I recently cleaned a friend's pc - deleted temp files, apply patches, clean registry, etc. I recommeneded and installaled Trend Micro Worry Free Business Security Services.
Today he called saying he's getting a pop up from trend about blocked IP addresses - his machine was trying to get to some URLs that were numbers (http://xx.yy.zz.com/gibberish ) - a sign that he has the TDSS rootkit. he said he was on some nudey sites.
I am trying to remove tdss - there's a fast app from Kaspersky - tdss killer that has helped me before. even the new version didn't help this time.
Looking on the web, tdss has been out for 2+ years. how do you justify a leading security app not stopping it?
|