BleepingComputer.com: Rootkit.tdss.gen Found by Malware. How to remove?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Rootkit.tdss.gen Found by Malware. How to remove?

#1 User is offline   jlb3skip 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 12-August 10

Posted 16 April 2011 - 04:46 PM

Hi Gang,

Well it happened. I got nailed last night. I knew I was in trouble when I was hitting a site I go to all time that is forums for VBA programming and I got a weird pop-up saying something about a program that can't be run. Sorry I don’t have a screen shot; I was working and sort of ignored it. Well, sure enough my memory resident Trend Micro is intercepting calls to other sites (I have screen shots, but can't figure out how to get them in here). Also, Malware Bytes detected it - here is the language from the scan logs:

Files Infected:
c:\documents and settings\xxxxxx\local settings\temp\temporary internet files\Content.IE5\DVD9PEF1\162zzjs[1] (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.

Unfortunately, it seemed to not really remove it as I am ill experiencing the same issue. I am not sure, but it might be some sort of redirector, but I'm not enough in the know to determine that.

I've run GMER - it doesn’t see anything. SpyBot Search and Destroy, Super Antispyware, MalwareBytes all with updated signatures - also nothing now (after the scan that MalwareBytes thought it got it.

I'm open for anything - can anyone help me work through this? I need this computer back up and running by tomorrow, so anything will help.

I have to pick up a family member, but will be back within an hour - Please, please, I am groveling! :-)

Thanks advance...Skip

#2 User is offline   Budapest 

  • Bleepin' Cynic
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 22,235
  • Joined: 11-November 06
  • Gender:Male

Posted 17 April 2011 - 06:16 PM

Try this:

http://www.bleepingcomputer.com/virus-removal/remove-tdss-tdl3-alureon-rootkit-using-tdsskiller
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users