I have recently been infected with Malware on my system. The computer that was infected is set up on a network in which another computer on the network was infected. I have been able to download Malwarebytes and Superspyware as well as Ccleaner and Spybot on my networked computer and ran the scans. The initial scans on the networked computer weren't able to clean the files fully. However, when I ran the scans in Safemode w/o networking they were able to clean the networked computer fully. Now when I go to the computer where the Malware originated from it won't allow me to download Superantispyware, Spybot, Adaware, or CCleaner. It does allow me to download Malwarebytes but when I click on it to open it nothing happens. I can find Malwarebytes running in my proccesses but nothing is happening. I have downloaded Spybot, Superantispyware and CCleaner to a pen drive and installed them onto the infected computer. It won't allow Spybot to connect to its server to install, and when I click on Superantispyware to open it it says this program is not working. I tried to download Hijackthis and it keeps redirecting me to another website(as it did with Superantispyware and the other anti malware programs). The only way I could download hijackthis is if I copied and pasted the download site into the address bar. However, when I try to install Hijackthis it doesn't do anything.
My Norton Antivirus 2009 can not update its virus definitions either cause it says it can not connect to the server, and when I run a scan with Norton it only scans 3190 objects then says its complete. When I try to run check disk it says that Windows can not perform this task. I repeatedly get random internet pop ups of random internet sites and when I try to type in antispyware websites I get referred to a search engine and if I click on the links I get redirected to random sites sometimes having nothing to do with what I am looking for. The only spyware program I am able to run is Adaware but half way through the scan it says it has a unhandled exception and if I click on it then it locks up Adaware. I can also run CCleaner but that is the only thing I can run. I have cleared the Host file but still get redirected on the internet. When I reboot my system in normal mode the C:/Windows/System32 file opens and then I get an error message that Norton can not connect to the server. If I let it sit at the desktop for a little bit it will open up a web page randomly.
Right now while I am sending this message I am in Safe Mode with Networking. It seems that running the computer in safemode is the only way I can keep it somewhat stable but I can't even run the antispyware in safemode and even Adaware messes up half way through. I still get redirected on the internet while in safemode and I was even lucky to get to this website while in safemode since in normal mode anything that may help gets redirected or doesn't work. This is my tasklist /svc in safemode.
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Administrator>tasklist /svc
Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 800 N/A
csrss.exe 856 N/A
winlogon.exe 880 N/A
services.exe 936 Eventlog
lsass.exe 948 N/A
svchost.exe 1140 DcomLaunch, TermService
svchost.exe 1316 RpcSs
svchost.exe 1468 Browser, CryptSvc, Dhcp, helpsvc,
lanmanserver, lanmanworkstation, Netman,
SharedAccess, srservice, winmgmt, WZCSVC
svchost.exe 1560 Dnscache
svchost.exe 1676 LmHosts
explorer.exe 2004 N/A
ctfmon.exe 832 N/A
iexplore.exe 1440 N/A
mbam-setup.exe 1964 N/A
HJTInstall.exe 272 N/A
HJTInstall.exe 1220 N/A
taskmgr.exe 552 N/A
cmd.exe 192 N/A
tasklist.exe 1432 N/A
wmiprvse.exe 1736 N/A
C:\Documents and Settings\Administrator>
And here is my Tasklist from Safemode:
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Administrator>tasklist /svc
Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 800 N/A
csrss.exe 856 N/A
winlogon.exe 880 N/A
services.exe 936 Eventlog
lsass.exe 948 N/A
svchost.exe 1140 DcomLaunch, TermService
svchost.exe 1316 RpcSs
svchost.exe 1468 Browser, CryptSvc, Dhcp, helpsvc,
lanmanserver, lanmanworkstation, Netman,
SharedAccess, srservice, winmgmt, WZCSVC
svchost.exe 1560 Dnscache
svchost.exe 1676 LmHosts
explorer.exe 2004 N/A
ctfmon.exe 832 N/A
iexplore.exe 1440 N/A
mbam-setup.exe 1964 N/A
HJTInstall.exe 272 N/A
HJTInstall.exe 1220 N/A
taskmgr.exe 552 N/A
cmd.exe 192 N/A
tasklist.exe 1432 N/A
wmiprvse.exe 1736 N/A
C:\Documents and Settings\Administrator>
I am not sure if the tasklists help or anything I did notice however that while running in normal mode on my proccesses that services is the one that is running the most usages the entire time(anywhere from 50% to 65%)
My Norton Antivirus 2009 can not update its virus definitions either cause it says it can not connect to the server, and when I run a scan with Norton it only scans 3190 objects then says its complete. When I try to run check disk it says that Windows can not perform this task. I repeatedly get random internet pop ups of random internet sites and when I try to type in antispyware websites I get referred to a search engine and if I click on the links I get redirected to random sites sometimes having nothing to do with what I am looking for. The only spyware program I am able to run is Adaware but half way through the scan it says it has a unhandled exception and if I click on it then it locks up Adaware. I can also run CCleaner but that is the only thing I can run. I have cleared the Host file but still get redirected on the internet. When I reboot my system in normal mode the C:/Windows/System32 file opens and then I get an error message that Norton can not connect to the server. If I let it sit at the desktop for a little bit it will open up a web page randomly.
Right now while I am sending this message I am in Safe Mode with Networking. It seems that running the computer in safemode is the only way I can keep it somewhat stable but I can't even run the antispyware in safemode and even Adaware messes up half way through. I still get redirected on the internet while in safemode and I was even lucky to get to this website while in safemode since in normal mode anything that may help gets redirected or doesn't work. This is my tasklist /svc in safemode.
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Administrator>tasklist /svc
Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 800 N/A
csrss.exe 856 N/A
winlogon.exe 880 N/A
services.exe 936 Eventlog
lsass.exe 948 N/A
svchost.exe 1140 DcomLaunch, TermService
svchost.exe 1316 RpcSs
svchost.exe 1468 Browser, CryptSvc, Dhcp, helpsvc,
lanmanserver, lanmanworkstation, Netman,
SharedAccess, srservice, winmgmt, WZCSVC
svchost.exe 1560 Dnscache
svchost.exe 1676 LmHosts
explorer.exe 2004 N/A
ctfmon.exe 832 N/A
iexplore.exe 1440 N/A
mbam-setup.exe 1964 N/A
HJTInstall.exe 272 N/A
HJTInstall.exe 1220 N/A
taskmgr.exe 552 N/A
cmd.exe 192 N/A
tasklist.exe 1432 N/A
wmiprvse.exe 1736 N/A
C:\Documents and Settings\Administrator>
And here is my Tasklist from Safemode:
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Administrator>tasklist /svc
Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 800 N/A
csrss.exe 856 N/A
winlogon.exe 880 N/A
services.exe 936 Eventlog
lsass.exe 948 N/A
svchost.exe 1140 DcomLaunch, TermService
svchost.exe 1316 RpcSs
svchost.exe 1468 Browser, CryptSvc, Dhcp, helpsvc,
lanmanserver, lanmanworkstation, Netman,
SharedAccess, srservice, winmgmt, WZCSVC
svchost.exe 1560 Dnscache
svchost.exe 1676 LmHosts
explorer.exe 2004 N/A
ctfmon.exe 832 N/A
iexplore.exe 1440 N/A
mbam-setup.exe 1964 N/A
HJTInstall.exe 272 N/A
HJTInstall.exe 1220 N/A
taskmgr.exe 552 N/A
cmd.exe 192 N/A
tasklist.exe 1432 N/A
wmiprvse.exe 1736 N/A
C:\Documents and Settings\Administrator>
I am not sure if the tasklists help or anything I did notice however that while running in normal mode on my proccesses that services is the one that is running the most usages the entire time(anywhere from 50% to 65%)