Hello, thank you for helping
I have a serious malware infection on my brother's computer. He downloaded a file, which after running it(I told him to download from a certain source, and he downloaded from other sources, which 90%+ of the time are infected) made the system act weird.
First it only showed an error message like this:
svchost.exe - Application Error
The instruction at 'series of numbers and letters' referenced at memory '0x0000000'. The memory could not be "written"
And then, I could not connect to internet(still cant).
Then I came here to bleepingcomputer.com, and saw posts and threads. And tried to run MalwareBytes, GMER and other applications(via USB), but whenever I tried to open them, or nothing would happen or a black console windows would appear and dissapear(in less than a second) really quickly. But that only happens with applications which I pass through the USB, as I dont have internet, I can't download them or anything. I've tried renaming them (for example to explorer.exe, iexplorer.exe, Google Chrome.exe), changing the extension( for example to explorer.com, explorer.scr- which displayed an error saying that scr wasnt a valid extension recognized by Win32-), running .reg files(supposedly to solve that problem), and nothing has worked.
Ran SFC.exe and it did not ask for my Windows XP disk(which according to http://www.bleepingcomputer.com/forums/topic43051.html
is because everything is ok), also I've tried resetting winsock, via a Winsock XP Fix application, but to no avail.
Also ran Avast!(a free version and with updates) and Spybot S&D(with no updates though, because I cant download them) and they didn't show anything.
I also ran Hijack This! but the files changed its content(somehow, probably the malware) to nonsense(weird characters).
I browsed through the history(of the browser- Firefox -) and downloaded on my pc the downloaded files(sanboxed of course), and ran them through virustotal.com
So, I can't pass non-binary files back or forth the infected computer, nor execute binary files(except the ones already on the system). Cannot connect to internet, it apparently made changes on kernel(my dad says) and/or regedit.
I would appreciate ANY help at all, thank you for your time.
Oh, and here's the link to the virustotal report(as the trojan has many aliases) for information. Thank you:VirusTotal Report