Antimalware doctor removal tool?

Discussion in 'Application Software' started by gorski, Sep 22, 2010.

  1. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    My wife has the newest modified version... :eek:

    Help, please... KIS, NOD etc. are useless...:confused:

    Cheers!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. tcntad

    tcntad MDL Guru

    Oct 26, 2009
    4,488
    1,506
    150
    Tell her to stop pr0nsurf :p..

    WHy did she get it to begin with? Start in safemode and do a fullsearch scan using any fully updated AV and then MBAM for example or Superantispyware.
     
  3. urie

    urie Moderator
    Staff Member

    May 21, 2007
    9,039
    3,388
    300
  4. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    I am neither lazy, nor stupid, thanx a bunch! :p

    She got it searching for Montalbano subs on some Aussie TV website...

    As I said, it's the latest variant and only really good techies can know, I suppose...

    Why? KIS, NOD etc. are not helping at all, not seeing it all, which is a downer! KIS is updating every hour - for no apparent use right now...

    Can't go into safe mode... It's blocking a lot of stuff, fooling all the security SW I have, from KIS2010 to W7 Manager, Ccleaner and now I am trying NOD32 online scanner, then it will be Avira's turn and so on...

    I suppose I will have to try booting from USB or CD [Hiren] but the latter might not be current...

    The "delete the following Registry entries" advice was also useless...

    It's not going anywhere, sadly....

    So, any REAL ideas, please?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,527
    4,112
    270
    Unsure what your asking. If you experience something bad did you try a system restore?
     
  6. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    #6 gorski, Sep 22, 2010
    Last edited: Sep 22, 2010
    (OP)
    Btw, none of it applies in the exact same manner, as it's "mutating",,,

    Even the names of the files are different:

    Process Manager in W7 Manager, as well as Windows' Task Manager [can't see anything], sees "handlerfix70700en00.exe"... and not what you see on those websites!

    So, deep guano, it seems...

    I hope erasing the partition, reformatting etc. would do, if this forum discussion doesn't...
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    Never do a sys restore, me...
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,527
    4,112
    270
    So you have a virus or something. Have you tried malwarebytes or are you just going for a reinstall?

    :D
     
  9. NoJuan999

    NoJuan999 Experienced SLIC Tool Operator

    Jul 31, 2009
    9,918
    1,935
    300
  10. urie

    urie Moderator
    Staff Member

    May 21, 2007
    9,039
    3,388
    300
    Timesurfer i have dealt with this before you need to stop the processes running before you can even run malwarebytes.
     
  11. urie

    urie Moderator
    Staff Member

    May 21, 2007
    9,039
    3,388
    300
  12. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,527
    4,112
    270
    Cool that was neat learning that. Noticed you now have green link. Does that cost extra :eek:...lol
     
  13. urie

    urie Moderator
    Staff Member

    May 21, 2007
    9,039
    3,388
    300
    Yeah I think Green are the good guys and but we need to watch out for the guys in Red :D
     
  14. NoJuan999

    NoJuan999 Experienced SLIC Tool Operator

    Jul 31, 2009
    9,918
    1,935
    300
  15. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    Not so, at least in my experience. I tried and failed. Maybe it's me but I read about it a lot before I wrote about it here.

    As I said, the darn thing mutated in the meantime. Just as there was no easy way to sort it out initially, when it appeared, so it is rather difficult now, too... A new thing and passes KISS etc. defences... It blocks all sorts of stuff. Can't be stopped, as a process. I am still going with various tools but for now, nothing worked. It's still there after scanning, rebooting and deleting registry entries etc.

    My wife, unlike me, didn't have NoScript in her FF. No IE8 for me or her, mind.

    @ All, thank you kindly for your contributions!!! :)

    Will keep you posted... ;)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    Well, whaddya know... I stand corrected.

    One of them did the right thing. Sadly, it wasn't "my" KIS2010 but NOD32 Online Scanner. Found it, removed it. Rebooted. Not there! Elegant. Simple for users. As it should be... :)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  17. NoJuan999

    NoJuan999 Experienced SLIC Tool Operator

    Jul 31, 2009
    9,918
    1,935
    300
    Glad you got it worked out.
    I knew it wasn't that difficult to remove because I just walked someone else through removing that 2 days ago.
    He said he spent a week trying to remove it and after reading the info I gave him he had it gone in about an hour.
    He used the Avira Rescue Disk and Malwarebytes though.
     
  18. gorski

    gorski MDL Guru

    Oct 21, 2009
    5,518
    1,453
    180
    I'm badly surprised by KIS on this one...

    Legit copy of KIS2010 let it in, didn't catch it afterwards, still doesn't see it as a problem. Bad!

    But if you read back a bit: I followed all the advice, deleting registry entries, unistalling etc. but is still didn't work... Dunno, maybe it was me...
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  19. fubar121

    fubar121 MDL Novice

    Nov 23, 2009
    48
    1
    0
    #20 fubar121, Sep 23, 2010
    Last edited: Sep 23, 2010
    my two cents

    Yes I had this on a work computer, the "normal" removals did not work. even after it was removed by numerous programs its just comes back. I finally had to get IT to fix it and they just said ya its bad and formated the machine. It opens 3 each off iexplorer.exe and explorer.exe, it also closes task manger on opening. I just wanted to say this to all the its an easy removal blah blah blah. This is very nasty and hard to remove.