Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post. - BleepingComputer Management |
This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.
If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic: Preparation Guide For Use Before Posting A Hijackthis Log
![]() ![]() |
Dec 30 2006, 10:54 PM
Post
#1
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 29,367 Joined: 24-January 04 From: USA Member No.: 3 |
How to remove Kill & Clean and SpyMarshal (Removal Instructions) What this program does: Kill & Clean and SpyMarshal are rogue anti-spyware applications that install rootkits, other malware, fake autostarts to the Windows Registry, display fake scan results, and provides misleading information. When Kill and Clean or SpyMarshal is installed on your computer it will install random autostart entries into the Windows Registry that appear to be malware related. These entries, though, are not real and are only added so that the program can find them and state that you are infected. When you try to clean them, it states that you need to purchase the full version of the program in order to clean them. This is obviously a tactic used in order to scare you into buying their software. Needless to say, you should not purchase Kill & Clean or SpyMarshal. Due to the fact that Kill & Clean and SpyMarshal install random names for the fake entries it installs in the Registry, this guide can not remove these essentially harmless but unwanted entries. What this guide will do, though, is allow you to determine if you have this software installed, remove the rootkit and its associated infectors, and remove Kill & Clean itself. To further remove the fake random entries from your Windows Registry we suggest you follow the instructions at the link below to post a HijackThis log. When posting the log please reference this guide so people understand why you are posting the log. Preparation Guide For Use Before Posting A Hijackthis Log [Link] ![]() Kill & Clean Screenshot Tools Needed for this fix: Symptoms in a HijackThis Log (Not all of these symptoms may be in the same log): O4 - HKCU\..\Run: [KillAndClean] C:\Program Files\KillAndClean\KillAndClean.exe O4 - HKCU\..\Run: [SpyMarshal] C:\Program Files\SpyMarshal\SpyMarshal.exe O9 - Extra button: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - C:\Program Files\KillAndClean\KillAndClean.exe (HKCU) O9 - Extra 'Tools' menuitem: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - C:\Program Files\KillAndClean\KillAndClean.exe (HKCU) Sample of fake malware entries in a HijackThis Log: R3 - URLSearchHook: (no name) - {AF083D28-2650-CA80-E017-41974D7AA625} - Brong32.dll (file missing) R3 - URLSearchHook: (no name) - {4CFA5D1A-8050-F260-9AC4-BAB092DBF7D9} - sound64.dll (file missing) R3 - URLSearchHook: (no name) - {1C722BC0-0EAB-39B1-8483-391EAE7B189B} - NsCplTray.dll (file missing) R3 - URLSearchHook: (no name) - {4A67DB37-F1C1-68C8-3AEA-818C7C21D5D0} - msag.dll (file missing) O4 - HKLM\..\Run: [avpmondll] ABCXYZ.exe O4 - HKLM\..\Run: [MONITER] ERTYDF.exe O4 - HKCU\..\Run: [SYSTRAV] clamav.exe O4 - HKCU\..\Run: [nmdllw] XTermInit.exe O4 - HKCU\..\Run: [typeconf] PasswdMon.exe O4 - HKLM\..\Run: [NSYSCPLSTR] MON76234.exe O4 - HKLM\..\Run: [XTermInit] MONITER.exe O4 - HKCU\..\Run: [uio] EXE32EXE.exe O4 - HKCU\..\Run: [KeywordFinder] ssweeper.exe O4 - HKCU\..\Run: [SpyElim] sysconf16.exe O4 - HKLM\..\Run: [cnftips] AppMasterCenter.exe O4 - HKLM\..\Run: [TForm1] 34763.exe O4 - HKCU\..\Run: [bingo9] sysconf16.exe O4 - HKCU\..\Run: [install2] TorontoMail.exe O4 - HKCU\..\Run: [NsCplTray] KeywordFinder.exe O4 - HKLM\..\Run: [WTFCTF] newbreed.exe O4 - HKLM\..\Run: [progmen] ABCXYZ.exe O4 - HKCU\..\Run: [driver32] nmdllw.exe O4 - HKCU\..\Run: [gabber] Serviceprocess.exe O4 - HKCU\..\Run: [sysmon12] ftbar.exe Revision History No revisions. Kill and Clean and SpyMarshal Removal Instructions: Please note that these instructions may appear to be very long, but in reality it should not take too long to complete. The reason the instructions appear long is because we have provided as much detail as possible when writing this fix.
The Kill & Clean or SpyMarshal infection should now be removed from your computer. It is still advised that you post a HijackThis log to further clean up the fake random entries in your Windows Registry. Once again the guide on how to post a HijackThis log is below. Preparation Guide For Use Before Posting A Hijackthis Log [Link] This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you. -------------------- Lawrence
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2008 - 04:51 AM |