This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Infected and can't get it off!

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just can't seem to figure this one out, and I consider myself pretty computer savvy. I checked my email and saw that my little brother sent me a suspicious email with a single link. I asked him about it, and he swears on his life he didn't send it. Well I thought his email was simply hacked, so I told him to change the password.
Now, his Windows XP computer has been infected. The viruses I've gotten the pleasure of running into are named:
- Worm.Win32.netsky
- TrojanDownloader: Win32/Fakeinit
- Trojan Spm/lx

I don't know if they're directly related or not, I just know that whatever I do, they won't rid themselves from the computer.
Here are the problems:
- Task Manager is unaccessible. Start > Run > taskmgr does not work, a pop up appears that reads "Application cannot be executed. The file is infected. Please activate your antivirus software".
- Registry Editing is also unaccessible. Start > Run > regedit gives off the same pop up as trying to run taskmgr.
- Wallpaper is changed so that it reads "YOUR SYSTEM IS INFECTED! System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommeded to use spyware removal tool to prevent data loss. Do not use th computer before all spyware removed." Yeah, it's spelled wrong.
- On the task bar, a pop up appears from the system tray that states I have spyware that needs to be removed (I know it is the virus's pop up because the icon is not from Windows)
- A lot of programs cannot be opened/accessed because of the same pop up box that appears just like the one when I'm trying to open taskmgr.
- In Firefox (I haven't tested in IE), when opening a link in a new tab, or when I do a Google search from the search bar installed in Firefox, the page immediately redirects to a malicious site or a phishing/spam page.
- Upon startup, a box pops up saying I have worm.win32.netsky:

Spyware Alert!
Security Warning!
Worm.win32.Netsky detected on your machine.
The virus is destributed via the internet through e-mail and Active-x objects.
the worm has its own SMTP engine which means it gathers e-mails from your local compter and re-distributes itself.
In worst cases this worm can allow attachers to access your computer, stealing passwords and personal data.
Viruses can damage your confidential data and work on your computer.
Continue working in unprotected mode is very dangerous.

Type: Virus
System affected: Windows, 2000, NT, ME, XP, VISTA, 7
Security risk(0-5): 5
Recomendations: It is necessary to perform a full system scan.




- Once in a while, I'll get a pop up that reads "Attention! System detected a potential hazard (TrojanSPM/LX) on your computer that may infect executable files. You private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need update your current security software. Click OK to download official intrusion detection system (IDS software)"

I've tried:
- Doing a full system scan with Mcafee, my main AntiVirus program (found nothing)
- Full system scan with Windows Malicious Software Removal Tool (got nada)
- Running ComboFix (it found and deleted some stuff that I'm not sure were related to the virus, problem still persists)
- Manually removing/fixing the registry keys that one of the virus changed (with help from a Microsoft page), but they change back upon reboot. Now, regedit cannot even be accessed.
Now here's the tricky part.
- I ran MalwareBytes (it removed a virus from the system a couple years ago when Norton couldn't) and it found 7 objected infected in the QuickScan and Full Scan (I ran both), and I had them removed immediately. However, when restarted, the virus(es) still remain. I run the QuickScan again, it finds the infected objects, I remove them successfully (or so it says), but they reappear.
- Windows Defender starts automatically when Windows does. At start up, I get an alert from WD that finds the TrojanDownloader:Win32/Fakeinit. I click "Remove All", and it "successfully" removes it, but all the symptoms are still there, and the next time I start up the computer, I get the alert again.
- SmitfraudFix is downloaded onto the computer but cannot be ran. I get the "Application cannot be executed" pop up.

I need to resolve this issue ASAP as I'm afraid of using my laptop, and both of us are behind the same router/network. I don't want anymore things to download and I don't wanna pay for anything because if I can't fix this problem, I'd rather just purchase a new system. For now, I've disconnected the infected PC from the modem and router and separated it from the rest of the other computers.
I can't post a HijackThis or a ComboFix log, because the programs won't load, but tell me whatever you need to know and I'll try my best to post it in a reply. Sorry the post is long, I just needed to make sure I was thorough and clear about the problem.

Thanks in advance for any help!

Something new, I just noticed that MalwareBytes was last updated manually in June of 2009. Does the program update itself, or could this be the reason why it detects the registry infection/change and "removes" it, yet upon restart the values change back?
[external image: Posted Image]

I see you've been busy making changes.

MBAM doesn't update itself unless you have the paid for version.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this for XP.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

You do not need to download MBAM again but be sure to follow the instructions for updating and running.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
The infected computer has been disconnected from the internet and isolated for fear of getting any viruses onto other computers in my home network. I have empty CDs I can write the logs on (via Notepad), or a USB flash drive, but would it be safe to get it onto my laptop to post onto these forums?

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.

It was already selected like that under the View tab.

Also, the infected computer's performance itself hasn't really changed. It runs pretty smoothly and whatnot. The only thing REALLY affecting it is the no accessing Task Manager or Registry Editing, as well as the infected Wallpaper and pop ups.

I could be wrong though.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI