Wednesday, February 10, 2010

Antivirus2010pro.com, antispywarecomp.com and other site that promote Windows Defender 2010 virus

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Previously I wrote about the fake anti-spyware program called Windows Defender 2010. Today I want to draw your attention to six new websites that promote this rogue software. The website listed below use the dame web template and false information about illegitimate security application. Please don’t visit these websites as you may infect your computer. If you were redirected to any of these websites while surfing the Internet leave it immediately. However, if windef2010.com or for example antiviruscarecom.com website constantly comes up on your screen that means that your computer is probably infected with Windows Defender 2010 virus. Please read Windows Defender 2010 removal instructions and remove this infection from your computer as soon as possible.
  • spywaredestroyerone.com
  • windef2010.com
  • antivirus-live-one.com
  • antiviruscarecom.com
  • antivirus2010pro.com
  • antispywarecomp.com
Screenshot of antispywarecomp.com

How to remove Security Antivirus fake program? (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Security Antivirus is a fake security program and if you are reading this article then your computer is probably infected with this irritating virus. The good news is that it can be removed for free, but unfortunately there's no quick "one-click" fix for this problem. First of all, let's find out what exactly is Security Antivirus and where did it come from? It's classified as a rogue anti-spyware program, but actually it's a Trojan virus that pretends to be legitimate security software. This one is a clone of other rogue programs: PC Live Guard, Live PC Care and Additional Guard. Usually such fake programs are promoted through the use of fake online scanners, bogus websites/online ads and even using social engineering methods. For example, you can receive a message in Facebook with a link to something supposedly very funny or interesting. You should always be careful with such things especially when messages come from people you don't know.



Security Antivirus video: (thanks to rogueamp)


Once installed, SecurityAntivirus runs a fake system scan and reports false threats. Then it prompts to pay for a full version of the program to remove the false threats. By the way, this misleading software creates several harmless and fake files on your computer and then detects these files as infections/threats. SecurityAntivirus creates the following files in %UserProfile%\Recent\ directory: tjd.sys, ANTIGEN.exe, cid.dll, PE.drv, ANTIGEN.drv, DBOLE.sys, CLSV.drv, ddv.dll, FS.drv, ddv.sys, energy.tmp, gid.drv, PE.exe, PE.sys, PE.tmp, tjd.drv, ANTIGEN.drv, runddlkey.dll std.exe. These file will be associated with infections listed below:
  • Trojan-Spy.HTML.Bankfraud.ra
  • Virus.Win32.Faker.a
  • BAT.Looper
  • Trojan-PSW.Win32.Delf.d
  • Trojan-Spy.HTML.Bayfraud.hn
  • Trojan-Spy.HTML.Bankfraud.ix
  • Trojan-Spy.HTML.Citifraud
  • Packed.Win32.PolyCrypt
  • and etc.
Furthermore, this fake software will display many fake warnings claiming "Warning! Identity theft attempt detected" or "Security Antivirus has detected potentially harmful software in your system" and similar alerts. Some of the fake security alerts you will see:





Now, the worst part is that Security Antivirus blocks Task Manager and other useful system tools. Of course, it blocks security software in the first place. The rogue program installs BHO (Browser Helper Object) and modifies Windows Hosts file (adds 62 malicious entries) so that you will be constantly redirected to various bogus websites. Google search results will be also hijacked, it will display search results from indgala.com instead. As you can see, this program is a total scam. Don't purchase. It you already did that, contact your credit card company and dispute the charges. Then remove Security Antivirus from your computer as soon as possible. We’ve got the instructions to help you get rid of this annoying infection. Please read further. Good luck!


Security Antivirus removal instructions (method #1):

Download one of the following legitimate anti-malware applications and run a quick system scan. Don’t forget to update it first. All programs a free.
NOTE1: if you can't run any of the above programs you must rename the installer of selected program before saving it on your PC. For example: if you choose MalwareBytes then you have to rename mbam-setup.exe to iexplore.exe, explorer.exe or any random name like test123.exe before saving it.

NOTE2: if you still can't run the renamed file then you need to change file extension too not only the name.
1. Go to "My Computer".
2. Select "Tools" from menu and click "Folder Options".
3. Select "View" tab and uncheck the checkbox labeled "Hide file extensions for known file types". Click OK.
4. Rename mbam-setup.exe to either test123.com or test123.pif
5. Double-click to run renamed file.



Removing Security Antivirus in Safe Mode with Networking (method #2):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



NOTE: Login as the same user you were previously logged in with in the normal Windows mode.
If you can't reboot your PC in Safe Mode with Networking, download SafeBootKeyRepair and run it. If the rogue program blocks it then download and run this file RenamedSBKRepair. Follow the prompts. Then reboot your PC in Safe Mode with Networking.

2.Download one of the following legitimate anti-malware applications and run a quick system scan. Don’t forget to update it first. All programs a free.

Security Antivirus associated files and registry values:

Folders and files:
  • C:\Documents and settings\All Users\ Application Data\d5fcc6
  • C:\Documents and settings\All Users\ Application Data\d5fcc6\72.mof
  • C:\Documents and settings\All Users\ Application Data\d5fcc6\mozcrt19.dll
  • C:\Documents and settings\All Users\ Application Data\d5fcc6\SA345d.exe
  • C:\Documents and settings\All Users\ Application Data\d5fcc6\SAV.ico
  • C:\Documents and settings\All Users\ Application Data\d5fcc6\sqlite3.dll
  • C:\Documents and Settings\All Users\Application Data\SADFIOPODIV\SAAKDUPV.cfg
  • %UserProfile%\Application Data\Security Antivirus
  • %UserProfile%\Recent\ANTIGEN.drv
  • %UserProfile%\Recent\ANTIGEN.exe
  • %UserProfile%\Recent\cid.dll
  • %UserProfile%\Recent\CLSV.drv
  • %UserProfile%\Recent\DBOLE.sys
  • %UserProfile%\Recent\ddv.dll
  • %UserProfile%\Recent\ddv.sys
  • %UserProfile%\Recent\energy.tmp
  • %UserProfile%\Recent\FS.drv
  • %UserProfile%\Recent\gid.drv
  • %UserProfile%\Recent\PE.drv
  • %UserProfile%\Recent\PE.exe
  • %UserProfile%\Recent\PE.sys
  • %UserProfile%\Recent\PE.tmp
  • %UserProfile%\Recent\runddlkey.dll
  • %UserProfile%\Recent\std.exe
  • %UserProfile%\Recent\tjd.drv
  • %UserProfile%\Recent\tjd.sys
  • C:\Program Files\Mozilla Firefox\searchplugins\search.xml
Registry values:
  • HKEY_CURRENT_USER\Software\3
  • HKEY_CLASSES_ROOT\SA345d.DocHostUIHandler
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=195&q={searchTerms}"
  • HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=195&q={searchTerms}"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" ="http://127.0.0.1:27777/?inj=%ORIGINAL%"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "App/7.00195"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Security Antivirus"


Share this information with other people:

How to remove Advanced Defender fake antivirus program? (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Advanced Defender is a fake and very annoying antivirus program. Basically it's the same thing as Personal Protector scareware which was released last year. Both programs look the same only the name is different. AdvancedDefender is promoted and installed through the use of Trojans, however the fake program still has to be manually installed. Cyber criminals use various misleading methods to trick you into downloading ans installing  this bogus software. This infection may come from fake online scanners, bogus websites or bundled with other malicious software. Also note that the scammers use such well know sites as Facebook and MySpace to promote their products. Don't download or install anything if you are not sure what it is and especially don't open any links sent by unknown people.



Once installed, Advanced Defender creates numerous harmless and fake files on your computer, then runs a fake system scan and detects those files as serious system threats. The fake files are located in C:\Windows\ folder. The files are:
  • secureit.com
  • microsoftdefend.dll
  • explorers.exe
  • certofsystem.exe
  • regp.exe
  • spoos.exe
Of course, it can also include legitimate Windows files in its false scan results. That's why don't trust it and don't delete any of those reported files otherwise you can damage your system. As a typical scareware, Advanced Defender prompts you to purchase the program in order to remove the infections or computer threats. Of course, yous shouldn't buy it. Cyber criminals won't return your money, believe me. Contact your credit card company and dispute the charges if you already purchased it.

Furthermore, this fake application displays fake security alerts and system error messages claiming that nearly all executable files are infected and that you should purchase AdvancedDefender in order to fix this problem.



"Advanced Defender Warning
C:\Windows\Sytem32\cmd.exe is infected with worm
Lsas.Blaster.Keylogger. This worm is trying to send your credit
card details using C:\Windows\Sytem32\cmd.exe to
connect to remote post."


That's actually a very clever self protection method used by almost all rogue programs nowadays. There are more such fake notifications. Ignore false scan results and those fake warnings. Then remove Advanced Defender from your computer as soon as possible. Use the removal guide below. It will show you how to get rid of this infection for free using legitimate and reliable anti-malware software. If you have any questions don't hesitate and leave a comment. Good luck!


Advanced Defender removal instructions:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



NOTE: Login as the same user you were previously logged in with in the normal Windows mode.
If you can't reboot your PC in Safe Mode with Networking, download SafeBootKeyRepair and run it. If the rogue program blocks it then download and run this file RenamedSBKRepair. Follow the prompts. Then reboot your PC in Safe Mode with Networking.

2. Download one of the following legitimate anti-malware applications and run a full system scan. Don’t forget to update it first. All programs a free.

Advanced Defender associated files and registry values:

Directories and Files:
  • C:\Documents and Settings\All Users\Microsoft PData
  • %UserProfile%\Start Menu\Programs\Advanced Defender
  • C:\Program Files\Advanced Defender
  • C:\Program Files\Advanced Defender\advanceddefender.exe
  • C:\Program Files\Advanced Defender\base.wdb
  • C:\Program Files\Advanced Defender\baseadd.wdb
  • C:\Program Files\Advanced Defender\conf.wcf
  • C:\Program Files\Advanced Defender\quarant.wdb
  • C:\Program Files\Advanced Defender\q
  • C:\WINDOWS\certofsystem.exe
  • C:\WINDOWS\explorers.exe
  • C:\WINDOWS\microsoftdefend.dll
  • C:\WINDOWS\regp.exe
  • C:\WINDOWS\secureit.com
  • C:\WINDOWS\spoos.exe
  • C:\WINDOWS\system32\winscent.exe

Registry values:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Advanced Defender
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Defender
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "advanceddefender"



Share this information with other people:

Monday, February 8, 2010

Fake "Tracking software found!" warning (How to remove)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
"Tracking software found!" is a fake warning from the rogue anti-virus software called Vista Guardian, but it may show up when your computer is infected with other rogue software too. It’s one of the many fake notifications displayed by bogus software. The fake notification claims:

"Tracking software found!
Your PC activity is being monitored. Possible spyware infection. Your data security may be compromised. Sensitive data can be stolen. Prevent damage now by completing a security scan."

If you see this fake warning then your computer is infected either with Vista Guardian virus or Trojan virus that promotes fake software. Read here how to remove Vista Guardian and related malicious software from your computer for free using legitimate and reliable anti-spyware software.

How to remove Paladin Antivirus fake security program? (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Paladin Antivirus is one of many fake (rogue) anti-virus programs. If you’ve got a computer infected by this virus then you probably know how irritating it can be. There can be a bunch of different ways how Paladin Antivirus gets into a computer. However, most of the time, this virus is promoted through the use of Trojans and other malicious software. Usually, Trojans come from rogue websites and misleading online ads. Fake pop-ups may also come up on well know and trusted websites like Facebook and MySpace. That’s why you should always check twice before accepting, downloading and installing files from the Internet.



Paladin Antivirus video: (thanks to rogueamp)


Once installed, Paladin Antivirus will be configured to scan your computer automatically each time Windows starts. Of course, it only imitates a system scan and then reports predetermined system threats just to scare you into thinking that your computer is infected with Trojans, worms and other viruses. Then it will prompt you to pay for a full version of the program to remove the infections which don’t even exist.



Simply ignore those false reports and remove Paladin Antivirus from your computer as soon as possible. Remember, don’t remove any of the reported threats because they may actually be a legitimate Windows files. Read the Paladin Antivirus removal instructions below.

This fake security program is from the same family as Malware Defense. It’s not an exact copy of Malware Defense, but it uses the same misleading methods to protect itself from being removed. When running, Paladin Antivirus will claim that that you must remove currently installed antivirus software in order to avoid conflicts. The rogue program will attempt to remove the following anti-virus software:
  • Malwarebytes Anti-Malware
  • F-Secure
  • AVG8
  • ESET NOD32
  • Norton Internet Security
  • Avira AntiVir
  • Avast!
Furthermore, it will display numerous fake alerts and pop-ups claiming that your computer is compromised or is being attacked from a remote PC.



"Adware module detected on your PC!
Zlob.Porn.Ad adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now."

Just like the false scan results, these fake warnings were designed to make you think that your computer is infected when in reality it’s not. If you find that your computer is infected with this virus, please don’t delay and get rid of Paladin Antivirus immediately.


Paladin Antivirus removal instructions:

1. Download the file TDSSKiller.zip and extract it into a folder
2. Execute the file TDSSKiller.exe (NOTE: you may have to rename TDSSKiller.exe to explorer.com yourself or download already renamed explorer.com file in order to run it)
3. Wait for the scan and disinfection process to be over. Close all programs and press “Y” key to restart your computer.
More detail TDSSKiller tutorial: http://support.kaspersky.com/viruses/solutions?qid=208280684
4. Download one of the following anti-malware software and run a full system scan:

Paladin Antivirus associated files and registry values:

Files:
  • %UserProfile%\Start Menu\Programs\Paladin Antivirus
  • C:\Program Files\Paladin Antivirus
  • C:\Program Files\Paladin Antivirus\help.ico
  • C:\Program Files\Paladin Antivirus\pav.db
  • C:\Program Files\Paladin Antivirus\pav.exe
  • C:\Program Files\Paladin Antivirus\pavext.dll
  • C:\Program Files\Paladin Antivirus\phook.dll
  • C:\Program Files\Paladin Antivirus\uninstall.exe
Registry:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus
  • HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus

Please share this information with other people:

 
//PART 2