1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Wild Tangent Removal, psqlpwd.dll detected as trojan

Discussion in 'Malware and Virus Removal Archive' started by sniper9228, 2008/11/08.

  1. 2008/11/09
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    later tonight

    later tonight i will get to it
     
  2. 2008/11/09
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    sorry it took so long

    --


    ! REG.EXE VERSION 3.0

    HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}

    HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}\1.0


    Let me know if you need rsit or spybot scans or you want me to run them.
     

  3. to hide this advert.

  4. 2008/11/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Download and install SubInACL from Microsoft.

    Close out all other programs and open windows.

    Highlight and copy the contents of the code box below.
    Code:
    cd /d  "%ProgramFiles%\Windows Resource Kits\Tools "
    subinacl /subkeyreg HKEY_LOCAL_MACHINE /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subkeyreg HKEY_CURRENT_USER /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subkeyreg HKEY_CLASSES_ROOT /owner=administrators /grant=administrators=f /grant=system=f /grant=RESTRICTED=r
    subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
    subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
    secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose 
    exit
    cls
    
    Click Start>Run and type cmd then hit enter to open a command window.
    Right click in the command window and select paste.
    It will take a while for the commands to process, so please be patient.
    The command window should close on it's own when finished.
    Reboot for the changes to take effect.


    Now, highlight and copy the contents of the code box below and paste them into a command window.

    Code:
    reg delete  "HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}\1.0" /f
    reg delete  "HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}" /f
    reg query  "HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}" /s >log.txt
    start notepad log.txt
    exit
    cls
    Post the contents of the log that opens, if any.
     
  5. 2008/11/09
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    system is beeping

    I kept Spyware Terminator realtime protection enabled. The program was not open though. Is that alright?
     
  6. 2008/11/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Shouldn't be a problem. ;)
     
  7. 2008/11/09
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    the log is empty
     
  8. 2008/11/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Reboot once more and scan with Spybot. Let me know the results.
     
  9. 2008/11/10
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    Yay

    You killed it. The monster is gone. Spybot did not find Wild Tangent.:D
     
  10. 2008/11/10
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Great! So we are resolved?

    Did you send a copy of that file to Spybot with the scan log?
     
  11. 2008/11/10
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    no

    The reason why is because I did not find that Protector Suite in the results anymore.
     
  12. 2008/11/10
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Is that because of something you set in Spybot's exclusion list? If not manually tweaked, will Spybot still tag the file as a rogue? If so, the creators need to be made aware of it, which is best done by submitting the file and the scan log in which it was tagged.
     
  13. 2008/11/10
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    Bad Avast

    Do not mark resolved yet. Avast - update package broken. I uninstalled and reinstalled avast. So I will have to see later in the day whether that works or not.
     
  14. 2008/11/10
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    I do not believe that I added it to the exclusions list, but I will see in the next couple days. I did not save the previous logs when it was included, so it detecting it again would be the only way.
     
  15. 2008/11/10
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Scan logs are created automatically. If you click View Previous Report you should get several to choose from.
     
  16. 2008/11/10
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    response

    I still got to scan, but it seems that the spyware problem with WildTangent is gone.

    Avast seems to working ok, so I guess you can mark "resolved," Once I scan, I will let you know about it if I find it again. I believe I deleted the previous reports.

    I have to find time too scan so mark resolved and I will pm you or post here if I need it active again. I will also post an update of what happens.

    If it finds it or avast has a problem, maybe we can make it active. I dont know.
     
  17. 2008/11/12
    sniper9228

    sniper9228 Well-Known Member Thread Starter

    Joined:
    2005/08/31
    Messages:
    615
    Likes Received:
    1
    update

    I checked my exclusion list and saw nothing was checked, scanned again with spybot, did not find a thing.

    I guess that method with the twist solved both of those detections.
    As of now, I am unable to send them a report as I do not have a previous log and it no longer is being detected. Who knows if it was a false positive?

    ---
    My laptop system is better than it ever was. Thanks for the help noahdfear. All spyware gone.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.