Got a new virus on 2 different systems. Systems are from 2 completely different people and one of the systems was in New Mexico when infected (they bought it to me) and the other in San Francisco.
The virus disables any programs that check for viruses or do system testing. Hijackthis starts to run once, will show the screen and when you pick any option it immediately shuts down and won't run again getting an error message saying I don't have permission to access the file.
I can run
cacls hijackthis.exe /g administrator:f
And it will get Hijackthis (or any other program) to run once again, but it immediately gets locked out when doing it.
I tried to run Housecall, the moment it started running the scan the window closes.
I have been running UBCD to get into the system and try and clean files and the registry.
The system had a few viruses... now I have to hit CTRL+ALT+DEL and run Explorer manually, half the time, to get it to come up with a desktop. Wierd thing is....sometimes it comes up without doing that.
The registry exefile key was changed to run another program, I corrected it.
The registry userinit key was changed to run another program, I fixed it.
Active Desktop Recovery is up on the screen, and it can't be resolved, even by renaming the HTT file.
Tried using Avast, can get it to install and even do the boot time scan, but once the system comes up it disables the main service.
I have run McAfee from the UBCD using the latest virus definitions (9/9/09) and it still can't find a virus on the system.
I have looked in all the usual places for viruses...some of them are , Windows, windows\system32, the dllcache and drivers folders. Temp in the windows folder and the users. all users Administrative tools, Root of C:, Program Files, Program files/common files, Temporary Internet and even some more. Found many infected files and renamed all of them (Ex change exe to xex and dll to lld, in case the file is needed to boot I can change it back).
I am at a loss when it comes to resolving this, think it is brand new (I have been cleaning viruses almost daily for 6 months) since I have not seen this particular problem until Friday.
The virus disables any programs that check for viruses or do system testing. Hijackthis starts to run once, will show the screen and when you pick any option it immediately shuts down and won't run again getting an error message saying I don't have permission to access the file.
I can run
cacls hijackthis.exe /g administrator:f
And it will get Hijackthis (or any other program) to run once again, but it immediately gets locked out when doing it.
I tried to run Housecall, the moment it started running the scan the window closes.
I have been running UBCD to get into the system and try and clean files and the registry.
The system had a few viruses... now I have to hit CTRL+ALT+DEL and run Explorer manually, half the time, to get it to come up with a desktop. Wierd thing is....sometimes it comes up without doing that.
The registry exefile key was changed to run another program, I corrected it.
The registry userinit key was changed to run another program, I fixed it.
Active Desktop Recovery is up on the screen, and it can't be resolved, even by renaming the HTT file.
Tried using Avast, can get it to install and even do the boot time scan, but once the system comes up it disables the main service.
I have run McAfee from the UBCD using the latest virus definitions (9/9/09) and it still can't find a virus on the system.
I have looked in all the usual places for viruses...some of them are , Windows, windows\system32, the dllcache and drivers folders. Temp in the windows folder and the users. all users Administrative tools, Root of C:, Program Files, Program files/common files, Temporary Internet and even some more. Found many infected files and renamed all of them (Ex change exe to xex and dll to lld, in case the file is needed to boot I can change it back).
I am at a loss when it comes to resolving this, think it is brand new (I have been cleaning viruses almost daily for 6 months) since I have not seen this particular problem until Friday.