Unsolved
This post is more than 5 years old
2 Posts
0
7749
August 15th, 2009 11:00
Hello... New member... Registry issue/ question
Hello everyone
we are new members and have question regarding alert (below) we keep receiving from MacroVirus scan ....
Warning You still have 2 Detections on your computer
Type Catagory Object Location
browser helper... my web search {9afb8248-617... hkey_classes_root\clsid\{ 9afb8248-617...
browser helper... my web search treatas hkey_classes_root\clsid\{ 9afb8248-617...
Can anyone tell me A) If These should be removed and
B) how to
Thanx in advace


Bugbatter
4 Apprentice
•
20.5K Posts
0
August 15th, 2009 12:00
Welcome to Dell Community. :emotion-1:
If this is the "MacroVirus" scan that you ran, it is classified as a rogue product: http://www.malwarebytes.org/malwarenet.php?name=Rogue.MacroVirus
Do not remove what it found, but remove the rogue program instead by running a scan with a MalwareBytes Anti-Malware. If you, in fact, really have those registry issues, MBAM will find them and remove them along with the rogue.
You can download to your desktop Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
and just double-click on mbam-rules.exe to install.
Alternatively, you can update through MBAM's interface from a clean computer,
copy the definitions (rules.ref) located in
C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
Click Remove Selected.
1. Just click the "Post A Message" button (upper right) in the Malware Removal forum HERE
to start your own thread requesting assistance for a follow-up check to be sure the malware is gone.
2. In the discussion window that opens, simply Right-Click and select Paste.
Extra Notes:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
* If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to your CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.-- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes.
**If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from http://www.malwarebytes.org/mbam-clean.exe
DjStiggy
2 Posts
0
August 15th, 2009 15:00
:emotion-1: Thank You for your prompt and detailed reply.
I already had Malware Anti...sfotware installed , and yes, as you expected it showed infectious files (48 in all) stemming from the rouge program . Disinfection went smoothly . Afterward ran complete scan on both Trend (already installed) and Malware Anti..... both thankfully returned clean reports...
I also have Ccleaner installed ...it often tells me of registry issues as well .....however- As I am not familiar with and somewhat afraid of registry files I ignore these.....
I am very happy I decided to join this community and seek advice ..... I will check back often to see whats new .......... Again Thank You.
Bugbatter
4 Apprentice
•
20.5K Posts
0
August 15th, 2009 16:00
Glad to hear that things went smoothly. I'm glad you do not use the registry issues component of CCleaner. I don't support the use of so called "registry cleaners" because they can aggravate a situation and take steps we are many times not manually aware of.
It is better not to resort to such programs where you don't know what is happening with the proposed fix and the registry.
Otherwise, a change to the registry can make a system unbootable by one mistake.
Here are some good discussions:
http://aumha.net/viewtopic.php?t=28099
http://www.whatthetech.com/2007/11/25/do-i-need-a-registry-cleaner/
http://billpstudios.blogspot.com/2007/04/do-i-need-registry-cleaner.html
Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.
Please keep MBAM updated and use it to scan every so often for malware, or upgrade to the paid version for realtime scanning and auto updating.
The following suggestions are general prevention and are not customized for your computer. You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:
1. Visit Microsoft Update: Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS. Microsoft's widows Update: http://v4.windowsupdate.microsoft.com/en/default.asp
2. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
3.You might consider installing Mozilla / Firefox.
http://www.mozilla.com/en-US/
4. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.
5. Before using or purchasing any Spyware/Malware protection/removal program, always check the following Rogue/Suspect Spyware Lists. http://www.spywarewarrior.com/rogue_anti-spyware.htm http://www.malwarebytes.org/database.php
6. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/ ** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.
7.Web Of Trust , uses colored alerts to warn about risky websites warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
There is a Web Of Trust version for Firefox as well.
8. You might consider installing SpywareBlaster: http://www.javacoolsoftware.com/spywareblaster.html
It will:
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
Block spyware/tracking cookies in Internet Explorer and Mozilla Firefox.
Restrict the actions of potentially unwanted sites in Internet Explorer.
Tutorial here:http://www.bleepingcomputer.com/forums/tutorial49.html
Periodically check for updates
9. Here are some helpful articles:
"How did I get infected?"
http://www.bleepingcomputer.com/forums/topic2520.html
"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx
Evermore
2 Intern
•
338 Posts
0
August 16th, 2009 07:00
Bugbatter; I see you suggested installing Mozilla\Firefox. Are you suggesting that we use Firefox over I. E.? I do have Firefox installed but use IE as my primary Browser . I will use Firefox if it is a better and more secure. Thanks for your recommendation.
Bugbatter
4 Apprentice
•
20.5K Posts
0
August 16th, 2009 13:00