Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.
If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic: Preparation Guide For Use Before Posting A Hijackthis Log
Jul 13 2006, 04:20 PM
Post
#1
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 32,139 Joined: 24-January 04 From: USA Member No.: 3 |
How To Remove Systemdoctor 2006, System Doctor, and Messenger Blocker What this program does: SystemDoctor 2006 is a rogue anti-spyware application that gets installed by Spyware/malware without asking for permission. This infection can also be accompanied by other malware that changes your desktop background to a fake warning or by Trojans that issue fake taskbar security alerts. These are all used as a scare tactic to have you purchase their commercial software. System Doctor may also install a rogue security software called Messenger Blocker. Messenger Blocker is a program that supposed protects you from popups to the Windows Messenger service. After its 7 day trial, though, it will actually turn on your Messenger service if it was already off, and spam advertisements to it. The files you need to remove for this addition have been added to the guide as well. A screenshot of SystemDoctor can be seen below.
System Doctor 2006 Symptoms in a HijackThis Log: O4 - HKLM\..\Run: [SystemDoctor 2006 Free] C:\Program Files\SystemDoctor 2006 Free\sd2006.exe -scan O4 - HKLM\..\Run: [dc6_check] C:\Program Files\SystemDoctor 2006 Free\dcmon.exe O4 - HKLM\..\Run: [USDR6cw] C:\Program Files\SystemDoctor 2006 Free\USDR6cw.exe -c O4 - HKLM\..\Run: [cmonitor] C:\Program Files\SystemDoctor 2006 Free\pasmon.exe O4 - HKCU\..\Run: [AdwareProtector] C:\Program Files\SystemDoctor 2006\AdwareProtector.exe O4 - HKLM\..\Run: [System Doctor Free] C:\Program Files\System Doctor Free\systemdoc.exe -scan O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\System Doctor\dcmon.exe" O4 - HKLM\..\Run: [InternetService] C:\Program Files\Common Files\System\isvc.exe O4 - HKLM\..\Run: [SystemDoctor Free] C:\Program Files\System Doctor Free\systemdoc.exe /min O4 - HKLM\..\Run: [WindowsExplorer] C:\Program Files\Common Files\System\csrss.exe O4 - HKLM\..\Run: [SystemData] C:\Program Files\MBlocker\MBlocker.exe -c O4 - HKLM\..\Run: [WindowsFirewall] C:\Program Files\Common Files\System\lsass.exe Revision History 11/13/06 - Added new symptoms from a HJT log. 10/11/07 - Updated for new version and MessengerBlocker Removal Instructions: In order to remove this infection we will need to use HijackThis to manually remove the infection:
Your computer should now be free of System Doctor 2006, System Doctor, and MessengerBlocker. It is possible, though, that this infection was installed with other malware. If you need help removing it, post a hijackthis log in the forums. This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you. |