Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Rootkit.tdss.gen Found by Malware. How to remove?

  • Please log in to reply
1 reply to this topic

#1 jlb3skip


  • Members
  • 1 posts
  • Local time:11:39 PM

Posted 16 April 2011 - 04:46 PM

Hi Gang,

Well it happened. I got nailed last night. I knew I was in trouble when I was hitting a site I go to all time that is forums for VBA programming and I got a weird pop-up saying something about a program that can't be run. Sorry I donít have a screen shot; I was working and sort of ignored it. Well, sure enough my memory resident Trend Micro is intercepting calls to other sites (I have screen shots, but can't figure out how to get them in here). Also, Malware Bytes detected it - here is the language from the scan logs:

Files Infected:
c:\documents and settings\xxxxxx\local settings\temp\temporary internet files\Content.IE5\DVD9PEF1\162zzjs[1] (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.

Unfortunately, it seemed to not really remove it as I am ill experiencing the same issue. I am not sure, but it might be some sort of redirector, but I'm not enough in the know to determine that.

I've run GMER - it doesnít see anything. SpyBot Search and Destroy, Super Antispyware, MalwareBytes all with updated signatures - also nothing now (after the scan that MalwareBytes thought it got it.

I'm open for anything - can anyone help me work through this? I need this computer back up and running by tomorrow, so anything will help.

I have to pick up a family member, but will be back within an hour - Please, please, I am groveling! :-)

Thanks advance...Skip

BC AdBot (Login to Remove)


#2 Budapest


    Bleepin' Cynic

  • Moderator
  • 23,579 posts
  • Gender:Male
  • Local time:01:39 PM

Posted 17 April 2011 - 06:16 PM

Try this:

The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users