Computing.Net > Forums > Security and Virus > Can't get rid of winupgro.exe

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Can't get rid of winupgro.exe

Reply to Message Icon

Name: trekkers
Date: December 29, 2008 at 12:01:07 Pacific
OS: Windows XP
CPU/Ram: 2300ghz/256MB
Product: Hewlett-packard / PAVILION 510C
Comment:

Hi,
I'm infected with winupgro.exe and can't get rid of it. I delete the file from the application data/drivers folder, but it comes back every time I restart the computer. I've tried several tools but can't get anything to run. AVG won't run and I can't get it to reinstall. Can you help me please?



Sponsored Link
Ads by Google

Response Number 1
Name: amvinfe
Date: December 29, 2008 at 13:53:26 Pacific
Reply:

Hi,

download
http://download.bleepingcomputer.co...
when you save changes to the desktop in the name Co @ 12 as described in the picture
http://img236.imageshack.us/img236/...

Run Co@12.exe and carefully follow the procedures that you are recommended.

NB
remember that there should be no internet connection.
Do not use your PC, including mouse during the removal.

Log on to load http://freefilehosting.net are in the C: \ (ComboFix.txt)

Ciao,

Marco


0

Response Number 2
Name: trekkers
Date: December 29, 2008 at 15:59:29 Pacific
Reply:

Marco,
I got ComboFix to run following your instructions. I also uploaded the ComboFix text file as you requested.


0

Response Number 3
Name: trekkers
Date: December 29, 2008 at 16:09:07 Pacific
Reply:

Here is the link:

http://freefilehosting.net/download...

ComboFix_1230598529933_1260.txt

[URL="http://freefilehosting.net/download/43dd3"]ComboFix_1230598529933_1260.txt[/URL]


0

Response Number 4
Name: amvinfe
Date: December 29, 2008 at 16:51:29 Pacific
Reply:

ok, now I read


0

Response Number 5
Name: amvinfe
Date: December 29, 2008 at 17:01:27 Pacific
Reply:

ok,
download http://freefilehosting.net/download...
install it, you'll have an icon on the desktop.
Run FindKill.exe choose the language and then dial 2 and the OK
After rebooting you still FindKill.exe select the language and then dial 3 to uninstall it.
Write the result of the scan
thanks


0

Related Posts

See More



Response Number 6
Name: trekkers
Date: December 29, 2008 at 20:04:20 Pacific
Reply:

I ran FindyKill and I thought the results were saved to c:\findykill.txt, but after uninstalling findykill, the file was not there.


0

Response Number 7
Name: amvinfe
Date: December 30, 2008 at 09:15:16 Pacific
Reply:

hi,

download to your desktop
http://www.suspectfile.com/systemscan
open it and make sure that all options are checked, click on "Scan Now" at the end of the scan will be released (always on your desktop inside the folder suspectfile) two files.
Go to office http://www.freefilehosting.net the zip file and write in your next reply URL where I can get it.

Remember the scan with no connection with the antivirus disabled unless then resume scanning finished.

NB
the duration of the scan may be long, it might even seem that the program is not working, do not worry is not so;)

SystemScan is recognized, mistake, by some antivirus as infected.
--

Ciao,
Marco

--


0

Response Number 8
Name: trekkers
Date: December 30, 2008 at 20:45:24 Pacific
Reply:

Marco,
Here's the file you asked for:

http://freefilehosting.net/download...

I want you to know that I really appreciate you taking the time to help me with this problem. I am truly grateful.

clyde


0

Response Number 9
Name: amvinfe
Date: December 31, 2008 at 08:47:09 Pacific
Reply:

Hi Clyde,
the only values that I saw in the report are related to spyware (AskTBar toolbar) that is installed when you install other programs like Nero, ZoneAlarm and many others, but it is also true that some people choose to install the toolbar.

You must tell me you if you want to delete it ;)

Here is some information (in Italian) on this spyware
http://www.suspectfile.com/wblog/?p=42

or English
http://sunbeltblog.blogspot.com/200...

and these values toolbar
HKCR\CLSID\{9CB65206-89C4-402c-BA80-02D8C59F9B1D}\InprocServer32 @="C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL"

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}

HKCR\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}


You have other problems?

Ciao,

Marco

happy new year


0

Response Number 10
Name: trekkers
Date: December 31, 2008 at 17:09:55 Pacific
Reply:

Marco,
I want to get rid of it. Please tell me how. Also, can you recommend a program for me install to keep spyware and malware off my computer. Thanks again, and Happy New Year.

clyde


0

Response Number 11
Name: trekkers
Date: December 31, 2008 at 17:13:17 Pacific
Reply:

Marco,
Sorry, I forgot to answer your last question, a few months ago, my USB ports which which had been 2.0 suddenly were no longer 2.0. Any clues?

clyde


0

Response Number 12
Name: amvinfe
Date: January 1, 2009 at 04:40:26 Pacific
Reply:

Hi,
for the toolbar:

Open Notepad and enter inside (copy / paste):

Windows Registry Editor Version 5.00

[-HKEY_CLASSES_ROOT\CLSID\{9CB65206-89C4-402c-BA80-02D8C59F9B1D}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}]
[-HKEY_CLASSES_ROOT\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}]
;


Click on the upper left on "File" then "Save As" from the window that opens click under "Save as:" > select "All Files" > in the "File name" Send fix.reg > Save the file to your desktop.
Now double-click on fix.reg, allow the changes, restart the PC.

--

For the USB problem I think is a problem of driver, you can try to resolve by making upgrades Microsoft (Windows Update)

A good day
;)


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Can't get rid of winupgro.exe

Can't get rid of RUN entry/Service www.computing.net/answers/security/cant-get-rid-of-run-entryservice/17409.html

Can't get rid of cws.searchx www.computing.net/answers/security/cant-get-rid-of-cwssearchx/12067.html

Can't get rid of onemoresearch.net www.computing.net/answers/security/cant-get-rid-of-onemoresearchnet/14181.html