Saturday, July 10, 2010

AntivirusGT removal instructions (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
AntivirusGT is one of many fake anti-virus programs that report fake viruses and prompt you to pay for a full version of the program to remove the infections or viruses which don't even exist. This fake program prevents users from doing most things. It blocks Task Manager, Registry editor, legitimate anti-virus and anti-malware programs or other useful system utilities. AntivirusGT also gives you loads of fake security warnings and pop-ups. Those fake warnings claim that your computer is infected with spyware, adware, Trojans, computer worms and other viruses. Antivirus GT performs a very quick scan and displays a list of non-existent infections. If you are reading this article, then your computer is probably infected with this virus and you're looking for removal help. Thankfully, we've got free AntivirusGT removal instructions to help you get rid of this malicious software.



Please note that such fake programs usually come from fake anti-malware scanners, misleading online video websites and other bogus pages. AntivirusGT virus may come bundled with other malware as well. In some cases the rogue program has to be manually installed, but it usually pretends to be a legitimate program such as flash player, video codec or any other application. While running, the rogue program blocks nearly all legit programs and displays an error message with the following text (process name may vary):

AntivirusGT Resident Shield: Virus Detected
Warning! Active virus detected!
Threat Detected: Trojan.Injector.BZ
Infected File: C:\Windows\System32\rundll32.exe



What is more, AntivirusGT hijacks Internet Explorer and Mozilla Firefox, adds malicious browser helper object and displays fake security warning every time you attempt to visit security related websites. The text of this alert is:

Attention! Your web page request has been cancelled.
This web site refused your connection as it was reported as a malicious request. This can be caused by Viruses, Trojans or Malware installed on your computer.



Antivirus GT is from the same family as Antivirus 7 malware. It goes without saying that AntivirusGT is needless and potentially harmful software. Also, note that malware authors constantly changes code of such rogue programs to avoid detection and to maximize their return of investment. Most importantly, don't purchase this rogue program. If you have already paid for it then you should contact your credit card company and dispute the charges. Finally, please follow the removal instructions below to remove AntivirusGT from your computer for free using legitimate anti-malware programs. And last, but not least, if you have any questions or additional information about this malware, please don't hesitate and leave a comment. Good luck and be safe!


AntivirusGT removal instructions (method #1):

1. (Proceed to step 2 if you your web browser is not hijacked) Open Internet Explorer. Go to: Tools->Manage Add-ons. Find and select UpdateCheck.dll from the list of add-ons. Click "Disable" button and close Manager Add-ons windows. Close Internet Explorer and run it once again.
2. Right click on Windows Task Bar, select Task Manager (or press Ctrl+Shift+Esc at the same time). Look for antivirusGT.exe process and terminate it (click End Process button).
3. Download one of the following legitimate anti-malware applications and run a quick system scan. Don’t forget to update it first. All programs a free.
NOTE1: If you can't run any of the above programs you must rename the installer of selected program before saving it on your PC. For example: if you choose MalwareBytes then you have to rename mbam-setup.exe to iexplore.exe, explorer.exe or any random name like test123.exe before saving it. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator.

NOTE2: if you still can't run the renamed file then you need to change file extension too not only the name.
1. Go to "My Computer".
2. Select "Tools" from menu and click "Folder Options".
3. Select "View" tab and uncheck the checkbox labeled "Hide file extensions for known file types". Click OK.
4. Rename mbam-setup.exe to either test123.com or test123.pif
5. Double-click to run renamed file.


Removing AntivirusGT in Safe Mode with Networking (method #2):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2.Download one of the following legitimate anti-malware applications and run a quick system scan. Don’t forget to update it first. All programs a free.

AntivirusGT files and registry values:

Files:
  • C:\Documents and Settings\All Users\Start Menu\AVGT\
  • C:\Program Files\AVGT\
  • C:\Program Files\AVGT\antivirusGT.exe
  • %Temp%\MICROS~1.DLL
Registry values:
  • HKEY_CURRENT_USER\Software\EVA246
  • HKEY_CURRENT_USER\Software\WinFD
  • HKEY_CLASSES_ROOT\CLSID\{3304F17F-732C-4AC6-BF67-DBDC8B88C11F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3304F17F-732C-4AC6-BF67-DBDC8B88C11F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AVGT"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "WinNT-EVI 05.07.2010"
Share this information with other people:

Monday, June 28, 2010

How to remove Defense Center (Uninstall Instructions)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Defense Center is a typical fake anti-spyware program. It displays fake security warnings like every one or two minutes and states that your computer is infected with malware. Once installed, it will report numerous false system security threats. The rogue program may flag legitimate and safe Microsoft Windows files as Trojan Horses or other viruses. Don't attempt to remove those files. Otherwise your PC won't operate properly. As a typical rogue program Defense Center will prompt you to pay for a full version of the program to remove the infections which don't even exist. It goes without saying that you should remove Defense Center from your computer as soon as possible. Thankfully, we've got free Defense Center removal instructions to help you. Detailed removal guide is outlined below.



False scan results and fake security alerts shouldn't surprise you because DefenseCenter scareware will do all its best to trick you into purchase the program. It will even attempt to uninstall antivirus software from your computer. If you use let's say Norton Antivirus, then most likely you will see a fake pop-up claiming that your antivirus software is infected and should be uninstalled immediately. Defense Center will even block certain security related websites and block other useful utilities to protect itself from being removed. The text of some fake security alerts are:

"Warning! Virus threat detected!
Virus activity detected!
Net-Worm.Win32 has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat."


"Danger!
A security threat detected on your computer. TrojanASPX.JS.Win32. It strongly recommended to remove this threat right now. Click on the message to remove it."


"Warning! Adware detected!
Adware module detected on your PC!
Zlob.Porn.Ad adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now."

Also note, that this rogue program is promoted mainly through the use of Trojan Horses. Very often Trojans download TDSS rootkit and other malware alongside Defense Center. That's why we think manual removal is not an options in this case. We strongly recommend you to run a full system scan with at least two anti-malware programs. Below you will find a list of free and reputable anti-malware programs which will remove Defense Center from your computer for good. By the way, if you have already purchased this bogus program, then please contact your credit card company and dispute the charges. Finally, if you have any questions about this virus, please don't hesitate and leave a comment.


Defense Center removal instructions (in Safe Mode with Networking, Method 1):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download SUPERAntispyware, MalwareBytes Anti-malware, Spybot - Search & Destroy or Spyware Doctor and run a full system scan. NOTE: before saving the selected program onto your computer, please rename the installer to winlogon.exe or iexplore.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning. Then reboot your computer in "Normal Mode" and run  a system scan again. That's it!
4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Defense Center removal instructions: (Method 2)

1. Download TDSSKiller.exe from Kaspersky website.
2. Execute the file TDSSKiller.exe (NOTE: you may have to rename TDSSKiller.exe to explorer.com yourself or download already renamed explorer.com file in order to run it)
3. Follow the prompts and wait for the scan and disinfection process to be over. Close all programs and press “Y” key to restart your computer.
More detail TDSSKiller tutorial: http://support.kaspersky.com/viruses/solutions?qid=208280684
4. Download one of the following anti-malware software and run a full system scan:
5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Defense Center associated files and registry values:

Files:
  • C:\Program Files\Defense Center
  • C:\Program Files\Defense Center\about.ico
  • C:\Program Files\Defense Center\activate.ico
  • C:\Program Files\Defense Center\buy.ico
  • C:\Program Files\Defense Center\def.db
  • C:\Program Files\Defense Center\defcnt.exe
  • C:\Program Files\Defense Center\defext.dll
  • C:\Program Files\Defense Center\defhook.dll
  • C:\Program Files\Defense Center\help.ico
  • C:\Program Files\Defense Center\scan.ico
  • C:\Program Files\Defense Center\settings.ico
  • C:\Program Files\Defense Center\splash.mp3
  • C:\Program Files\Defense Center\Uninstall.exe
  • C:\Program Files\Defense Center\update.ico
  • C:\Program Files\Defense Center\virus.mp3
  • %UserProfile%\Desktop\spam001.exe
  • %UserProfile%\Desktop\spam003.exe
  • %UserProfile%\Desktop\troj000.exe
  • %UserProfile%\Desktop\youporn.com.lnk
  • %UserProfile%\Start Menu\Programs\Defense Center
Registry:
  • HKEY_USERS\S-1-5-21-861567501-152049171-1708537768-1003_Classes\secfile
  • HKEY_CURRENT_USER\Software\Classes\secfile
  • HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
  • HKEY_CLASSES_ROOT\secfile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Defense Center
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Defense Center
  • HKEY_LOCAL_MACHINE\SOFTWARE\Program Groups
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Defense Center"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = "1"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5E2121EE-0300-11D4-8D3B-444553540000}"
Please share this information with other people:

How to remove Noexe.exe ransomware (Free Removal)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Noexe.exe is a malicious file/process. It displays fake Windows activation screen in Russian and claims that you should send and SMS with a certain text to receive your activation code. Although, Noexe.exe ransomware was made for people who live in Russia, but this doesn't mean that your PC is safe if you live somewhere else. If you got infected with Noexe.exe ransomware, please follow Noexe.exe removal instructions below to remove it from your computer as soon as possible.




Noexe.exe removal instructions
Download at least one anti-malware program from the list below and run a full system scan.
NOTE: with all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.


Noexe.exe associated files and registry values:

Files:
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\tmp1.tmp
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\tmp2.tmp
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\tmp4.tmp
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\tmp5.tmp
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\tmp6.tmp
  • C:\Documents and Settings\[UserName]\Local Settings\Temp\tmp7.tmp
  • C:\Windows\NoExe.exe
Registry values:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "explorer.exe = "%Windir%\explorer.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\runas\command
Share this information with other people: 

Thursday, June 24, 2010

Remove Profantivir.com (Free Removal)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Two days ago we posted a quick note about Antispybase.com scam. Today, we came across another rogue website related to AV Security Suite malware - Profantivir.com. As you can see both websites share the same web template. Furthermore, Profantivir.com provides false information about fake antivirus program and recommends buying it. Without a doubt, there are many more such websites that promote AV Security Suite virus. That's why you should be very careful and don't click any links which looks suspicious to you. Note, that cyber criminals use social engineering to mislead users into downloading rogue programs.

If you have accidentally installed AV Security Suite on your computer then you should follow AV Security Suite removal instructions. As you can see fake Profantivir.com website is only a small piece of the whole scam. By the way, if you have already purchased this bogus program then you should contact your credit card company and dispute the charges. If you have any questions or additional information about this malware, please leave a comment. Good luck and be safe!

Screenshot of Profantivir.com


Share this information with other people:

Wednesday, June 23, 2010

Remove Tango Toolbar (Free Removal)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Tango Toolbar is a piece of malware which is spammed mostly on peer-to-peer file sharing networks. Infection route is download of a tainted media file or cracked software. Tango Toolbar claims that it has a pop-up blocker, a built in search function and inline related keywords search. Usually, users don't know where did they get this toolbar from and can't uninstall it from their computers. TangoToolbar may redirect you to misleading websites full of advertisements or display various pop-ups while browsing the web. It goes without saying that you should remove Tango Toolbar from your computer as soon as possible. By the way, this toolbar is not related to marketing company called Brand Tango. The toolbar is attempting to mislead people by sending them to a domain which belongs to Brand Tango (tangosearch(dot)com).



Unfortunately, you won't be able to remove Tango Toolbar with the option of the Control Panel of Windows. If you find that your computer is infected with this toolbar, please use the anti-malware programs listed below. Please note that you may have to use two or more anti-malware programs to completely remove this malware from your computer. If you have any questions or additional information about this toolbar, don't hesitate and leave a comment. Good luck and be safe.


Tango Toolbar removal instructions
Download at least one anti-malware program from the list below and run a full system scan.

NOTE: before saving the selected program onto your computer, please rename the installer to winlogon.exe or iexplore.exe.With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.


Tango Toolbar associated files and registry values:

Files:
Windows XP
  • C:\Documents and Settings\[UserName]\Application Data\Microsoft\Windows\jnipmo.exe
  • C:\Documents and Settings\[UserName]\Application Data\Gabpath\Gabpath.exe
Windows Vista & Windows 7
  • C:\Users\[UserName]\AppData\Roaming\Microsoft\Windows\jnipmo.exe
  • C:\Users\UserName]\AppData\Roaming\GabPath\GabPath.exe
Registry values:
  • HKEY_USERS\S-1-5-21-2333105494-1048492065-1185645942-1006\Software\Microsoft\Windows\CurrentVersion Run "SfKg6wIPuSp"
  • HKEY_USERS\S-1-5-21-2333105494-1048492065-1185645942-1006\Software\Microsoft\Windows\CurrentVersion Run "GabPath"
Share this information with other people: 

 
//PART 2