can't logon. xp trojans rootkits
Posted on 2009-12-29
XP Home machine. Cant log on. After Windows starts, the icons for user account display. When any is clicked, the desktop wallpaper for the account disslays, but nothing else: no tasks bar, no desktop icons. Ctrl-Alt-Del causes an hourglass to display for a few seconds but nothing else. SafeMode no different.
MalwareBytes discovered 11 RootKit.MBR items in the HelpAssistant folder, two in Local Settings for a user accont, a Rogue.Installer in the ProgramFiles\InternetSecurity folder, and a Rogue.Installer in the system32 folder. The trojans were mainly multippe occurrences of Generic9.ACDR and Agent2.ADWC. MalwareBytes seems to have neutralized them, but the damage to the registry remains.
While MalwareBytes was running, AVG also was finding things including these in the system32 folder: winupdate86.exe and AVR10.exe
The user reports having reacted to a popup warning of infection and asking for his credit card number, and itt security code on the back, and his ATM number and password. Not sure what he did (but he didn't enter the information), but the machine was frozen as described above afterwards.
By connecting the drive to another machine via USB (its how I ran MalwareBytes) I deleted tens of thousands of files in the Temp and Temporary Internet Files folders. (There was one file I couldn't delete except by connecting the drive to a Linux machine)
Any suggetions for the next step in getting past where it is freezing?