Computing.Net > Forums > Security and Virus > adware and registry key trojan

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

adware and registry key trojan

Reply to Message Icon

Name: thedreamer
Date: September 14, 2006 at 15:21:32 Pacific
OS: windows xp pro
CPU/Ram: 512
Product: dell inspiron
Comment:

adware.max search keeps coming back everytime its deleted, and the registry key MSSMGR keeps returning after being deleted, antivirus detects it as a trojan. can someone help me get rid of them?



Sponsored Link
Ads by Google

Response Number 1
Name: www
Date: September 14, 2006 at 16:23:25 Pacific
Reply:

(some of this info is from antispyware forums)
1st disable system restore:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives" as shown in this illustration:
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Proceed with what you need to do; for example, virus removal. When you have finished, restart the computer and follow the instructions in the next section to turn on System Restore.
(after everything is clean ,turn it back on)
To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
Download and install the 30 day trial of Ewido Anti-Spyware from HERE

http://www.ewido.net/en/download/

1. Download it to your desktop
2. Doubleclick the ewido icon to start the ewido setup process...
3. update the definition files....
Click the Update icon then select the Update now link...
Select the Start Update button, the update will start and a progress bar will show the updates being installed.
4. select the Scanner icon at the top of the screen, then select the Settings tab
click on Recommended actions and then select Quarantine
5. Under Reports...
Select Automatically generate report after every scan
Un-Select Only if threats were found
6. Close Ewido > Do not run the scan yet.

Boot your computer into Safemode

1. Go to Start> Shut Off your Computer> Restart
2. As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
3. Use the Up and Down Arrow Keys to scroll up to SAFEMODE
4. Then press the Enter on your Keyboard

IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning

proccess

1. Lauch Ewido-Anti-Spyware by double-clicking the icon on your desktop.
2. Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
3. Ewido will now begin the scanning process, be patient this may take a little time.

4. Once the scan is complete do the following:
5. If you have any infections you will prompted, then select Apply all actions


6. Close Ewido


--
Download: SmitfraudFix.zip from

smitfraudfix (the file contains both English and French versions)

1. Reboot into >>>safe mode
2. Double-click smitfraudfix.cmd
3. Select 2 and hit Enter to delete infected files
4. You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection
5. The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file
6. A reboot may be needed to finish the cleaning process.

download -install -update
AVG Anti-Rootkit 1.0.0.13 Beta
in normal mode, run perform indepth search.
have it clean anything it finds.


0

Response Number 2
Name: thedreamer
Date: September 14, 2006 at 22:37:03 Pacific
Reply:

i did everything listed above, but i still have the adware.max and the registry key. also, the last few times i've started safe mode. explorer.exe doesn't start up in processes, so the desktop doesn't show up.


0

Response Number 3
Name: www
Date: September 15, 2006 at 22:33:11 Pacific
Reply:

try online scans at
f-secure

http://www.kaspersky.com/virusscanner

http://housecall.trendmicro.com/

(reboot in between scans, was suggested )
if those don't help , you may want to try posting a hijackthis log at
http://www.techsupportforum.com/forumdisplay.php?f=50


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: adware and registry key trojan

Trojan Vundo in registry key www.computing.net/answers/security/trojan-vundo-in-registry-key/24073.html

spyblaster, registry keys, AWTool www.computing.net/answers/security/spyblaster-registry-keys-awtool/15442.html

hidr.exe and flec006.exe and exefld www.computing.net/answers/security/hidrexe-and-flec006exe-and-exefld/21513.html