I was getting fake antivirus popups and fake pornsites in the browser. Attempts to engage AVG scans or anything like Malwarebytes, Spybot, Trend Micro online, etc were blocked.
I googled these symptoms and found some similar situations with various solutions. One of them recommended a utility called rskill which would supposedly shut this thing down. I tried that and it did. Most functionality was temporarily restored.
However, I ran into trouble while trying to clean up. The system bluescreens out when trying to boot into safe mode, or when I attempt to run the XP disc (it initiates but after the reading files process it errors out). I ran Malwarebytes which found some things and deleted them, then AVG which did the same. AVG pointed out that the System32\userinit.exe file was infected, but couldn't remove it. I replaced it with a copy from a known good system.
Then I ran Windows Security Essentials, which said it dealt with the infection and asked to reboot. Now the system gets to the logon screen but won't logon.
I read some more and realized that replacing the userinit.exe file was a waste of time as this beast apparently modifies the registry to point elsewhere. I tried to run regedit on the infected box via the network from my box, but that requires a logon password and I cant remember what logon password is, or if I ever set one up at all.
Am I fubared?
are you able to reach the safe mode advanced menu?
reboot and tap F8 repeatedly upon startup until the advanced menu appears
arrow up to "last Known Good Configuration" > select it and see if you can boot normally
If you can't try again and see if you can boot into safe mode:
if you can the please run the following scans:
Please download MBRCheck.exe to your desktop.
Be sure to disable your security programs
Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
A window will open on your desktop
if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
If nothing unusual is found just press Enter
A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
Please post the contents of that file.
NEXT
Please download DDS from either of these links
LINK 1 LINK 2
and save it to your desktop.
Disable any script blocking protection
Double click dds.pif to run the tool.
When done, two DDS.txt's will open.
Save both reports to your desktop.
————————————————— Please include the contents of the following in your next reply:
DDS.txt Attach.txt.
NEXT
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries