Security
•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  just4fun
RegRun Security Suite
Not an antivirus. A powerful tool kit against Trojans, viruses, spyware, adware and rootkits
Features
Benefits

Startup Monitor...

Bootlog Analyser...

Advanced MSConfig...

Know more?
Screenshots

FAQ

On-line manual

Print PDF

One-click purchase
RegRun NIVA Platinum

NIVA+CD-ROM

Download trial
RegRun NIVA Platinum
Forums
Greatis Forum

NI Forum

Mickey Forum

Thank you!

International
Download Russian

Download Ukrainian

Join our localization team

Home Download Order Support   Newsletter Your shopping cart ?
Google redirect problem solved using RegRunCK.exe. It detects MAX++ rootkit and removes rootkit's NTFS mount points

If you have the similar problem :
"I am having a problem with Google redirects. Almost everytime I do a google search, when I click on a search result, I get redirected to another site."
 
You should check your computer immeditelly. Probably you are infected by MAX++ or TDSS rootkit.
Download and open RegRunCK.exe.
RegRunCK.exe is a free of charge. It doesn't include viruses/adware/spyware.
You will see DOS-like window:


Wait for finishing executing of the RegRunCK.exe.
You will see execution log on the screen.
RegRunck.exe v.1.0.3
Processing C:\WINDOWS.

Found rootkit point!
C:\WINDOWS\$hf_mig$\KB912812\KB912812
Type is MOUNT POINT
Final Destination:
\Device\__max++>\^


If you see the words "
Device\__max++"  in your result report - you are infected.
Search the report for "Access is denied" text.
If you find the result linke this:
Failed to open:
C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe
Access is denied.
some of your system files are infected by rootkit and need to be replaced by original files from Windows CD or from another sources.


Why it is dangerous?

The rootkit is hard in removal and you need be very careful!
If you simply delete rootkit files c:\windows\win32k.sys:1,
c:\windows\win32k.sys:2 using your antivirus or another software, this may cause the Windows BSOD at next reboot.



Removal

Please, follow our instructions step by step:

1. Download RegRun Reanimator (free of charge, no ads):
http://www.greatis.com/reanimator.html
or update your UnHackMe or RegRun Suite software.
Reanimator already includes RegRunCK.exe.


If you do not have enough computer skill -
contact our support center
.
Attach your detailed report made by RegRun Suite or Reanimator.
We will send you detailed instructions.



2. Open "Scan for Viruses" screen using  Reanimator.
Look at the video lesson how to use "Scan for Viruses".
Watch Video
Reanimator automatically detects presence of the rootkit and starts the "RegRunCK.exe" for removing rootkit's mount points.
RegRunCK has a switch "/f" that is used for going to the removal mode.
To start RegRunCK manually, open Windows Start menu, "All Programs", "Run", type the path to the RegRunCK and switch /f:
regrunck.exe /f

3. Be careful! The "win32k.sys" is stored in the Windows folder is a rootkit file.
The legitimate win32k.sys is located in the Windows\System32 folder.

4. Rootkit will be removed after Windows reboot.

5. Restore infected system files.

Contact our support center if you have any questions.

Suggest you to use RegRun Platinum Edition to be sure that you are clean!

Good luck!

Dmitry Sokolov


Would you like to add your opinion?

Your Name (Not Required):

Your E-mail to contact (Not Required):


Description:

What's new?

November 20 2009

Released RegRun Suite Platinum 6.5 (6.5.6.65)


November 17 2009
Updated RegRun Reanimator 6.5.6.65 - freeware software for detecting and removing rootkits/malware.

November 9 2009
Updated RegRun Reanimator 6.5.6.64 - freeware software for detecting and removing rootkits/malware.

October 28 2009
Updated RegRun Reanimator 6.5.6.62 - freeware software for detecting and removing rootkits/malware.

Updated RegRun Suite Platinum 6.5 beta (6.5.6.62)

Resolving problem with Google redirect MAX++/TDSS rootkit (win32k.sys:1, win3k.sys:2).


October 23 2009
Updated RegRun Reanimator 6.5.6.61 - freeware software for detecting and removing rootkits/malware.

Updated RegRun Suite Platinum 6.5 beta (6.5.6.61)

Video Lesson how to remove WinLocker Trojan


October 16 2009
Updated RegRun Reanimator 6.5.6.60 - freeware software for detecting and removing rootkits/malware.

October 13 2009
Updated RegRun Reanimator 6.5.6.57 - freeware software for detecting and removing rootkits/malware.

October 6 2009
Try RegRun Suite Platinum 6.5 beta

Updated RegRun Reanimator 6.5.6.55 - freeware software for detecting and removing rootkits/malware.

Malware Removal Lesson

September 25 2009
Updated RegRun Reanimator 6.5.6.54 - freeware software for detecting and removing rootkits/malware.

September 18 2009
Updated RegRun Reanimator 6.5.6.53 - freeware software for detecting and removing rootkits/malware.

September 8 2008
Windows Explorer Redirection DLLS is a new dangerous Windows startup hole...

September 4 2008
Updated RegRun Reanimator - freeware software for detecting and removing rootkits/malware.

June 5 2008
RegRun has been reviewed by 3d2f.com Software Directory: RegRun Security Suite is an excellent tool that will reliably protect you from a plethora of existing and emerging threats and will keep malware at bay.

March 7 2008
Partizan.exe is not a worm. Partizan.exe is a part of RegRun Suite, UnHackMe antirootkit. Updated. Symantec fixed false positive.

February 11 2008
Spyware Doctor false positive. Partizan.sys wrong detection.

What is spXX.sys?

January 28 2007
Removing Medichi Rootkit

October 26 2007
Removal of Noskrnl.exe and Noskrnl.sys Rootkit (Spooldr clone)

July 25 2007
Removal Baidu rootkit (cnprov.sys)

July 24 2007
Removal Spooldr(ecard.exe) rootkit

June 25 2007
Fixing BSOD
in Winlogon Process

June 4 2007
Removal Areses Trojan

May 25 2007
Virus Feebs rootkit removal story

RegRun 5.5 beta updated

Release RegRun Reanimator 5.5.5.900

April 5 2007
What's this? Rthdcpl.exe - Illegal System DLL Relocation...

March 1 2007
Warning! Rootkit Unhooker

February 9 2007
Read our article about Unreal rootkit...

December 28 2006
Released free Rustock Rootkit(lzx32.sys) removal tool

November 29 2006
A#######.sys is a rootkit?

September 8 2006
Rootkit Removal instructions: ntsystem.exe

April 24 2006
What is BDGuard.sys?

April 17 2006
Virus or not? SPTD####.sys

March 31 2006
What is mc21.tmp, mc22.tmp, mc23.tmp?

January 19 2006
ICQCHK.exe, MSX.DLL free remover...
Educational discount...

Services
Ask Computer Guys

Windows startup programs

Articles
Using Registry Tracer...

RegRun against Trojans and Viruses

Specify an order for startup programs

RunGuard prevents a launch...

Using Bootlog Analyser...

They say
"RegRun Security Suite is one of those very rare tool kits that no one who is serious about protecting their PC should ever be without. This toolkit covers all the bases when it comes to eradicating the attempted security threats from malware that we all face - daily. The near real time tech support, direct from Greatis, is nothing sort of superb, something that can be rarely said these days! I have no hesitation in recommending this suite to anyone."

Miles Pearson

Wilders.ORG. Security advisors recommend...

Testimonials
You guys are awesome!!!!
Traci www.pentagonattack911.com

Bob Schmulian:
Absolutely love it and have recommended to many people!

Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since I purchased it less than 6 months ago. I now would not run my system without it... it's worth many times the cost! The service and support are terrific. Helpful - friendly - and accommodating; and generally a reply is received within 12 hours. Just great.

Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.

Awards
Paul's Picks
Shareware Winner  

More...


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | just4fun

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2008 Greatis Software