Very Bad Virus - need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by kstucchi, Jan 7, 2009.

  1. kstucchi

    kstucchi Private E-2

    I need help! Please! I'm helping a friend fix her son's computer and it's in bad shape. I cannot reinstall XP because she was given this computer by her sister, who got it from her job and they do not have the CDs (Win XP Pro).

    I cannot post a hijackthis log because I cannot get onto the Internet with it. I can't print. I do not want to put this computer on my network for fear that it will infect my other computers.

    So here are the symptoms:

    - c:\ drive appears as RAW drive and cannot do chkdsk (although after booting using diagnostic disk, hard drive passed)
    - cannot do ctrl/alt/delete
    - cannot install programs
    - cannot remove programs from add/remove programs
    - very slow and freezes up after a few minutes, even in safemode
    - cannot run ANY cleaning tools: malwarebytes, combofix, etc. I get a splash screen and then nothing
    - I was able to run MGTools at one point (in safemode), but now I cannot run anything. MGTools gave error message about registry being disabled by administrator but did proceed
    - I can boot in safemode with dos and that stays up for a little while before freezing

    There are several suspicious programs, all created on the same day 12/14/2008:

    c:\xohlv.exe
    c:\wjcp.exe
    c:\uugrv.exe
    c:\log.udt
    c:\-2000389155
    c:\aasejx.exe

    Is this a Rootkit Virus?

    Help.

    Thank you.
     
  2. kstucchi

    kstucchi Private E-2

    Thanks but I figured it out. It's got TDSS, among other viruses. I deleted the incriminating files from c:\windows\system32 after booting up with the UBCD. Once I did that I could run SDFix, which removed most of it and allowed me to actually run programs again.

    So the rest I can do myself. Thanks anyway.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry we could not get to you in time since we are exceptionally busy. But we are happy to hear you fixed your problem.


    If you had read & run our sticky procedures, they would have cleaned this up for you without een needing the UBCD. Example sticky:

    TDSSserv Non-Plug & Play Driver Disable

    And in almost every thread where someone asks for help, the below is posted which easily fixes TDSSserv problems and much much more.

     
  4. kstucchi

    kstucchi Private E-2


    Thank you. I don't know how I missed it, but I did not see the TDSSServe fix link when I was fixing the problem. Oh well. It's fixed now.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Glad to to hear it's fixed now. If you need any further help just post the requested logs from the READ ME.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds