Hello there everyone, I need your immediate help. My relative's laptop just got infected by a rootkit in my opinion. He told me he was on a website and then the page just changed by itself and it took him to another page. Now here are the symptoms that I saw and what I did :
1. ) There was a balloon popup in the notification area of the system tray of the infamous XP Security tool coming up many times saying the computer was infected. | What I did --> I tried to open firefox to get windows defender as my relative didn't have it installed.
2. ) The "item" was preventing the OS from opening a browser. At first i kept trying to open it and when I tried to open IE 7 it would close it. And when I managed to open firefox after persistence, the "xp security tool" closed firefox and posted a dialog box saying that firefox was infected. | What I did --> I opened Task manager and closed the process which was running this "xp security tool".
After this the messages stopped popping up and then I could now open firefox and promptly downloaded Windows Defender. I downloaded it and scanned the computer but oddly enough, nothing was detected. Now after this "that xp security tool" has been preventing the computer from connecting to the wireless network we use. Every time now I even try to open the application which is a Dell Wireless tool, i get a notice saying the file rundll32.exe cannot be found. Now things get interesting after this.
That certain infection seems to have adapted to block connection. As i found it strange that no file was deleted by my relative and I cannot even connect to the internet. So I tried lookign around just seeing if I can spot some other symptoms. And very interestingly there are other symptoms as and here they are :
1. ) Everytime I try to open firefox or IE i get a dialog box asking me to select which application I would like to use to open firefox, so I choose firefoxon the list and then I get asked if I would like to save the application which was downloaded from "C:/windows..../firefox.exe . So i answer yes and I can open firefoxbut just to open any browser every time I have to do this.
2. ) I went to the Control panel to see if i can find what starnge software was installed in the list but I am not allowed to choose the "Install and Uninstall program" choice in the control panel. I get a message saying windows cannot locate the file rundll32.exe . So I have no access to that part of the system.
3. ) Windows defender cannot download the latest updates. When I open windows defender, I get a message at the top of windows defender in yellow saying Windows defender could not download updates and then I get this memory like address problem : 0x0000.... (I don'tknow it exactly). I have tried to google for info but oddly enough not anyone else has suffered these same symptoms.
So I need your help with that !! Please help !! I considered formatting the whole computer but I wanted that to be the last option as there are alot of files on there that may be of importance, maybe I am not sure. But this is it and so I ask you for help.
Oh and also, the system info is this :
- Windows Media center edition 2005
- 512 MB RAM
- Dell Inspiron
Thank you for reading this,
Jackson Konyango.