Well my daughter finally complained to me about her laptop. It is definitely infected with a number of viruses, trojans, and "what nots".
System:
HP Laptop computer.
Windows XP SP2
Description of what we are facing:
What we have tried so far (and the results :sad: )
I do have a number of other computers that do not seem to be affected at this time. I also have the ability to remove her harddrive and connect it to other systems as an "External Drive" (I did this once to make a backup when I needed to send the system in for repairs when the graphics system died on the laptop.)
I'll try almost anything at this point, and was wondering if it would make sense to attache the hard drive to another system, run Spybot S&D on it then put it back into the laptop. I know the registry won't be cleaned, but I suspect the problem files would be gone. I could then run Spybot S&D on the system which would clean up the registry (I think).
Is there a less drastic way to get rid of the things that are preventing me from running Spybot S&D?
(Of course to add insult to injury, my daughter has a term paper due on Nov 3, and if we can't fix the lap top soon, she'll have to retype the whole thing [yea right, mom and dad will end up retyping it! Not something I'm looking forward to.]
Any help would be really appreciated.
Dave
System:
HP Laptop computer.
Windows XP SP2
Description of what we are facing:
- Background is changed to a blue screen with a message about the virus application is out of date and a big link in the middle of the screen leading off to a site (no one has clicked it).
- A pop up shows up every so often claiming to be from "Microsoft Security Center", it is red (again with links leading off).
- A Yellow Triangle with an exclamation mark in the middle shows up every soften in the System Tray with a balloon about virus protection being out of date.
- A Red ball icon has appeared in the system tray, again with a balloon that pops up every so often telling us that the virus checker is out of date and we need to install an update (again from a site that we know nothing about).
- The Task Manager has been disabled.
- Using IE or Firefox is impossible. New tabs are opened automatically, sometimes IE starts on its own and attempts to load up to 20 or so tabs at once.
- Running in Safe Mode causes system to reboot. (We can get to the login screen and Windows starts up, but about 2-3 seconds after we get the normal background, the system turns itself off.)
What we have tried so far (and the results :sad: )
- Installed Spybot S&D 1.6.0.30
- Installed updates manually using "spybotsd_includes-2008-10-01.exe" (Attempting to download updates using the internet connection results in "unable to obtain update file" messages.
- Attempted to run Spybot S&D
Results: Spybot S&D will not load or run - Installed and ran CWS.SmartKiller from "http://www.safer-networking.org/files/"
Results: Message Box indicates "CS ...v1/v2" is not installed. - Downloaded and installed HIJackThis.
Results: Program will not run. - Was able to load MSConfig and supposedly starting programs and services and unchecked as many as I felt I could that would not cause problems.
Results: No real change - Was able to install and run System Explorer by Mister Group 20008, version 1.4. I can see some of the processes, but do not necessarily know what to look for at this point.
I do have a number of other computers that do not seem to be affected at this time. I also have the ability to remove her harddrive and connect it to other systems as an "External Drive" (I did this once to make a backup when I needed to send the system in for repairs when the graphics system died on the laptop.)
I'll try almost anything at this point, and was wondering if it would make sense to attache the hard drive to another system, run Spybot S&D on it then put it back into the laptop. I know the registry won't be cleaned, but I suspect the problem files would be gone. I could then run Spybot S&D on the system which would clean up the registry (I think).
Is there a less drastic way to get rid of the things that are preventing me from running Spybot S&D?
(Of course to add insult to injury, my daughter has a term paper due on Nov 3, and if we can't fix the lap top soon, she'll have to retype the whole thing [yea right, mom and dad will end up retyping it! Not something I'm looking forward to.]
Any help would be really appreciated.
Dave