PC Review


Reply
Thread Tools Rate Thread

Appropos media stubborn

 
 
Snowball
Guest
Posts: n/a
 
      26th Sep 2005
I ran the MS Antispyware. It detected and offered to
remove it. However, it keeps coming back eg.
HKEY_LOCAL_MACHINE/SOFTWARE/Apprps

I tried to delete this with regedit and keep hitting
refresh and it comes back right away. SO clearly it is
not removed.

How do I find out which is the program name to delete
from the silesystem/registry? Thx


-- snowball
 
Reply With Quote
 
 
 
 
Alan
Guest
Posts: n/a
 
      26th Sep 2005
Try the following tool from Symantec:
http://securityresponse.symantec.com...r/FixAprop.exe
..

If you have either Norton or McAfee installed (AV), they
can detect and remove this as well. Spybot
(http://www.download.com/3001-8022_4-10401314.html?idl=n)
and Ad-Aware (http://www.download.com/3000-2144-
10045910.html) can also detect and remove Apropos, and I
think that ewido (http://www.download.com/Ewido-Security-
Suite/3000-8022_4-10326287.html) can also detect and
remove Apropos. Make certain to downlaod all the updates
for the apps and boot into Safe Mode (press F8 before
initial Windows screen during boot/reboot, press F8 again
to get to advanced option menu, and select the Safe Mode
option that only states Safe Mode). Now run a full
system scan with each app, making certain to remove what
it finds before running a scan with the other apps. When
installing ewido remove the check mark next to ewido
guard and the auto-update feature. Updates for ewido are
provided daily, so update often.

The problem when trying to remove this malware is that it
uses registered .dll files that must first be
deregistered before you can remove it, otherwise the
removal WILL fail. This is why many apps fail to remove
these types of infections.

One more thing. If you are running XP, delete the entire
contents of c:\windows\prefetch just to be safe. YOu
might have to do this in Safe Mode.

Alan

>-----Original Message-----
>I ran the MS Antispyware. It detected and offered to
>remove it. However, it keeps coming back eg.
>HKEY_LOCAL_MACHINE/SOFTWARE/Apprps
>
>I tried to delete this with regedit and keep hitting
>refresh and it comes back right away. SO clearly it is
>not removed.
>
>How do I find out which is the program name to delete
>from the silesystem/registry? Thx
>
>
>-- snowball
>.
>

 
Reply With Quote
 
Snowball
Guest
Posts: n/a
 
      27th Sep 2005
Thx Alan.

I ran the tool in safemode. When I restarted I don't find
the symptoms of an Ad popping up when I close IE.

However, I see that HKLM/software/apprps still exists in
the registry. When I remove it and hit refresh after a
few seconds it comes back.

I don't know if this means the spyware is still on the
machine but its functionality is disabled? Who puts this
key back? Is it MS AntiSpyware trying to stomp over this
key to confuse or disable the spyware?

Any details on exactly what are the files that this
spyware installs and how they work (eg. service, startup
command etc would help me to manually verify that this
has been indeed successfully removed).

Thx

-- snow

>-----Original Message-----
>Try the following tool from Symantec:
>http://securityresponse.symantec.com...er/FixAprop.ex

e
>..
>
>If you have either Norton or McAfee installed (AV), they
>can detect and remove this as well. Spybot
>(http://www.download.com/3001-8022_4-10401314.html?

idl=n)
>and Ad-Aware (http://www.download.com/3000-2144-
>10045910.html) can also detect and remove Apropos, and I
>think that ewido (http://www.download.com/Ewido-Security-
>Suite/3000-8022_4-10326287.html) can also detect and
>remove Apropos. Make certain to downlaod all the

updates
>for the apps and boot into Safe Mode (press F8 before
>initial Windows screen during boot/reboot, press F8

again
>to get to advanced option menu, and select the Safe Mode
>option that only states Safe Mode). Now run a full
>system scan with each app, making certain to remove what
>it finds before running a scan with the other apps.

When
>installing ewido remove the check mark next to ewido
>guard and the auto-update feature. Updates for ewido

are
>provided daily, so update often.
>
>The problem when trying to remove this malware is that

it
>uses registered .dll files that must first be
>deregistered before you can remove it, otherwise the
>removal WILL fail. This is why many apps fail to remove
>these types of infections.
>
>One more thing. If you are running XP, delete the

entire
>contents of c:\windows\prefetch just to be safe. YOu
>might have to do this in Safe Mode.
>
>Alan
>
>>-----Original Message-----
>>I ran the MS Antispyware. It detected and offered to
>>remove it. However, it keeps coming back eg.
>>HKEY_LOCAL_MACHINE/SOFTWARE/Apprps
>>
>>I tried to delete this with regedit and keep hitting
>>refresh and it comes back right away. SO clearly it is
>>not removed.
>>
>>How do I find out which is the program name to delete
>>from the silesystem/registry? Thx
>>
>>
>>-- snowball
>>.
>>

>.
>

 
Reply With Quote
 
=?Utf-8?B?ZnV6em1hc3Rlcg==?=
Guest
Posts: n/a
 
      8th Oct 2005
I have the same problem!

Did you ever find a solution that worked??

Thanks,

Jonny

"Snowball" wrote:

> Thx Alan.
>
> I ran the tool in safemode. When I restarted I don't find
> the symptoms of an Ad popping up when I close IE.
>
> However, I see that HKLM/software/apprps still exists in
> the registry. When I remove it and hit refresh after a
> few seconds it comes back.
>
> I don't know if this means the spyware is still on the
> machine but its functionality is disabled? Who puts this
> key back? Is it MS AntiSpyware trying to stomp over this
> key to confuse or disable the spyware?
>
> Any details on exactly what are the files that this
> spyware installs and how they work (eg. service, startup
> command etc would help me to manually verify that this
> has been indeed successfully removed).
>
> Thx
>
> -- snow
>
> >-----Original Message-----
> >Try the following tool from Symantec:
> >http://securityresponse.symantec.com...er/FixAprop.ex

> e
> >..
> >
> >If you have either Norton or McAfee installed (AV), they
> >can detect and remove this as well. Spybot
> >(http://www.download.com/3001-8022_4-10401314.html?

> idl=n)
> >and Ad-Aware (http://www.download.com/3000-2144-
> >10045910.html) can also detect and remove Apropos, and I
> >think that ewido (http://www.download.com/Ewido-Security-
> >Suite/3000-8022_4-10326287.html) can also detect and
> >remove Apropos. Make certain to downlaod all the

> updates
> >for the apps and boot into Safe Mode (press F8 before
> >initial Windows screen during boot/reboot, press F8

> again
> >to get to advanced option menu, and select the Safe Mode
> >option that only states Safe Mode). Now run a full
> >system scan with each app, making certain to remove what
> >it finds before running a scan with the other apps.

> When
> >installing ewido remove the check mark next to ewido
> >guard and the auto-update feature. Updates for ewido

> are
> >provided daily, so update often.
> >
> >The problem when trying to remove this malware is that

> it
> >uses registered .dll files that must first be
> >deregistered before you can remove it, otherwise the
> >removal WILL fail. This is why many apps fail to remove
> >these types of infections.
> >
> >One more thing. If you are running XP, delete the

> entire
> >contents of c:\windows\prefetch just to be safe. YOu
> >might have to do this in Safe Mode.
> >
> >Alan
> >
> >>-----Original Message-----
> >>I ran the MS Antispyware. It detected and offered to
> >>remove it. However, it keeps coming back eg.
> >>HKEY_LOCAL_MACHINE/SOFTWARE/Apprps
> >>
> >>I tried to delete this with regedit and keep hitting
> >>refresh and it comes back right away. SO clearly it is
> >>not removed.
> >>
> >>How do I find out which is the program name to delete
> >>from the silesystem/registry? Thx
> >>
> >>
> >>-- snowball
> >>.
> >>

> >.
> >

>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
stubborn digit =?Utf-8?B?YmpsMTIyODU0?= Windows XP General 4 21st Oct 2005 05:38 PM
Stubborn Pagefile.sys =?Utf-8?B?c3JuMTEyMA==?= Windows XP Help 0 18th Dec 2004 09:03 PM
stubborn pop-up Laurice Windows XP Internet Explorer 0 5th Sep 2004 02:33 PM
Stubborn uninstall Mark G. Windows XP General 3 2nd Oct 2003 08:57 AM
Stubborn web proxy toa Microsoft Dot NET 1 10th Jul 2003 10:56 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:41 PM.