#5
Post
by axur-delmeria » Thu Dec 03, 2015 8:36 am
Sounds like a virus or some other malware as well. I've encountered this issue long ago, on client's computers, and it's most definitely a virus.
I've forgotten the procedure I did to remove it (it's been ~10 years), but my current go-to procedure involves rkill, combofix, adwcleaner, and a standalone cleaner like Avira PC Cleaner, in that order. The first three can be downloaded from bleeping-computer.com
An alternative is to use a bootable CD/DVD ISO like Avira Rescue System, though I haven't used this particular software in a long while.
You can also try isolating the malicious program itself by using Autoruns and Process Explorer from Microsoft Technet. Autoruns will list all programs that run on startup. Since Microsoft entries are automatically hidden, suspicious-looking software is easier to spot. Process Explorer is basically Task Manager on steroids, and shows processes/programs that can hide from Task Manager. Once you terminate the suspicious program, you can run a virus scanning program.
I use a write-protected USB flash drive (hard to find these days) to make sure that my software tools are safe from infection, though you can burn them to a CD/DVD to get the same effect.
Important Note: disconnect from the Internet if possible. If your Windows is not at SP3 (Service Pack 3), update immediately.
Daily driver: X220 4291-P79 i5-2520M
In reserve: X61 T7500, X60 T2300
In pieces: X60s CS U1300 [board only], two retired but working X61Ts
RIP: 760XD 9546-U9E