Home Malware Programs Trojans Tidserv Activity 2

Tidserv Activity 2

Posted: July 28, 2011

Tidserv Activity 2 is a warning that's displayed by security software that attempts to block certain types of malicious Trojan behavior without being able to detect or delete the responsible Trojan. Although security software that creates Tidserv Activity 2 warnings may be able to prevent a Trojan from sending or receiving information over a network, the Trojan will still be on your computer and should be removed with an appropriate security program. Check to make sure that all your anti-virus scanners and other PC security products are up-to-date and run a full scan in Safe Mode; until you delete the responsible Tidserv Trojan, you'll be unable to stop Tidserv Activity 2 errors from appearing.

Tidserv Activity 2 - A Security Threat Halted but Still Not Down for the Co

Tidserv Activity 2 is similar to a heuristic or behavior-based threat detection in that Tidserv Activity 2 relies on detecting malicious behavior instead of directly finding the responsible Trojan. Tidserv Activity 2 is used in cases where a variant of a Backdoor.Tidserv Trojan tries to utilize network resources to receive instructions, update itself or send information to remote criminals.

Like all backdoor Trojans, the foremost purpose of a Tidserv infection is to attack your computer's security and create vulnerabilities that our SpywareRemove.com malware researchers have found to be extremely dangerous. This can be exploited to cause a wide range of harm, including:

  • Having other malicious programs installed on your PC. This may include browser hijackers that alter your web browser's behavior, spyware that records keyboard input to steal passwords or rogue security programs that try to steal your credit card information.
  • Having your system settings altered to disable network and anti-virus security, including Windows programs like Task Manager and automatic update features.
  • Suffering from your computer being controlled by remote criminals. Remote-controlled attacks often steal personal information and may exploit your PC resources to force your computer to commit DDoS crimes.

The appearance of a Tidserv Activity 2 warning indicates that your anti-virus software has caught this behavior and stopped it from happening, but this doesn't indicate that all possible Trojan behavior has been halted. Additionally, this Trojan will still remain on your computer and use up system resources until you find a security product that can detect and delete the Tidserv Activity 2 Trojan.

Why the Failure of Standard Anti-Virus Software Doesn't Mean Giving Up to Tidserv Activity 2

One common reason for anti-virus programs fail to detect the Trojan behind a Tidserv Activity 2 problem lies in a lack of frequent threat definition updates. You should keep your anti-virus and security software updated for new threats on a daily basis, to prevent a new variant of Backdoor.Tidserv, such as Backdoor.Tidserv.J, from attacking your PC.

Another probable cause for Tidserv remaining undetected is the usage of improper system scans. Whenever possible, scan your entire computer for the source of Tidserv Activity 2 problems, since our SpywareRemove.com malware experts have found that many Trojans will infect the Registry, Windows System Restore and other obtuse and well-hidden components of Windows.

Finally, use Safe Mode to scan for Tidserv Activity 2 Trojans, since many Trojans will remain active and avoid being caught if you boot your PC in a normal mode. Safe Mode will bypass most corrupted Registry startup entries and prevent a Tidserv backdoor Trojan from hiding before you can delete your Tidserv Activity 2 problems for good.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Desktop\Tidserv Activity 2.lnk File name: %UserProfile%\Desktop\Tidserv Activity 2.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Start Menu\Programs\Tidserv Activity 2\ File name: %UserProfile%\Start Menu\Programs\Tidserv Activity 2\
%UserProfile%\Start Menu\Programs\Tidserv Activity 2\Uninstall Tidserv Activity 2.lnk File name: %UserProfile%\Start Menu\Programs\Tidserv Activity 2\Uninstall Tidserv Activity 2.lnk
File type: Shortcut
Mime Type: unknown/lnk
%UserProfile%\Start Menu\Programs\Tidserv Activity 2\Tidserv Activity 2.lnk File name: %UserProfile%\Start Menu\Programs\Tidserv Activity 2\Tidserv Activity 2.lnk
File type: Shortcut
Mime Type: unknown/lnk

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s's:/ogn:/uyu:/dyd:/c'u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/'wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v'w:/rbs:'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = 0'
Loading...