Hello,
I've been at this all day and I'm still baffled as to whats even wrong in the first place. I THINK I have the System Security 2009 malware but that I'm not quite sure of. I believe I got this malware a couple days ago when my Spyware Doctor expired. I got it reinstalled and was happy to see that they had upgraded me to Spyware Doctor and Antivirus. I quickly ran a Smart Update and an IntelliScan, and as it should it found several malwares including some files that included Trojan.FakeAV, Rootkit.TDSS, and RogueAntiSpyware.AntiVirusN1 to name a few. I also had a pop up alert that said that my computer was infected which was exactly the same as a screenshot of a System Security pop up, so with all of the above I'm fairly certain it is.
Now for the symptoms -
* Spyware Doctor is no longer able to use Smart Update, claiming there is no internet connection
* I can't use IE, it pops up for a second but then disappears
* I can't install new malware programs such as MalwareBytes using a flash drive
- I also tried renaming the setup file of MalwareBytes so it couldn't be recognized however upon starting MalwareBytes the message "Failed to load control 'vbalGrid' from vbalsgrid6.ocx. Your version of vbalsgrid6.ocx may be outdated. Make sure you are using the version of the control that was provided with your aplication"
* I've also tried using Hit Man Pro since its an external malware detector, but that also timed out on the internet connection
* I can access Run, Task Manager, use the task bar and Start Menu, however I can't use Search
* Microsoft Security Center is also disabled
* System Restore is disabled
* I still have all my icons on the desktop but my list of programs in Start > All Programs has greatly diminished
Things I've tried -
* I've done full system scans with Spyware Doctor, it found files mentioned above and more(quarantined or deleted them) but I'm still having problems. Also I can't install new malware programs
* I've scoured through lists of known registries pertaining to System Security and haven't found any matches
* There was only one process that I found using MSCONFIG called mradll.exe located under ...\ApplicationData\gwr\mradll.exe. This is the only process I found (which was just under startup) even when I accessed Task Manager IMMEDIATELY upon windows opening. There isn't any other suspicious processes running.
- I did not try to delete the ...\ApplicationData\gwr folder, but instead renamed it hoping it would fool itself and give me a chance to access IE so I could install and run other malware programs. However that did not work and furthermore the folder has disappeared (since I removed it from the start up processes) even after unhiding all folders (which I had to do when I first located the gwr folder)
* I've tried booting in safe mode and the networking safe mode and running full scans with Spy Doctor, nothing more has been detected.
* I can't install new programs in safe mode
I'm sure I'm forgetting a couple things I should have mentioned or things I've tried. I've been at this for a good 12 hours scouring the internet (on a mac on the network, ha) with no progress. Any suggestions would be great.
Thanks!
Configuration: Windows XP Home Edition