I have recently been asked to help out a couple of my friends to clean up some troubles they are having with their computers. and while I talked the first guy into a system restore and he is happy about that, the other guy I think I will be able to save his machine.
So here is what he's got going on.
First off I was asked to help because he had antivirus 2008 which he paid for
which then lead him to upgrade to av2009 which he hasnt paid for.
the good news is he got the money back for 2008 but there was still the garbage on his computer.
so I happened to already know how to take care of av2009 based on some research deleting the registry entries and files from the computer. That was easy enough.
the bad part is there is alot of other stuff on there.
After killing av2009 and realizing his mccafree was dead I downloaded AVG free for him, which has an error with one file (asking to end task on a non-responsive avgsomthingerother.exe which I can find out the exact name if needed but dont know it off the top of my head) but then pulls up several infections.
here is a list of those files.
micro antivirus (microav.exe)
winlogon.exe(616) (I guess they infected his winlogon file)
explorer.exe(1824) (they got his explorer as well)
c:\program files\pchealth\1.exe 2.exe 3.exe 4.exe and 2 different copies of 5.exe
system.exe (on the root of the c drive)
and when shutting down windows it hangs on pwbkring.exe (but that might be legit)
so I started trying to tackle micro antivirus the same way that I did av2009 (or at least the part that I could guess) by going through the registry searching for micro antivirus and microav and deleting all keys and then deleting all files the same way...
the problem with that is one of the registry keys was hung up and wouldnt let me delete, as well as one of the exe's windows says that I cant delete them.
I tried booting into command prompt safe mode but it crashes when loading video drivers.
so I guess my main question is...
is there something bootable that I could run on this guys computer that would at least make it so that I can get in there and take care of this stuff with avg? I see that stinger by mcafee can do that kind of thing but I dont see microav on the list of stuff that it takes care of.
also, would disabling system restore help to make it possible to take care of these infections better?
anyway... sorry for this initial post being long, I just want to be thourogh and explain everything up front.