Bad Malware program--Windows Services

beeson76

Distinguished
Dec 4, 2006
29
0
18,530
I got hit with a bad malware program called Contraviro. I have removed everything from the Registry and hard drive associated with it. I have unregistered the dll's and removed them. I have run Malwarebytes (which is an awesome program by the way) and run two different antivirus programs. I have taken the hard drive out and scanned it on another computer for both viruses and malware...so I am pretty sure that the hard drive is "clean" from the malware. But I think there is some other program (virus) that is controlling my computer which nothing finds. It has disabled all my services and I cannot get Windows Defender to work to see what programs are loading. It has taken all my main exe (such as AVG, Spybot, Adaware) and removed them. The only reason I got to scan from Avast and Malwarebytes is from a freak time it started right, and I was able to do some scans. Also I was able to do a scan from Avast because I installed it and it worked--after having a little bit of problems loading the services for it. But I really need to find out what programs are loading. I can go to Task Manager and access everything from there such as msconfig, regedit, and cmd. So I have some small idea from MSCONFIG what programs are starting but I don't think its telling me everything. It hangs for a long time at the login menu, so I think that the problem "starts" there. Any help?

Just to fill you in on some details. From MSCONFIG I am seeing that programs named "u" and "a" are loading which I think are viruses. I have disabled them but I cannot find them in the directories listed. And when I get to my desktop, the start menu and taskbar are completely gone. I can see the little blue bar and the cursor turns to a double sided arrow when I go down there, but I cannot maximize it or anything.
 

pat mcgroin

Distinguished
Nov 21, 2007
1,687
0
19,960
Try to get the program hijack this and run a scan with it.
The log isnt easy to read but it will tell what is loaded and from where.

Also when looking for those files make sure the show system and hidden files is enabled.