WORM_TDSS.TX
tag:Worm
0
0
In the right panel, locate and delete the entry:
maxhttpredirects = 8888
Again In the right panel, locate and delete the entry:
enablehttp1_1 = 1
Close Registry Editor.
Step 7
Restore this modified registry value
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer"s registry.
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
- From: CurrentLevel=0
To: CurrentLevel=69632
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
To restore the registry value this malware/grayware/spyware modified:
- Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
- In the left panel, double-click the following:
HKEY_USERS>.DEFAULT>Software>Microsoft>Windows>CurrentVersion>Internet Settings>Zones>3
- In the right panel, locate the registry value:
CurrentLevel = 0
- Right-click on the value name and choose Modify. Change the value data of this entry to:
CurrentLevel = 69632
- Again in In the right panel, locate the registry value:
1601 = 0
- Right-click on the value name and choose Modify. Change the value data of this entry to:
1601 = 1
- Close Registry Editor.
Step 8
Restart in normal mode and scan your computer with your Trend Micro product for files detected as WORM_TDSS.TX If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files.
Step 9
Download and apply this security patch Refrain from using these products until the appropriate patches have been installed. Trend Micro advises users to download critical patches upon release by vendors.
Hot Articles