Wednesday, April 14, 2010

Remove "Copyright Violation: Copyrighted Content Detected" fake warning (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Fake warning "Copyright Violation: Copyrighted Content Detected" is a part of ransomware infection that attempts to convince you to pay a fee for allegedly found copyrighted material on your computer. Actually it's a Trojan horse Trojan.Fakecopyright [Symantec]. Once this Trojan is installed, it will scan your computer for .torrent files and then will display fake Copyright Violation alert window stating that copyrighted material have been found and that you should pay a fee ($399.85) or they will pass your case to the courts where you will be tried by a judge. That's ridiculous, you shouldn't trust it. This is yet another scam. If you find that your computer is infected with I-Q Manager Antipiracy foundation (Copyright Violation: Copyrighted Content Detected) ransomware please follow the removal instructions below to remove it from your PC as soon as possible.




(Video by rogueamp)

"Copyright violation alert
Copyright violation: copyrighted content detected
Windows has detected that you are using content that was downloaded in violation of the copyright of its respective owners. Please read the following bulletin and try solving the problem in one of the recommended ways."



If you select the "Pass the case to court", or "Settle case in pre-trial order", the threat will attempt to display a web page that contains an online order form for the amount of $399.85.



The biggest problem is that this threat then may lock the compromised computer until the user enters a correct license number for the program. Thankfully, S!Ri posted a registration code which should unlock your computer: RFHM2-TPX47-YD6RT-H4KDM. (I haven't tested it, so I don't know for sure)

The home page of the bogus ICPP Foundation is icpp-online.com (193.33.114.77). You should add it and add icpp-online.com to the list of blocked web sites. Also note that this fake Copyright Violation alert has been localized to the following languages: Czech, Danish, Dutch, English, French, German, Italian, Portuguese, Slovak and Spanish.


"Copyright Violation: Copyrighted Content Detected" or I-Q Manager alert removal instructions:

1. Click Start -> Control Panel
2. When in the Control Panel, double-click on one of the options below depending on your version of Windows
a) Add or Remove Programs icon (for Windows XP users)
b) Uninstall Program (for Windows Vista and Windows 7 users)
3. The Add or Remove Programs (Windows XP) or the Uninstall Program (Windows Vista & 7) screen will be displayed. Scroll through the list of programs and look for entries with I-Q Manager, uninstall them. You are done, close the Control Panel screen.
NOTE: If the programs ask you to reboot your computer, do not allow it to reboot until you have uninstalled all of the program.

Your computer should now be free of the I-Q Manager or Copyright Violation: Copyrighted Content Detected malware. However, if it's still on your computer then complete these additional steps:

1. Click Start -> Run.
2. Input: regedit. Then click OK.
3. Navigate to and delete the following registry entries and subkeys:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"iqmanager.exe" = "%UserProfile%\Application Data\IQManager\iqmanager.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IQManager
4. Exit the Registry Editor.
5. Download one of the following anti-malware programs (all programs are free):
6. Install selected anti-malware program, update it and run a full system scan.


I-Q Manager or Copyright violation alert files and registry values:

Files:
  • %UserProfile%\Application Data\IQManager
  • %UserProfile%\Application Data\IQManager\iqmanager.exe
  • %UserProfile%\Application Data\IQManager\settings.ini
  • %UserProfile%\Application Data\IQManager\torrents
  • %UserProfile%\Application Data\IQManager\languages
Registry:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IQManager
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "iqmanager.exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%UserProfile%\Application Data\IQManager\iqmanager.exe"
Share this information with other people:

Tuesday, April 13, 2010

Remove fake "Security breach!" warning (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
If you see a notification that pops up from the Windows taskbar and it's titled "Security breach!" then your computer is infected with XP Internet Security 2010 malware. Fake Security breach! alert reads:

"Security breach!
Beware! Spyware infection was found. Your system security is at risk. Private information may get stolen, and your PC activity may get modified. Click for an anti-spyware scan."

Here's how it looks like:


As you can see, it looks like a legitimate notification from the Windows taskbar. However, this one is fake and it's a part of XP Internet Security 2010 scam. The rogue program wants to make you think that your computer is infected with malicious software. Then it prompts you to pay for a so called "full" version of the program to remove the infections which don't actually exist. Most importantly, don’t purchase this bogus program! If you find that your computer is infected with this malware and you constantly see "Security breach!" notification on your computer screen, then please follow the XP Internet Security 2010 removal instructions to remove this virus from your computer for free using legitimate anti-malware programs. If you have any questions or additional information about this infection, don't hesitate and leave a comment. Good luck and be safe!

Share this information with other people:

Remove "Virus infection!" fake pop-up (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Yet another fake XP Internet Security 2010 notification:

"Virus infection!
System security was found to be compromised. Your computer is now infected. Attention, irreversible system changes may occur. Private data may get stolen. Click here now for an instant anti-virus scan."



This fake warning states that your sensitive information can be stolen. Just like all the other fake warnings from XP Internet Security 2010 malware, "Virus infection!" was made to scare you into thinking that your computer is infected with malicious software. Then the rogue program prompts you to pay for a full version of the program to remove the infections which in reality don't even exist. Don't purchase it! Instead, please use the XP Internet Security 2010 removal instructions to remove this virus from your computer for free using legitimate anti-malware programs. If you have already purchased this phony program then you contact your credit card company and dispute the charges. If you have any questions or additional information about this infection, please don't hesitate and leave a comment. Good luck and be safe!

Share this information with other people:

Monday, April 12, 2010

Remove Antivirus-armature.com (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Antivirus-armature.com is a misleading web site that promotes the rogue anti-virus program called Antivirus Suite. It's a typical fake web site full of false information about illegitimate anti-virus program. There are many such web sites and obviously we can’t inform our visitors about each of them separately. However, we’ve got several complaints about Antivirus Armature infection. One of our readers thought that Antivirus-armature.com is an infection itself, but actually it's only a part of malware infection.

If you are being constantly redirected to Antivirus-armature.com or similar web sites then this mean that your computer is infected with either Antivirus Suite malware or Trojans that promote rogue programs. Now, if you find that your computer is infected with Antivirus Suite malware, please read our blog entry how to remove Antivirus Suite. If you don't know what infection you have on your computer then you should scan your PC with a legit anti-malware or anti-virus program. You may choose from thee following free anti-malware programs:
If you have any questions or useful information about this infection don't hesitate and leave a comment. Good luck and be safe!



Share this information with other people:

Saturday, April 10, 2010

How to remove Digital Protection malware (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Digital Protection is a fake antivirus program from the same family as Dr. Guard and User Protection. DigitalProtection is a typical rogue security program that displays fake warnings about malware infection on your computer and reports false system security threats to make you think that your PC is infected with spyware, adware and various other malicious software. As usual, such bogus programs are promoted through the use of Trojans that most of the time come from fake online anti-malware scanners or misleading video web sites. Cyber criminals may also use social engineering to distribute their bogus product.



Can Digital Protection steal your personal information? Well, usually such programs don't steal passwords or other personal information. However, please note that it may come bundled with other malware and it can be actually password stealing Trojans or similar programs, so we highly recommend you to scan your computer with legit and reliable anti-virus or anti-malware programs. Don't rely on on one anti-malware program. You should scan your computer with at least two programs to make sure that there are no other malware installed on your PC.

As a typical rogue anti-virus program Digital Protection displays fake warning and fake infections to scare you into purchasing the program. Some of the fake security alerts will state:

"Warning! Virus threat detected!
Virus activity detected!
Trojan-Clicker.Win32 adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now."

"A security threat detected on your computer. TrojanASPX.JS.Win32. It strongly recommended to remove this threat right now. Click on the message to remove it."

Most importantly, don't purchase Digital Protection because it's a scam. Instead, you should uninstall it from your computer as soon as possible. Please use the removal instructions below to remove Digital Protection malware. The rogue program may come bundled with TDSS rootkit. If so, then you should use the second removal method (Method 2) or read the TDSS rootkit removal instructions. If you have any questions or useful information about this infection, don't hesitate and leave a comment. Good luck and be safe!


Digital Protection removal instructions (in Safe Mode with Networking, Method 1):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download SUPERAntispyware, MalwareBytes Anti-malware or Spybot - Search & Destroy and run a full system scan. NOTE: before saving the selected program onto your computer, please rename the installer to winlogon.exe or iexplore.exe. Launch the program and follow the prompts. Don't forget to update the installed program before scanning. Then reboot your computer in "Normal Mode" and run  a system scan again. That's it!
4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Digital Protection removal instructions: (Method 2)

1. Download the file TDSSKiller.zip and extract it into a folder
2. Execute the file TDSSKiller.exe (NOTE: you may have to rename TDSSKiller.exe to explorer.com yourself or download already renamed explorer.com file in order to run it)
3. Follow the prompts and wait for the scan and disinfection process to be over. Close all programs and press “Y” key to restart your computer.
More detail TDSSKiller tutorial: http://support.kaspersky.com/viruses/solutions?qid=208280684
4. Download one of the following anti-malware software and run a full system scan:
5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Digital Protection associated files and registry values:

Files:
  • C:\Documents and Settings\All Users\Application Data\[random].dll
  • %UserProfile%\Start Menu\Programs\Digital Protection
  • C:\Program Files\Digital Protection
  • C:\Program Files\Digital Protection\dig.db
  • C:\Program Files\Digital Protection\digext.dll
  • C:\Program Files\Digital Protection\dighook.dll
  • C:\Program Files\Digital Protection\digprot.exe
  • C:\Program Files\Digital Protection\Uninstall.exe
  • %Temp%\4otjesjty.mof
  • %Temp%\asd1.tmp
  • %Temp%\davclnt.exe
  • %Temp%\dhdhtrdhdrtr5y
  • %Temp%\dig.dat
Registry:
  • HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
  • HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Digital Protection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Digital Protection
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Digital Protection"
Please share this information with other people:

 
//PART 2