My daughter has come to me to help a friend with a laptop that has some nasty virus or rootkit on it. She was first alerted when the machine would not start up at all so she took the laptop to a local PC shop who said it was badly infected and by the way, it was not running a genuine copy of Windows (Ultimate). She had purchased the laptop in Thailand so that isn't a surprise.
Well they got the machine to boot up but told her she needed to purchase a copy of Windows. She did so purchasing Home Premium and this is where I was asked to help - how to install it?
Well it's easy enough to install if you want to do a clean installation but you lose all programs (I think Windows stuffs them into windows.old) so you really have to re-install everything. I thought I might circumvent that by editing the registry to change the version of Windows that it was running and then an upgrade and this is where I encountered problems.
Everytime I run regedit, msconfig or task manager, a genuine looking antivirus program pops up saying allow or deny this program to run. This is clearly a virus that has trapped those programs. I have tried firing up in safe mode but that AV software still runs. I tried booting from a Windows 7 disk, going to the command prompt and running a standalone virus checker (McAfee Stinger) but it finds nothing. I suspect there might be a root kit installed also.
Short of blowing away the current Windows installation, is there anything else I could do? I was thinking of a regedit replacement which might let me look at the startup programs to kill the fake AV program.
Any advice appreciated. I am not really a desktop support specialist!