Hey. First of all, I guess I should apologise for making another thread on this nasty little piece of malware, given that there's a few already on here. But, none of the info in any of them could help me, and I was loath to hijack one of them with my own complaint, so here I am.
I'm running XP, SP2.
I'm writing from my laptop at the moment, as it's virtually shut down my tower PC.
I picked it up a few days ago, and after a good few hours of struggling with it, I've managed to get rid of the annoying popups, and the actual interface is gone too. However, the rootkit and the nasty little trojans that came with it are still on the PC. The task manager no longer shows any programs running that shouldn't be, initially there was "WindowsPolicePro.exe" and "svchast.exe". Having said that, there are two streams of random numbers in there, along the lines of "0.038538587632.exe". These can be closed down by ending the process tree, but doing that seems to have no effect on the computer. To begin with, these were listed as having been started by me, under my user name, but now they're listed as "SYSTEM". I don't know if that means anything or nothing, but it bothers me.
The computer itself has been slowed down by this to such a degree that it's essentially non-functional. It takes almost 10 minutes to boot up. More irritating, however, is that it's now completely unable to open any exe files, at all. Nothing works, Windows just states that I haven't got the permissions to open the file. This includes regedit and msconfig. I can get into My Documents, and My Computer, but I can't open or view any files. Nor can I open my AV, or any anti-spyware. Unfortunately, this also means that I can't provide any logs for HijackThis, or MalwareBytes, for which I apologise. I don't have a flash drive to get them onto the affected PC, either :(.
I also can't get the damn thing into Safe Mode. I don't know if that's down to the virus or not, but as soon as I get into the mode selection screen, my keyboard stops working, and I have to hit the reset button on the front of the tower.
I think that's all the information I can provide, I know it isn't what's mentioned in the sticky at the top of the forum, but I can't conform to that at the moment :(.
I have one more question: As mentioned above, I have no flash drive, but I do have a USB HD that I use to back stuff up from time to time. In the event that I can't fix this, and have to reformat, would it be possible to connect that up and transfer some files onto it before I restart the machine over? Or would the virus just infect the external HD too? I don't even know if it will let me do that in it's current state, but it's worth a try, I guess.
Thank you for reading my long essay. Any help at all would be much, much appreciated. Thanks again!