You came here because you have that stupid
spyware called sandboxer? You came to the right
place, here you can heal your computer from
SANDBOXER!
I know it's very annoying to get these sandboxer popups..
Download
SPYSWEEPER
And automatically remove sandboxer!
Spysweeper will help you with all the other annoying ADS, too!
So you better go and download it now!
Manual removal (not recommended if you are not experienced
user):
Using RegEdit, in HKEY_LOCAL_MACHINE\Software find all Keys having 14 random characters, and beginning with a digit (such as 4#D3LTM36@@M2#) and remove these.
Remove the comparable string value at HKLM\software\microsoft\windows\currentversion\run\ (ie., any value that has 14 random characters, and beginning with a digit (such as 4#D3LTM36@@M2#)
Using PestPatrol's Running Processes tab, find the two files that have identical MD5 values, are 225,336 bytes in size, and that are located in your Windows System32 directory. These are running, and need to be deleted. Note their names. Kill them using Task Manager (Ctrl-Alt-Del). Delete them on disk, and any other files in the System32 directory that have a size of 225,336 bytes. There should be six such files, each with names such as: C:\WINNT\System32\HPHipm09.exe C:\WINNT\system32\Yjjq5g.exe C:\WINNT\system32\Ovc7J0i.exe C:\WINNT\system32\Uflmw.exe These files are marked "system" and "hidden", so you will need to ensure that Windows Explorer can see such files if you are to delete them manually.
Note that SandBoxer renames its files while you work away on them... so you may need to do your work quickly.
Stop Running Processes: Kill these running processes with Task Manager:
Remove AutoRun
Reference:
Go to the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\od-asia4,
delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\2swzkn82r5k47c,
delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\3z6f4j35#h46s9,
delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\4s2nsla3qs#366,
delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\idjqqk,
delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ymcjqxfa,
delete it and reboot the machine immediately.
Clean
Registry:
Remove these registry items (if present) with RegEdit: