I know that I’m new to this but my cousin asked me to help him with his computer because it has become badly infected by a tenacious virus.
System:
-OS is Windows XP Professional Service Pack 3
Possible infection point:
-My cousin downloads music torrent files so I’m led to think that this is how he got infected in the first place. Since I know torrent files are notorious for having some nasty viruses embedded in them.
Symptoms:
- Creates pop-ups that will open the browser to display either will be a window that says “You won a Walmart Gift card, put in you email on the next page to get,” or it will bring up a fake news webpage that reports faulty news.
- It will freeze up the computer completely or it may just really slow the computer down
- It will change the settings on his AV programs to disable them
Observations:
-I’ve taken several steps which Essexboy has instructed me in the past and if needed I will include the logs once they’ve finished
-I’ve use aswMBR, Combofix, and now I’m scanning with Kaspersky.
-I tried using the silentRunner program but it wasn’t running at all, I know that it may seem like it isn’t working but this time I had no prompts at all so I knew it wasn’t running
-While running Kaspersky the first time it found 3 threats and 1 of them was in the memory but then it locked down the computer. What I mean is it let me close Kaspersky but when I tried opening any of the programs I mentioned earlier it said they were invalid files and wouldn’t run them. Also I disconnected the wireless adapter and it still said that it was connected, which is impossible because I took away its access completely to the network with removing the adapter.
-I’m currently running Kaspersky in safe mode on the highest settings because it appears to me that this computer is as some would say a cluster$@#!, you can figure that out I assume. So this has led me to wonder if this virus has some type of self-preservation protocol built into its programming.
Basically I’ve reached the limit of my knowledge with this and I would like to know if I should just tell him to scrap the hard drive and start from scratch. As stated I will include the logs and zip files once they’re complete. I just need to know if there’s any suggestions as to what I should do from this point on.