Monday, September 6, 2010

Remove Defence-center.com and Windows-defence.com (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Defence-center.com and Windows-defence.com are potentially harmful websites that promote rogue anti-spyware programs called Defence Center and Windows Defence. Basically, it's one rogue application with two different names. Graphical user interface is the same. Defence-center.com and Windows-defence.com also shares the same web template and information which is obviously false. There are no visible download links on any of these websites but purchase the rogue program without any problems. The bad guys use plimus payment system. Both sites claim that they will provide extended customers support and that you will save your money if you choose to buy their products. That's a scam. Both sites, defence-center.com and windows-defence.com gives a false sense of security so they should be avoided.

Most importantly, if your computer got infected with Defence Center or Windows Defence malware then please don't purchase it and remove the rogue program from the system as soon as possible. We've got the removal instructions to help you to remove these rogue programs. Please read how to remove Defence Center and how to remove Windows Defence. If you have any questions please leave a comment. Additional information about defence-center.com and windows-defence.com is welcome too. Good luck and be safe online!

A screen shot of defence-center.com:


A screen shot of windows-defence.com:


Share this information with other people:

Sunday, September 5, 2010

How to remove Defence Center (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Defence Center is a rogue anti-spyware program that mimics legitimate secuity products and claims that your computer system is infected with mailicious software. It's a clone of Windows Defence which is also a ripoff rogue program. Once installed, Defence Center will pretend to scan your computer for malware and claim to find infected files or system security threats. Surprisingly, it will claim that you need to pay a registration fee in order to updagre the rogue program because the current version can't remove found malware and infected files from your computer. Don't fall victim to this scam and don't buy the rogue program. If you choose to pay for DefenceCenter then it will give you a false sense of security and what is more, it won't remove any infected files from your computer simply because they don't even exist. If you are reading this article then your computer is probably infected with this malware. Thankfully, we've got the instructions to help you to remove Defence Center from your computer for free. Please follow the removal instructions below.




(Thanks to rogueamp)

First of all, can this rogue program delete your files? In theory, it may come bundled or download other malware onto your computer that could delete your files but personaly I haven't heard of any such case. Defence Center reports false system security threats, displays fake warnings, hijacks web browsers and disbles certain system utilities and legitimate anti-virus programs. So, your files should be safe. You may wonder, where did it came from? Well, usually it has to be manually installed so you've probably clicked on infected ads or links. If you think you didn't then it could be that your computer was already infected with Trojans that downloaded the rogue program onto your computer without your permission or knowledge. On way or another this Defence Center malware should be removed upon detection. Once installed, it will display fake security warnings claiming that your computer is under attack from a remote computer or badly infected with malware. It will also display fake alerts while srfing the Internet. The main web page of this rogue program is defence-center.com.

A screen shot of rogue's main web page:


Without a doubt, Defence Center is nothing more but a scam. Don't buy it. If you have already purhcased this rogue security product then contact tour credit card compnay and dispute the charges. Then please follow Defence Center removal instructions below. If you have any questions or additional information about this malware please leave a comment. Good luck and be safe!


Defence Center removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download anti-malware software from the list below and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Defence Center removal instructions in Normal mode:

1. Download Process Explorer iexplore.exe. Double click to open it. Look for Defence Center in the process list and terminate its process(es). Should be smmservice.exe and DefenceCenter.exe.
2. Download  anti-malware software from the list below. Update it and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.
3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Defence Center associated files and registry values:

Files:
  • C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\smmservice.exe
  • C:\Documents and Settings\All Users\Application Data\mswd\
  • C:\Documents and Settings\All Users\Application Data\mswd\Base.dat
  • C:\Documents and Settings\All Users\Application Data\mswd\db.avdb
  • C:\Documents and Settings\All Users\Application Data\mswd\DefenceCenter.exe
  • C:\Documents and Settings\All Users\Start Menu\Programs\Defence Center\
  • C:\Documents and Settings\All Users\Start Menu\Programs\Defence Center\Defence Center.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\Defence Center\Uninstall\
  • C:\Documents and Settings\All Users\Start Menu\Programs\Defence Center\Uninstall\Uninstall.lnk
Registry:
  • HKEY_LOCAL_MACHINE\SOFTWARE\WSI
  • HKEY_LOCAL_MACHINE\SOFTWARE\WSI\MPI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DefenceCenter
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DefenceCenter\Info
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SMMSERVICE
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SMMSERVICE\0000
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SMMSERVICE\0000\Control
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\smmservice
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\smmservice\Security
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\smmservice\Enum
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DefenceCenter
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DefenceCenter\Info
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMMSERVICE
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMMSERVICE\0000
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SMMSERVICE\0000\Control
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\smmservice
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\smmservice\Security
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\smmservice\Enum
  • HKEY_USERS\.DEFAULT\Software\Microsoft\GDIPlus
  • HKEY_USERS\.DEFAULT\Software\DefenceCenter
  • HKEY_CURRENT_USER\Software\WSI
  • HKEY_CURRENT_USER\Software\WSI\MPI
Share this information with other people:

How to remove Windows Defence (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows Defence is a rogue anti-spyware program that attempts to deceive users into buying the full version of the program to remove malicious software supposedly found during a false system scan. This fake program is promoted through the use of Trojans, fake online scanners and infected web pages. The fake scanner has a blue shield icon with lightning on it. Once installed, it will pretend to scan your computer for malware. Then it will claim that your computer is infected with spyware, Trojans, worms, adware and other viruses to make you think that your computer is really infected when in fact it's free of virus and the only security threat is Windows Defence itself. What is more, the rogue program will open up randomly and display fake security warnings like every one or two minutes. It goes without saying that you should remove Windows Defence from your computer. Thanfully, you can use free and genuine anti-malware software to remove this malware from your computer. Please follow the removal instructions below.


Image source: symantec.com

While running, Windows Defence will block legitimate anti-virus and anti-spyware programs, system tools and utilities such as task manager and registry editor. There are at least several variants of this bogus program and in some cases Windows Defence may disable system restore and safe mode. It will also hijack your web browser and redirect you to its main web page which is windows-defence.com.

A screen shot of rogue's main web page:


Reboot your computer is safe mode or safe mode with networking if you can and run a system scan with anti-malware software. If you can't do that then you will have to remove it in normal mode. Please follow detailed Windows Defence removal instructions below. Last, but not least, if you have already purchased this rogue product then contact your credit card company and dispute the charges. And, of course, if you have any questions or additional information, don't hesitate and leave a comment. Good luck and be safe online!


Windows Defence removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download anti-malware software from the list below and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Windows Defence removal instructions in Normal mode:

1. Download Process Explorer iexplore.exe. Double click to open it. Look for Windows Defence in the process list and terminate its process(es).
2. Download  anti-malware software from the list below. Update it and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.
3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Windows Defence associated files and registry values:

Files:
  • C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\smmservice.exe
  • C:\Documents and Settings\All Users\Application Data\mswd\
  • C:\Documents and Settings\All Users\Application Data\mswd\Base.dat
  • C:\Documents and Settings\All Users\Application Data\mswd\db.avdb
  • C:\Documents and Settings\All Users\Application Data\mswd\WindowsDefence.exe
  • C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defence\
  • C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defence\Windows Defence.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defence\Uninstall\
  • C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defence\Uninstall\Uninstall.lnk
Registry:
  • HKEY_USERS\.DEFAULT\Software\WindowsDefence
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\smmservice
Share this information with other people:

Saturday, September 4, 2010

Remove Win7av.com (Removal Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Win7av.com is a misleading website that promotes the rogue anti-virus program called Win7 AV. The similarity between the fake website ant the legitimate Microsoft Security Essential website is obvious and we have to admit that the bad guys did a good job because Win7av.com looks very genuine. It's almost the exact copy of the legitimate Microsoft Security Essential website. The bad guys copied the awards received by Microsoft and they claim that Win7 AV is the best anti-virus solution on the market. To be clear, the rogue program and its main web page Win7av.com has nothing to do with Microsoft. If you are looking for free anti-virus software then you should visit the official Microsoft Security Essentials website. It's free, absolutely genuine and it does protect your computer from malware. Whereas Win7 AV is a scam. It's costs $59.95 USD and you can't even download a trial version. The rogue program claims that it has certifications from Icsa Labs and Virus Bulletin but that's obvious not true. If you are being redirected to Win7av.com then your computer is probably infected with Trojans or Win7 AV scareware. Please follow Win7 AV removal guide.

A screenshot of the rogue's main website:


A screenshot of the genuine Microsoft Security Essentials page:


Share this information with other people:

How to remove Win7 AV malware (Uninstall Instructions)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Win7 AV is a fake anti-virus program that masquerades as legitimate security software. This rogue program pretends to scan your computer for malware and claims to find malicious files. Of course, the scan results are either false or grossly exaggerated because it flags harmless or non-existing files as worms, Trojans, dialers and other malware. What is more, Win7 AV forces to pay for a full version of the program to remove malicious files from your computer. Don't purchase it! It's a typical rogue anti-virus scanner that tries to deceive users into paying registration fees to remove malware from their computers. You should remove Win7 AV from your computer as soon as possible because it gives you a false sense of security. Thankfully, you can use legitimate anti-malware software to remove this rogue program from the system for free. Please follow our removal instructions below.




(Thanks to rogueamp)

Win 7 AV comes from fake online scanners and misleading malware warning pages or through the use of Trojans. These fake warning pages look very genuine. They claim that the website you are about to visit is infected or malicious and claim that you should install reliable anti-malware software to protect your computer against various threats and viruses. If you choose to install their software you will end up with Win7 AV on your computer. These fake browser messages are:

In Internet Explorer:


In Mozilla Firefox:


In Google Chrome:


Once Win7AV is installed it will pretend to scan your computer and give exaggerated reports of threats. It will block legitimate anti-virus and anti-spyware programs and hijack web browsers. Then it will redirect your web browser to win7av.com which is the main web page of this rogue program to buy a license which costs $59.95 USD. Win7av.com impersonates the legitimate Microsoft Security Essentials web page.

A screen shot of the rogue's main web page:


It goes without saying that you should remove Win7 AV from your computer upon detection. You can remove the rogue's files manually, they are listed below, but it would be a lot better idea to scan your computer with genuine anti-malware software because the rogue program may come bundled with other malware such as rootkits and Trojans. Also, if you have already purchased Win7 AV then please contact your credit card company and dispute the charges. Then follow the removal instructions below. If you have any questions or additional information about this malware, don't hesitate and leave a comment. Good luck and browse safely!


Win7 AV removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download at least one anti-malware program from the list below and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Win7 AV removal instructions in Normal mode:

1. Donwload Process Explorer iexplore.exe. Double click to open it. Look for  Win7 AV.exe and Win7Browser.exe in the process list and terminate both processes.
2. Download  anti-malware software from the list below. Update it and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.
3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Win7 AV associated files and registry values:

Files:
  • C:\Program Files\Win7 AV\
  • C:\Program Files\Win7 AV\sbhostcl.dll
  • C:\Program Files\Win7 AV\svhostesl.dll
  • C:\Program Files\Win7 AV\svhostqt.dll
  • C:\Program Files\Win7 AV\VmDetectLibrary.dll
  • C:\Program Files\Win7 AV\Win7 AV.exe
  • C:\Program Files\Win7 AV\Win7Browser.exe
  • C:\Program Files\Win7 AV\Win7Common.dll
Share this information with other people:

 
//PART 2