InterviewSolution
Saved Bookmarks
| 1. |
Solve : Sh4ldr removal help windows 7? |
|
Answer» ESET Online Scan Please run a free online scan with the ESET Online Scanner
Any more issues? We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here. Many of the things to note for US would be:
DMJ: Follow up questions. How do I safely remove the malicious SpyHunter 4 program I got tricked into downloading to fix the original sh4ldr virus? I've read that 'Enigma' created both the virus and then the fake fix program. I've heard uninstalling normally can cause it to erase my BIOS? Also, the sh4ldr folder is still in my C: as well as it's accompaning temp file. I know I need to safely remove them from my computer as well. Lastly, are there registry files that will need to be cleaned? Thanks again!!!! From TDSSKiller report: 13:02:44.0098 6932 [ 2ED464C8CBC399E69FBF776A8EBC3302 ] SpyHunter 4 Service C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE 13:02:44.0134 6932 SpyHunter 4 Service - ok In Combo Fix posted report: 2012-10-14 11:02 . 2012-10-14 11:02 -------- d-----w- C:\sh4ldr 2012-10-14 11:02 . 2012-10-14 11:02 -------- d-----w- c:\program files\Enigma Software GroupEnigma Software Group is legitimate software company that have a lot of hating people. It's their fault they ruined their own reputation, but it's not a big deal. I think you can uninstall it via the Control Panel and be in good hands. Here is a VirusTotal scan of that file that was running in the processes list from SpyHunter: https://www.virustotal.com/file/4a0df1d6220c3d93d0502a576b758705f554af3ae32f65ca5d0208336afa43b4/analysis/ This is a SpyHunter folder: sh4ldr, literally "SpyHunter Folder". However, your computer was infected by a serious rootkit, which had nothing to do with SpyHunter, Enigma Software Group, or the like. We will finish up now to make sure your computer is protected from malware in the future. Clean up System Restore Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
Purge old temporary files Download CCleaner Slim and save it to your Desktop - Alternate download link When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe Follow the prompts to install the program. * Double-click the CCleaner shortcut on the desktop to start the program. * Click on the Options block on the left, then choose Cookies. * Under Cookies to Delete, highlight any cookies you would like to retain permanently * Click the right arrow > to move them to the Cookies to Keep window. * Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours * Click Cleaner on the left then Run Cleaner on the right to run the program. * Important: Make sure that ALL BROWSER windows are closed before selecting Run Cleaner Caution: Only use the Registry FEATURE if you are very familiar with the registry. Always back up your registry before making any changes. Exit CCleaner after it has completed it's process. Security Check Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|