Posted 03 August 2011 - 12:08 PM
About a week ago, while searching for a trial version of a .dwg to .pdf converter to run on my HP Pavilion zd8000, running Windows XP Media Edition, Service pack 2, I apparently downloaded this virus. Immediately started getting the bogus search results associated with this infection and all sorts of popups about how my antivirus was disabled and etc, etc...
I tried to run Malwarebytes...no go.
I tried to restore to an earlier date...no go.
I started searching for options, switching between Chrome, IE and Firefox to find real search results. Found this forum, down loaded tdsskiller and ran it. It identified the above mentioned virus and the fact that it was counterfeiting an AFD.sys file and an mrxsmb.sys file. TDSSKilller could only "cure" the mrxsmb issue, the other returned "processing error" results. I tried running MBAM, it wouldn't let me. I tried renaming the exe file, it told me I didn't have those permissions. I turned it off and let it sit for the weekend while I worked.
I have a friend who is a long time systems admin for mid size corporation. Went to his house last night, with the notion of possibly using his clean boot disk as a way around. No go. He spent some time searching this forum and we tried several things in a effort to get this thing off my computer. The newest wrinkle is that the computer hangs while "Acquiring Network Address" and I can't get online with it. In fact, I'm writing this on my girlfriend's Mac (and don't think I'm not getting crap about THAT!)
So, that's the problem. What I need to know is whether or not I can recover from this point. I can access this forum through the Mac I'm using now and can access the software you will want me to download, what I don't know is if I can download that software to a flash drive and then use it on my PC, or will the Mac want to convert everything to it's file system before it loads it on the flash drive, rendering it unusable on my computer.
Thank you for taking a look, I look forward to hearing from someone.