Computer Hope

Software => Computer viruses and spyware => Topic started by: xiahoudas on May 06, 2008, 07:18:11 PM

Title: Spyware + some disabled processes
Post by: xiahoudas on May 06, 2008, 07:18:11 PM
My computer is being hit with some REALLY annoying popups and my desktop background was changed to some ad for spyware removal.  I tried to follow the instructions in the before you get started thread and I found  that some of the apps listed are being blocked by the administrator, which is me but I didn't block them.  Task manager is also disabled.

So here's what I've done so far:

1. Nothing suspicious in add/remove programs

2. CCleaner did it's thing

3. Blocked from installing SAS

4.  Was able to install and run  Malwarebyte's   (Log at end of post)

5. Found I have java 6.4 but blocked from updating

6.  was able to run Hijackthis




Could someone please tell me what I need to do to at least get this mess fixed?   Thanks

[recovering space - attachment deleted by admin]
Title: Re: Spyware + some disabled processes
Post by: evilfantasy on May 06, 2008, 07:35:39 PM
Welcome to CH.

Download SDFix.exe (http://downloads.andymanchesta.com/RemovalTools/SDFix.exe) and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following:

Title: Re: Spyware + some disabled processes
Post by: xiahoudas on May 11, 2008, 04:50:17 AM
ok

[recovering space - attachment deleted by admin]
Title: Re: Spyware + some disabled processes
Post by: evilfantasy on May 11, 2008, 11:15:19 AM
Looks good so far. Still some work to do.

Please download Combofix by sUBs from one of the below links.
(Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall.
If needed, see this  Combofix tutorial (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) with screenshots that will detail the downloading and running of combofix more thoroughly. Still be sure to rename combofix as detailed above.

Next post please add:
Combofix log