followed SpywareQuake & SpyFalcon Removal Procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by somewhatvexed, Jun 3, 2006.

  1. somewhatvexed

    somewhatvexed Private E-2

    Hey there, i did a panda and trojanhunter search earlier on today and found a few things. Trojan hunter said that i have "trojandownloader.Zlob.100" and 350 and 362. Panda said, amoungst other things (doubleclick, emediacodec, security error... i think) that i have spyquake.

    So i've now followed all the instructions for "SpywareQuake & SpyFalcon Removal Procedure", please find attached my smitfiles report thing.
    I think that the only one that i could find was: System32%\imfdfcj.dll.

    hopefully, it has worked. ?

    Thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Yes it looks like the procedure worked! Are you having any other malware problems?

    Attach a new Panda log. The EmediaCodec item may still be there. You may need to manually delete C:\Program Files\eMedia Codec
     
  3. somewhatvexed

    somewhatvexed Private E-2

    hmm it seems it isn't all gone :S
    couldn't see emediacodec in program files.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only item of minr concern in your Panda log is a leftover (fairly benign) registry entry for Emediacodec. Since Panda gives no specific info on what or where it is finding this, we can only try to guess.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  5. somewhatvexed

    somewhatvexed Private E-2

    hello, thanks for getting back to me: it is greatly appreciated.
    I have now done the above, did another panda search (attached). hehe he's still there!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is problematic with Panda not telling us anything useful. Let's try a few searches!

    Now download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    emediacodec

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread.

    Then repeat the above search sequence on the below two strings:
    Media-Codec
    64ba30a2-811a-4597-b0af-d551128be340


    Attach all three logs!
     
  7. somewhatvexed

    somewhatvexed Private E-2

    The search ran and found one entry for emediacodec. I then clicked ok to see the report and it said error "the system cannot find the file specified" (refering i think to the reg srch).

    I have to go and do a joyful exam now, but i'll try it again when i get back in later.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it again! It should work without that kind of problem. Where did you put the RegSrch.vbs file?

    If you ran the READ ME and installed Spybot and used the Immunize feature, I think it should find a bunch of things for emediacodec
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds