How to remove Trust Cleaner (Removal Instructions)
Trust Cleaner Program
Fake Desktop Popup
Fake Taskbar Alert
- Block your access to any msn.com web page.
- Change your home page to one that strikingly resembles Google but is in
fact the site hxxp://www.mswindowssearch.com,.
- Show popups with ads when you visit certain sites such as Google, Yahoo,
and CNN among others.
- Not allow you to restart your computer till you kill the trustinpopups.exe process.
- Install a toolbar into your Internet Explorer web browser.
- FixTC.reg (Only if you are doing the manual fix)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\local.html
O2 - BHO: tisa.MyBHO - {6BBD6756-F9BA-4A7E-8C94-A801F740A608} - C:\WINDOWS\system32\tisa.dll
O2 - BHO: TrustIn Bar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\Program Files\trustin bar\trustin.dll
O2 - BHO: ticont.MyBHO - {F365382D-CF21-45BA-80CF-B868C6ED9634} - C:\WINDOWS\system32\ticont.dll
O2 - BHO: SpoofBHO Class - {07A78AEA-4A54-4967-9A60-4B68592D30C7} - C:\WINDOWS\se_spoof.dll O2 - BHO: WeeklyExecuter Class - {590FFB84-6A29-4797-9C0E-B15DF2C4CDCB} - C:\WINDOWS\inetloader.dll O2 - BHO: ContextualAds Class - {FE6C16C4-16AD-47B6-B250-26AD1829E49A} - C:\Program Files\TrustIn Contextual\trustincontext.dll O3 - Toolbar: TrustIn Bar - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\Program Files\trustin bar\trustin.dll
O4 - HKCU\..\Run: [TrustIn Popups] "C:\Program Files\TrustIn Popups\TrustInPopups.exe"
O4 - HKCU\..\Run: [Trust Cleaner] "C:\Program Files\Trust Cleaner\Trust Cleaner.exe"
- Print out these instructions as we will need to close every window that
is open later in the fix.
- Download FixTC.reg to your desktop by right clicking on the following link
and then selecting Save Link As or Save
File as, depending on your browser.
FixTC.reg Download Link
Confirm that the file FixTC.reg now resides on your desktop as we will need it later.
- Click on the Start Menu
- Click on the Control Panel option.
- Double-click on the Add or Remove Programs icon.
- Find the following entries and double-click on each of them. Follow the
prompts to uninstall the programs, but do not allow it to reboot the computer
if it asks. If after you uninstall a particular entry below it still remains,
double-click on the entry again to remove it.
Trust Cleaner
TrustIn Bar
TrustIn Contextual Ads
Trustin Popups
TrustIn Search Assistant
Trust Cleaner Promo
- When it has completed uninstalling you can close Add or Remove Programs
and your Control Panel.
- Next, please reboot your computer into Safe
Mode by doing the following:
- Restart your computer
- After hearing your computer beep once during startup, but before the
Windows icon appears, press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
- When you are at the logon prompt, log in as the user account you were
logged on as when you extracted the SmitRem files.
- Restart your computer
- When your computer has started in safe mode and you see the desktop.
- Go to your desktop and double click on the FixTC.reg file
that you downloaded earlier. When it asks if you would like to merge the information,
press the Yes button and then the OK button.
- Delete the following files and folders (Do
not be concerned if a folder or file does not exist):
C:\Program Files\TrustIn Popups
C:\Program Files\TrustIn Bar
C:\Program Files\TrustIn Contextual
C:\Program Files\TrustIn Popups
C:\Program Files\TrustIn Search
%Temp%\wschtm35.dll
%Temp%\srsvc.exe
C:\WINDOWS\local.html
C:\WINDOWS\SYSTEM32\tisa.dll
C:\WINDOWS\SYSTEM32\lut.dat
C:\WINDOWS\SYSTEM32\tisa.cnf
C:\WINDOWS\SYSTEM32\ticads.exe
C:\WINDOWS\SYSTEM32\tctool.exe
C:\WINDOWS\SYSTEM32\ticont.dll
C:\WINDOWS\SYSTEM32\tpopup.exe
C:\WINDOWS\SYSTEM32\tconini.dat
C:\WINDOWS\SYSTEM32\lcch.dat
C:\WINDOWS\onlineshopping.ico
C:\WINDOWS\removeadware.ico
C:\WINDOWS\sexpersonals.ico
C:\WINDOWS\local.html
C:\WINDOWS\SYSTEM32\tu.exe
C:\WINDOWS\SYSTEM32\ttu.exe C:\WINDOWS\se_spoof.dll C:\WINDOWS\inetloader.dll C:\Windows\mxd.exe C:\Windows\tse.exe C:\Windows\trustinbar.exe C:\Windows\ads.js C:\WINDOWS\videoslots.ico
Delete these icons from your Desktop: Online Shopping.url Remove Adware.url Sex Personals.url Video Slots.url - Close all open Windows.
- Reboot your computer back to normal mode.
- Download the ATF-Cleaner to your desktop from the following link:
http://www.atribune.org/ccount/click.php?id=1
When it is download to your desktop, double-click on the program to run it. Select the box labeled Select All and then press the Empty Select button. When it is done you can close the program.
- Perform an onlinescan with Panda: Panda
Online
- Once you are on the Panda site click the Scan your PC
button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note:
It may take a few minutes)
- When download is complete, click on Local Disks to start the scan
- Once you are on the Panda site click the Scan your PC
button
Preparation Guide For Use Before Posting A Hijackthis Log
This is a self-help guide. Use at your own risk.
BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum.
If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.



Back to top







