Posted 16 January 2011 - 09:35 PM
Any and all help will be warmly appreciated. The infected PC is the work tool of a self-employed CAD professional working hourly. Thanks a bunch...
Toshiba Tecra A10 running Windows 7.
McAfee Internet Security (with real-time scanning regrettably turned off), subscription is current
It started as some unexpected and unwanted Internet Explorer redirections. Various destinations, all unsavory. Porn and the like. These were unfortunately ignored for about a day, in the press of urgent current issues. Then it sprang into full bloom. Popped up bogus Windows Security messages. Wanted to run a virus scan (not McAfee) - said no to that. Then it started trying to sell an AV package, the name of which we unfortunately didn't note. At one point, it reported an infection by Banker.Fox, but we haven't been able to find any of the files and registry entries that are listed in web notes on B.F. Powering down and rebooting, it progressed to the following:
Behavior at its worst
When you boot the PC normally, each time that it tries to load one of the many usual processes, a "Windows Security" message pops up and advises that the process is infected, offering to scan, etc. IE won't access the web at all. "Internet Explorer cannot display the webpage". Ctl-Alt-Del won't start Task Manager.
The PC will boot in safe mode. Even though "safe mode with networking" does connect to the wireless router successfully, IE8 still won't access the Internet. Same message. Task Manager will start.
Scans and so forth
A complete scan by McAfee reported the PC as clean, other than deleting a handful of tracking cookies. I ran HiJack This, DDS, and MER. I'm a total amateur at this, but the last entry in HKCU.../Run looks suspicious to me.
The first cut at a fix
I found a suspicious-looking entry in the registry at:
Key is named tvkgjvcn
Search found another instance at:
Same data as above
Renamed that exe with AAA at start of name. Rebooted.
Boot proceeded without bogus security alerts.
Task Manager runs, and doesn’t show any obviously bogus processes.
IE8 won’t access the Internet
“Toshiba Service Station” reports that it has stopped working
It accesses the internet to look for updates
Suspect that nothing can access the internet
Hope that's enough to get started.