Help removing difficult Malware/spyware

By masterplan
Nov 1, 2007
  1. Hi there. I was hoping I wouldnt have to resort to a post, but this is driving me crazy now. I believe that I have contracted some type(s) of spyware or malware and despite trying to follow various different procedures for removal on this site and on others, I am not further along. Hopefully with the right information someone migth be able to help, which would be highly appreicated. I would reformat but due to essay deadlines at university I cannot.

    1.) Desktop wallpaper changed to a black and red message saying
    "warning! spyware threat has been detected on your PC. Your computer has several fatal errors due to spyware activity. Your ip address is <insert> and via this address an unauthorized access was gained by another computer. It is strongly recommended to install an antispyware software to close all security vunerabilities"
    2.) Periodic tooltip messages hosting various warnings and basically telling me to use a type of (blatantly illiegitamate) spyware cleaner. These appear in safe mode also.
    3.) Occasional IE7 pop-ups with either the root being on my harddrive advertising a spyware product, or just normal pop-up ads (which I never had beforehand)
    4.) Task manager is disabled. Message "task manager has been disabeld by your administrator". I am the only user. Have tried editing registry and other files to restore this but it defaults back to '1' and thus does not work.

    Programs I have tried (in safe mode also):
    spybot S&D
    Hitman pro
    few other files off major geeks

    from own research it sounds more like smitfraud than most things but i still cannot get rid.

    hjt file attached. hope you guys can help <3
  2. Rik

    Rik Banned Posts: 3,814

    Hi masterplan and welcome to TechSpot.:wave:

    You need to have a read of this - If your system is infected. Read this before deciding whether to CLEAN or REFORMAT.

    Then if you should wish to proceed with cleaning your system you need to go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT, Combofix , and AVG Antispyware logs as ATTACHMENTS into this thread, only after doing the above.
    We also need to know the result of Panda Antirootkit.

    This thread is for the use of masterplan only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. masterplan

    masterplan TS Rookie Topic Starter

    thanks for the quick reply. I will get to work on those steps.
