What the Tech logo

What the Tech? It's as easy as 1,2,3! ( Log In | Register )
Easy as 1,2,3!

 
Reply to this topicStart new topic
> How to remove Trojan.Win32.LinkReplacer, System Error!
Blair
post Dec 14 2007, 12:33 AM
Post #1


SuperMember
Group Icon

Group: Root Admin
Posts: 1,497
Joined: 2-February 04
Member No.: 2,905
Operating System: Windows Vista Ultimate




How to remove Trojan.Win32.LinkReplacer, and "System Error!" warnings.

Trojan.Win32.LinkReplacer System Error! popup:
QUOTE
Your browser was hijacked by Trojan.Win32.LinkReplacer
It's dangerous for your system, some files can be lost and your browser can be slow!
Click OK to download the antispyware program to clean your computer! (Recommended)

Trojan.Win32.LinkReplacer has a new trick, it's being installed by a warning to update Macromedia Flash Player. Usually after clicking a link to watch a video:


If you click to Continue, it will serve relentless popups advertising for IEDefender.


If you have install IEDefender, you may have notice it doesn't easily go away, and has its own annoying warnings. These instructions should remove that as well. The motive of the infection is to get you to buy IEDefender. It works like this: Infect your system, display fake warning popups, install a rogue antispyware application, and then charge you to buy the program that claims to remove the infection they installed.


Trojan.Win32.LinkReplacer Removal Instructions:
ShadowPuterDude has authored an automated tool for removal of Trojan.Win32.LinkReplacer. You can find the download and instructions here.
    NOTE: You will need to temporarily disable any programs you have running that will block attempts to edit the registry. As FixIEDef calls REGEDIT to delete registry keys added by Zlob, Trojan.Downloader.Delf, AntiSpyPro, and IE Defender.

  1. Download FixIEDef.exe by ShadowPuterDude to the Desktop.
    Note: FixIEDef now supports Non-English Language Systems

  2. Double-click FixIEDef.exe:


  3. That will open the About FixIEDef screen. Click OK to continue:


  4. Next, press the Scan! button:


  5. FixIEDef needs to run as Administrator to perform correctly. This message simply confirms it was able to run with admin privileges. Click OK to continue:


  6. Wait for the scan to finish. It shouldn't take very long:


  7. After the !!! All Finished !!! message is displayed, click Exit:


  8. That's it! You're done, and the infection should be removed.

    Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. See: http://www.beyondlogic.org/consulting/proc...processutil.htm

    Mirrors: Alternate official download locations for FixIEDef.exe

    http://it-mate.co.uk/downloads/fixiedef/fixiedef.exe
    http://hosts-file.net/download/fixiedef/fixiedef.exe
    http://avant.it-mate.co.uk/?c=Download&f=Tools/FixIEDef
    http://archives.mysteryfcm.co.uk/?f=Securi...pyware/FixIEDef


If after running this tool the Trojan.Win32.LinkReplacer infection is still present, post a HiJackThis log in the Malware Removal Forum.

=====================================================================
This is a self-help guide. Use at your own risk.

Important Note: If you need assistance, please start a new topic in our Malware Removal Forum. This topic is also open for comments, but not all will receive a reply. Please NO HijackThis logs in this topic.

This post has been edited by Blair: Jan 12 2008, 11:57 AM
Reason for edit: support for non-English
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 21st November 2009 - 03:57 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy