
Cons
Characters
Summary
I have used TDSSKiller for a long time along with many security products I have used for years. I used TDSSKiller again on April 15th. It showed a number of supposed detections of supposed serious infections. I recklessly and foolishly followed the advice to delete them. My PC was rendered unusable. I now have a different drive installed and a fresh Windows install.
Not all is shown here below.
Only a little copied and pasted.
The file name is shown, and also
the very top and very bottom of it.
TDSSKiller.2.8.16.0_15.04.2013_20.00.32_log.txt
20:00:32.0348 2684 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:00:32.0848 2684 ============================================================
20:00:32.0848 2684 Current date / time: 2013/04/15 20:00:32.0848
20:00:32.0848 2684 SystemInfo:
20:00:32.0848 2684
20:00:32.0848 2684 OS Version: 6.1.7601 ServicePack: 1.0
20:00:32.0848 2684 Product type: Workstation
20:00:32.0849 2684 ComputerName: PC
20:00:32.0849 2684 UserName: ComodoNEW
20:00:32.0849 2684 Windows directory: C:\Windows
20:00:32.0849 2684 System windows directory: C:\Windows
20:00:32.0849 2684 Running under WOW64
20:00:32.0849 2684 Processor architecture: Intel x64
20:00:32.0849 2684 Number of processors: 4
20:00:32.0849 2684 Page size: 0x1000
20:00:32.0849 2684 Boot type: Normal boot
\/\/\/\/\/\/\/\/\/\
20:01:37.0264 4172 ============================================================
20:01:37.0264 4172 Scan finished
20:01:37.0264 4172 ============================================================
20:01:37.0269 3104 Detected object count: 23
20:01:37.0269 3104 Actual detected object count: 23
20:03:15.0320 3104 C:\Windows\system32\CLFS.sys - copied to quarantine
20:03:15.0416 3104 HKLM\SYSTEM\ControlSet001\services\CLFS - will be deleted on reboot
20:03:15.0456 3104 HKLM\SYSTEM\ControlSet003\services\CLFS - will be deleted on reboot
20:03:15.0466 3104 HKLM\SYSTEM\ControlSet004\services\CLFS - will be deleted on reboot
20:03:15.0552 3104 C:\Windows\system32\CLFS.sys - will be deleted on reboot
20:03:15.0552 3104 CLFS ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:15.0582 3104 C:\Windows\system32\drivers\DefragFS.sys - copied to quarantine
20:03:15.0655 3104 HKLM\SYSTEM\ControlSet001\services\DefragFS - will be deleted on reboot
20:03:15.0655 3104 HKLM\SYSTEM\ControlSet004\services\DefragFS - will be deleted on reboot
20:03:15.0658 3104 C:\Windows\system32\drivers\DefragFS.sys - will be deleted on reboot
20:03:15.0658 3104 DefragFS ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:15.0676 3104 C:\Windows\system32\DRIVERS\disk.sys - copied to quarantine
20:03:15.0744 3104 HKLM\SYSTEM\ControlSet001\services\Disk - will be deleted on reboot
20:03:15.0744 3104 HKLM\SYSTEM\ControlSet003\services\Disk - will be deleted on reboot
20:03:15.0745 3104 HKLM\SYSTEM\ControlSet004\services\Disk - will be deleted on reboot
20:03:15.0748 3104 C:\Windows\system32\DRIVERS\disk.sys - will be deleted on reboot
20:03:15.0748 3104 Disk ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:15.0772 3104 C:\Windows\system32\Drivers\EtronXHCI.sys - copied to quarantine
20:03:15.0848 3104 HKLM\SYSTEM\ControlSet001\services\EtronXHCI - will be deleted on reboot
20:03:15.0855 3104 HKLM\SYSTEM\ControlSet003\services\EtronXHCI - will be deleted on reboot
20:03:15.0855 3104 HKLM\SYSTEM\ControlSet004\services\EtronXHCI - will be deleted on reboot
20:03:15.0858 3104 C:\Windows\system32\Drivers\EtronXHCI.sys - will be deleted on reboot
20:03:15.0858 3104 EtronXHCI ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:15.0882 3104 C:\Windows\system32\DRIVERS\fltsrv.sys - copied to quarantine
20:03:15.0952 3104 HKLM\SYSTEM\ControlSet001\services\fltsrv - will be deleted on reboot
20:03:15.0953 3104 HKLM\SYSTEM\ControlSet003\services\fltsrv - will be deleted on reboot
20:03:15.0953 3104 HKLM\SYSTEM\ControlSet004\services\fltsrv - will be deleted on reboot
20:03:15.0956 3104 C:\Windows\system32\DRIVERS\fltsrv.sys - will be deleted on reboot
20:03:15.0956 3104 fltsrv ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0003 3104 C:\Windows\system32\drivers\hwpolicy.sys - copied to quarantine
20:03:16.0099 3104 HKLM\SYSTEM\ControlSet001\services\hwpolicy - will be deleted on reboot
20:03:16.0107 3104 HKLM\SYSTEM\ControlSet003\services\hwpolicy - will be deleted on reboot
20:03:16.0107 3104 HKLM\SYSTEM\ControlSet004\services\hwpolicy - will be deleted on reboot
20:03:16.0110 3104 C:\Windows\system32\drivers\hwpolicy.sys - will be deleted on reboot
20:03:16.0110 3104 hwpolicy ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0159 3104 C:\Windows\system32\DRIVERS\jraid.sys - copied to quarantine
20:03:16.0227 3104 HKLM\SYSTEM\ControlSet001\services\JRAID - will be deleted on reboot
20:03:16.0227 3104 HKLM\SYSTEM\ControlSet003\services\JRAID - will be deleted on reboot
20:03:16.0228 3104 HKLM\SYSTEM\ControlSet004\services\JRAID - will be deleted on reboot
20:03:16.0230 3104 C:\Windows\system32\DRIVERS\jraid.sys - will be deleted on reboot
20:03:16.0230 3104 JRAID ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0254 3104 C:\Windows\system32\DRIVERS\kbdclass.sys - copied to quarantine
20:03:16.0320 3104 HKLM\SYSTEM\ControlSet001\services\kbdclass - will be deleted on reboot
20:03:16.0320 3104 HKLM\SYSTEM\ControlSet003\services\kbdclass - will be deleted on reboot
20:03:16.0321 3104 HKLM\SYSTEM\ControlSet004\services\kbdclass - will be deleted on reboot
20:03:16.0323 3104 C:\Windows\system32\DRIVERS\kbdclass.sys - will be deleted on reboot
20:03:16.0324 3104 kbdclass ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0350 3104 C:\Windows\system32\DRIVERS\kbdhid.sys - copied to quarantine
20:03:16.0413 3104 HKLM\SYSTEM\ControlSet001\services\kbdhid - will be deleted on reboot
20:03:16.0413 3104 HKLM\SYSTEM\ControlSet003\services\kbdhid - will be deleted on reboot
20:03:16.0414 3104 HKLM\SYSTEM\ControlSet004\services\kbdhid - will be deleted on reboot
20:03:16.0417 3104 C:\Windows\system32\DRIVERS\kbdhid.sys - will be deleted on reboot
20:03:16.0417 3104 kbdhid ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0431 3104 C:\Windows\system32\drivers\mbam.sys - copied to quarantine
20:03:16.0508 3104 HKLM\SYSTEM\ControlSet001\services\MBAMProtector - will be deleted on reboot
20:03:16.0532 3104 HKLM\SYSTEM\ControlSet003\services\MBAMProtector - will be deleted on reboot
20:03:16.0533 3104 HKLM\SYSTEM\ControlSet004\services\MBAMProtector - will be deleted on reboot
20:03:16.0536 3104 C:\Windows\system32\drivers\mbam.sys - will be deleted on reboot
20:03:16.0536 3104 MBAMProtector ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0563 3104 C:\Windows\system32\DRIVERS\mouclass.sys - copied to quarantine
20:03:16.0650 3104 HKLM\SYSTEM\ControlSet001\services\mouclass - will be deleted on reboot
20:03:16.0657 3104 HKLM\SYSTEM\ControlSet003\services\mouclass - will be deleted on reboot
20:03:16.0658 3104 HKLM\SYSTEM\ControlSet004\services\mouclass - will be deleted on reboot
20:03:16.0660 3104 C:\Windows\system32\DRIVERS\mouclass.sys - will be deleted on reboot
20:03:16.0661 3104 mouclass ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0683 3104 C:\Windows\system32\DRIVERS\mouhid.sys - copied to quarantine
20:03:16.0747 3104 HKLM\SYSTEM\ControlSet001\services\mouhid - will be deleted on reboot
20:03:16.0748 3104 HKLM\SYSTEM\ControlSet003\services\mouhid - will be deleted on reboot
20:03:16.0748 3104 HKLM\SYSTEM\ControlSet004\services\mouhid - will be deleted on reboot
20:03:16.0751 3104 C:\Windows\system32\DRIVERS\mouhid.sys - will be deleted on reboot
20:03:16.0751 3104 mouhid ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0775 3104 C:\Windows\system32\drivers\Msfs.sys - copied to quarantine
20:03:16.0837 3104 HKLM\SYSTEM\ControlSet001\services\Msfs - will be deleted on reboot
20:03:16.0838 3104 HKLM\SYSTEM\ControlSet003\services\Msfs - will be deleted on reboot
20:03:16.0838 3104 HKLM\SYSTEM\ControlSet004\services\Msfs - will be deleted on reboot
20:03:16.0841 3104 C:\Windows\system32\drivers\Msfs.sys - will be deleted on reboot
20:03:16.0841 3104 Msfs ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:16.0881 3104 C:\Windows\system32\drivers
dis.sys - copied to quarantine
20:03:16.0977 3104 HKLM\SYSTEM\ControlSet001\services\NDIS - will be deleted on reboot
20:03:16.0988 3104 HKLM\SYSTEM\ControlSet001\control\safeboot\Network\NDIS - will be deleted on reboot
20:03:16.0988 3104 HKLM\SYSTEM\ControlSet003\services\NDIS - will be deleted on reboot
20:03:16.0998 3104 HKLM\SYSTEM\ControlSet003\control\safeboot\Network\NDIS - will be deleted on reboot
20:03:16.0998 3104 HKLM\SYSTEM\ControlSet004\services\NDIS - will be deleted on reboot
20:03:17.0007 3104 HKLM\SYSTEM\ControlSet004\control\safeboot\Network\NDIS - will be deleted on reboot
20:03:17.0010 3104 C:\Windows\system32\drivers
dis.sys - will be deleted on reboot
20:03:17.0010 3104 NDIS ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0021 3104 C:\Windows\system32\drivers\Npfs.sys - copied to quarantine
20:03:17.0083 3104 HKLM\SYSTEM\ControlSet001\services\Npfs - will be deleted on reboot
20:03:17.0084 3104 HKLM\SYSTEM\ControlSet003\services\Npfs - will be deleted on reboot
20:03:17.0084 3104 HKLM\SYSTEM\ControlSet004\services\Npfs - will be deleted on reboot
20:03:17.0087 3104 C:\Windows\system32\drivers\Npfs.sys - will be deleted on reboot
20:03:17.0087 3104 Npfs ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0110 3104 C:\Windows\system32\drivers\Null.sys - copied to quarantine
20:03:17.0175 3104 HKLM\SYSTEM\ControlSet001\services\Null - will be deleted on reboot
20:03:17.0176 3104 HKLM\SYSTEM\ControlSet003\services\Null - will be deleted on reboot
20:03:17.0176 3104 HKLM\SYSTEM\ControlSet004\services\Null - will be deleted on reboot
20:03:17.0179 3104 C:\Windows\system32\drivers\Null.sys - will be deleted on reboot
20:03:17.0179 3104 Null ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0204 3104 C:\Windows\system32\DRIVERS\oanet.sys - copied to quarantine
20:03:17.0277 3104 HKLM\SYSTEM\ControlSet001\services\OAnet - will be deleted on reboot
20:03:17.0277 3104 HKLM\SYSTEM\ControlSet004\services\OAnet - will be deleted on reboot
20:03:17.0280 3104 C:\Windows\system32\DRIVERS\oanet.sys - will be deleted on reboot
20:03:17.0280 3104 OAnet ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0321 3104 C:\Windows\system32\drivers\PLTGC.sys - copied to quarantine
20:03:17.0405 3104 HKLM\SYSTEM\ControlSet001\services\PlantronicsGC - will be deleted on reboot
20:03:17.0425 3104 HKLM\SYSTEM\ControlSet003\services\PlantronicsGC - will be deleted on reboot
20:03:17.0425 3104 HKLM\SYSTEM\ControlSet004\services\PlantronicsGC - will be deleted on reboot
20:03:17.0428 3104 C:\Windows\system32\drivers\PLTGC.sys - will be deleted on reboot
20:03:17.0428 3104 PlantronicsGC ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0444 3104 C:\Windows\system32\DRIVERS\rdpbus.sys - copied to quarantine
20:03:17.0511 3104 HKLM\SYSTEM\ControlSet001\services\rdpbus - will be deleted on reboot
20:03:17.0511 3104 HKLM\SYSTEM\ControlSet003\services\rdpbus - will be deleted on reboot
20:03:17.0511 3104 HKLM\SYSTEM\ControlSet004\services\rdpbus - will be deleted on reboot
20:03:17.0514 3104 C:\Windows\system32\DRIVERS\rdpbus.sys - will be deleted on reboot
20:03:17.0514 3104 rdpbus ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0530 3104 C:\Windows\system32\DRIVERS\serial.sys - copied to quarantine
20:03:17.0592 3104 HKLM\SYSTEM\ControlSet001\services\Serial - will be deleted on reboot
20:03:17.0592 3104 HKLM\SYSTEM\ControlSet003\services\Serial - will be deleted on reboot
20:03:17.0593 3104 HKLM\SYSTEM\ControlSet004\services\Serial - will be deleted on reboot
20:03:17.0596 3104 C:\Windows\system32\DRIVERS\serial.sys - will be deleted on reboot
20:03:17.0596 3104 Serial ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0629 3104 C:\Windows\system32\DRIVERS\tap0901.sys - copied to quarantine
20:03:17.0733 3104 HKLM\SYSTEM\ControlSet001\services\tap0901 - will be deleted on reboot
20:03:17.0739 3104 HKLM\SYSTEM\ControlSet003\services\tap0901 - will be deleted on reboot
20:03:17.0739 3104 HKLM\SYSTEM\ControlSet004\services\tap0901 - will be deleted on reboot
20:03:17.0743 3104 C:\Windows\system32\DRIVERS\tap0901.sys - will be deleted on reboot
20:03:17.0743 3104 tap0901 ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0784 3104 C:\Windows\system32\Drivers\usbvideo.sys - copied to quarantine
20:03:17.0883 3104 HKLM\SYSTEM\ControlSet001\services\usbvideo - will be deleted on reboot
20:03:17.0890 3104 HKLM\SYSTEM\ControlSet003\services\usbvideo - will be deleted on reboot
20:03:17.0890 3104 HKLM\SYSTEM\ControlSet004\services\usbvideo - will be deleted on reboot
20:03:17.0893 3104 C:\Windows\system32\Drivers\usbvideo.sys - will be deleted on reboot
20:03:17.0893 3104 usbvideo ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:17.0975 3104 C:\Windows\system32\wbem\WMIsvc.dll - copied to quarantine
20:03:18.0125 3104 HKLM\SYSTEM\ControlSet001\services\Winmgmt - will be deleted on reboot
20:03:18.0130 3104 HKLM\SYSTEM\ControlSet001\control\safeboot\Minimal\Winmgmt - will be deleted on reboot
20:03:18.0130 3104 HKLM\SYSTEM\ControlSet001\control\safeboot\Network\Winmgmt - will be deleted on reboot
20:03:18.0140 3104 HKLM\SYSTEM\ControlSet003\services\Winmgmt - will be deleted on reboot
20:03:18.0140 3104 HKLM\SYSTEM\ControlSet003\control\safeboot\Minimal\Winmgmt - will be deleted on reboot
20:03:18.0148 3104 HKLM\SYSTEM\ControlSet003\control\safeboot\Network\Winmgmt - will be deleted on reboot
20:03:18.0148 3104 HKLM\SYSTEM\ControlSet004\services\Winmgmt - will be deleted on reboot
20:03:18.0148 3104 HKLM\SYSTEM\ControlSet004\control\safeboot\Minimal\Winmgmt - will be deleted on reboot
20:03:18.0148 3104 HKLM\SYSTEM\ControlSet004\control\safeboot\Network\Winmgmt - will be deleted on reboot
20:03:18.0149 3104 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - will be cured on reboot
20:03:18.0150 3104 HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - will be cured on reboot
20:03:18.0151 3104 C:\Windows\system32\wbem\WMIsvc.dll - will be deleted on reboot
20:03:18.0151 3104 Winmgmt ( ForgedFile.Multi.Generic ) - User select action: Delete
20:03:28.0032 2660 Deinitialize success
Thanks because I finally installed my SSD.
Results 1-1 of 1
Add Your Review
Submit your reply
E-mail this review
Report offensive content
Previous Versions:







