Security Shield Removal

  1. #1
    mikey393 is offline Junior Member

    Question Security Shield Removal

    Help needed urgently to remove please.
    Thanks
    Mike

  2. #2
    broni is offline Senior Member
    Please, read HERE and post all required logs.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

  3. #3
    mikey393 is offline Junior Member
    Thanks very much. Have already managed to sort out earlier today but your answer is very thorough as always.

  4. #4
    broni is offline Senior Member
    Yes, you better post all logs, so we're sure, nothing is hiding there.

  5. #5
    mikey393 is offline Junior Member
    Thanks Broni & have taken on board & will check you instructions. I got the advice from "Bleeping Computer". They suggested to use Malware Bytes to remove. Using DKill first. Followed their instructions by the letter. I hope that was o.k.?
    Mike

  6. #6
    mikey393 is offline Junior Member
    Log details: Malwarebytes' Anti-Malware 1.50
    Malwarebytes

    Database version: 5298

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18975

    12/12/2010 14:13:33
    mbam-log-2010-12-12 (14-13-33).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 314908
    Time elapsed: 2 hour(s), 1 minute(s), 49 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 30
    Registry Values Infected: 6
    Registry Data Items Infected: 0
    Folders Infected: 3
    Files Infected: 8

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Settings\{C5428486-50A0-4A02-9D20-520B59A9F9B2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Settings\{C5428486-50A0-4A02-9D20-520B59A9F9B3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\HBMain.CommBand (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\HBMain.CommBand.1 (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\hbr.HbMain (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\hbr.HbMain.1 (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\HostIE.Bho (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\HostIE.Bho.1 (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.HbAx (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.HbAx.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.HbInfoBand (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.HbInfoBand.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.IEButton (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.IEButton.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.IEButtonA (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.IEButtonA.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.RprtCtrl (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\ShoppingReport.RprtCtrl.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Toolbar.HtmlMenuUI (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Toolbar.HtmlMenuUI.1 (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Toolbar.ToolbarCtl (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Toolbar.ToolbarCtl.1 (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\dark (Trojan.Banker) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\winntR1 (Trojan.Downloader) -> Value: winntR1 -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\winntR2 (Trojan.Downloader) -> Value: winntR2 -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\winnt2 (Trojan.Downloader) -> Value: winnt2 -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\winnt3 (Trojan.Downloader) -> Value: winnt3 -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\winnt5 (Trojan.Downloader) -> Value: winnt5 -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\winnt6 (Trojan.Downloader) -> Value: winnt6 -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    c:\program files\shoppingreport (Adware.ShopperReports) -> Quarantined and deleted successfully.
    c:\program files\shoppingreport\Bin (Adware.ShopperReports) -> Quarantined and deleted successfully.
    c:\program files\shoppingreport\Bin\2.5.0 (Adware.ShopperReports) -> Quarantined and deleted successfully.

    Files Infected:
    c:\Users\mikey\AppData\Local\192965.exe (Trojan.GBFE) -> Quarantined and deleted successfully.
    c:\Users\mikey\AppData\Local\Temp\ZAN147E.exe (Adware.Seekmo) -> Quarantined and deleted successfully.
    c:\Users\mikey\AppData\Local\Temp\nsb197B.tmp\Inst all.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
    c:\Users\mikey\AppData\Local\Temp\nsb197B.tmp\laun chhelp.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
    c:\Users\mikey\AppData\Local\Temp\nsb197B.tmp\Reso urce.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
    c:\Windows\Temp\tmp000000157edc65d31e826e47 (Trojan.Dropper) -> Quarantined and deleted successfully.
    c:\Users\mikey\AppData\Roaming\microsoft\Windows\s tart menu\Programs\security shield.lnk (Rogue.SecurityShield) -> Quarantined and deleted successfully.
    c:\Users\mikey\favorites\free porn videos - sex, xxx, free pornos at you porn.com.url (Rogue.Link) -> Quarantined and deleted successfully.
    Mike

  7. #7
    broni is offline Senior Member
    You did well
    Go on....

  8. #8
    mikey393 is offline Junior Member
    Thanks Broni. Do I need to do anything else now? You said Go on................
    Mike

  9. #9
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Please, read HERE and post all required logs.
    .

Closed Thread