BleepingComputer.com: Win 7 anti-spyware 2011

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Win 7 anti-spyware 2011 FixNCR.reg doesn't seem to work

#1 User is offline   Richard75 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 14-May 11

Posted 14 May 2011 - 06:49 AM

Hi

I'm new to BleepingComputer but found you through Google when researching how to get rid of Win 7 Anti-spyware 2011 malware. Read the description of what to do at http://www.bleepingcomputer.com/virus-removal/remove-win-7-internet-security-2011 but the step to load FixNCR.reg didn't appear to work. Having run it from a memory stick, I got the message "Cannot import K:|FixNCR.reg. Not all data was successfully written to the registry. Some keys are open by the system or other processes." If I try to go to the page to download RKill, the malware just diverts away to a highjacked IE warning screen.

What do you recommend next?

Many thanks

Richard75

#2 User is offline   B-boy/StyLe/ 

  • Bleeping Freestyler
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,760
  • Joined: 28-September 09
  • Gender:Male
  • Location:Bulgaria

Posted 22 May 2011 - 06:08 AM

Hello Richard75 ! Welcome to BleepingComputer Forums! :welcome:


My name is Georgi and and I will be helping you with your computer problems.


Before we begin, please note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The logs can take some time to research, so please be patient with me.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • Please do not run any tools until requested ! The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.
  • Please perform all steps in the order received. If you can't understand something don't hesitate to ask.
  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. I will not help you if you do not follow my instructions.




To protect your clean computer, please use Flash Disinfector

Download Flash_Disinfector.exe by sUBs from >here< and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.


Note: If using Firefox right-click on any download links and choose Save As

Please download OTH to your flashdrive
Please download OTL to your flashdrive

Move the flashdrive to your infected computer.

Double click the OTH file to run it and click Kill All Processes, your desktop will go blank.

Posted Image

Then select Start OTL. OTL will now run

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

  • Click the Internet Explorer button, post these logs in your Virus Removal topic.


If needed use your other computer to post the logs (they are saved on your flashdrive)



Regards,
Georgi
Posted Image

I'll be unavailable for the next 2 days. (26 and 27 may).
I will reply at Monday (28 may). Sorry for the inconvenience!

#3 User is offline   B-boy/StyLe/ 

  • Bleeping Freestyler
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,760
  • Joined: 28-September 09
  • Gender:Male
  • Location:Bulgaria

Posted 26 May 2011 - 05:34 AM

Hi Richard75 ,



It's been several days. Do you still need help on this?
This thread will be closed if you don't respond within 48 hours.



Regards,
Georgi
Posted Image

I'll be unavailable for the next 2 days. (26 and 27 may).
I will reply at Monday (28 may). Sorry for the inconvenience!

#4 User is offline   B-boy/StyLe/ 

  • Bleeping Freestyler
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 2,760
  • Joined: 28-September 09
  • Gender:Male
  • Location:Bulgaria

Posted 29 May 2011 - 09:00 PM

Due to the lack of feedback, this topic is now closed.
In the event you still have problems, please send a Private Message to any Moderator or the Malware Helper who replied to you here and ask them to reopen this topic within the next 5 days.
Posted Image

I'll be unavailable for the next 2 days. (26 and 27 may).
I will reply at Monday (28 may). Sorry for the inconvenience!

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users