Thankyou for the removal guide!....most of the way there

Discussion in 'Malware Help (A Specialist Will Reply)' started by sayminame, May 7, 2009.

  1. sayminame

    sayminame Private E-2

    THANKYOU SO MUCH FOR THE REMOVAL GUIDE!!!!

    I was having so much trouble with google searches being redirected/hijacked and now that has all stopped.

    My AVG is now clear (0/0)

    Malwarebytes is still picking up a trojan.bho.h in the c:\windows\system32\card.dll though.

    I click on remove selected and it marks it for delete on reboot, but if I run the scan again, it is still there.

    I would love to have a totally clear system. If you could have a look at it, it would be awesome.

    Please help me MajorGeeks!

    (Not sure if you want all the logs, so just going to post them anyway so you can see the history....will post the latest mbam on next post if you like)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not much to do ....let's just see if this clears it up:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0"
    Java 2 Runtime Environment, SE v1.4.2_03"
    Viewpoint Media Player (Remove Only)

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.it up:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\card.dll
    C:\WINDOWS\system32\zefogedi

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds