Posted 21 October 2009 - 12:47 AM
Hello, thanks for reading my post. Heres my situation:
Windows xp MCE sp2
About 6 hours ago, I was surfing the net with firefox, when I was redirected to another page and IE opened. As soon as that happened, I killed both firefox and IE with task manager, but it was too late I think.
First and foremost I had a bubble pop up from the start bar, which looked like a legit windows warning, - it was about antivirus software, saying I needed to upgrade and to click it. However, I noticed the word prevent was misspelled in the text, so I checked out my processes. I noticed a few processes I didn't recognize, one in particular "a.exe". So, I disconnected my hardline to the internet, then I manually tried to kill these processes but they kept rebooting themselves. I ran HJT, and it was immediately terminated. I watched the process menu and noticed a process or two popped up and went away as soon as HJT was killed. The same thing happened for SmitFraudFix, and I was unable to run either program after they were killed the first time. After getting back online, I found a program from microsoft that scanned for click fraud virus type problems, but it was killed too. Well, then I located some of the corresponding registry keys for these processes and deleted them, but it made little difference other than fixing the bubble that was popping up.
And about firefox - it was slow, and I noticed that searching through google showed "Transferring data from wewewesearch.com" for a split second in the status bar. After reinstalling firefox, it was no different.
I spent the next 3 hours researching my symptoms (I had read about a case similar to mine, and dl'ed ComboFix during that time), and then things got worse.
randomly, I fired up firefox and:
Instead of loading my homepage, firefox either showed my computer or had a mock-up website of it, and it had several pop-ups - I managed to scribble one thing down from it "HTTP://spyware-remover-free.org"
Something then tried to access something from microsoft word, which caused microsoft's installer to launch and prompt me because I don't have it installed. This was not caused by me.
The last thing that happened - my default fontsize changed (my clock and desktop fonts were like twice the size, google too), so when I saw that, I killed firefox, IE (which had opened again), msi.exe, everything else I could, and even explorer.exe
That all happened within about twenty seconds, and at that point I ran ComboFix and figured if ComboFix didn't work I'd reformat.
another three hours of researching later, I happened across these forums and decided to ask for advice. Things are better so far, - they seem normal - but I thought it would be wise to ask you guys. I've got my log from ComboFix if you guys want to see it.
I really appreciate it,