Posted 09 July 2009 - 05:25 PM
Hey, I've got a rather disturbing virus lodged in my system. At first it looked like just another one of those fake Spyware programs but soon after I started taking steps to remove it, I was inundated with multiple infections as well as a desktop hijack that changed my background to some weird message in broken english about how spyware will "break my life". Soon after all of my anti-spyware and virus programs shut down, Explorer crashed and anytime I attempted to access folders on my computer it would crash again. I'm unable to access the control panel, start menu, task manager, command prompt or any web browsers. ComboFix spontaneously deleted itself (though I suspect it was the virus that nailed it). Safe Mode causes a system crash. The only thing I seem to be allowed to do is stare at the fake spyware program while it throws ads at me. Is there anything I can do short of trying to salvage what data I can and starting over?
So far I've been able to log in and operate on the computer's Guest Account without too many issues, but I can't seem to run any anti-spyware programs from it. I've noticed in the task manager several processes have been duplicated which I assume are part of the infected files with process names such as "taskmgr .exe" or "AAWService .exe", they all have a space between the name and the file extension. I've also located a number of files created today in my system32 folder that I can't delete. Are there any other places I should look for cleaning out suspicious files?