Home  |  Contact Us  |  Advertise   |   Follow:

Go Back   2CoolFishing > General Interest Forums > Technical Support Board

Technical Support Board From browser hijackers to viruses, this is the place to figure it all out.

Reply
 
Thread Tools Display Modes
  #1  
Old 01-07-2012, 03:07 PM
CoastalOutfitters's Avatar
CoastalOutfitters CoastalOutfitters is offline
regional director of directional regions
 
Join Date: Aug 20 2004
Posts: 16,295
Rep Power: 21494356
CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters
HKCR\.exe issue

this keeps popping up , when i run spyware removers

i delete it and it comes back

some sites say it is a false issue, others say remove it

what removal tool to use ? thanks
Reply With Quote
  #2  
Old 01-07-2012, 04:12 PM
bill's Avatar
bill bill is offline

 
Join Date: May 21 2004
Posts: 23,038
Rep Power: 21501190
bill bill bill bill bill bill bill bill bill bill bill
turn off system restore
http://windows.microsoft.com/en-US/w...system-restore

what are you exactly deleting?
http://windows7themes.net/what-is-hkcr-exe.html
__________________


Reply With Quote
  #3  
Old 01-07-2012, 08:50 PM
CoastalOutfitters's Avatar
CoastalOutfitters CoastalOutfitters is offline
regional director of directional regions
 
Join Date: Aug 20 2004
Posts: 16,295
Rep Power: 21494356
CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters
Bill,

superantispyware finds it and deletes it

have been holding off on the system restore turnoff because was not sure if this is really an issue since it was reported on some sites to be a fake virus.

will run it w system restore off and reprt

thanks
Reply With Quote
  #4  
Old 01-07-2012, 10:12 PM
bill's Avatar
bill bill is offline

 
Join Date: May 21 2004
Posts: 23,038
Rep Power: 21501190
bill bill bill bill bill bill bill bill bill bill bill
it's a legit registry entry...could be corrupted or infected??????????

problem is with system restore on, every time you reboot....all infections get replaced

what should happen, system restore off, scan completed, reboot, turn on system restore, set new date
__________________


Reply With Quote
  #5  
Old 01-08-2012, 02:51 PM
zeos386sx's Avatar
zeos386sx zeos386sx is offline
jambalaya a crawfish pie and file gumbo
 
Join Date: Oct 25 2006
Location: waco, tx
Age: 34
Posts: 77
Rep Power: 265067
zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx zeos386sx
If you're worried that system restore is infected you should delete the "system volume information" folder which contains all the restore points. It really isn't necessary to do this anymore as almost all antivirus and antispyware programs are capable of finding and removing infections from within the restore points.

for another way to check out that registry entry; download this program.

http://technet.microsoft.com/en-us/s...rnals/bb963902

Recently I have seen several variants of the fakeav's add themselves to exe and explorer associations so that whenever you start a program or right click on something or open my computer the fakeav will launch. Usually it is a random 3 letter executable file, rlq.exe for example, that is located in a userprofile or sometimes in programdata on vista/7 systems.

If it keeps coming back and your certain it is an infection you may need to clean the master boot record and boot sector. assuming you have a common setup (1 hard drive 1 os) here are the instructions.

Be careful this is a measure twice cut once kind of procedure!

XP (see resolution for cause 2, method 1)
http://support.microsoft.com/kb/314503

vista/7
http://support.microsoft.com/kb/927392
Reply With Quote
  #6  
Old 01-08-2012, 03:51 PM
CoastalOutfitters's Avatar
CoastalOutfitters CoastalOutfitters is offline
regional director of directional regions
 
Join Date: Aug 20 2004
Posts: 16,295
Rep Power: 21494356
CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters
turned off sys restore, booted to safe mode and ran spyware search,

it didn't show up there at all

running again in reg. mode w sys restore off to see if it shows


a real head scratcher
Reply With Quote
  #7  
Old 01-08-2012, 10:04 PM
CoastalOutfitters's Avatar
CoastalOutfitters CoastalOutfitters is offline
regional director of directional regions
 
Join Date: Aug 20 2004
Posts: 16,295
Rep Power: 21494356
CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters CoastalOutfitters
2nd pass didn't find it

turned restore on and ran it again and its back grrrrrrr
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 04:09 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
copyright 2013
© 2008 Noreast Media, LLC | Terms of Service| Contact Us | Advertise