Looks as if we need to regain a ‘hold’ on that computer!
We can do so with a bootable LiveCD that runs a scan before Windows shows up.
If you have a clean computer to burn an .ISO image to a CD, and >wish to give this a try<, this is what you need to do:
DrWeb Live CD Instructions: (Emergency Rescue CD)
Step 1: Download the ISO and burn to a CD:
Dr.Web LiveCD ISO image needs to download to a computer that is not infected:
Save to the Desktop
Make sure the CD burner program used burns ISO images to a CD!
Proceed with burning the ISO image.
InfraRecorder works well for this task:
Install the InfraRecorder program
Insert a blank disk in your CD burner, and open the program
Click: Actions on the top bar
Then click: Burn Image
Locate the DR Web drweb-livecd-600.iso, double click it, and follow the onscreen prompts.
Step 2: Prepare to boot from LiveCD:
Make sure the infected computer can boot from the CD
When the computer starts, pay close attention to the initial screen for the key used to access the BIOS (Setup).
Some of the keys used to grant access to the BIOS set up menu are: F1, F2, F10 or DEL
If, for example, the key is F2, press the key until the BIOS screen shows up.
Go to the Boot tab, and make the appropriate changes to boot from CD
Save the changes!!
Before exiting the BIOS, insert the LiveCD in the appropriate drive.
Exit the BIOS, and the computer starts.
Step 3: DrWeb LiveCD loads...
To launch the Graphic User Interface version of Dr.Web LiveCD, select Dr.
When you boot Dr.Web LiveCD in default (GUI) mode, Dr.Web Control Center for Linux will be started automatically.
At the Dr.Web Control Center for Linux, select: Scanner
At the main window of the scanner, place a check on the drive(s) to scan.
After selecting the drive(s), press: Start
The process may take a while…
Step 4: Scan Results
Scan results are shown as a table in the bottom of the Scanner main window. There you can find information on infected and suspicious objects found during the scan: their location, their reasons to be included into the current selection and actions performed by the program over these objects.
Below the report field is a row of buttons where you can select the desired action for every object in the list: Cure or Delete. (Delete is NOT recommended!)
The Cure action is not available for archives, containers, and mail files.
When done, exit the program, remove the CD, and start the computer.
Let us know how it goes.