Home > General > Http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2


When the scan is complete, click OK, then Show Results to view the results. File delete failed. This will result in fewer programs running when you boot your system, and should improve preformance.If that does not work, you can try the steps mentioned in Slow Computer/browser? Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dllO3 - Toolbar: AVG Security Toolbar - his comment is here

These registry keys and values are respectively listed in the Registry Keys and Registry Values sections on this page.For instructions on deleting the softwarereferral.com registry keys and registry values, see the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\iiffedut -> Quarantined and deleted successfully. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> Quarantined and deleted successfully. Are things running okay? Back to top BC AdBot (Login to Remove) BleepingComputer.com Register to remove ads #2 Shaba Shaba Koutsi Members 7,872 posts OFFLINE Gender:Male Location:Finland Local time:08:31 PM Posted 03 September

If you are using Windows VistaClick the "Start Menu" (or Windows Orb)Click "All Programs"Click "Windows Update"On the left, choose "Change Settings"Ensure that the checkbox "Use Microsoft Update" at the bottom of HKEY_CLASSES_ROOT\TypeLib\{d6450504-f78d-4107-90d1-754001c42ca4} (Trojan.FakeAlert) -> Quarantined and deleted successfully. This applies only to the original topic starter. Because of this, spyware, malware and adware often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.To

Install Malwarebytes Anti-Malware which does not seem to be able to solve the I.E problem.3. Simply download this tool to your desktop and run it. You will be prompted : “Registry cleaning - Do you want to clean the registry ?“; answer “Yes” by typing Y and press “Enter” in order to remove the Desktop background I have not tried ComboFix.exe as it seems risky..

The tool will now check if wininet.dll is infected. Please see here for instructionshow to install HijackThis and make a logfile. And for the online scan log... # version=4 # OnlineScanner.ocx= # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3520 (20081014) # vers_arch_module=1.064 (20080214) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3.

  1. That's good news.
  2. Using the site is easy and fun.
  3. C:\Documents and Settings\Simon\Local Settings\Temp\lwpwer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
  4. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\nmdjvi.dll (Trojan.Vundo.H) -> Delete on reboot.

or read our Welcome Guide to learn how to use this site. Sometimes adware is attached to free software to enable the developers to cover the overhead involved in created the software. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then C:\DOCUME~1\Desmond\LOCALS~1\Temp\Perflib_Perfdata_594.dat scheduled to be deleted on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{58e6b017-b79c-4fd9-ad09-9ab8200bdc9f} (Trojan.FakeAlert) -> Quarantined and deleted successfully. Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.Keep Windows (and your other Microsoft software) up to The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other

Click here to Register a free account now! What I have done previously:1. HKEY_CLASSES_ROOT\CLSID\{8d3d10a9-46f3-4c21-a5c8-174270ccc3a2} (Trojan.Vundo.H) -> Delete on reboot. Several functions may not work.

Please re-enable javascript to access full functionality. Using SmitfraudFix (by S!Ri). When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Internet connection is totally stuffed following this - won't connect at all on the laptop but will connect through my nokia tablet, so think settings have gone awol !!

Check Here First; It May Not Be MalwareWe Need to Remove ComboFixPlease go to Start -> RunEnter "ComboFix /u" (without quotes). C:\DOCUME~1\Desmond\LOCALS~1\Temp\Perflib_Perfdata_4cc.dat scheduled to be deleted on reboot. C:\DOCUME~1\Desmond\LOCALS~1\Temp\~DFA1D2.tmp moved successfully. Sign In Sign Up Browse Back Browse Forums Guidelines Staff Online Users Members Activity Back Activity All Activity My Activity Streams Unread Content Content I Started Search Malwarebytes.com Back Malwarebytes.com Malwarebytes

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Double-click SmitfraudFix.exe. MS Antivirus appears to have cleared following first run of Malware but would be grateful for any more help / assistance. If your computer was infected, you got many popups, Internet Explorer start page changed to softwarereferral.com, blinking stopsign with X in system tray, continual system alert popups.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully. Then I ran SSD but this didn't find anything so haven't included the log. HKEY_CURRENT_USER\SOFTWARE\MicroAV (Rogue.MicroAntivirus) -> Quarantined and deleted successfully. Microsoft MVP Consumer Security Back to top #5 Dashimon Dashimon Topic Starter Members 19 posts OFFLINE Local time:01:31 PM Posted 01 October 2008 - 10:28 PM Hi shaba,Okie basically, I

Service fsbl-standalone deleted successfully. ========== FILES ========== C:\WINDOWS\DUMP4527.tmp moved successfully. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Note: If you need help with the instructions, then post your questions in our Spyware Removal forum. C:\WINDOWS\system32\iiffeDuT.dll (Trojan.Vundo.H) -> Delete on reboot.

Coops replied to Coops's topic in Resolved Malware Removal Logs Thanks for this. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. September 17, 2008 6 replies All Activity Home Coops Privacy Policy Contact Us Back to Top Malwarebytes Community Software by Invision Power Services, Inc. × Existing user? If your PC takes a lot longer than normal to restart or your Internet connection is extremely slow, your computer may well be infected with softwarereferral.com.New desktop shortcuts have appeared or

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2) Good: (http://www.google.com/) -> Quarantined and deleted successfully. If you are using Windows XP or earlier Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Press the number 2 on your keyboard and the press the enter key to choose the option Clean (safe mode recommended). C:\WINDOWS\system32\auuyaust.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

I will be posting the log soon.What I have discovered:1. This window consists of two panes. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.