Jump to content

Dad Gummit do I need help - Malware Defender 2009


Shug7272

Recommended Posts

So a girl I work with got some shit on her pc at work. Not sure what it is. It looks like a spyware removal program. Its called Malware Defender 2009. It looks just like a program that pops up and scans, its not though. Seems to be pretty new. I need help getting it off. I have googled around and it looks like it is a new version of what was called Perfect Defender 2009 which is also malware. Any help is appreciated.

Link to solution - Thanks Tangle

Link to comment
Share on other sites

Did you delete  system restore too? Try deleting the program and system restore  in safe mode

Already did it.

Already used these links too.  :haha: Like I said the Personal Defender 2009 is a little different. The removal tools for it dont work on this "Malware Defender 2009". I have tried every tried and true trick in the book.... DANGIT!!! :tickedoff: :tickedoff:

Link to comment
Share on other sites

How about this page as a start....

http://www.threatexpert.com/report.aspx?md5=a33c9afba1683c2927a1cb18920be6ca

File System Modifications

    * The following files were created in the system:

# Filename(s) File Size File MD5 Alias

1 %System%conf.cfg 0 bytes 0xD41D8CD98F00B204E9800998ECF8427E (not available)

2 %System%queue.vdb 369,222 bytes 0xF5CE0E589E22755A887AD37E9ADE9758 (not available)

3 [file and pathname of the sample #1] 1,011,712 bytes 0xA33C9AFBA1683C2927A1CB18920BE6CA Virus.Win32.Fasec [ikarus]

Registry Modifications

    * The following Registry Keys were created:

          o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet

          o HKEY_LOCAL_MACHINESOFTWAREMalware Defender 2009

          o HKEY_LOCAL_MACHINESOFTWAREMalware Defender 2009Lic

    * The newly created Registry Value is:

          o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]

                + malwaredef = "[file and pathname of the sample #1]"

            so that [file and pathname of the sample #1] runs every time Windows starts

Link to comment
Share on other sites

How about this page as a start....

http://www.threatexpert.com/report.aspx?md5=a33c9afba1683c2927a1cb18920be6ca

File System Modifications

    * The following files were created in the system:

# Filename(s) File Size File MD5 Alias

1 %System%conf.cfg 0 bytes 0xD41D8CD98F00B204E9800998ECF8427E (not available)

2 %System%queue.vdb 369,222 bytes 0xF5CE0E589E22755A887AD37E9ADE9758 (not available)

3 [file and pathname of the sample #1] 1,011,712 bytes 0xA33C9AFBA1683C2927A1CB18920BE6CA Virus.Win32.Fasec [ikarus]

Registry Modifications

    * The following Registry Keys were created:

          o HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet

          o HKEY_LOCAL_MACHINESOFTWAREMalware Defender 2009

          o HKEY_LOCAL_MACHINESOFTWAREMalware Defender 2009Lic

    * The newly created Registry Value is:

          o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]

                + malwaredef = "[file and pathname of the sample #1]"

            so that [file and pathname of the sample #1] runs every time Windows starts

Thanks man, I already found that too. The weird thing is I dont have all of the same files, just a few.

try http://www.superantispyware.com

Make sure to run the updates on it first...

Will try, thanks. Thanks to all the replies.
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...