Unsolved

This post is more than 5 years old

2 Posts

7749

August 15th, 2009 11:00

Hello... New member... Registry issue/ question

 

Hello everyone 

we are new members  and have   question regarding alert  (below) we  keep receiving  from  MacroVirus  scan  ....

                                                                                                                                                                

Warning   You still have  2 Detections on your  computer

  Type                              Catagory                                                         Object                                                            Location                                    

browser helper...    my web search                                            {9afb8248-617...                           hkey_classes_root\clsid\{ 9afb8248-617...

 browser helper...    my web search                                            treatas                                            hkey_classes_root\clsid\{ 9afb8248-617...    

                                                                                                                                                                 

Can anyone tell me     A)  If These should be removed    and

                                         B) how to

Thanx in advace

          

4 Apprentice

 • 

20.5K Posts

August 15th, 2009 12:00

Welcome to Dell Community. :emotion-1:

If this is the "MacroVirus" scan that you ran, it is classified as a rogue product: http://www.malwarebytes.org/malwarenet.php?name=Rogue.MacroVirus

Do not remove what it found, but remove the rogue program instead by running a scan with a MalwareBytes Anti-Malware. If you, in fact, really have those registry issues, MBAM will find them and remove them along with the rogue.
You can download to your desktop Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates,
  • manually download them from here
    and just double-click on mbam-rules.exe to install.
    Alternatively, you can update through MBAM's interface from a clean computer,
    copy the definitions (rules.ref) located in
    C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
    Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
  • Once the program has loaded, select "Perform Quick Scan"; then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checkedPhotobucket
    Click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • If you are still having problems and/or would like a follow-up check to be sure the infection as well as vulnerabilities are gone, copy and paste the entire report into a New Message on the Malware Removal forum. Also include a fresh HijackThis log. Instructions for downloading HijackThis are in the "Please Read..." announcement at the top of that forum.

    1. Just click the "Post A Message" button (upper right) in the Malware Removal forum HERE
    to start your own thread requesting assistance for a follow-up check to be sure the malware is gone.

    2. In the discussion window that opens, simply Right-Click and select Paste.

    Extra Notes:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

     

    * If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM. Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "catchjunk.exe". Copy the installer file and the update file to your CD or flash drive. Transfer the file to the infected computer. Install the "catchjunk.exe" file, then run the update so that you will have the current definitions. After that, run a full system scan and select to have the program REMOVE whatever it finds.

    -- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes.

    **If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from http://www.malwarebytes.org/mbam-clean.exe

     

2 Posts

August 15th, 2009 15:00

:emotion-1:  Thank You for your prompt and detailed reply.

I already had Malware Anti...sfotware installed , and yes, as you expected it showed infectious files (48 in all) stemming from the rouge program .  Disinfection went smoothly . Afterward  ran  complete scan on both  Trend (already installed) and Malware Anti.....  both  thankfully returned clean reports...

I also have Ccleaner installed ...it often tells me  of  registry issues as well  .....however- As I am not familiar  with  and  somewhat afraid of  registry files  I ignore these.....

 I am very happy I decided to join this community and seek  advice .....  I will check back often  to see whats  new  .......... Again Thank You.

 

4 Apprentice

 • 

20.5K Posts

August 15th, 2009 16:00

Glad to hear that things went smoothly. I'm glad you do not use the registry issues component of CCleaner. I don't support the use of so called "registry cleaners" because they can aggravate a situation and take steps we are many times not manually aware of.
 It is better not to resort to such programs where you don't know what is happening with the proposed fix and the registry.
Otherwise, a change to the registry can make a system unbootable by one mistake.
Here are some good discussions:
http://aumha.net/viewtopic.php?t=28099
http://www.whatthetech.com/2007/11/25/do-i-need-a-registry-cleaner/
http://billpstudios.blogspot.com/2007/04/do-i-need-registry-cleaner.html

Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

Please keep MBAM updated and use it to scan every so often for malware, or upgrade to the paid version for realtime scanning and auto updating.

The following suggestions are general prevention and are not customized for your computer. You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:


1. Visit Microsoft Update: Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS. Microsoft's widows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

2. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.

3.You might consider installing Mozilla / Firefox.
http://www.mozilla.com/en-US/

4. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.

5. Before using or purchasing any Spyware/Malware protection/removal program, always check the following Rogue/Suspect Spyware Lists. http://www.spywarewarrior.com/rogue_anti-spyware.htm http://www.malwarebytes.org/database.php

6. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/ ** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

7.Web Of Trust , uses colored alerts to warn about risky websites warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

  • Red for Warning = STOP
  • Yellow for Use Caution
  • Green for Safe
  • Grey for Unknown

There is a Web Of Trust version for Firefox as well.

 

8. You might consider installing SpywareBlaster: http://www.javacoolsoftware.com/spywareblaster.html
It will:
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
Block spyware/tracking cookies in Internet Explorer and Mozilla Firefox.
Restrict the actions of potentially unwanted sites in Internet Explorer.
Tutorial here:http://www.bleepingcomputer.com/forums/tutorial49.html
Periodically check for updates

9. Here are some helpful articles:
"How did I get infected?"
http://www.bleepingcomputer.com/forums/topic2520.html


"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

2 Intern

 • 

338 Posts

August 16th, 2009 07:00

Bugbatter; I see you suggested installing Mozilla\Firefox. Are you suggesting that we use Firefox over I. E.? I do have Firefox installed but use IE as my primary  Browser . I will use Firefox if it is a better and more secure. Thanks for your recommendation.

4 Apprentice

 • 

20.5K Posts

August 16th, 2009 13:00

Are you suggesting that we use Firefox over I. E.?
Not necessarily.  It is always good to have an alternate browser on board. What you have is fine.

No Events found!

Top