Use Spyware Doctor to remove it for you.
http://www.pctools.com/mrc
Cheers,
rsivanandan
Main Topics
Browse All TopicsI seem to have a brand new virus that nobody seems to have and there doesn't seem to be anything on Google whatsoever. When I do a scan from various virus and malware scanners, I get the same result. It finds a rootkit.tdss virus called rotscxwickkwrm. But it's in my registry under HKEY_LOCAL_MACHINE\System/
I can't delete it, it keeps coming back. Even in safemode.
It's also in the HKEY LOCAL MACHINE area.
I'm running Windows XP, SP2.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Use Spyware Doctor to remove it for you.
http://www.pctools.com/mrc
Cheers,
rsivanandan
Also, try Malwarebytes' Anti-Malware (http://www.malwarebytes.o
1st of all - make a backup of your data files (documents, photos etc.) BEFORE you completely screw the system.
IMHO, once you got a virus you never can be sure you cleaned it completely. Save you time and nerves - make a clean reinstall. Reset MBR, during Windows installation reformat HDD.
It's up to you to choose to struggle with the rootkit or make a clean install but make a backup before you do anything else.
Hope it helps.
I tried Malwarebytes...That was one of the first ones I tried because I've always thought that was one of the best ones. But it just told me the name of the virus. And yes igor-1965, I know I could just do a clean install, but that would just cause 100 times the aggrevation, and 100 times the time reinstalling every program I have on my computer now. That's why I was asking if anybody knew how to get rid of this thing. Maybe somebody knows of a way that's not too difficult.
Please download ComboFix from here:
http://www.bleepingcompute
Read the instructions carefully before running it. Make sure to disable computer security programs before running it.
ComboFix will delete all the TDSS rootkit files and the leftovers can be removed by using MalwareBytes (as already suggested) or SuperAntiSpyware (www.superantispyware.com)
Please don't forget to send us the ComboFix log.
Hope it helps.
Hey Warturtle...I think that did it bud! I deleted all 3 of the rotscx in my registry, plus whatever made them reappear, and deleted some hidden files in my rootkit. My internet is running a lot faster, so far no windows are closing by themselves, and my computer isn't hanging. Man, thanks hella. I read in your comment that you wanted me to post the Combofix log. Was that only if it didn't fix it, so you can read it and figure it out? Or do you still want me to post it? Let me know. That combofix is a badass program. Thanks again.
Business Accounts
Answer for Membership
by: GoatmetalPosted on 2009-09-09 at 09:33:15ID: 25292961
I hope I gave enough info.