Windows XP TONS of problems/trojans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TomSirvaux, Feb 4, 2012.

  1. TomSirvaux

    TomSirvaux Private E-2

    Okay, so I made the mistake of not writing down specific names before I got here. So, for the past 24 hours, I was experiencing some sort of malware hijacking my Internet (changed my home page and then re-directed me when I did searches). I scanned my computer with IOrbit. It found some viruses and trojans, but then said that there were no forms of malware detected. I then used AVG's rootkit search and removed 1 hidden executable file (I forgot to write it down, and now my logs are not to be found). Next, I restarted. The malware was still there (on Firefox and IE). So, I thought maybe IOrbit was to blame, so I got rid of the toolbar and program. That did nothing, so I cleared my entire Internet search history from Firefox. Then, everything got jacked.

    My computer started reporting errors on System 32. I thought maybe this was the malware trying to scare me, so I missed the names and clicked "cancel." Next, half my destop icons disappeared. Okay, no big deal, I can just restore them, since they're obviously hidden. I couldn't do a system restore to an earlier date--the "administrator" had disabled that function. Okay, so this is messing up the systems restore, I thought. I tried restarting in "debugging mode." No improvement. I tried restarting with the last known good configuration. That didn't do it. I scanned my computer with Avira. 9 trojans showed up, 7 of which were on the system restore. I removed them.

    I switched to "safe mode." I have to be the "administrator," instead of my own name (which was always the administrator). I tried a system restore now, but it won't actually work. Currently in safe mode, I cannot connect to the Internet. My wireless "switch" (this is a laptop) is permanently orange, meaning it is off, no matter how I move the switch. Apparently, "A program on your computer has corrupted your default search provider setting for Internet Explorer."

    I can add (theoretically) or remove programs in my control panel, and I can edit my registry (if necessary). I burned a disk of HijackThis, but I get a message in my installer of, "The system administrator has set policies to prevent this installation."

    I would appreciate any suggestions for how to fix my computer. I need to be able to use it ASAP. I know there's a button in the back to reset it (which is tempting), but I do not have the original CDs--it was a gift from a relative who couldn't use the computer and lost the CDs. I have CDs for a Dell XP desktop (currently non-functional), but I don't know what that would do to an HP laptop. Thanks!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. TomSirvaux

    TomSirvaux Private E-2

    Thanks! It's definitely an improvement...now to finish cleaning it so I can actually connect to the Internet with my laptop.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the requested logs from doing the Read and Run First instructions so we can be sure you are clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds