If You Could See My StartUp list...You'd know why I'm here!

Discussion in 'Malware Help (A Specialist Will Reply)' started by bejay, Mar 25, 2008.

  1. bejay

    bejay Private E-2

    Per instructions here is a bit of what i'm up to! I didn't attach a HJT.log since this is my first post, although instructions for BFU say to post after running and attach one.

    Attempting to work through and have read your malware removal instructions...I had previously tried to get rid of some malware, but it still shows in StartUp and elsewhere so decided to try your suggestions.

    Began with the Special Removal Procedures and Brute Force Uninstaller to remove SurfSideKick. I ran BFU in Normal StartUp mode and Normal Boot w/internet connection enabled. Didn't see anywhere saying to run in Safe Mode, though end of instructions say to reboot to Normal Mode...
    Received these errors after computer restarted:
    mnyexpr.exe faileld to start, msvcrtdm.dll not found
    error loading C:\Windows\System32\rwfrscmw.dll, module not found
    error loading C:\Windows\System32\ilvhpfbe.dll, module not found

    Also, a shortcut was created on my desktop for SmitfraudFix.exe. Not being sure i should use it and not being able to post to board [lost password], i deleted it. Will download same from your site, as i do believe i have SmitFraud, after a response to this post.

    I then ran HJT and created a log. Did not make any changes to the scan. Didn't run a HJT scan before running BFU. I do have one from the 22nd, but it was ran with Selective StartUp and many changes have been made since then!

    Ran CCleaner and disk CleanUp.

    Will wait to hear from you, before continueing with SmitFraud removal instructions.

    Thanks for any help you can offer!
    BJ
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not sure why you are using BFU. Did you know for a fact that you had a SurfSideKick problem? The same goes for SmitFraud. You should not be running those procedures unless you know for sure that you have the related malware.

    Just run the steps in the READ ME and attach the requested logs. Ignore the Special Removal Procedures for now unless we ask you to run one.
     
  3. bejay

    bejay Private E-2

    Some of the spyware removal programs i had run previously [before posting here] showed smitfraud and surfsidekick, among numerous other infections [virtumondo, winantispyware...]. I thought i was following the Read and Run Me First procedures, by doing the things listed under Special Removal Procedures...Sorry for my misunderstanding.

    Should i delete the BFU and smitfraud removal programs and any files they might have saved? If so, anything special i need to know about doing so or since neither is listed in Add/Remove programs, do i simply try to locate the folders/files they created and delete them?

    Also, the BFU instructions say to run cleanmgr. I tried, but this program will no longer run...the window pops up, but nothing happens. It worked properly a few days prior to running BFU [not blaming BFU!].

    Will follow your advice and start with the XP removal procedures tomorrow.

    Thanks much for your time and consideration!

    BJ

    PS
    A bit of history...
    Much of the malware on this thing was spotted by various removal programs a couple of years ago and i attempted to remove it. Also used msconfig [i know now this is a no no!] to remove from the startup list. While following MGs' instructions to enable everything in startup, well of course some of them have reappeared. Tis mighty tempting to delete them through HJT or other means, but will patiently work through the steps and let one who is much more knowledgable than myself guide me!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you were following the READ ME as far as running the Special Removal Procedures. I just wanted to be sure that you had something telling you that you had those particular infections.

    You can leave them for now but we probably will not need them. If that becomes the case, you can just delete them later.

    Don't worry about Cleanmgr now. It is 100 times slower than CCleaner anyway. Just run Ccleaner as given in the main steps of the READ ME. After you finish the main steps of the READ ME (ignoring the Special Procedures for now), move onto the XP Cleaning Procedure.

    Just follow our instructions as written and we will get all them remove. You will not need to use MSconfig to control anything unless we ask to and that would only be a temporary debugging measure.
     
  5. bejay

    bejay Private E-2

    Tried to work through the first part of R&RM. Didn't update Java...had a problem trying to update it a few days ago, so did a sys restore to date before then and now i've really got a mess as it kept the new files also! Looks like, from reading the java site, that tis quite an ordeal to undo all i've done, so hope it's OK to wait til i have time to mess with it.

    Ran CCleaner [already had]

    Downloaded:
    SAS [already had]
    SpybotSD [already had it, but it got messed up same time as java mess above, so deleted and re-downloaded]
    MBAM
    MGTools [already had]

    Upon trying to run SAS got error:
    SAS.exe unable to locate compponent, ap failed to start msvcrtdm.dll not found. Clicked "X' 5-6 times to close window.

    SAS opened and i updated then ran it, hopefully following all instructions! QUESTION: under scan options should ignore system restore volume be left unchecked? I did not check it. When told to reboot, chose yes, but had to manually do it. After reboot got error messege: msvcrtdm.dll failed to load and C:\Windows\system32\rwfrscma.dll and ilvhpfbe.dll modules not found.

    Reconnected to internet. Attached SAS log.

    Thanks again!

    BJ

    PS
    I get the msvcrtdm.dll, rwfrscmw.dll and ilvhpfbe.dll errors quite often when opening programs, but after clicking the messege off 5-6 times the program usually opens.

    Can not open the "system" folder in control panel.

    Can not change time [get the msvcrtdm.dll error].
     

    Attached Files:

  6. bejay

    bejay Private E-2

    OK, guess i've read the instructions wrong...I'm tryin to get it right! But they are a bit confusing!

    At the end of the SAS instructions it says "Please attach the Scan Log results to your next reply. " Well...i took this to mean that i should post a reply and send that log after running just that scan. Sorry.

    Am i to run all of the scans, then if still infected, start a new post and ONLY THEN attach all of the logs [as stated in Step 3. Yes, I'm still having problems]?

    Geez...i'm bound to get it right sooner or later!

    Thanks

    BJ
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to realize that the procedure describing how to run SUPERAntispyware is not just used while running the READ ME. It is also run independently. It does not hurt to attach the log at this point but you still needed to continue on with the cleaning instructions in the main part of the READ ME. It did not say stop after running any of those scans.

    Yes you need to complete all of the instructions in the READ ME for your Windows version and then attach all of the logs. Thus you need to finish with Malwarebytes Anti-Malware and MGtools and then attach those two logs.
     
  8. bejay

    bejay Private E-2

    I'm slowly catchin on! Again, sorry for the misunderstasnding [at this point ya probably think i'm i real dummy!]. I was planning to continue with running the rest of the programs, just misunderstood about sending the SAS log. Anyway, on with the show!

    Still running slower than normal and receiving pop-ups without a blocker on. Still getting the msvcrtdm.dll, etc errors as ,mentioned earlier, can't change clock, can't access "system" file in control panel and in my scheduled tasks [have it disabled] are about 24 tasks that i didn't put in there [it says they have all failed to start]. Also lots of things in my startup/task manager that i know are no good.

    Anyway 2 logs are attached [attached SAS log to earlier post], correctly i hope! No SpyBot log needed, right?

    I do thank ya for your help!

    BJ
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must start by putting your system into Normal Startup mode with MSconfig as was requested in step 1 of the READ ME. You must remain in this mode.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\TISKY009.exe SKY009
    O4 - HKLM\..\Run: [YslMjjKW.exe] C:\documents and settings\hayley\local settings\temp\YslMjjKW.exe
    O4 - HKLM\..\Run: [xhMF.exe] C:\documents and settings\hayley\local settings\temp\xhMF.exe
    O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
    O4 - HKLM\..\Run: [wahm] C:\windows\eee2.exe
    O4 - HKLM\..\Run: [Vk.exe] C:\documents and settings\hayley\local settings\temp\Vk.exe
    O4 - HKLM\..\Run: [virtual-ie] winlogi.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [System service79] C:\WINDOWS\\\etb\\pokapoka79.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [rubquyiA] C:\WINDOWS\rubquyiA.exe
    O4 - HKLM\..\Run: [qQ.exe] C:\documents and settings\hayley\local settings\temp\qQ.exe
    O4 - HKLM\..\Run: [ptjazuuA] C:\WINDOWS\ptjazuuA.exe
    O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
    O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto
    O4 - HKLM\..\Run: [jMG.exe] C:\documents and settings\hayley\local settings\temp\jMG.exe
    O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\rwfrscmw.dll",forkonce
    O4 - HKLM\..\Run: [g4356cbvy63] C:\WINDOWS\g4356cbvy63
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKLM\..\Run: [2F9W3ni] imeauto.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
    O4 - HKCU\..\Run: [HijackThisRemote] C:\Program Files\HijackRemote\HijackThisRemoteClient.exe
    O4 - HKCU\..\Run: [EQTraffic] "C:\Program Files\EQTraffic\EQTraffic.exe"
    O4 - HKCU\..\Run: [Cjwbynq] "C:\Program Files\Common Files\s?stem32\??plorer.exe"
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
    O4 - HKCU\..\Run: [Aida] "C:\PROGRA~1\YSTEM~1\attrib.exe" -vt yazb
    O4 - HKCU\..\Policies\Explorer\Run: [dhccho] C:\WINDOWS\system32\dhccho.exe
    O15 - Trusted Zone: *.ewido.com
    O15 - Trusted Zone: http://www.kaspersky.com

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. bejay

    bejay Private E-2

    Thanks for assisting!

    Sorry for not in "Normal StartUp"...kids had changed it and i didn't think to check.

    Ran Disable/Remove Windows Messenger

    Attempted to remove all Java via Add/Remove. Not certain it is all gone.

    Ran C:\MGtools\analyse.exe, but [ya know i gotta mess up somewhere!] out of habit i chose do a scan and save a log. Didn't find:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    or
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" in the analysis.

    fixME.reg, i copied and pasted into notepad, saved to desktop, type all files. Save window also asked what type of encoding. It is set on ANSI so i left it at that. When double clicking the file on desktop, window opens asking what program i want to open it with. Can you help me with that, because i don't have a clue! Not fond of messin with things i don't know i.e. registry!

    I'm going to stop at this point and wait for your reply in re the fixME.reg file.

    Thanks again

    BJ
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC lost the Windows File Association for .REG files. Let's fix it.

    Now Copy the bold text below to notepad. Save it as RegFix.reg to your desktop. Be sure the "Save as" type is set to "all files". Then Click Start, Run, and enter regedit and click OK. This will open the Registry Editor.

    In the Registry Editor click File and Import. Navigate to the RegFix.reg patch you saved on your Desktop and double click on it. Click OK at the prompt to add to the registry. Do you get a success message for this?
    Then retry the fixME.reg patch and continue on with the rest of the instructions.
     
  12. bejay

    bejay Private E-2

    Ran RegFix.reg and FixMe.reg with no probllems. Thanks!

    Downloaded and ran avenger. After reboot got error message "mnyexpr.exe - Unable to locate component, application failed to start because msvcrtdm.dll not found", but avenger log did open.

    Downloaded and installed latest java version then rebooted. When i goto IE/tools/SunJava Console it places java icon in taskbar. If i double click taskbar icon or right click and choose "open console" nothing happens. If i choose "open control panel" i get error "java virtual machine launcher, could not find main class, program will exit". If i goto sun java or other java installation checking website and click verify installation, i get error: microsoft visual c+ + runtime library, runtime error, program C:\program files\internet explorer\ieexplore.exe, this application has requested the runtime to terminate in an unusual way, please contact...", i click "ok" and IE window closes. If you've suggestions, i'd be more than happy to hear them or perhaps this is more of a software issue and should be asked in that forum?

    Ran CCleaner.

    Ran C:\MGtools\GetLogs.bat.

    Took a deep breath!

    Attached requested files.

    Haven't done much surfing/computing since these fixes, but haven't noticed errors other than those mentioned above. There are a couple of strange[?] files in c:\documents and settings\[usename]\, created same day and time: pww.txt and zzz.exe. zzz.exe is by company named XTC.
    The pww.txt shows:
    Resource Name : http://webmail.central.cox.net/
    Resource Type : AutoComplete Passwords
    User Name/Value : [my username/email address]
    Password :

    Also, as mentioned earlier, i have 24 tasks in task scheduler that we didn't set up. They are scheduled to run daily and it shows "created by: NetScheduleJobAdd and Run As" NT Authority\System". Possibly put ther by malware? Is it safe to delete these?

    Tis nice to see a StartUp list without all that malware in it! Hope our problems are solved!

    Hopefully i've completed the required steps and i'll let you guide me the rest of the way!

    Many thanks

    BJ


    PS
    You've done such a good job, i think i'll be back and let you take a look at the mess on the other computer!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This file is actually malware and it is associated with W32/Crimea.dr which you can read about here: http://vil.nai.com/vil/content/v_142626.htm

    It more than likely infected your System32\imm32.dll so we have to check this and also look for a replacement on your PC. I'll post something for you to do in my next message.

    Not sure what this is right now but let's wait until we are sure all malware issues have been removed.


    Is Cox your ISP?

    Just delete them.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached FindFile.zip file to your C:\MGtools folder. Then extract the FindFile.bat file from this ZIP into that same C:\MGtools folder. You must extract the file from the ZIP. DO NOT try to run the batch file from inside of the ZIP file. Now double click on the FindFile.bat file to run this batch file script. This will search your hard disk for copies of the imm32.dll file so we can check its infection status and also look for a backup copy to replace it with. It will create a report.txt log and automatically add it to the C:\MGlogs.zip file which I will ask you for a new copy of after we also do some other steps.


    Copy the bold text below to notepad. Save it as fixME.reg to your Desktop thus overwritng the previous file of the same name.. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     

    Attached Files:

  15. bejay

    bejay Private E-2

    Took 2 deep breaths...and attempted to correctly follow your instructions. Log attached.

    Yes, Cox is my ISP.

    Errors i am receiving or things not working correctly:

    Can't change clock settings from taskbar. No response.

    From Control Panel i can't access Date and Time, Java, Regional and Language Options or System. No response.

    Looks like you are working on correcting the msvcrtdm.dll error, but thought it might help to know when i receive it. When trying to access Help Center or any Help file get error "HelpCtr.exe-Unable to load component, msvcrtdm.dll etc." Help Center opens behind the message, but have to click it off 5-15 times before it goes away, then as soon as i click in the Help window the same error and again the clicking off routine 5 or 6 times then finally the message quits popping-up. I have received the msvcrtdm.dll error when opening other programs, but have not noted them...

    Tons of changes to Start Menu/.../System Information, all made at same time to Software Environment, changed from NT Authority to Default and a few added/removed changes that i recognized as ones we had done. This may be normal...

    When visiting random websites i get the error: microsoft visual c+ + runtime library, runtime error, program C:\program files\internet explorer\ieexplore.exe, this application has requested the runtime to terminate in an unusual way, please contact...". IE shuts down.

    Probably others that i'm not thinking of or have mentioned previously!

    Thanks again for your time. I know you folks are extremely busy, but i was beginning to wonder if i missed part of the R&RM so went back to see if i was doing things correctly and saw Step 3. says to start a new thread, which i didn't do, so was just about to do so when i saw you had responded to my last post! At this point should i simply continue in this post rather than start a new thread?

    Thanks again

    BJ
     

    Attached Files:

    Last edited: Apr 1, 2008
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached Fix-imm32.zip file into your C:\MGtools folder. And then extract the Fix-imm32.bat file from it into the same C:\MGtools folder. Now double click on the Fix-imm32.bat file.

    Then attach this file to your next message which should be created when the above is finished: C:\dirlog.txt

    After attaching this dirlog.txt file. Reboot your PC and tell me if you notice any changes to your problems.
     

    Attached Files:

  17. bejay

    bejay Private E-2

    Piece of cake!

    Requested file is attached as asked. I shall reboot and let you know what happens!

    Thanks

    BJ
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like we successfully copied the correct file. So is there any change to any of your problems.
     
  19. bejay

    bejay Private E-2

    Yeah!!!

    So the Control Panel errors mentioned below were related to malware [W32/Crimea.dr]... I had thought perhaps it was caused by file corruption not related to such...Hadn't mentioned that Word Perfect and some other word processor programs weren't working..Now they are! Many thanks!

    All of the below are working properly! Even my Java installation!

    Haven't noticed this one appearing yet, but haven't had time to do a lot of surfing. My guess is that it is also fixed!

    The below may be normal?

    Cox is my ISP. These caught my eye because of the odd names [pww.txt and zzz.exe]. They are still there.

    Think i have covered all and most has been answered/repaired.

    Many thanks for your time! I've been pretty much ignoring the mess for a year or so, other than disabling in msconfig, which didn't do much!

    BJ
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just move these file into a temp folder (like C:\Temp ) and if everything runs okay without them for a couple days then just delete them. Are you having any remaining malware issues.


    Yes and this caused more harm then good. Do not use it like this any more.
     
  21. bejay

    bejay Private E-2

    Will do.

    None [!] noticed so far. Thanks!

    Yessir, Boss!!!

    I do appreciate you taking your time to clean up my system. Many thanks!

    BJ
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Since you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. bejay

    bejay Private E-2

    All seems to be in proper working order!

    I've attempted to follow the steps in your above post.

    Is it safe to remove all references i see to java versions prior to 6 update 5 and Norton? Even those found in the registry [i may be getting too brave here!]?

    Once again, i can't thank you enough for taking your time to help me repair this system!

    Hope its not to much to ask for help in removing any found malware on another home desktop? Hate to wear out my welcome!

    BJ
     
  24. bejay

    bejay Private E-2

    Yikes...

    Hadn't tried Start/Run/type regedit/click OK until now and i get error message:

    Regedit.exe - Application Error, The application failed to initialize properly {0xc0000005}. CLick OK to terminate the application.

    Have to click the message 3-4 times before it closes.

    Any ideas?

    Thanks

    BJ
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not sound like malware. It could be related but right now I doubt it. Do you have a SoundBlaster type sound card? I'm not sure but it may be related to what Microsoft states in the below:

    http://support.microsoft.com/kb/217134



    Download Registry Search (see the link titled RegSearch Download Link)

    * Extract the files from Regsearch.zip into a folder.
    * Doubleclick regsearch.exe to start the program.
    * Enter RPCKDM in the top area of the form and then click "OK".
    * Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.


    [edit] Another idea just occurred to me! Click Start, Run and enter sfc /scannow into the run box and click OK. There is a space after the sfc. After this finishes running reboot. Any change.
     
  26. bejay

    bejay Private E-2

    Aah...It worked, THANKS!!! My heart was pounding, thinking that after all you had done to fix things, i had messed it up by deleting something while in the process of cleaning up the programs/files created to remove the malware!

    Thanks again!
    BJ
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds