Yesterday I was trying to repair a friends computer that had a possible infection of PC Protection Center 2008. Let me list the basic details of what I see occuring.
Wallpaper on desktop was hijacked and set to a active desktop wallpaper displaying a blue and yellow advertisement that says the following, "Your computer has several fatal errors due to spyware activity". Along with "Update your anti-spyware protection".
Then there are the traditional balloons in the lower right hand corner saying there's an infection with the exclamation point warning sign. Then with a about 3 minutes it opens a Window asking to install PC Protection Center 2008.
I tried booting into Safe Mode and the infection prevents me from doing so. It just sits at the black screen with the Safe Mode text border. I tried the Diagnostics boot and the infection didn't like that either. The virus/malware still loaded and it messed with Windows Genuine Advantage. Windows now thinks that the hardware drastically change and we now have 3 days to verify the copy Windows. Trying to Verify it again just results in it saying there's an Active X issue and that it can't.
I also tried accessing TaskManager to see if the process was running but it disabled my ability to access TaskManager saying the Administrator disabled it even though I was on a Administrator account. So instead I tried Proc Explorer but I couldn't find anything in there that was suspicious.
I tried running Spybot and it wont load at all. Tried installing Malware Anti-Malware Bytes and SuperAntiSypware and the installers wouldn't run. I also tried HiJackThis and that would not load as well. And I also tried the SmitFraud Fix, I almost got some where with that but when it tried to delete the infected files it couldn't. It then went into disk clean up shortly after and the computer just froze up after the disk clean up wizard disappeared which resulted in having to press the reset button on the tower.
I made a backup of the registry, would this file be of use to anyone who can help me?
Should I try pulling out the hard drive, connect it to another computer as a external drive and scan it from that PC?
At this point I'm lost on what else I should try to do. Any suggestions?
Edited by StandardsDT, 25 November 2008 - 11:04 AM.