Type: Rogue Anti-Spyware
Malware Author: Unknown
Threat Level: Critical
Screenshot:

How to remove Malware Catcher 2009 manually:
It's possible to remove Malware Catcher 2009 manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.
The files to be deleted:
%UserProfile%\Recent\cb.tmp
%UserProfile%\Recent\CLSV.dll
%UserProfile%\Recent\CLSV.drv
%UserProfile%\Recent\eb.tmp
%UserProfile%\Recent\energy.exe
%UserProfile%\Recent\energy.sys
%UserProfile%\Recent\energy.tmp
%UserProfile%\Recent\exec.dll
%UserProfile%\Recent\fix.sys
%UserProfile%\Recent\PE.drv
%UserProfile%\Recent\PE.sys
%UserProfile%\Recent\std.drv
%UserProfile%\Recent\tjd.exe
%UserProfile%\Recent\tjd.tmp
%UserProfile%\Start Menu\Malware Catcher 2009.lnk
%UserProfile%\Start Menu\Programs\Malware Catcher 2009.lnk
c:\Documents and Settings\All Users\Application Data\7c69f0c
c:\Documents and Settings\All Users\Application Data\7c69f0c\MCatcher.exe
c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemFeed
c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemFeed\vd952342.bd
c:\Documents and Settings\All Users\Application Data\SystemFeed
c:\Documents and Settings\All Users\Application Data\SystemFeed\mctch.ini
%UserProfile%\Application Data\Malware Catcher 2009
%UserProfile%\Application Data\Malware Catcher 2009\Instructions.ini
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Catcher 2009.lnk
%UserProfile%\Desktop\Malware Catcher 2009.lnk
Remove registry entries:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\MCatcher.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "[xSP_2:2092962508]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "6989019803"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Malware Catcher 2009"
Please be careful because manual removal of Malware Catcher 2009 may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
No comments:
Post a Comment