I am trying to fix a computer that apparently has the WPP virus. The guy that owns it said it just showed up and he thought he had removed it....translation....he removed a lot of files and now I'm not sure what's left or if the error messages I'm getting are the result of the virus or his "fixing" it. I'll give you the background on it:
The laptop is running Windows XP. When he gave it to me to fix he said it was booting into normal mode but when I booted it the first time I could only get it into Safe Mode. It will run Safe Mode with Networking through an Ethernet. I could not get any kind of anti-malware, anti-spyware, or anti virus to run. He was using SuperAntiSpyware as an antivirus..no other protection. Not only that the SAS hadn't been updated for a month or so. I was able to run Kapersky Rescue disk on a burned CD booting first to the CDROM. I could not get a log to save so I ran it again and wrote down everything it found. Here's the list:
Trojan.Downloader.SWF.Gida.a
Virus.Win32.Parite.b
not-a-virus:Adware.Win32.BHO.gkp
Packed.Win32.Krap.ah
Virus.Win32.Virut.ce
Trojan.Win32.Agent2.clzx
Packed.Win32.Krap.af
Trojan-Downloader.Win32.Klever.at
Trojan.Win32.FraudPack.ztd
Trojan-Downloader.JavaAgent.ab
Packed.Win32.Krap.w
Virus.Win32.Virut.ce
Trojan.Win32.FraudPack.zgr
P2P-Worm.Win32.Vilsel.mcg
Packed.Win32.TDSS.z
Trojan-Downloader.Win32.Klever.ah
Trojan.Win32.Koblu.bdl
Packed.Win32.Koblu.c
Trojan.Win32.Koblu.bkm
Trojan.Win32.Koblu.bdm
Backdoor.Win32.Delf.rmm
Trojan-Spy.Win32.Gologger.20.ab
Backdoor.Win32.Bredolab.azc
Trojan.Win32.Pincav.lym
Trojan-Downloader.Win32.Small.aohr
Packed.Win32.Katusha.g
Trojan.Win32.Pasta.dha
Trojan-Downloader.Win32.Genome.xbc
Trojan-Downloader.Win32.Small.aohr
Virus.Win32.Virut.ce
Trojan-PSW.Win32.Kates.c
I can't get into any .exe files. I have tried and it just sits there. I haven't tried Safe Mode with command prompt, but I'm hoping it'll work since the other Safe Modes are. Can someone help with the next step? I have read other posts about using ComboFix but I have also read on ComboFix's tutorial not to use it unless you have someone who knows how to use it and what to look for. So I came here. Also, the guy doesn't have his CD's and didn't make a recovery CD...big surprise. So wiping the drive isn't an option. I dealt with other viruses but this WPP seems to be a doozy of a rootkit so I know I need guidance with this one. I appreciate the help!