Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.



  • Please log in to reply
1 reply to this topic

#1 afletcherlady


  • Members
  • 3 posts
  • Local time:02:54 PM

Posted 15 April 2010 - 09:15 AM

Hello Im loosing my mind so bare with me. I know a little but not not a lot about computers.

This is my parents computer and I am trying to fix it and stay sane.

When I first got on it was infected with XP Defender.

I ran McAfee and it found a lot of viruses and deleted them.

I ran SUPER Anti- Spyware and it found tons of stuff and deleted it.

I cannot access add/remove tool.

I cannot download most things from the internet AND my explorer re-directs me all the time.

When I try to run/ save things from this site it wont let me.

I did run the GMER thing and here is the report:

GMER - http://www.gmer.net
Rootkit scan 2010-04-15 09:11:49
Windows 5.1.2600 Service Pack 3
Running: 6wl34y73.exe

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys@imagepath \systemroot\system32\drivers\_VOIDounqpvitqg.sys
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys\modules@_VOIDc \\?\globalroot\systemroot\system32\_VOIDhopivhwdlo.dll
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys\modules@_VOIDd \\?\globalroot\systemroot\system32\drivers\_VOIDounqpvitqg.sys
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys\modules@_VOIDsrcr \\?\globalroot\systemroot\system32\_VOIDvjwpjdmbxw.dat
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys\modules@_voidserf \\?\globalroot\systemroot\system32\_VOIDjawvsdilar.dll
Reg HKLM\SYSTEM\ControlSet001\Services\_VOIDd.sys\modules@_voidbbr \\?\globalroot\systemroot\system32\_VOIDhbuhxhhagr.dll
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@NoChange 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@

---- EOF - GMER 1.0.15 ----


BC AdBot (Login to Remove)


#2 boopme


    To Insanity and Beyond

  • Global Moderator
  • 73,566 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:02:54 PM

Posted 20 April 2010 - 09:15 PM

Hello, this is rootkit of the TDDS family. A wipe and reinstall may be the best option.
We can try this first to see if we can get some fubnctionality and then get you to our DDS fourum.

You may need to sopy these from a clean PC to a flash/mobile drive or a CD and then run on this one.
How to remove the TDSS, TDL3, or Alureon rootkit

If that will not work or does, as we need to get you here, see if you can also do this.
Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9 which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
Include the GMER logs you posted earlier.
Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users