Followed your removal instructions - hope this is correct way to post results

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ctesias, Jan 23, 2009.

  1. ctesias

    ctesias Private E-2

    Followed your removal instructions - hope this is correct way to post results :)

    Problems started with Perfect Defender - expect someone clicked something in error (!) then we seem to have a number of other issues too.

    Alarmingly, the initial symptom was that every time we tried to run IE we got a "IE has encounered a serious problem and has to close" message. We are running AVG and it seemmed to partially deal with the problem and did find the trojan(?) and IE began working again.

    Have been through your removal guide, so please see files attached.

    Thanks for your help.

    Ctesias
     

    Attached Files:

  2. ctesias

    ctesias Private E-2

    Re: Followed your removal instructions - OTHER FILES ATTACHED

    Files attached, thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware so let's get updated and run a new scan just to be safe.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Uninstall the below old versions of software:
    Ad-Aware SE Personal <-- to out of date to be useful
    Java(TM) 6 Update 10
    Spyware Doctor 3.1 <-- to out of date to be useful

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot and after reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • the new SUPERAntiSpyware log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds