Need help with winh32

Status
Not open for further replies.
I hope someone can help me remove a virus from a computer. its running windows XP.

anti-virus captures winh32.exe as a trojan (among other things). It keeps showing up. the desktop background is being changed to a screen which says "Warning! Spyware threat has been detected on your PC." it goes on to say that unauthorized access was gained by another computer. I cannot bring up the task manager because the option is greyed out (spybot found the reg key which is doing this, but it reappears after being removed) I am also getting pop ups and security warnings in the taskbar. one of the pop-ups is a suspicious looking window with poorly formatted graphics, it has links to some pay-ware anti-spyware stuff.

I have run spybot and adaware, it has avg antivirus. I will post the hijack this and combofix logs below. I would greatly appreciate any help anyone could offer to clear this computer.
 
Hi spark plugs and welcome to techspot. =)

It appears your system is most likely infected with some rogue anti-spyware.
I suggest you do the following before doing anything else

Important: Please read this thread HERE before deciding if you should CLEAN or FORMAT your system

Should you decide to that cleaning your system is the best option, please go to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given.
Do follow all the instructions exactly.

Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

Our experts here will tend to your queries thereafter.

Also, please provide the results of the Antirootkit scan


Regards,
momok =)

This thread is for the use of spark plugs only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
The HijackThis scan needs to be ran after all other cleaning is done. Running it before will show entries that have been removed by other tools.
 
Status
Not open for further replies.
Back