Sorry to post in a couple of different threads on this one but I, too, have recently been bitten by this backdoor.
I am running SEP-11. Initially, SEP-11 was reporting via pop-ups that incoming and outgoing activity was flagged/halted. I eventually ended up using the Kaspersky TDSSKiller app to fix the problem. Or so it seems. Lately, newer updates to SEP-11 have quarantined a couple of tmp files as having been associated with backdoor.tidserv as well.
However, I still can occasionally get a BSOD similar to the one shown in the tidserv removal KB that has been referenced in various threads here. I am paranoid enough as it is so I am feeling like there is still a malingering trojan running around. SEP-11 doesn't see anything, Spybot Search and Destroy is clean, TDSSKiller is clean, and Malwarebytes Malaware is clean (thus far).
None of the registry entries referenced in the KB exist, I don't see the files (TDSSServ.sys, etc.) anywhere. I did see a couple of registry entries that I believe may be holdovers from the earlier infection but I have wiped those and am monitoring them.
When running SEP quick scans, I do see "TDSSServ.sys" and "...\FauxVirus\.." scroll through the list of scanned items. My other post is related to this -- are these files on the system? Or are they known files that SEP displays as it looks for them? Seeing them on the scan list is disconcerting after having been hit by them.