I am a school tech and a teacher asked me if I would look at his home computer and try to fix it. He said he has a lot of popups and a virus. He also said that his personal photo desktop background would only appear for a second, then the background would change to the default blue. He said he tried System Restore but there weren't any restore points, and he said he couldn't get Nortons to work.
I had hoped a simple Spybot cleanup would do the trick, but this thing is a total mess! I couldn't get anything done under the user's login because of constant failed attempts to automatically connect to the Internet (through automatic AOL (ugh!) settings) and continuous "Your Computer is Infected with a Virus!" warnings. The teacher admitted to clicking on that and downloading the fake anti-spyware programs because he said he thought the message was a legit one from Windows. I also found Limeware installed, but I haven't uninstalled it...yet.
I used Safe Mode with Networking to download and run Spybot S&D. It found and fixed a boatload of stuff, but could not clean out the above malware. Unfortunately, since running Spybot S&D, the user's desktop will no longer load in normal startup. His personal photo background is all that loads, and the error "svchost32.exe has encountered a problem and needs to close." I am able to use Task Manager to browse and connect to the Internet via IE. I used this to download HijackThis in anticipation of needing it for analysis.
I tried reinstalling Norton's from the cd he gave me, but I get the message that there is already an installation. I tried uninstalling it to reinstall, but nothing happens. I used the Windows Cleanup utility, but that didn't help.
I also ran "sfc /scannow" which I saw on another forum, but that didn't help load the desktop or allow a successful Norton's install.
His computer is running Windows XP Home. I am typing this on my own laptop, because his computer is virtually useless. I don't know what I'm going to charge this teacher, but he's going to pay!
I am at a standstill. Can this be cleaned up?