
I recently fixed a machine that got infected by a virus that works like this: every time you click on a directory, an error message gets displayed that goes like this:
bq. Attention, [name]! Some dangerous trojan horses detected in your system. Microsoft Windows XP files corrupted. This may lead to the destruction of important files in C:\WINDOWS. Download protection software now!
This error message is then followed by a dialog box. Clicking on it takes you to the website http://free-viruscan.com/id/4912933/4/1/ (WARNING: The website is a FAKE meant to deceive the visitor into downloading and executing a program that will create more virii. Do not interact with it).

Normally it takes me 5 minutes to find a kill a virus but today I was stumped. The way the virus operated was unusual. It does not load any memory-resident programs. It does not get loaded on startup. It does not run a service.
Finally convinced that this was beyond my own power, I downloaded and ran HijackThis. Still nothing. Now things were getting real interesting. I did not want to resort to using an antivirus. That would be too easy. I wanted to know what exactly the virus does and how.
After what seemed like hours of research I finally came upon the FixIEDef program developed by ShadowPuterDude of Malwareteks. Ran it, it was bye bye virus. The logs showed the following entries:
!!! Files that have been deleted !!!
C:\WINDOWS\system32\dadef.dll
C:\WINDOWS\system32\dapol.dll
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\tmp.txt!!! Registry entries that have been removed !!!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\bind “comment”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.BhoApp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.BhoApp.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2FF811E6-8925-4084-A649-C159955E67E8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CAF9D798-C659-4B9B-8E19-EE27C3D04EE7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2FF811E6-8925-4084-A649-C159955E67E8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “KernelFaultCheck”
Wish I knew more about how it worked, but I guess I should be happy and contented for now that the virus is gone.
Addendum:
It appears that a new strain of this “dangerous trojan horses” virus comes out almost every week, if running the program does not solve your problem, or if you have any support requests, please visit the official website at http://malwareteks.com/. Note again that I did not create this program. ShadowPuterDude did. Hence, I cannot provide any support
255 Responses to How to fix the “Attention, some dangerous trojan horses detected” virus
godie
June 23rd, 2008 at 12:25 am
I guess you’re using IE? Its a BHO (browser helper object) which can be installed through exploit on IE silently. I guess your windows is not patched too for that to happen.
Fortunately BHOs can’t (by default) do much damage except do annoying stuff or fool you into downloading more dangerous program.
The problem with IE is aside from being a web browser, its also Window’s file manager so BHOs also runs when youre just browsing your files.
Get FireFox now and never use IE for Internet browsing.
godie’s last blog post..First True Mobile P2P Solution Developed in Philippines
rb
June 23rd, 2008 at 12:51 pm
MACAFEE noticed a trojan and shut that FIXIEDEF.exe down!
JackA
June 23rd, 2008 at 3:26 pm
To godie:
I don’t know how Firefox manages this threat, but I want to mention that neither IE nor Opera do. I’ll probably use FixIEDef, because I can’t get the warnings off my PC… despite two antiviruses scanning in turns and one more antispyware solution. No, they don’t conflict, but yes, they can do almost nothing.
I quite agree with the author… a rare kind of truly smart viruses… I’d be sorry for the lack of these, had they been less annoying.
john
June 23rd, 2008 at 3:50 pm
Hi,
I also have this problem, and the fix isn’t fixing it! BTW, i DO use firefox. I click on the box (yes or no) and it opens up firefox and takes me to that web page.
coolnetalias
June 23rd, 2008 at 4:46 pm
Thanks it resolved my errors.
coolnetalias
June 23rd, 2008 at 4:47 pm
Thanks, my virus got removed. Now i m doing further investigation.
ajay
June 23rd, 2008 at 11:04 pm
hey great work dude!!!!!!!!!!!!!
i also had same problem today i got it cleared…
!!! All Finshed !!!
Maclaine
June 23rd, 2008 at 11:31 pm
thanks dude,
i had the same problem this morning by inserting my usb key in my computer and it’s gone with FixIEDef…
Matt
June 23rd, 2008 at 11:37 pm
It worked! Thank you!
cdog619
June 23rd, 2008 at 11:40 pm
thanks a lot! it fixed my issue too…only took about a minute…
vishal
June 24th, 2008 at 1:11 am
Thnx DUde…. Maan this fraekin virus….
great post …tHANks million….
Qvintus
June 24th, 2008 at 4:09 am
uhm this wont work for me any know why?
chux
June 24th, 2008 at 4:20 am
this dose not work for me, probably because i am running Vista.
i had this problem once before and got rid of it but i can’t seem to remember how but i can remember that u have to find it in regedit and remove it
sapguy
June 24th, 2008 at 9:36 am
It worked for me. Where can you find the logs for this nifty program?
eliasmtz
June 24th, 2008 at 10:05 am
Encontrastes la solución?
Entonces eres bueno, manolo, tio hombre!
Beebrown
June 24th, 2008 at 11:36 am
Oh My God this lprogram really worked thanks…This is a proof that people can actually help you online. I downloaded a key gen and all of a sudden my IE was acting up giving me this error message..Thank God I found this site..
A girl from Montreal
ShadowPuterDude
June 24th, 2008 at 11:39 am
FixIEDef has been updated to include the newest variant .
FixIEDef does run on Vista.
Any tool that alerts on FixIEDef as being a Trojan is incorrect. It is alerting on the signatures of files targeted by FixIEDef for removal.
If you are experiencing problems with FixIEDef; please visit my site and report issues in the bug tracker or start a support thread in the forum.
Natasha Jeconiah
June 24th, 2008 at 3:44 pm
Hi !!!!!
thank’s a lot for this page !!!! You have made me experience how to kill this problem….My computer has been infected like this then I searched how to kill the proccess and I get your page…
Thank’s a lot yach !!!!
It helps me !!!!
GBU
- Natasha – Indonesia -
PotatoChip
June 24th, 2008 at 6:06 pm
Thanks mate, it solved the popup when I was trying to enter the WINDOWS folder.
I’m glad to be helped.
Dennison Uy - Graphic Designer
June 24th, 2008 at 10:03 pm
Hey SPD thanks for dropping by and for releasing the FixIEDef program. As evident by the comments here it saved a lot of lives. Cheers!
john
June 24th, 2008 at 10:37 pm
run the program in safe mode!
cheers
Craig
June 25th, 2008 at 2:51 am
Thanks Man, I use XP Service pack 2 and Firefox 2 with Kaspersky antivirus, not much has got past kaspersky, but this one did, fix was excellent and so easy.
AsdolAsdol
June 25th, 2008 at 4:05 am
Thank you Dennison. It resolved my problem too in one minute. God bless u!
David
June 25th, 2008 at 5:35 am
thanks man I almost got nuts
paul
June 25th, 2008 at 10:22 am
OMG something that actually works first time with no probs at all.
I had this virus on xp using firefox, bin driving me mad for weeks, cleaned it up in seconds.
Thanks a lot.
Hamidi
June 25th, 2008 at 1:38 pm
hi
thanks. It worked very well
only one minute
Andrew
June 25th, 2008 at 1:58 pm
Thought I might’ve had to resort to completely formatting the computer.. Thanks for this, fixed it in a matter of seconds
.
Thanks!
June 25th, 2008 at 3:33 pm
Add me to the list of ppl who are thankful for the tool!
dadang
June 25th, 2008 at 7:37 pm
thanks, i like this tools. verry good.
tk
June 25th, 2008 at 10:17 pm
I have tried running this removal tool but I just get the error message:
Line -1:
Error: Variable must be of type “Object1″
Can someone help me, this virus isn’t getting picked up by AVG for some reason, and I can’t get rid of it!
ShadowPuterDude
June 26th, 2008 at 12:34 am
Windows Scripting is not working properly on your system.
For Windows XP, download and Install Windows Script 5.7
http://www.microsoft.com/downloads/details.aspx?FamilyID=47809025-D896-482E-A0D6-524E7E844D81&displaylang=en
For Windows 2000, download and install Windows Script 5.6
http://www.microsoft.com/downloads/details.aspx?FamilyId=C717D943-7E4B-4622-86EB-95A22B832CAA&displaylang=en#Requirements
ShadowPuterDude
June 26th, 2008 at 9:35 am
Windows Scripting is not working correctly on your system.
Download and install:
Windows 5.7 if using XP
Windows 5.6 if using Windows 2000.
If this doesn’t resolve the issue, then there is a tool that can be used to rebuild the WMI engine.
ShadowPuterDude
June 26th, 2008 at 9:36 am
Sorry, Windows Script 5.7 and Windows Script 5.6
Elijah
June 26th, 2008 at 11:42 am
Cool! Best tool ever when anti-virus can not perform.
Ronosu
June 26th, 2008 at 1:24 pm
Brilliant. Just brilliant. I was reading the comments and saw that some people who were running vista had problems. I ran it once and it was still there. So i just changed the compatability to xp service pack 2 and ran it in admin privileges and bam. G-O-N-E. Hope that helps anyone else. Thank you ever so much.
bluevenderlac
June 27th, 2008 at 1:10 pm
hey thank you so much…
Nithin
June 29th, 2008 at 5:49 pm
awesome ! thanks a billion !
ty
June 29th, 2008 at 6:06 pm
Thanks, it help solve my problem
Art
June 29th, 2008 at 6:08 pm
I tried McAfee, AVG, Lavasoft, and a lot more BUT the virus DIDN’T DISAPPEAR.
This one finally works! Thank you very much.
r2
June 29th, 2008 at 9:02 pm
thank you
Andy
June 29th, 2008 at 9:55 pm
THANK U M8!!! U ARE REAL HERO FOR ME. good luck in life..
hope these virus developers will rot and die.
grateful person
June 30th, 2008 at 1:26 am
wow thnx
MAE
June 30th, 2008 at 8:08 am
Thank you so much. I finally got rid of that annoying thing. now i can work back again…. swiftly… Thanks again… U R d BEST!
Alex
June 30th, 2008 at 9:02 am
In Vista change compatibility to XP SP2 and Run as Administrator.
Thanks.
pete
June 30th, 2008 at 9:10 am
thanks – worked – I’m switching to a mac as soon as I get some money , I’ve had enough so has Bill
rhumbus
June 30th, 2008 at 4:02 pm
thank you!
Randy
June 30th, 2008 at 5:04 pm
Thank you!
Randy’s last blog post..UMASS Dartmouth Men’s Restroom – North Dartmouth, MA
Amit
June 30th, 2008 at 5:31 pm
Thank you very much to the Malwareteks team, and you for putting the solution up on the internet and to Google which helped me find your site. Solved my problem like a charm. It was quite annoying. Thanks once again!
liewxta
June 30th, 2008 at 5:49 pm
wow tks lots for this GREAT help
zaGor
July 1st, 2008 at 3:25 am
THANK YOU VERY MUCH!! Great help.
Nikhil
July 1st, 2008 at 3:56 am
Thanks a lot … u solved my problem
Thomas
July 1st, 2008 at 9:22 am
Ty your like god to me teehee
Scott
July 1st, 2008 at 1:03 pm
Another happy camper!! Thanks worked as advertised on XP system. Virus deleted in mere minutes.
William
July 1st, 2008 at 1:52 pm
thanks a lot!
it works!
Steve
July 1st, 2008 at 2:14 pm
Happy camper #2, thank you so very much!
Anindya
July 1st, 2008 at 6:53 pm
thank you…thank you…thank you…thank you…thank you…thank you…thank you…thank you…thank you…thank you…thank you…thank you…
Waleed
July 1st, 2008 at 9:28 pm
Thanks for your excellent FixIEDef
Slava aka Schwed
July 1st, 2008 at 9:29 pm
It’s really works! Thanks MAN!
))
ESED Smart Security don’t find this trojan
Jiac
July 1st, 2008 at 10:57 pm
Thanks, SPD. It’s great to have geniuses like u
Martin
July 2nd, 2008 at 12:52 am
Thank you, your’e great, this thing was keeping me from opening program files and documents, really thanks a lot
yairoman
July 2nd, 2008 at 7:43 am
Realmente me funcionó el programa, saludos.
Gracias
Sithuoth
July 2nd, 2008 at 11:02 am
Thanks very much!
Now, my computer run well
Jitendra
July 2nd, 2008 at 1:18 pm
Kill the xmlsys.dll from taskmanager and delete following file to remove this virus.
C:\WINDOWS\system32\xmlsys.dll
Or use FixIEDef.exe to remove it.
Enjoy!!!!!!
Danni
July 2nd, 2008 at 5:39 pm
Well… I have the virus, I ran the FixIEDef.exe…
But, it did’nt work…
ShadowPuterDude
July 2nd, 2008 at 7:13 pm
Dani,
Then you have a variant that is not currently targeted by FixIEDef.
Visit my site and post a HijackThis log. That will give me some clue as to what is going on.
ShadowPuterDude
July 2nd, 2008 at 7:15 pm
Jitendra,
If it was as simple as killing the running process and then deleting the malicious file; then there would be no need for FixIEDef. There is way more to the infection then just a file.
Erkan
July 3rd, 2008 at 12:20 am
thanks a lot maaaaaan !!!
Aleks
July 3rd, 2008 at 7:06 am
Hey, I have a problem with FixIEDef…
Here what it shows in the log after scanning:
——————————————————————————–
!!! Files that have been deleted !!!
No malicious files found
——————————————————————————–
!!! Directories that have been removed !!!
No malicious directories to be removed
——————————————————————————–
!!! Registry entries that have been removed !!!
No malicious Registry entries found
ShadowPuterDude
July 3rd, 2008 at 7:28 am
As the author of the tool.
This is not the support site for FixIEDef, this is simply a blog by Dennison about how FixIEDef solved the problem for him.
There is nothing wrong with your log, it is simply stating that FixIEDef found nothing to remove.
There are a few hundred variants of the IE Defender family of ‘Fake Alert’ Trojans. New variants are constantly being unleashed on unsuspecting surfers. Because of this there will be variants not included in FixIEDef’s database.
I am currently researching a new ’strain’ of the IE Defender ‘Fake Alert’ Trojan. An updated tool should be out tomorrow, if not tonight.
If you are experiencing problems with FixIEDef or something is not being removed, that you think should be targeted by FixIEDef; then you need to register at malwareteks, and start a support thread in the forums.
MalwarTeks is the support site for FixIEDef.
sylvester
July 3rd, 2008 at 9:38 am
thank you so much puter dude you are the man!!!!!!!!!!! i almost threw my computer against the wall!!! now its fixed
Jatin
July 3rd, 2008 at 9:38 am
I just tried it, and it didnt work! What am I doing wrong!
ShadowPuterDude
July 3rd, 2008 at 9:54 am
Hello, Jatin,
As I have stated in an earlier comment, this is not the support site for FixIEDef,
Please go to mawareteks.com, register and then post in the FixIEDef support forum.
jafer1985
July 3rd, 2008 at 12:16 pm
hi,, lot of thanks to u.. it really work out!!
lea
July 3rd, 2008 at 2:09 pm
Thanks thanks thanks
it works for me too.This is the real salvation:)
candyman
July 3rd, 2008 at 3:42 pm
Thanks a lot for this fix… i too had that damn virus and after trying to get rid on my own i finally accepted that its beyond my capabilities and ended up here. Thanks again for the fix!
Ksenia
July 3rd, 2008 at 4:57 pm
Thanks a lot!!!!!!!!!!!!! one more saved laptop!!!!!!!!!!!!!
Rene -
July 3rd, 2008 at 5:08 pm
Thanks…Worked for me…


Im happy that good people like you are around
Thanks…
Prashant
July 3rd, 2008 at 8:34 pm
this finally worked….
soyware doctor and norton could not do nething to get this problem sorted…
but this program finally did…
thanks to all…
Sandeep
July 3rd, 2008 at 10:27 pm
Thanks a million…i was worried about the virus
dude
July 4th, 2008 at 1:53 am
wow.. it worked really, even on vista.. hope i didn’t get an even worser virus now..
BobbyG
July 4th, 2008 at 3:33 am
You’re my new hero! Ths
Eduardo
July 4th, 2008 at 5:21 am
I have the Kaspersky and it doesn’t found nothing! Thank you!
Raza
July 4th, 2008 at 12:03 pm
I noticed the author of that program came on briefly and in case he ever does again I just want to say THANK YOU. I ran some really great anti-virus and anti-spyware crap and nothing caught this son of a bitch except for yours! *BIG HUG*
toto
July 4th, 2008 at 4:37 pm
OMG its worked & kicked that f*****g virus a**
)
very very thanx to the author
Fizban
July 4th, 2008 at 5:23 pm
Thank you guy, I was been mad to remove this virus, nothing detected it, but now this program worked very good to destroy it
DDD
bamzandu
July 4th, 2008 at 11:54 pm
Looks to have worked for me too.. Thanks a million. The window says creating log, but I couldnt locate it. Can you point me to the probable location ?
ShadowPuterDude
July 5th, 2008 at 12:55 am
The FixIEDef log should be on your Desktop.
VIJAY N
July 5th, 2008 at 1:58 am
THANK YOU V MUCH. IT WORKED GREAT TO REMOVE “FREE-VIRUSSCAN” VIRUS WITHIN A MINUTE.
Giselle Cardozo
July 5th, 2008 at 6:55 am
Hello, this removal tool doesn’t remove the IE virus on my computer. Please help me. The problem it’s same at Aleks.
Kshitij
July 5th, 2008 at 8:13 am
Thanks, it worked for me.
ShadowPuterDude
July 5th, 2008 at 10:45 am
First , this is not the OFFICIAL support site for FixIEDef.
I don’t know how many times I can say this before it sinks in.
Second,the authors of the IE Defender Family of ‘Fake Alert’ Trojans release at least 3 new variant’s each week.
There is no way that FixIEDef will be be able to remove every possible variant of the IE Defender Family of ‘Fake Alert’ Trojans..
If you suspect that you are infected with a variant of the IE Defender Family of ‘Fake Alert’ Trojans, post in Malware Removal Forum of malwareteks.com
Mr_corolla
July 5th, 2008 at 12:55 pm
Awesome program and advice, really appreciate it!
zawgyi
July 6th, 2008 at 12:08 am
Hi….I run this..but could not remove this virus….
the following is the out put log file:-
!!! Files that have been deleted !!!
C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\*.*
——————————————————————————–
!!! Directories that have been removed !!!
No malicious directories to be removed
——————————————————————————–
!!! Registry entries that have been removed !!!
No malicious Registry entries found
================================================================================
All Done
T-Liggett
July 6th, 2008 at 12:44 pm
Ha i usualy never reply/comment on blogs but damn this shit saved my ass, and it was fast. thanks man.
TIME
July 6th, 2008 at 2:57 pm
All I can say is thank you – I too was tearing my hair out.
Lauren
July 6th, 2008 at 4:01 pm
Thank you so much. This was driving me nuts! Avast couldn’t even get rid of it. I use Firefox too but I need IE for some things as well.
siddharta
July 6th, 2008 at 8:44 pm
Amazing ..awesome..excellent….realy thanx a milion
Ivan
July 7th, 2008 at 5:29 am
Thank you very much!!!
Jeff
July 7th, 2008 at 8:58 am
Couldn’t get to a fix because of the constant redirecting of my IE browser. Finally opened FireFox in order to get access to any website other than the one of the jackass who infected me. Good thing I already had that installed and operational.
BUT – as soon as I used The Fix, I found that now all of my files have changed so the extensions are visible in all of the names. I think there’s an easy fix to this, but… anyone else experiencing the same issue?
By the way, here’s the WhoIs info for the criminal who is responsible for this particular malware:
http://free-viruscan.com = [ 58.65.238.34 ]
(Asked whois.estdomains.com:43 about free-viruscan.com)
Registration Service Provided By: ESTDOMAINS INC
Contact: 1.3027224217
Website: http://www.estdomains.com
Domain Name: FREE-VIRUSCAN.COM
Registrant:
N/A
Alexander iedefender@gmail.com
Yborevicha street
Kiev
Kiev Oblast 93000
UA
Tel. 380.993363649
Creation Date: 18-Jun-2008
Expiration Date: 18-Jun-2009
Domain servers in listed order:
ns2.free-viruscan.com
ns1.free-viruscan.com
Administrative Contact:
N/A
Alexander iedefender@gmail.com
Yborevicha street
Kiev
Kiev Oblast 93000
UA
Tel. 380.993363649
Technical Contact:
N/A
Alexander iedefender@gmail.com
Yborevicha street
Kiev
Kiev Oblast 93000
UA
Tel. 380.993363649
Billing Contact:
N/A
Alexander iedefender@gmail.com
Yborevicha street
Kiev
Kiev Oblast 93000
UA
Tel. 380.993363649
Status: ACTIVE
Felipe
July 7th, 2008 at 9:55 pm
Hey guy
thank you it solved my troubles!!!
thanks!!!!!!
richy
July 8th, 2008 at 2:54 am
I can’t get onto the your website anymore shadow dude. did I get booted?
richy
July 8th, 2008 at 2:57 am
I mean, I posted in someone else’s forum and now I am denied access to the site
ShadowPuterDude
July 8th, 2008 at 4:57 am
Try now.
The site software has an auto ban feature, that if flooding is detected it will automatically ban the IP if you are detected as clicking on pages to quickly.
I just removed a bunch of banned IPs that were Banned for Flooding.
ThisSuxs
July 8th, 2008 at 5:19 pm
Yeah I was browsing your malware tools as the FixIEDef didnt fix my issue and suddenly I couldnt go to your website anymore
i was like omg this site mite fix my problem! and then i got banned and went omg this suxs
ShadowPuterDude
July 8th, 2008 at 7:13 pm
As I stated earlier, the site software has built in protection against flooding. If you are moving between pages quickly the software will see this behavior as “Flooding” and will automatically ban your IP.
I have cleared all auto banned IPs, again this morning. You should now be able to reach the site.
Henry
July 9th, 2008 at 10:24 am
Hi man,
I faced the problem and it drove me crazy. I have tried to scan the virus but nothing detected. Because IE always lead me to that website, it make me install mozilla and get the information about this virus on this page.
Your solution works well and really help me.
Thank you, dude..!!
Rod
July 9th, 2008 at 11:56 am
Thanks bro!
It seems the problem is solved!
Joned Harsadi
July 9th, 2008 at 7:18 pm
Dear ShadowPuterDude and Dennison,
Thank you very much. At first, I get frustated. But now, I can relax because of your GREAT Tool.
Even My BitDefender Total Security 2008 can not detect the virus.
The Virus is very unique, though. It’s really interesting.
Joned. Indonesia.
datedoctor_papi@yahoo.com
manitu_hu
July 9th, 2008 at 11:59 pm
It worked.
I had this problem since I ran an ugly Keygen a few hours ago for a WM6 app. (so far I trusted on NOD32 so much that dared to run any exe, so far it always denied it if infected – this is first time I ran into a problem file that passed it)
Not even reboot or Safe Mode was needed, just run the exe and worked – no more pop-up on explorer clicks.
Thank you for the help and for the FixIEDef developer.
fenixsaz
July 10th, 2008 at 1:34 am
Great Post.
Fix my problem.
Stealth
July 10th, 2008 at 2:39 am
Thanks very much, it help in one minute, after i has problem from keygen.
rwmurrow
July 10th, 2008 at 3:24 am
I got banned again.
ShadowPuterDude
July 10th, 2008 at 5:35 am
rwmurrow,
All auto-bans have been cleared.
You are moving from page to page too quickly. The software sees this as “flooding” and if you continue to keep clicking on pages after the pop-up warning, you will be banned automatically.
This is a defense mechanism to mitigate DDoS attacks.
Steve
July 10th, 2008 at 9:33 am
Thanks, it worked great on my Laptop and my PC…
Dmack33
July 10th, 2008 at 9:40 am
YOU ROCK MAN>> THANKS!! WAS JUST ABOUT TO REINSTALL!!!
Ghassan
July 10th, 2008 at 12:50 pm
Thanks Man! ITS GREAT
Its working Normal again……
You saved my day! Hats Off to you….
rwmurrow
July 10th, 2008 at 1:57 pm
sorry I got blocked again, I will be more careful.
Mat
July 10th, 2008 at 6:11 pm
Thanks! Works great!
Mat
July 10th, 2008 at 6:13 pm
…got the infection from keygen….
Dave
July 11th, 2008 at 9:28 am
My log says:
——————————————————————————-
!!! Registry entries that have been removed !!!
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.BhoApp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.BhoApp.1
But those entries are still there. Please help me get these deleted!!!
Yvette
July 11th, 2008 at 3:06 pm
THANK YOU you are a lifesaver that was terribly annoying and i’ve never seen anything like it
jessica
July 11th, 2008 at 3:26 pm
i know youve received so many thanks and this will probably fall on deaf ears but i just had to make my point. THANK YOU SO MUUUUUCH
nlt
July 11th, 2008 at 5:51 pm
Thxs i been trying to fix this problem for like a week
thxs to Dennison Uy for pointing this program out
thxs to ShadowPuterDude for developing the program
Stephanie
July 12th, 2008 at 4:16 am
OMGG. thank you soo much. I almost wanted to kick my computer. thanks soo much u r suchaa lifesaver
vswsc
July 12th, 2008 at 5:03 am
It didn’t work and the log show
!!! Files that have been deleted !!!
No malicious files found
——————————————————————————–
!!! Directories that have been removed !!!
No malicious directories to be removed
——————————————————————————–
!!! Registry entries that have been removed !!!
No malicious Registry entries found
Please could anyone help
sundar
July 12th, 2008 at 9:30 am
hi, thanks a lot. I have remove IE virus with your tool.
Thanks again.
Pax
July 12th, 2008 at 10:24 am
Hi it only took a minute, and for now everything seems just dandy, thanx, if I get a problem I’ll repost.
thought i’d let you see a copy of my log, thanx again! happy campin everybody!
********************************************************************************
* *
* FixIEDef Log *
* Version 1.4.20.5956 *
* *
********************************************************************************
Created at 19:17:49 on Friday, July 11, 2008
Time Zone : (GMT-08:00) Pacific Time (US & Canada)
Logged On User : Pax
Operating System : Microsoft Windows XP Home Edition Service Pack 2
OS Version : 5.1.2600
System Langauge : English (United States)
Keyboard Layout : English (United States)
Processor : X86 Intel(R) Pentium(R) 4 CPU 2.00GHz
System Drive : C:\
Windows Directory : C:\WINDOWS
System Directory : C:\WINDOWS\system32
Total Physical Memory : 1039695872 bytes
Free Physical Memory : 678484 bytes
Total Virtual Memory : 2097024 bytes
Free Virtual Memory : 2054012 bytes
Boot State : Normal boot
——————————————————————————–
!!! Files that have been deleted !!!
C:\Program Files\Codec Pack – All In 1\DivXconfig.exe
C:\Program Files\Codec Pack – All In 1\ac3filter.ico
C:\Program Files\Codec Pack – All In 1\DivXSetup.ico
C:\Program Files\Codec Pack – All In 1\dvobsub.ico
C:\Program Files\Codec Pack – All In 1\ffdshow.ico
C:\Program Files\Codec Pack – All In 1\g400.ico
C:\Program Files\Codec Pack – All In 1\ie.ico
C:\Program Files\Codec Pack – All In 1\irunin.bmp
C:\Program Files\Codec Pack – All In 1\irunin.dat
C:\Program Files\Codec Pack – All In 1\irunin.ini
C:\Program Files\Codec Pack – All In 1\irunin.lng
C:\Program Files\Codec Pack – All In 1\Thumbs.db
C:\Program Files\Codec Pack – All In 1\verze.txt
C:\Program Files\Codec Pack – All In 1\xvid.ico
C:\WINDOWS\system32\nvgflt.dll
——————————————————————————–
!!! Directories that have been removed !!!
C:\Program Files\Codec Pack – All In 1
——————————————————————————–
!!! Registry entries that have been removed !!!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\bind “comment”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFE59EC6-5491-4EF3-BA0D-77B0D895B4F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4937D5D1-2039-409A-BD83-FEC9B39B2356}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CAF9D798-C659-4B9B-8E19-EE27C3D04EE7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{15C7D7AD-A87A-4C0D-9D8B-637FCD3488EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFE59EC6-5491-4EF3-BA0D-77B0D895B4F7}
================================================================================
All Done
ShadowPuterDude
Safe Surfing!!!
Boakye
July 12th, 2008 at 5:59 pm
Thank You!!! ACIŪ from Lithuania:)
Winnefred
July 12th, 2008 at 7:55 pm
Hey Dude ! thnx a lot ! its all happened just like that and the virus vanished
KICKERMAN360
July 12th, 2008 at 8:11 pm
Thanks, ShadowPuterDude,
This virus is a weird one, no services or processes (on task manager or start up) and couldn’t find anything in Application data, stumped me, and Trend Micro couldn’t even find it.
I wonder how i got it, i don’t use IE, only FF3
Marco
July 13th, 2008 at 1:10 am
Worked great and quick. Thanx a lot.
Sass
July 13th, 2008 at 4:43 am
THANK U VERY MUCH ! IT SOLVED MY PROBLEMS ! :>
king kay
July 13th, 2008 at 6:23 am
Thank you. It worked great.
I tried few antivirus and spyware softwares before this and none worked.
Brilliant!!
HarryuSally
July 13th, 2008 at 7:51 pm
thank you very much…
it’s gone…
great work…
THANK You!!!
ken
July 14th, 2008 at 1:19 am
thanks — really helped — usually very careful not sure how it happened though!
Anthony
July 14th, 2008 at 3:50 am
THANK YOU SOOOOOOOOOOOOOOOO MUCH!!! IT WORKED!
Nick Torres
July 14th, 2008 at 8:45 am
Thank you so much, my computer just got infected with this today and Firefox did not solve the problem… I have a terrible history with computers and this is the family’s computer, my parents threatened to never by me a electronic device again if I recked it… anyway sorry to ramble on but i just want to say thank you so much for this post
Mohammed Ziya
July 14th, 2008 at 6:19 pm
Thanks a lot!! You have done a great help. Keep going
Sue
July 15th, 2008 at 12:56 am
THANK YOU, THANK YOU, THANK YOU!!!
I was ready to call McAfee and pay $2.95 per miniute
If I could hug you I would – I’m hugging my puter instead.
Thanks again!
LasseDK
July 15th, 2008 at 4:57 pm
Nice program.
I run it and the log says it not find anything but now the mailware is gone.
Thanks
Parag
July 15th, 2008 at 11:54 pm
Thanks man really worked, cool dude thanks again
jono
July 16th, 2008 at 4:09 am
Cool, thx for that. It really helped.
you say using a anti-virus is a easy option, What other options are there? im interested.
chris macfarlane
July 16th, 2008 at 8:09 am
i used this program it works perfectly. althought mcafee didnt find the rat this fixed it . now i can click my computer safely and anydocuments i have. i had the rat for 5 minuets and its gone now
. tyvm
scott
July 16th, 2008 at 1:51 pm
WOW. glad i got rid of that i was about to toss my compter out the window then run out with matches and gas and light it on fire. then hit it with a bat till the ashes was beat into the ground
Jay
July 17th, 2008 at 9:01 am
Had the issue earlier, googled it and came to this blog. Tried the program and it worked like a charm, thanks a lot!
Larry
July 17th, 2008 at 9:36 am
Two sleepless nights trying to get rid of the virus i unknowingly infected the wife’s computer with. now that the computer is free of the virus, i am now allowed to sleep with the wife again. YEAH!
hackcute9
July 17th, 2008 at 6:25 pm
thank you, thank you, thank you so much…
this program was so great !!!!!!!
AJ
July 18th, 2008 at 8:21 am
I wonder if I have a new variant since the original post of this forum. I had dozens of “attention…” pop-ups and similar “errors” which would cause more pop-up windows to order anti-virus or malware-removal sites. The program worked to stop most of the pop-ups, but a few still show up. The difference is that I can click them to close now.
The new problems since is that I have problems starting up, to the point where sometimes I can’t even get to desktop, or the desktop goes black on me. I noticed one person above said that they can’t see the extention to their files anymore. I noticed the same thing. I have a ton of other files in the /Windows directory when this trojan first appeared.
Maybe an updated version will come up soon to fully remove this trojan and some lasting side effects?
FM
July 18th, 2008 at 9:14 pm
Hi, thanks for the program, fixed all my problems
AJ, i got version: 1.5.0.94854…….
dunno know if its the latest version, but it seems like it
Russell
July 19th, 2008 at 1:01 am
Great work!! thanks a lot.
Mr. AJ. it seems you don’t surf internet, you cultivate virus.
If there is any way to export the virus, you could be new bill gates. ha,ha,ha
Anthony
July 19th, 2008 at 1:35 am
Can someone please help! I had the the first time, and used this and it worked. Now I have it again, and I used it again and it still has that pop up! PLEASE HELP!
Cameron
July 20th, 2008 at 2:08 am
OMG MAN THANKS SOOOOO MUCH!!!!
IM COMMON TO TROJAN VIRUSES CAUSE I “PIRATE” ALOT
BUT THANKS MAN!!!!!
IVE HAD TO REFORMAT MY COMP ABOUT 4 TIMES THIS YEAR THANKS FOR SAVING ME 70$
Lucky Luke
July 20th, 2008 at 8:25 am
thank u so much . it’s so great
prab
July 20th, 2008 at 2:06 pm
THanks
it worked for me very well.
Vijay
July 20th, 2008 at 7:20 pm
Thanks, Man !! This saved my day. The bloody trojan didnt allow me to access any internet pages, as every click used to try taking me to the ‘free-virsucan.com…’ site. Finally I had to install mozilla browser to search for help and then run this utility.
Thanks a ton !!
dj
July 20th, 2008 at 9:41 pm
Hi
it works thnx man. Now i can go further with my business!
ac
July 20th, 2008 at 11:03 pm
I luv you!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! lol

eset failed me
Thanks alot man cause that virus was pissing me of!
pearl
July 21st, 2008 at 4:34 am
hey thank you,
becs
July 21st, 2008 at 11:27 am
Also adding my thanks. Hopefully it’s gone, although I didn’t get a log or anything, it just ran a scan and then said scan finished. Does this sound right?
tiff
July 21st, 2008 at 3:03 pm
thanks sooo much! It works!
dani
July 21st, 2008 at 11:25 pm
thankz alot man
dani
July 21st, 2008 at 11:27 pm
thanks dude
it works
Rachael
July 22nd, 2008 at 5:15 am
Thanks so much !!! FixIEDef saved my life!!!
Anthony
July 22nd, 2008 at 10:32 pm
it wont work,………. leme try on the safe mode xD wish me luck
Martin
July 23rd, 2008 at 1:56 am
Thanks a lot, it helped:)
Nickg
July 23rd, 2008 at 3:08 am
THANKS!! You da man.
Awesome.
Tom
July 23rd, 2008 at 7:17 am
Thanks for the advice
» IE Critical Update Needed | DoZ-log |
July 24th, 2008 at 3:54 pm
[...] La soluzione si è dimostrata molto semplice, in quanto si trattava più che altro di un piccolo “sputtanamento” di chiavi di registro e di qualche DLL maligna, come spiegato nel sito di codesignstudios. [...]
anil kumar
July 24th, 2008 at 4:54 pm
thanks a lot..its working very fine…and solved my problem
da juansta420
July 25th, 2008 at 8:55 am
worked, thanks for the fix. damn trojan’s. thats why i stick with lifestyles.
vgl
July 26th, 2008 at 3:29 am
i tried both in normal and safe mode.nothing happened.please give me an advice on how to remove that friggin virus of my pc. :@
TD
July 26th, 2008 at 10:30 am
Worked like a charm. Thanks so much!
jason
July 26th, 2008 at 6:52 pm
thanx a bunch!!
Mikey
July 27th, 2008 at 6:18 pm
Thanks a million! Saved my laptop – spent a whole downloading different AV’s and anti-spyware and Widnows Defender – nothing helped….except this…should have done a google search before. ShadowPuterDude you’re the best!
By the way does anyone know what I should have installed on my laptop to prevent this and anthing else that might pop-up? E.g. AVG, Panda, Spydoctorm Adaware etc…any expert advice would be great (because it seems a lot of websites have differing opinions on what is the best!). Thanking everyone in advance.
Harry
July 27th, 2008 at 6:46 pm
Thanks a lot. I had the same problem and had made up my mind to reinstall my system.Finally Tried “FixIEDef “.It worked like a dream and solved the Problem.
Mike
July 28th, 2008 at 2:05 am
Thanks so much. I too was about to nuke my hard drive, but this worked like a charm.
Branden
July 29th, 2008 at 1:21 pm
Just want to say I was honestly skeptical about downloading this and was not sure but I took the leap of faith and it took care of the virus.
Thank you very much.
crinimo
July 30th, 2008 at 1:53 pm
THANKSSSSS
U ARE THE BEST
jagan
July 30th, 2008 at 6:58 pm
thnks man you are a genious…..
ishan
July 30th, 2008 at 7:56 pm
thanks dude.that worked…
Randi
July 31st, 2008 at 5:52 am
Thank you SOOOOO much…I just spend 3 hours figthting this thing…on a BRAND NEW computer! Was ready to throw it out the window until I found this…so THANX!!!!!!!
Emin
July 31st, 2008 at 6:04 am
Thanks man! you just saved my life!
Emin’s last blog post..Undergraduate Scholarships for International Students/Australia
chuckroast
July 31st, 2008 at 7:40 am
woo hoo! worked like a champ
Billy
July 31st, 2008 at 10:02 am
WOW!! is all I can say. I was struggling with this F-ing hijacking son of a B for a few days and this simple tool removed. GREAT JOB and many thanks.
Oliviu Radulescu
August 1st, 2008 at 5:17 am
very helpfull , thanks
Joemamanj
August 1st, 2008 at 10:13 am
Thanks a bunch! My mother-in-law got this and I searched the net right away. Came upon this post in a matter of 2 minutes. Saved me hours of pain. Thanks
mert toka
August 4th, 2008 at 8:43 pm
very very very thank you.. i have gone crazy about this f*cking thing… I guess it completely removed from my comp. thanks dude
shawn
August 5th, 2008 at 1:13 am
Dude, thanks, this is awesome, i was almost crying 5 minutes before till i see your blog. thanks!
JPL
August 5th, 2008 at 5:25 am
Thank you very much for this information! It worked like a charm and will keep it for future use!
Jackie
August 6th, 2008 at 5:48 am
Same here, there was no running process.
Couldn’t detect it at all, spent half an hour wondering before I gave up and asked Google.
Thanks for the info~
Jackie
DD
August 6th, 2008 at 9:14 am
Thanks! Worked for me:)
Ramakrishna Wunudurthy
August 6th, 2008 at 10:28 am
Thanks a ton. You saved me from this bugging.
Italiano
August 7th, 2008 at 1:50 am
Grazie mille io sono italiano e avevo questo virus da giorni grazie a te ho risolto il problema sei il migliore!
r0mmi3
August 7th, 2008 at 4:16 am
my cousin got this problem and he deleted the files but its still there. please help he e-mail me if you wanna!
Supreme Victory
August 7th, 2008 at 12:41 pm
Thank u too the author, jesus fucking christ, i spent hours fucking with other spyware programs, if the man who designed this program put up a paypal id send him a few dollars, lol
hendelr
August 8th, 2008 at 12:39 pm
Thanx
it works great!
kate
August 9th, 2008 at 3:59 am
thanks!!! you are a life saver.
Nex
August 10th, 2008 at 5:43 pm
omg thx u so much one run and my problems were gone
Kayla
August 10th, 2008 at 6:24 pm
You know what? i love you guys! seriously! lol anyways this fixed it, it wasn’t much of a threat just annoying xD
so Thankyou!!!!!!!!
PC
August 11th, 2008 at 1:59 am
Thank you so much for the info! I’ve been really worried about this virus… I’ve been running two anti-virus programs already and none worked. Thank you so much for your help
Dennison Uy - Graphic Designer
August 11th, 2008 at 2:34 pm
Thank you all for the words of appreciation. To answer Supreme Victory’s question, the author ShadowPuterDude does have a Paypal account. Just click on the donation link on his home page at http://www.malwareteks.com/
eisleyr
August 12th, 2008 at 11:28 am
ShadowPuterDude – you ROCK!! Working on a friends puter and your routen fixed it right up!!!
Thanks to Dennison Uy for posting this!!!
With out you both I would not have found this or fixed it.
omghai
August 12th, 2008 at 11:42 am
i dont think it worked, it reads for me
!!! Files that have been deleted !!!
——————————————————————————–
!!! Directories that have been removed !!!
No malicious directories to be removed
did it work, or not? please email me.
phxxl
August 12th, 2008 at 8:09 pm
Thanks very much. You are such a genius!
daksh
August 13th, 2008 at 3:44 am
dude
thnx a lot.
Michael
August 13th, 2008 at 7:21 am
it doesnt work man….the antivirus/antispyware deletes it…but when i restart it appears again……plz help
Majo
August 14th, 2008 at 12:30 pm
Thank You Dennison! I was very worried when the results of the scan using nod said that my laptop was clean, when I knew it had a virus; your post totally solved my problem.
JK
August 15th, 2008 at 3:03 am
Thank you so much for this- it had been driving me insane-
it only took a few minutes to download and run- and it’s gone!!
Thanks again!!
You rule- i owe ya one.
Gustavo
August 15th, 2008 at 1:56 pm
Olá, tenho uma duvida sobre Virus e gostaria aqui dividir com todos e quem sabe ser esclarecido por alguem.
É o seguinte: Ando tentando encontrar uma KEYGEN pra ativar os complementos do Adobe CS3. Bom, o fato é q todo vez q encontro e baixo uma desses Geradores de Codigos meu Anti-Virus detecta em cada um deles alguns virus como “Trojan”. Ja li alguma coisa sobre e alguns dizem ser eles inovencivos pq os Antivirus acusam tais “programinhas”. Qual a opniao de vcs?
Muito Obrigado pela atençao.
Grato!!
Dodgy
August 15th, 2008 at 6:04 pm
Hi All,
Worked great for me, deleted three files and 2 registry entries
Many Thanks
Dodgy
Adeel
August 16th, 2008 at 3:16 am
Thanks, Its works
Gabriel Sánchez
August 17th, 2008 at 11:22 am
Hi.. i got problems with this virus… i ran the FixIEDef but nothing, the log says that nothing was found, and the message is continue apearing…
Amit Dimri
August 17th, 2008 at 8:32 pm
Thanks buddy,
You just save lie life. I apply all the techniques to get rid of this sit but nothing work. This exe work like a miracle.
circuit breaker
August 18th, 2008 at 1:52 pm
guys, this virus is supposed to give the controller of it remote access to your machine.
I’m reinstalling. it’s not worth the assumed potential risk even if it was removed.
I freaking hate Windows.
simon
August 20th, 2008 at 7:10 pm
it did work for me, but after so many files deleted, it just started right over, is there something i missed?
simon
August 20th, 2008 at 7:30 pm
OMG, i did this a few days ago, and it didnt work, i tried it again today, and(i dont know if necesary)restarted my pc right after the scan, and now its gone
thanx!!!!
ShadowPuterDude
August 20th, 2008 at 8:36 pm
It’s been a while since I’ve check Dennison’s blog.
This is not a Virus, it’s a Trojan. There is a difference. Also this is not a remote Access/Administration Tool (RAT), it is a Downloader.
The Trojan connects to a specific URL looking for instructions on what to download next. For the past year it’s singular behavior is to display fake warnings every time you open Internet Explorer or Windows Explorer in an attempt to get you to download and purchase a rogue security application. They are after your money.
I know exactly what this does to your system, I’ve been tracking these guys for nearly a year, and run complete forensics on what this thing does to your system. Each and every time they release a new downloader. Which is 3-5 times a week. FixIEDef removes this Trojan completely from the system. Removes all files and registry entries added by the dropper.
Since the perpetrators of this fraud , change the infection frequently; FixIEDef doesn’t always contain the newest variant. I normally have the new dropper within minutes of its release onto the net. I’m not the only one watching these criminals. Unless I have to code entirely new routines and functions, FixIEDef is updated and published within an hour or two of the new variant being released.
If the new variant requires new routines and functions, then it may take a day or two before the tool is updated and published for general release. New code requires extensive testing before release.
val
August 21st, 2008 at 2:56 am
thank you so much!I really didn’t know what to do!:)
Mark
August 21st, 2008 at 4:43 pm
This did nothing for me, still getting the same pop ups, adaware, avg and windows defender also doing nothing.
Phil
August 21st, 2008 at 8:29 pm
Thanks a lot for putting together this blog, mate. Although my problems aren’t all fixed yet it has at least given me some hope.
I was getting those exact “Attention, some dangerous trojan horses detected” messages, and the FixIEDef seems to have stopped these pop ups for now. It deleted a file: c:\Windows\system32\tbs.dll. No registries were deleted though.
But, on top of those messages, something has really slowed down my Windows. Since the FixIEDef fix it has sped up slightly but it is still hoplessly slow. Spydoctor and AVG can’t find anything. I’m currently downloading the trial of Windows Live One Care which has got rid of the most malicious and undetectable files I’ve had in the past… but the way things are going, I’m not holding my breath.
Any more advice or info would be much appreciated, guys.
Phil
August 22nd, 2008 at 2:15 am
Ok, I think it’s safe for me to say (touch wood) that my computer is now running normally. Windows Live One Care advises the removal of AVG and (after spending ages trying to uninstall it and scanning with various other applications) AVG went and my PC returned to normal.
Needless to say, I’m confused. Did the trojan originally mentioned in this blog download something that attacks AVG? To be quite honest, that’s the only thing I can think of.
Anyway, thanks again. Without this blog I’d still have those annoying “system error” messages!
Marcel
August 22nd, 2008 at 2:29 pm
Great Job !
rick to the james irani
August 24th, 2008 at 10:35 am
THANK YOU!! :]
Trojan IEdef | erwin blog
August 24th, 2008 at 9:43 pm
[...] ku minta bantuan om ku, yakni om gogel, dan finnaly ketemu juga yang kucari2. Baca Artikel ini atau untuk download Removal [...]
Oh Namanya Trojan IEDEF « Coretan Si Abang
August 24th, 2008 at 10:09 pm
[...] ku minta bantuan om ku, yakni om gogel, dan finnaly ketemu juga yang kucari2. Baca Artikel ini atau untuk download Removal [...]
JOBBO
August 25th, 2008 at 12:06 am
Yes, This is what i’m talking about.
You the man!
Give Big Thanks for Dennison Uy
and ShadowPuterDude of Malwareteks.
Rob
August 25th, 2008 at 4:06 pm
Thanks alot man,
that was getting real annoying..but that program worked,
even tho it was a slightly different virus
Yuli G
August 26th, 2008 at 5:54 am
solved the problem on my computer, Thanks ShadowPuterDude
Dennison Uy
August 26th, 2008 at 1:32 pm
@Phil I believe your computer may still be infected by a different virus. Another possible cause is having too many applications running on the background. Hope that helps.
ben
August 29th, 2008 at 6:06 am
you are a legend! thanks for the help!
Matt
August 30th, 2008 at 12:49 am
you know what really makes me happy?
people like you who take the time to research the cure of this virus and then share it with other people, if there were more people like you on this earth we would probably completely rid the world of faggot virus geeks who have no life and get off on destroying peoples computers
you are honestly a saint, you fixed my machine from being hacked, you fixed my family from a potential secret information retrieval, and YOU have made a kid very happy so bless you! and well done and thankyou so very much!! thankyou thankyou thankyou! you are a bloody legend mate well DONE!
Istvan Horvath
August 31st, 2008 at 10:09 pm
God bless your soul! I’ve had this problem for days and it has been driving me nuts (especially, since it would crash windows explorer randomly).
Thank you so much!
Jess
September 3rd, 2008 at 12:34 am
Oh my goodness, thank you so, so, so, so much!!!!!
HAppy
September 3rd, 2008 at 2:59 am
thx man, just what i needed!!!
You the Man!
HAppy
September 3rd, 2008 at 3:01 am
greetings from Holland by the way…
Kabindra Bakey
September 4th, 2008 at 3:21 pm
Warm Greetings …
*********************************
!!! Files that have been deleted !!!
C:\WINDOWS\WLXPGSS.SCR
C:\WINDOWS\System32\jadz.dll
——————————————————————————–
!!! Directories that have been removed !!!
No malicious directories to be removed
——————————————————————————–
!!! Registry entries that have been removed !!!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\bind “comment”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.Bho
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WARP
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07EF0649-D5BA-4139-B0A2-4D047F223B2D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4889BC79-638C-4D09-99A3-2CB4AD8AB956}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D55D6501-3AFD-44B6-8C7D-4E5C6293EE33}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{15C7D7AD-A87A-4C0D-9D8B-637FCD3488EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07EF0649-D5BA-4139-B0A2-4D047F223B2D}
================================================================================
All Done
Imran Khan
September 5th, 2008 at 12:51 am
Wow, it saved me so much headache in this month of Ramadhan !!!
Thank You.
gus
September 6th, 2008 at 6:42 am
thanks a milli puterdude and thanks to Dennison Uy for the post! saved me mad time!
Kashif
September 7th, 2008 at 11:42 am
Thnx a lott brother, it worked
ekjgds
September 7th, 2008 at 6:36 pm
hey , its so wonderful , thanks a lot .
Ylli
September 9th, 2008 at 5:50 am
Many thanks from Albania. It worked perfectly
Arnab
September 13th, 2008 at 4:26 am
Thanks a lot dear friend. Even I was totally foxed by this pest. The remedy worked for me and also restored my mental balance too. I offer my gratitude to you for offering me this solution.
a-ron
September 16th, 2008 at 9:12 pm
Thanks!
subin
September 21st, 2008 at 12:04 pm
hey hav u gotta mesge.pls tell me about yours nex up coming album
subin
September 21st, 2008 at 12:07 pm
hey why dont u guys chat wit me
Tenco
September 26th, 2008 at 10:01 pm
Hey guy… thanks for the help with that blinking virus… the program really did the trick… and so quick too. No support needed (^-^)… thanks also to ur guy ShadowPuterDude, im glad he’s on our side… thanks again!!
Tejeshwar
October 11th, 2008 at 10:52 pm
Really really really thanks to you and ’shadowputerdude’. Thank you veeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeerrryyy much!!!!!!!. It was a headache for me for 3 days.At last I got rid of that damn thing.Oh god , so annoying.I thank you once again for putting up this matter on this blog.
Geesk
October 14th, 2008 at 2:27 pm
thanks for the link! excellent program.. =)
Yasmin
October 15th, 2008 at 6:52 pm
wow!…
thank u very much..
thanks a lot!!!!!
that fuckin virus already gone..
thanks!!!!
jamie
October 19th, 2008 at 5:43 pm
Thanks so mutch for this. I though I was goina get sacked for putin a virus (unknowingly) on my company laptop. Thanks so mutch for showin me how to removie it you have saved my job.
Michael
October 21st, 2008 at 7:35 pm
I actually had this trojan on a laptop of mine and it caused complete havoc. I could not figure out how to get rid of it and eventually it ended up with a root kit. I had to reinstall the entire operating system and hope that the rootkit was still not there. Thanks for the great tips on getting rid of this.
Stefan
October 22nd, 2008 at 2:26 am
Thanks for this it is a great help. Stumped me too and no AV was helping.
New virus in Net n soln!!! - Domain Discussion Board
October 24th, 2008 at 2:43 am
[...] AM If you are facing the problem with following Warning! box on your computer Preview Click Here to solve it [...]
soo
November 16th, 2008 at 12:39 am
tanks, tanks, Very Very TANKS!!!
Its horrable experience. but I fix it.
Your post save my laptop.
thankyou. (>.
Jack
December 7th, 2008 at 10:26 am
again…I would have collapsed if there is no such a virus cleaner….
thank you very very much