Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Win 7 Antivirus Pro 2013 removal without internet
Message
<blockquote data-quote="kuttus" data-source="post: 105111" data-attributes="member: 2676"><p>Hi and welcome to the malwaretips.com forums!</p><p></p><p>I'm <strong>Kuttus</strong> and I am going to try to assist you with your problem. Please take note of the below: </p><ul> <li data-xf-list-type="ul">I will start working on your malware issues, this may or may not, solve other issues you have with your machine.</li> <li data-xf-list-type="ul">The fixes are specific to your problem and should only be used for this issue on this machine!</li> <li data-xf-list-type="ul">The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.</li> <li data-xf-list-type="ul">If you don't know, <strong>stop and ask</strong>! Don't keep going on.</li> <li data-xf-list-type="ul">Please reply to this thread. Do not start a new topic.</li> <li data-xf-list-type="ul">Refrain from running self fixes as this will hinder the malware removal process.</li> <li data-xf-list-type="ul">It may prove beneficial if you print of the following instructions or save them to notepad as I post them.</li> </ul><p><span style="color: #FF0000">Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.</span></p><p></p><p></p><p><span style="color: #0000CD"><strong>Before we start:</strong></span></p><p>Please be aware that removing malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop. </p><p></p><p><span style="font-size: 15px"><strong>Because of this, I advise you to backup any personal files and folders before you start.</strong> </span></p><p><hr /></p><p></p><p><span style="font-size: 18px"><strong><span style="color: #FF1493">Since there is no Internet Connection in the infected computer you have to download the following 2 tools and Registry Fix file in another computer and save it to a Flash Drive. Then connect the Flash Drive to the infected computer and run the tools.</span></strong></span></p><p></p><p><span style="font-size: 15px">STEP 1: Repair your Windows Registry from this infection malicious changes.</span></p><p></p><p>This infection has changed your Windows registry settings so that when you try to run a executable file (ending with .exe ) , it will instead launch the infection rather than the desired program.</p><p></p><ol> <li data-xf-list-type="ol"> Download the <em><strong>registryfix.reg</strong></em> file to fix the malicious registry changes from this infection.<br /> <a href="http://malwaretips.com/attachment.php?aid=1000" target="_blank">REGISTRYFIX.REG DOWNLOAD LINK</a> (This link will automatically download the registry fix called registryfix.reg)</li> <li data-xf-list-type="ol"> Double-click on registryfix.reg file to run it. <strong>Click “Yes”</strong> for Registry Editor prompt window,then <strong>click OK.</strong></li> </ol><p><hr /></p><p></p><p></p><p><span style="font-size: 15px">STEP 2: Run a scan with RogueKiller</span></p><p><ol></p><p> <li>Please <<strong>>download the latest official version of </<strong>><<strong>>RogueKiller</<strong>>.</strong></strong></strong></strong></p><p><strong><strong><strong><strong><a href="http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe" rel="nofollow" target="_blank"><strong>RogueKiller Download Link</strong></a> <em>(This link will automatically download RogueKiller on your computer)</em></li></strong></strong></strong></strong></p><p><strong><strong><strong><strong> <li><<strong>>Double click on RogueKiller.exe</<strong>> to start this utility and then <<strong>>wait for the Prescan to complete</<strong>>.This should take only a few seconds and then you can <<strong>>click the Start button</<strong>> to perform a system scan.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><img title="Click on the Start button to perform a system scan" src="http://malwaretips.com/blogs/wp-content/uploads/2012/04/roguek-1.png" alt="[Image: roguekiller-1.png]" width="600" height="450" border="0" /></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>After the scan has completed, <<strong>>press the Delete button</<strong>> to remove any malicious registry keys.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><img title="Press Delete to remove the malicious registry keys" src="http://malwaretips.com/blogs/wp-content/uploads/2012/04/roguek-2.png" alt="[Image: roguekiller-2.png]" width="600" height="450" border="0" /></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Next we will need to restore your shortcuts, <<strong>>so click on the ShortcutsFix button </<strong>>and allow the program to run.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><img title="Click on the Start button to perform a system scan" src="http://malwaretips.com/blogs/wp-content/uploads/2012/04/roguek-3.png" alt="[Image: roguekiller-1.png]" width="600" height="450" border="0" /></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></ol></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>The report has been created on the desktop.In your next reply please post: </strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> </strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>All RKreport.txt </strong> text files located on your desktop.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><hr /></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><span style="font-size: 15px">STEP 3: Run a scan with OTL by OldTimer</span></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><ol><li>Download the OTL utility using the below link : </strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><<strong>><a title="External link" href="http://oldtimer.geekstogo.com/OTL.exe" rel="nofollow external">OTL DOWNLOAD LINK</a> <em>(This link will automatically download OTL on your computer)</em></<strong>></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><img src="http://malwaretips.com/blogs/wp-content/uploads/2012/07/OTL-logo.png" alt="" title="OTL-logo" width="106" height="118" class="alignnone size-full wp-image-3946" /></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>When the window appears, <<strong>>underneath Output</<strong>> at the top change it to <<strong>>Minimal Output</<strong>>.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>Check the boxes beside <<strong>>LOP Check</<strong>> and <<strong>>Purity Check</<strong>>.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>Click the<<strong>> Run Scan</<strong>> button.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><img src="http://malwaretips.com/blogs/wp-content/uploads/2012/07/OTL.png" alt="" title="OTL" width="658" height="584" class="alignnone size-full wp-image-3945" /></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>When the scan completes, it will open two notepad windows. <<strong>>OTL.Txt</<strong>> and <<strong>>Extras.Txt</<strong>>. These are saved in the same location as OTL.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><<strong>>Please post this 2 logs in your first reply.</<strong>>.</li></ol></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><em><u>Settings You need to Select in OTL</u></em></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><ol> <li data-xf-list-type="ol"><em> Click the <strong>Scan All Users</strong> checkbox.</em></li> <li data-xf-list-type="ol"><em> Change <strong>Standard Registry</strong> to <strong>All</strong>.</em></li> <li data-xf-list-type="ol"><em> Check the boxes beside <strong>LOP Check</strong> and <strong>Purity Check.</strong></em></li> </ol><p><em>Note: If OTL.exe will not run, it may be blocked by malware. Try these alternate versions: <a title="External link" href="http://www.itxassociates.com/OT-Tools/OTL.scr" rel="nofollow external">OTL.scr</a>, or <a title="External link" href="http://oldtimer.geekstogo.com/OTL.com" rel="nofollow external">OTL.com</a>.</em></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><hr /></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p></blockquote><p></p>
[QUOTE="kuttus, post: 105111, member: 2676"] Hi and welcome to the malwaretips.com forums! I'm [b]Kuttus[/b] and I am going to try to assist you with your problem. Please take note of the below: [list] [*]I will start working on your malware issues, this may or may not, solve other issues you have with your machine. [*]The fixes are specific to your problem and should only be used for this issue on this machine! [*]The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. [*]If you don't know, [b]stop and ask[/b]! Don't keep going on. [*]Please reply to this thread. Do not start a new topic. [*]Refrain from running self fixes as this will hinder the malware removal process. [*]It may prove beneficial if you print of the following instructions or save them to notepad as I post them.[/list] [color=#FF0000]Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.[/color] [color=#0000CD][b]Before we start:[/b][/color] Please be aware that removing malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop. [SIZE=4][b]Because of this, I advise you to backup any personal files and folders before you start.[/b] [/SIZE] <hr /> [SIZE=5][b][color=#FF1493]Since there is no Internet Connection in the infected computer you have to download the following 2 tools and Registry Fix file in another computer and save it to a Flash Drive. Then connect the Flash Drive to the infected computer and run the tools.[/color][/b][/SIZE] [SIZE=4]STEP 1: Repair your Windows Registry from this infection malicious changes.[/SIZE] This infection has changed your Windows registry settings so that when you try to run a executable file (ending with .exe ) , it will instead launch the infection rather than the desired program. [list=1] [*] Download the [i][b]registryfix.reg[/b][/i] file to fix the malicious registry changes from this infection. [url=http://malwaretips.com/attachment.php?aid=1000]REGISTRYFIX.REG DOWNLOAD LINK[/url] (This link will automatically download the registry fix called registryfix.reg) [*] Double-click on registryfix.reg file to run it. [b]Click “Yes”[/b] for Registry Editor prompt window,then [b]click OK.[/b] [/list] <hr /> [SIZE=4]STEP 2: Run a scan with RogueKiller[/SIZE] <ol> <li>Please <[b]>download the latest official version of </[b]><[b]>RogueKiller</[b]>. <a href="http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe" rel="nofollow" target="_blank">[b]RogueKiller Download Link[/b]</a> [i](This link will automatically download RogueKiller on your computer)[/i]</li> <li><[b]>Double click on RogueKiller.exe</[b]> to start this utility and then <[b]>wait for the Prescan to complete</[b]>.This should take only a few seconds and then you can <[b]>click the Start button</[b]> to perform a system scan. <img title="Click on the Start button to perform a system scan" src="http://malwaretips.com/blogs/wp-content/uploads/2012/04/roguek-1.png" alt="[Image: roguekiller-1.png]" width="600" height="450" border="0" /></li> <li>After the scan has completed, <[b]>press the Delete button</[b]> to remove any malicious registry keys. <img title="Press Delete to remove the malicious registry keys" src="http://malwaretips.com/blogs/wp-content/uploads/2012/04/roguek-2.png" alt="[Image: roguekiller-2.png]" width="600" height="450" border="0" /></li> <li>Next we will need to restore your shortcuts, <[b]>so click on the ShortcutsFix button </[b]>and allow the program to run. <img title="Click on the Start button to perform a system scan" src="http://malwaretips.com/blogs/wp-content/uploads/2012/04/roguek-3.png" alt="[Image: roguekiller-1.png]" width="600" height="450" border="0" /></li> </ol> The report has been created on the desktop.In your next reply please post: [b]All RKreport.txt [/b] text files located on your desktop. <hr /> [SIZE=4]STEP 3: Run a scan with OTL by OldTimer[/SIZE] <ol><li>Download the OTL utility using the below link : <[b]><a title="External link" href="http://oldtimer.geekstogo.com/OTL.exe" rel="nofollow external">OTL DOWNLOAD LINK</a> <em>(This link will automatically download OTL on your computer)</em></[b]></li> <li>Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. <img src="http://malwaretips.com/blogs/wp-content/uploads/2012/07/OTL-logo.png" alt="" title="OTL-logo" width="106" height="118" class="alignnone size-full wp-image-3946" /></li> <li>When the window appears, <[b]>underneath Output</[b]> at the top change it to <[b]>Minimal Output</[b]>.</li> <li>Check the boxes beside <[b]>LOP Check</[b]> and <[b]>Purity Check</[b]>.</li> <li>Click the<[b]> Run Scan</[b]> button. <img src="http://malwaretips.com/blogs/wp-content/uploads/2012/07/OTL.png" alt="" title="OTL" width="658" height="584" class="alignnone size-full wp-image-3945" /></li> <li>When the scan completes, it will open two notepad windows. <[b]>OTL.Txt</[b]> and <[b]>Extras.Txt</[b]>. These are saved in the same location as OTL. <[b]>Please post this 2 logs in your first reply.</[b]>.</li></ol> [i][u]Settings You need to Select in OTL[/u] [list=1] [*] Click the [b]Scan All Users[/b] checkbox. [*] Change [b]Standard Registry[/b] to [b]All[/b]. [*] Check the boxes beside [b]LOP Check[/b] and [b]Purity Check.[/b] [/list][/i] <em>Note: If OTL.exe will not run, it may be blocked by malware. Try these alternate versions: <a title="External link" href="http://www.itxassociates.com/OT-Tools/OTL.scr" rel="nofollow external">OTL.scr</a>, or <a title="External link" href="http://oldtimer.geekstogo.com/OTL.com" rel="nofollow external">OTL.com</a>.</em> <hr />[/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b] [/QUOTE]
Insert quotes…
Verification
Post reply
Top