Wednesday, July 13, 2011

How to Remove System Repair (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
System Repair is a rogue computer optimization and repair program that misleads users into buying doubtful value and unknown origin software by making you think your computer is infected or has some critical hard drive or system registry errors. Most of the time, users get infected when they click on a malicious link or fake pop-up messages which are really well made copies of Windows Security Center or other screens in Windows operating systems. Cyber crooks also use various social engineering tricks and fake online virus scanners in order to convince users to clean supposedly infected machines immediately with the offered tool. Some varieties of rogue computer security and optimization programs may get installed on your computer just by you visiting a website with a malicious advertisement or code, and you might never know you've been impacted. In such case, System Repair pop-ups on your computer screen like from nowhere and begins to scan your computer for viruses and system errors. If your computer is infected by this rogue applications, you should stop work and get rid of it immediately. To remove System Repair and associated malware from your computer, please follow the steps in the removal instructions below.

New graphical user interface (03/2013). The new one looks much better, has clean interface. Scammers are clearly following the latest software trends.



The fake scanner which was used previously by scammers to scare users into thinking that their computers have serious performance and stability issues. This scanner may still be downloaded from previously infected websites.



Once installed, System Repair performs a fake system scan for viruses and system/registry errors. After the fake scan, this rogue application reports eleven critical hard drive and system errors and immediately prompts you to pay for a full version of the program to fix found problems which actually do not even exist. What is more, System Repair hides certain files or copies them to Windows temporary folder (Temp). It makes your desktop background black and pretty much empty just to make you think that those falsely detected hard drive and registry errors truly exist. Furthermore, System Repair may drop a rootkit from the TDSS (TDL3 or TDL4) family which hides its presence from the user and may download other malware on your computer or re-install System Repair scareware if it was successfully removed from the system. You should use TDSSKiller and Backdoor.Tidserv removal tool before or after the removal of System Repair to make sure your PC is not infected by a rootkit from a TDSS family. Otherwise, System Repair might be re-downloaded to computer computer.

Here are some examples of a warning pop-up windows from this rogue program:







Additionally, you can activate the rogue program by entering one of the following registration codes and fake email as shown in the removal instructions below.

Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly. Most importantly, don't be fooled and do not pay for this phony system optimization and repair program. If you have already purchased it, please contact your credit card company and dispute the charges. Unlike viruses, rogue applications do not self-replicate and can not delete your files, so you shouldn't worry about that. If you have any further questions, please leave a comment below. Good luck and be safe online!

Update: Monday, March 18, 2013

I've found a new variant of System repair virus with a slightly modified graphical user interface (see the image above). This only confirms that the rogue application is being actively repacked and distributed. At its core, rogue application remains pretty much the same. Removal instructions that were written for previous versions of this malware works perfectly fine too. If you think that some parts of the removal instructions are not accurate, please leave a comment below or simply email me.


Method 1: System Repair virus removal using debugged activation keys:

1. Use the activation keys given below to activate your copy of System Repair virus. This will allow you to download and run recommended anti-malware software and automatically restore hidden files and shortcuts. Don't worry, you're not doing anything illegal and it won't make the situation worse.

Use fake email and the following activation key:

08467206738602987934024759008355
56723489134092874867245789235982



2. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.


Method 2: System Repair removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



If you still can't see any of your files, Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter explorer and hit Enter or click OK.



2. Open Internet Explorer. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter iexplore.exe and hit Enter or click OK.

Download recommended anti-malware software (direct download) and run a full system scan.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe. Don't forget to update the installed program before scanning.

3. Open Internet Explorer and download TDSSKiller or Backdoor.Tidserv Removal Tool. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller or Backdoor.Tidserv Removal Tool to remove the rootkit.




Method 3: Manual System Repair removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



2. The rogue application places an icon or your desktop. Right click on the icon, click Properties in the drop-down menu, then click the Shortcut tab.



The location of the malware is in the Target box.



On computers running Windows XP, malware hides in:
C:\Documents and Settings\All Users\Application Data\

NOTE: by default, Application Data folder is hidden. Malware files are hidden as well. To see hidden files and folders, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmark from the checkbox labeled:

- Hide extensions for known file types
- Hide protected operating system files

Click OK to save the changes. Now you will be able to see all files and folders in the Application Data directory.

On computers running Windows Vista/7, malware hides in:
C:\ProgramData\

3. Look for suspect ".exe" files in the given directories depending on the Windows version you have.

Example Windows XP:
C:\Documents and Settings\All Users\Application Data\16441124.exe
C:\Documents and Settings\All Users\Application Data\fWpYMRQgdRYv.exe

Example Windows Vista/7:
C:\ProgramData\16441124.exe
C:\ProgramData\fWpYMRQgdRYv.exe

Basically, there will be a couple of ".exe" file named with a series of numbers or letters.



Rename those files to 16441124.vir, fWpYMRQgdRYv.vir etc. For example:



It should be: C:\Documents and Settings\All Users\Application Data\16441124.vir

Instead of: C:\Documents and Settings\All Users\Application Data\16441124.exe

4. Restart your computer. The malware should be inactive after the restart.


5. Download recommended anti-malware software (direct download) and run a full system scan.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe. Don't forget to update the installed program before scanning.


6. Open Internet Explorer and download TDSSKiller or Backdoor.Tidserv Removal Tool. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller and remove the rootkit.




Associated System Repair files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\System Repair.lnk
  • %UsersProfile%\Start Menu\Programs\System Repair\
  • %UsersProfile%\Start Menu\Programs\System Repair\System Repair.lnk
  • %UsersProfile%\Start Menu\Programs\System Repair\Uninstall System Repair.lnk
%AllUsersProfile% refers to: C:\Documents and Settings\All Users
%UserProfile% refers to: C:\Documents and Settings\[User Name]

Windows Vista/7:
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\System Repair.lnk
  • %UsersProfile%\Start Menu\Programs\System Repair\
  • %UsersProfile%\Start Menu\Programs\System Repair\System Repair.lnk
  • %UsersProfile%\Start Menu\Programs\System Repair\Uninstall System Repair.lnk
%AllUsersProfile% refers to: C:\ProgramData
%UserProfile% refers to: C:\Users\[User Name]

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
Share this information with other people:

Tuesday, July 12, 2011

Are there any safe adult websites that won't give my computer a virus?

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
This summary is not available. Please click here to view the post.

Friday, July 8, 2011

Remove Windows XP Fix, Windows Vista Fix or Windows 7 Fix (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows XP Fix, Windows Vista Fix or Windows 7 Fix (depending on the version of Windows that your computer is running) is a fraudulent system optimization program that displays quite legitimate looking but unfortunately fake pop-up window warnings designed to scare you into thinking your computer has some really serious hardware and software issues. It generates dozens of erroneous infections or Windows stability issues and blocks legitimate applications to trick you into participating in fraudulent transactions.



Windows XP Fix, Windows Vista Fix claims that you should pay for a license to the rogue program in order to fix system errors, clean your registry and protect your computer against new threats with software updates. It's probably one of the most annoying and troublesome scareware that we've seen so far. Windows XP Fix moves software shortcuts found in various directories to Windows temporary folder, specifically %Temp%\smtmp, %Temp% refers to Windows temporary folder. What is more, the rogue application adds +h or otherwise known as hidden attribute to some of your files on folders. It's obvious that Windows Vista Fix or Windows 7 Fix wants to make you think that your files were deleted because of critical hard drive and system errors but at the same time it states that they could be restored if you pay for a full version of the rogue software. To remove Windows XP Fix, Windows Vista Fix or Windows 7 Fix from your computer and restore your files, please follow the steps in the removal guide below.

Here are some examples of a warning pop-up windows from this rogue program:







First of all, do not delete anything from Windows temporary folder; otherwise you won't be able to restore your software shortcuts and some other files. I'm saying this because I know that some of you guys use CCleaner or similar software to remove files from %Temp% folder that could be associated with malicious software. Although, that's a good idea when it comes to computer viruses, but Windows XP Fix is an entirely different side of the story. But that's not all, Windows XP Fix, Windows Vista Fix, Windows 7 Fix or in some cases malware droppers install the TDSS rookit as well. It could be either TDL3 or TDL4 version of this rootkit which is probably the most sophisticated piece of malicious software that I've ever seen. I think it should be already obvious that it's very hard or even impossible to remove this rogue application and associated malware manually. You will have to use anti-malware software and TDSS rootkit removal tools, either TDSSKiller from Kasperky lab Norton TDSS removal tool. For more information, please follow the removal steps below.

Additionally, you can activate the rogue program by entering this registration code 8475082234984902023718742058948 and any email as shown in the image below.



Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly. If you have any further questions, please leave a comment below. Good luck and be safe online!

Related malware:

Windows XP Fix, Windows Vista Fix or Windows 7 Fix removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



If you still can't see any of your files, Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter explorer and hit Enter or click OK.



2. Open Internet Explorer. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter iexplore.exe and hit Enter or click OK.

Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. Open Internet Explorer and download TDSSKiller or Backdoor.Tidserv Removal Tool. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller or Backdoor.Tidserv Removal Tool to remove the rootkit.




Alertane Windows XP Fix, Windows Vista Fix or Windows 7 Fix removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



2. The rogue application places an icon or your desktop. Right click on the icon, click Properties in the drop-down menu, then click the Shortcut tab.



The location of the malware is in the Target box.



On computers running Windows XP, malware hides in:
C:\Documents and Settings\All Users\Application Data\

NOTE: by default, Application Data folder is hidden. Malware files are hidden as well. To see hidden files and folders, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmark from the checkbox labeled:

- Hide extensions for known file types
- Hide protected operating system files

Click OK to save the changes. Now you will be able to see all files and folders in the Application Data directory.

On computers running Windows Vista/7, malware hides in:
C:\ProgramData\

3. Look for suspect ".exe" files in the given directories depending on the Windows version you have.

Example Windows XP:
C:\Documents and Settings\All Users\Application Data\24436516.exe
C:\Documents and Settings\All Users\Application Data\jTNIGvyiwfxUlB.exe

Example Windows Vista/7:
C:\ProgramData\24436516.exe
C:\ProgramData\jTNIGvyiwfxUlB.exe

Basically, there will be a couple of ".exe" file named with a series of numbers or letters.



Rename those files to 24436516.vir, jTNIGvyiwfxUlB.vir etc. For example:



It should be: C:\Documents and Settings\All Users\Application Data\24436516.vir

Instead of: C:\Documents and Settings\All Users\Application Data\24436516.exe

4. Restart your computer. The malware should be inactive after the restart.

5. Open Internet Explorer and download TDSSKiller. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller and remove the rootkit.



6. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

7. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated Windows XP Fix, Windows Vista Fix or Windows 7 Fix files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Windows XP Fix.lnk
  • %UsersProfile%\Start Menu\Programs\Windows XP Fix\
  • %UsersProfile%\Start Menu\Programs\Windows XP Fix\Windows XP Fix.lnk
  • %UsersProfile%\Start Menu\Programs\Windows XP Fix\Uninstall Windows XP Fix.lnk
%AllUsersProfile% refers to: C:\Documents and Settings\All Users
%UserProfile% refers to: C:\Documents and Settings\[User Name]

Windows Vista/7:
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Windows Vista Fix.lnk
  • %UsersProfile%\Start Menu\Programs\Windows Vista Fix\
  • %UsersProfile%\Start Menu\Programs\Windows Vista Fix\Windows Vista Fix.lnk
  • %UsersProfile%\Start Menu\Programs\Windows Vista Fix\Uninstall Windows Vista Fix.lnk
%AllUsersProfile% refers to: C:\ProgramData
%UserProfile% refers to: C:\Users\[User Name]

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
Share this information with other people:

"System process at address 0x3BC3 have just crashed" Ransomware Removal

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
"System process at address 0x3BC3 have just crashed, please follow these steps to deactivate it from your system." is a fraudulent system error warning that alerts users of an erroneous system risk and then prompts users to call the premium-rate phone numbers above to resolve the apparent issue. This fake error warning clearly indicates that there is a Trojan infection on your computer. The "System process at address 0x3BC3 have just crashed" message appears on a light blue screen just as Windows loads up. It blocks Task Manager and other system tools. Unfortunately, it takes over your computer screen in Safe Mode and Safe Mode with Networking too. Hopefully, it will let you to start your computer in Safe Mode with Networking so that you can follow the general Trojan.Ransomware removal guide. You can also use your Windows CD to repair your computer if you have it or download a Rescue Disk on another computer and then clean the infected one. For more information, please follow this removal guide. However, before proceeding to the manual removal instructions, you should try to unlock your computer by entering this code: 754-896-324-589-742. It might just work!



A screen shot of the "System process at address 0x3BC3 have just crashed" error warning:



Related malware:
Share the knowledge:

Wednesday, July 6, 2011

How to Remove Anti-Malware Lab (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Anti-Malware Lab is a rogue anti-virus application designed to scare you into buying bogus security products. It produces fake scan results and displays misleading security alerts to make you think you have a virus infection. The fake antivirus program then prompts you to pay for a full version of the Anti-Malware Lab to remove non-existent infections and to protect your computer against spyware, Trojans and other malicious software. Although such rogue antivirus programs as AntiMalware Lab have become increasingly common in a last few years, users may still fall victim to these scams because fake antivirus programs are designed to appear as legitimate as possible. Some of these fake AVs are even made to look like legitimate anti-virus applications as where Anti-Malware Lab looks more like a Windows Security scanner. Cyber crooks usually rely on visitors to wittingly install this bogus security application. They do this through social engineering most of the time. However, Anti-Malware Lab is also distributed through the use of Trojan horses, drive-by downloads that are able to install the rogue application without your interaction and other malware. If your computer is infected with this scareware, please follow the steps in the removal guide below to remove Anti-Malware Lab and any associated malware.



Anti-Malware Lab is from the same malware family as PC Security Guardian, Best Malware Protection and some other rogue AVs. The rogue application is configured to that run automatically when Windows starts. It may report up to twenty fake infections, e.g., Trojan-IM.Win32.Faker.a, Virus.BAT.Gray.705, Trojan-PSW.Win32.Dripper and many other non-existent threats. Below are a number of different images of fake security alerts that you may run across.



It also displays fake security alerts and notifications saying that your computer is infected or under attack from a remote machine. Basically, Anti-Malware Lab uses misleading security alerts to frighten you into purchasing worthless security software. If you have already purchased this this rogue applications, you should requested a refund from a fake antivirus firm if they provide contact information and also you should contact their credit card provider to dispute the charges. They even have their own support center.



OPTIONAL: In case you can't boot your PC in Safe Mode with Networking or you can't delete the malicious files manually, you can use this code U2FD-S2LA-H4KA-UEPB to register the rogue application in order to stop the fake security alerts. Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly. If you need help in removing Personal Shield Pro from your computer, please leave a comment below.

Anti-Malware Lab is not a virus and it can't log you keystrokes or delete your files. It's a low risk threat but you should uninstall this fake anti-virus program from your computer as soon as possible because it may download additional malware onto your computer and this is especially true if it comes bundled with Trojan downloaders. Last, but not least, may configure Internet Explorer to use a proxy over a LAN connection, so it pretty much hijacks the default web browser. To remove Anti-Malware Lab from from your computer, please follow the removal instructions below. If you need help removing this scarware, you can leave a comment below. Good luck and safe online!


Anti-Malware Lab removal instructions:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK. You may have to repeat steps 1-2 if you will have problems downloading malware removal programs.



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Alternate Anti-Malware Lab removal instructions using HijackThis or Process Explorer (in Normal mode):

1. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK.



2. Download Process Explorer.
3. Rename procexp.exe to iexplore.exe and run it. Look for similar process in the list and end it:
  • DMg4a_358.exe
OR download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it. Search for similar entries in the scan results:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:24525
O4 - HKCU\..\Run: [Anti-Malware Lab] "C:\Documents and Settings\All Users\Application Data\b3a2c8\DMg4a_358.exe" /s /d
Select all similar entries and click once on the "Fix checked" button. Close HijackThis tool.

4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated Anti-Malware Lab files and registry values:

Files:

Windows XP
  • C:\Documents and Settings\All Users\Application Data\b3a2c8\
  • C:\Documents and Settings\All Users\Application Data\b3a2c8\DMg4a_358.exe
  • C:\Documents and Settings\All Users\Application Data\b3a2c8\PSGSys
  • C:\Documents and Settings\All Users\Application Data\b3a2c8\Quarantine Items
  • C:\Documents and Settings\All Users\Application Data\b3a2c8\PSG.ico
  • C:\Documents and Settings\[UserName]\Application Data\Anti-Malware Lab\
Windows Vista/7
  • C:\ProgramData\b3a2c8
  • C:\ProgramData\b3a2c8\PSGSys
  • C:\ProgramData\b3a2c8\Quarantine Items
  • C:\ProgramData\b3a2c8\DMg4a_358.exe
  • C:\ProgramData\b3a2c8\PSG.ico
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Malware Lab
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Anti-Malware Lab"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
  • HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes\URL http://findgala.com/?&uid=247&q={searchTerms}
Share this information with other people:

 
//PART 2