Hello, I'm new here and I really need some help. My OS is Vista Home Premium. I don't have an anti-virus, just malware bytes and windows defender.
Yesterday I tried to run an application I downloaded (scanned it with malware bytes first and got nothing) but instead of an error (I didn't let it download fully because I changed my mind and I was going to delete it), a command window opened for a moment and closed. I did it again with the same result. I didn't think much of it so I tried to delete the file but I couldn't since it "was being used by another process". I thought it was just vista being vista so I restarted windows and tried again but I got the same error. I wanted to do a system restore but there were no restore points!
I spent most of my day uploading my most important files while scanning my computer with m.bytes (got nothing) and googling for clues (all those in safe-mode to avoid further mess). I googled the exe's name with "virus" and I found a few Indonesian blogs about hacking with batch files (still nothing I can do). I can find them again if needed.
Today I started my computer in normal mode and it's asking me for my computer's serial key (I actually started typing it but stopped so I dodged that bullet). I can still use my computer (I have it disconnected from the internet, just in case) so I was looking at the task manager while browsing with this laptop the rootkit list. I couldn't do much since this laptop seems to have some issues on it's own but I did find RasMan, the list says it's a keylogging backdoor Trojan.
I also checked for recent modified files and today I found a bunch of useless ones in appdata, in the roaming folder I think. One of the files created had the name "croxx quickbms script".
I haven't tried scanning with windows defender because a few days ago it was a bit wonky with its updates (it has happened to me before and after several days it fixed itself). I wasn't sure it'd do the job plus I was worried I might trigger something more.
Now I have my computer on stand by again because there's nothing I can do (I still can't believe how stupid I was). If someone could help me it'd be great.
Thanks in advance.
EDIT: I forgot to say what the message about the key was saying (sorry for the trouble!). My windows are not English so I can't type word for word:
Activation of Windows
An unauthorized change was made in Windows.
You have to type again the serial number of the Windows Vista Home Premium product for activation.
The sticker with the serial number is located on your computer or in the case of the installation disk in the windows package.
Example of sticker:(picture of a sticker)
Product's serial number:
Connect to verify that your OS is genuine. (this line could be clicked but I didn't)
Edited by Flyingshark, 09 October 2016 - 11:46 AM.