Removing pc-antispyware

By supertramp
Apr 12, 2008
  1. Have followed your instructions regarding the installation of below, please advise further instructions

    thanks and best regards Supertramp

    Malwarebytes' Anti-Malware 1.11
    Database version: 619

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 84495
    Time elapsed: 30 minute(s), 37 second(s)

    Memory Processes Infected: 3
    Memory Modules Infected: 0
    Registry Keys Infected: 7
    Registry Values Infected: 3
    Registry Data Items Infected: 0
    Folders Infected: 35
    Files Infected: 376

    Memory Processes Infected:
    C:\WINNT\system32\stipgtil.exe (Trojan.FakeAlert) -> Unloaded process successfully.
    C:\Documents and Settings\All Users\Application Data\gjgnsviv\oxspmjiv.exe (Trojan.FakeAlert) -> Unloaded process successfully.
    C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe (Rogue.AntiSpywareBot) -> Unloaded process successfully.

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{5b9512a7-c919-4035-a08d-8888aa6f5f7a} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{56621883-5d73-4fb4-9595-f290095fdafb} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{c72c7e28-1cd2-468b-8bf1-7da221e4e67a} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{28b80552-f693-48ae-92ce-132b7250de35} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\mwc (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VideoPlugin (Trojan.Fakealert) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uvwjghhp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\XO1VrDu015 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)
  2. kimsland

    kimsland Ex-TechSpotter Posts: 14,524

    Did you also try: SuperAntiSpyware Free
    • Launch SuperAntiSpyware
    • Click Check for Updates and update to the latest definitions.
    • Click Scan your Computer

    • Check all boxes in the Scan Location box.
    • Check the Complete Scan radio button.
    • Click Scanning Preferences/Control Centre button.
    • Uncheck Ignore files larger than 4MB (recommended)
    • Check Scan Alternate Data Streams.
    • Click Close.
    • Click Next
    • SuperAntiSpyware will now scan your computer for infection. (This could take in excess of an hour depending on the number of files scanned)
    • When finished it will present you with a summary of its findings.
    • Click OK.
    • The Removal Screen will open.
    • Check the items in the list to mark them for Quarantine.
    • Click Next and SAS will Quarantine them.

    pc-antispyware should be fully removed by now
  3. supertramp

    supertramp TS Rookie Topic Starter

    thanks kimsland Malware seems to have done the trick, but if i get any further threats will try Superantispyware

  4. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Your not clean

    Highjackthis Instructions
    • Make sure you have the LATEST version of HJT (currently v2.0.0.2) it can be downloaded from HERE
    • Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. Please don't change the directory.
    • After installing, the program launches automatically, select Scan now and save a log
    • After the scan is complete please attach your log onto the forums using the paper clip icon above your reply.
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...