1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved How do I remove malware from registry

Discussion in 'Malware and Virus Removal Archive' started by ODaisyRose, 2009/05/04.

  1. 2009/05/04
    ODaisyRose

    ODaisyRose Inactive Thread Starter

    Joined:
    2009/05/04
    Messages:
    3
    Likes Received:
    0
    [Resolved]How do I remove malware from registry

    Hi,

    Norton picked up what it termed a low level risk called uegig.exe that made 6 (unknown) modifications to my computer. It has proven to be 3 unmovable registry files: uegig.dat, uegig, uegig_Navps.dat.

    My problems began when I downloaded IE8. I noticed things were not working well on my computer when opening a browser, an unrelated page would load up behind it. I am concerned about the fact that Norton considers it a low security risk and I can't remove it. I have tried repeatedly to remove the files from the registry but they just come right back. I contacted Norton, but they were no help at all.

    Here is what the Norton report shows:

    Program is on c:\appdata\local\uegig.exe

    "uegig.exe made 6 modifications to your computer ".

    Affected area - System Configuration

    Activity and Resource listed as follows:

    Target files:

    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86\Internet Explorer\iexplore.exe
    C:\Window\explorer.exe

    Modified resource \REGISTRY\USER\S-1-5-21-3727071382-1425442539-322556776-1000\Software\Microsoft\Windows\CurrentVersion\Run

    Modified resource \REGISTRY\USER\S-1-5-21-3727071382-1425442539-322556776-1000\Software\Microsoft\Windows\CurrentVersion\Run\uegig

    Is it possible to remove this without having to do a restore?

    I read your previous posts, but did not see this particular item mentioned. Any help you can give would be greatly appreciated.

    Thank you. ODaisyRose
     
  2. 2009/05/04
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Hi,

    Read this post as indicated at the top of this forum & follow the instructions.
     

  3. to hide this advert.

  4. 2009/05/05
    ODaisyRose

    ODaisyRose Inactive Thread Starter

    Joined:
    2009/05/04
    Messages:
    3
    Likes Received:
    0
    The mirrors simply did not work. I tried to download them but it said it did not support my operating system (which is Vista). I went to the actual webpages in the URL, but could only find the forum on Mirrors 1&3. Two was unable to load.

    It appears that now my IP address has also been hijacked. The file in the registry is called falaz and company is grenouillai.

    Is this Conficker?
     
  5. 2009/05/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under Configuration and Preferences, click the Preferences button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Scan for tracking cookies.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * Back on the main screen, under Scan for Harmful Software click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under Complete Scan, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.
    NOTE: Tracking cookies may be omitted from the log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 3. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    STEP 4. Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackThis log.
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2009/05/16
    ODaisyRose

    ODaisyRose Inactive Thread Starter

    Joined:
    2009/05/04
    Messages:
    3
    Likes Received:
    0
    Thank you

    Hi,

    Thank you for your extensive answer to my question. I waited several days to hear from you and finally decided I had no other choice than to do a full recovery. However, the recovery did not work properly so now I am waiting for a new set of recovery disks to be delivered. However, the computer works to some extent. When the disks arrive, I will do a full recovery again in order to get back to the original factory settings. I will keep your instructions on hand in case of future problems.

    Again, thanks for taking the time to respond.

    Best regards, ODaisyRose
     
  7. 2009/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thank you for posting back :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.