Removing pc-antispyware

By supertramp
Apr 12, 2008
  1. Have followed your instructions regarding the installation of below, please advise further instructions

    thanks and best regards Supertramp

    Malwarebytes' Anti-Malware 1.11
    Database version: 619

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 84495
    Time elapsed: 30 minute(s), 37 second(s)

    Memory Processes Infected: 3
    Memory Modules Infected: 0
    Registry Keys Infected: 7
    Registry Values Infected: 3
    Registry Data Items Infected: 0
    Folders Infected: 35
    Files Infected: 376

    Memory Processes Infected:
    C:\WINNT\system32\stipgtil.exe (Trojan.FakeAlert) -> Unloaded process successfully.
    C:\Documents and Settings\All Users\Application Data\gjgnsviv\oxspmjiv.exe (Trojan.FakeAlert) -> Unloaded process successfully.
    C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe (Rogue.AntiSpywareBot) -> Unloaded process successfully.

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{5b9512a7-c919-4035-a08d-8888aa6f5f7a} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{56621883-5d73-4fb4-9595-f290095fdafb} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{c72c7e28-1cd2-468b-8bf1-7da221e4e67a} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{28b80552-f693-48ae-92ce-132b7250de35} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\mwc (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VideoPlugin (Trojan.Fakealert) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uvwjghhp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\XO1VrDu015 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)
  2. kimsland

    kimsland Ex-TechSpotter Posts: 14,525

    Did you also try: SuperAntiSpyware Free
    • Launch SuperAntiSpyware
    • Click Check for Updates and update to the latest definitions.
    • Click Scan your Computer

    • Check all boxes in the Scan Location box.
    • Check the Complete Scan radio button.
    • Click Scanning Preferences/Control Centre button.
    • Uncheck Ignore files larger than 4MB (recommended)
    • Check Scan Alternate Data Streams.
    • Click Close.
    • Click Next
    • SuperAntiSpyware will now scan your computer for infection. (This could take in excess of an hour depending on the number of files scanned)
    • When finished it will present you with a summary of its findings.
    • Click OK.
    • The Removal Screen will open.
    • Check the items in the list to mark them for Quarantine.
    • Click Next and SAS will Quarantine them.

    pc-antispyware should be fully removed by now
  3. supertramp

    supertramp TS Rookie Topic Starter

    thanks kimsland Malware seems to have done the trick, but if i get any further threats will try Superantispyware

  4. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Your not clean

    Highjackthis Instructions
    • Make sure you have the LATEST version of HJT (currently v2.0.0.2) it can be downloaded from HERE
    • Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. Please don't change the directory.
    • After installing, the program launches automatically, select Scan now and save a log
    • After the scan is complete please attach your log onto the forums using the paper clip icon above your reply.
Topic Status:
Not open for further replies.

Similar Topics

Create an account or login to comment

You need to be a member in order to leave a comment
TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...

Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.