Can't get rid of fakeWGA

Hi there
Here are the contents of check.txt:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Tmp]

I have no idea what this is telling me!
dumbo:red:
 
Hi :)

OK that is just a minor leftover...

Backup Your Registry with ERUNT:
  • Download erunt.zip to your Desktop from here:
    http://aumha.org/downloads/erunt.zip
  • Right-click erunt.zip, select Extract All... and follow the prompts to extract ERUNT to a new folder on your Desktop
  • Inside the new folder, double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note: to restore your registry, go to the backup folder and start ERDNT.exe


Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Tmp]
Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Save the document to your desktop as Fix.reg and filetype: All Files
Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to
merge the contents to the registry, click yes/ok.

Restart the computer and run Spybot scan again. Still finding FakeWGA ?
 
Unfortunately, I am still getting the same message, even after the running fix.reg. I think maybe the Spybot program is creating this on start-up. In fact now I think about it usually Spybot does not start up straight away and I have to double-click on it 2 or 3 times for it to run. I have tried uninstalling Spybot and downloading and installing it again - but the same thing happens :sad:
dumbo
 
Hi :)

Ok strange...And you didn't get no error message when you ran the regfix?

Please run the peek.bat again and post the contents of check.txt
 
Hi Mr JaK3
No - the message when I ran fix.reg said it had been entered into the Registry.
Peek.bat produces the same as last time:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Tmp]

When I ran Spybot & got the same fakeWGA finding, I got the same details as before:

SBI $88177DB5 Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Tmp

I then double-clicked the Registry icon looking for more details and got into Registry Editor where it said under
Name Type Data
[icon with Ab on it] (Default) REG_SZ (Value not set)

Didn't dare do anything with this! - I just noted it down.

Have you any suggestions, or should I just live with this?
Many thanks
dumbo
 
You can remove the tools we used.

=============

Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:

Stay clean and be safe ;)
 
Thank you

Many many thanks for all your help Mr JaK3.
Although I still I have what I thought was my problem, I have cured many I didn't realise I had! I am now putting into practice all your final advice.
Thanks again :)

dumbo
 
You're very welcome :D:

This topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.

Glad we could help :2thumb:
 
Back
Top