Friday, November 19, 2010

How to remove Scan Disk (Uninstall Instructions)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Scan Disk is a fake defragmenter and system optimization tool. It is promoted through the use of trojans, fake online scanners and other malicious websites. It can be also distributed via facebook, twitter or other social networks. Basically, Scan Disk will infect your computer to make you think that you have some really serious problems, e.g. hard drive errors, corrupted memory, bad sectors and other stuff. Then this bogus program will try to make you buy its software to fix supposedly found errors and other computer problems. Do not fall victim to Scan Disk because it is nothing more but a rip-off rogue, scam. If you got this annoying program on your computer then please follow the removal instructions below to remove Scan Disk and any other related malware from your computer for free using legitimate anti-malware software.

A screen shot of Scan Disk
ScanDisk is clone of Ultra Defragger, Quick Defragmenter and HDD Defragmenter. As a typical scareware, it will pretend to scan your hard drives and memory for problems. Of course, it will find some critical hard drive and computer memory errors. By the way, it displays the same problems (11 errors) on each infected computer. How rude. Probably the biggest problem is that Scan Disk won't allow you to run other programs on your computer. It will state that this program is corrupted or cannot be found. The fake message reads:
Windows detected a hard drive problem.
A hard drive error occurred while starting the application.


However, if you attempt to run a program enough times it will eventually work. So, don't give up easily. After the fake scan it will display a list of errors:
Drive C initializing error
Bad sectors on hard drive or damaged file allocation table
Read time of hard drive clusters less than 500 ms
Hard drive doesn't respond to system commands
Furthermore, it will display fake alert from your Windows taskbar. Some of the fake alerts that you will see are:
Critical Error!
Damaged hard drive clusters detected. Private data is at risk.
Critical Error
Hard Drive not found. Missing hard drive.
Critical Error
Windows can't find hard disk space. Hard drive error
As you can see, Scan Disk is not a legitimate program. It reports non-existent errors to scare you into purchasing the bogus program. If you have already purchased it then you should contact your credit card provider and dispute the charges or even cancel your credit card. Then please follow the removal instructions below. Please note that Scan Disk and additionally installed malware can download more malicious code onto your computer. Although, you can remove Scan Disk manually, we strongly recommend you to use anti-malware software listed below. And finally, if you have any questions or other information about this malware, please leave a comment. Good luck and be safe online!


Scan Disk removal instructions using Process Explorer (in Normal mode):

1. Download Process Explorer and end Scan Disk process:
  • [SET OF RANDOM CHARACTERS].exe
2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Scan Disk removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Scan Disk associated files and registry values:

Files:
  • %Temp%\[SET OF RANDOM CHARACTERS]
  • %Temp%\[SET OF RANDOM CHARACTERS].exe
  • %Temp%\dfrg
  • %Temp%\dfrgr
  • %Temp%\[SET OF RANDOM CHARACTERS].dll
  • %Temp%\tmp2.tmp
  • %UserProfile%\Desktop\Scan Disk.lnk
  • %UserProfile%\Start Menu\Programs\Scan Disk\
  • %UserProfile%\Start Menu\Programs\Scan Disk\Scan Disk.lnk
  • %UserProfile%\Start Menu\Programs\Scan Disk\Uninstall Scan Disk.lnk
%Temp% refers to:
C:\Documents and Settings\[UserName]\Local Settings\Temp (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Local\Temp (in Windows Vista & Windows 7)

%UserProfile% refers to:
C:\Documents and Settings\[UserName]\ (in Windows 2000/XP)
C:\Users\[UserName]\ (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

Monday, November 15, 2010

How to remove Ultra Defragger (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Ultra Defragger is a fake defragmentation tool that deliberately reports fake system and hard drive disk errors to make you think that your computer has some serious problems. Basically, it's a rip-off rogue because it prompts the user to pay for a full version of the program to fix non-existent hard drive and system memory errors. What is more, Ultra Defragger is promoted mostly through the use of infected websites, trojans and other malicious software. The scammers may even distribute it on Facebook and other social networks. If your computer is infected with this rogue program then please follow the removal instructions bellow to remove Ultra Defragger from your computer for free either manually or using legitimate anti-malware software.

A screen shot of Ultra Defragger
UltraDefragger is a very annoying piece of malware from the same family as HDD Defragmenter and Quick Defragmenter. It will hijack your computer, block nearly all programs and display fake error messages. Once installed, it will pretend your hard drives and memory for problems. Then it will display numerous errors (I bet it will find 11 errors) and ask you to pay for a full version of the program to fix the errors. By the way, if you choose to run the defragmentation then it will display a fake Safe Mode background. And when you attempt run a program it will display this error message:
Windows detected a hard drive problem.
A hard drive error occurred while starting the application.


However, it should be noted that if you attempt to run a program enough times it will eventually work. Here are some fake problems that Ultra Defragger detects on a victim's PC:
Requested registry access is not allowed. Registry defragmentation required
Read time of hard drive clusters less than 500 ms
Bad sectors on hard drive or damaged file allocation table
Drive C initializing error
Ram Temperature is 83 C. Optimization is required for normal operation.
Data Safety Problem. System integrity is at risk.
Registry Error - Critical Error
Ultra Defragger will also display fake "ballon messages" from your Windows task bar. Some of the fake alerts read:
Critical Error!
Damaged hard drive clusters detected. Private data is at risk.
Critical Error
Hard Drive not found. Missing hard drive.
Critical Error
RAM memory usage is critically high. RAM memory failure.

Critical Error
Windows can't find hard disk space. Hard drive error
As you can see, Ultra Defragger will claim that your hard drive is missing. That's actually impossible because otherwise you won't be able to use your computer at all. Without a doubt, UltraDefragger is nothing more but a scam. If you have already purchased it then you hould contact your credit card provider and dispute the charges and even cancel your credit card. Then please follow the removal instructions bellow. And finally, you should definitely scan your computer with at least two anti-malware programs, e.g. Malwarebytes' AntiMalware and Hitman pro ta make sure that you are not a part of a botnet and that Ultra Defragger and related malware were successfully removed from your computer. If you have any questions or additional information about Ultra Defragger, please leave a comment. Good luck and be safe!


Ultra Defragger removal instructions using Process Explorer (in Normal mode):

1. Download Process Explorer and end Ultra Defragmenter process:
  • [SET OF RANDOM CHARACTERS].exe
2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Ultra Defragger removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Ultra Defragger associated files and registry values:

Files:
  • %Temp%\[SET OF RANDOM CHARACTERS]
  • %Temp%\[SET OF RANDOM CHARACTERS].exe
  • %Temp%\dfrg
  • %Temp%\dfrgr
  • %Temp%\[SET OF RANDOM CHARACTERS]>.dll
  • %Temp%\tmp2.tmp
  • %UserProfile%\Desktop\Ultra Defragger.lnk
  • %UserProfile%\Start Menu\Programs\Ultra Defragger\
  • %UserProfile%\Start Menu\Programs\Ultra Defragger\Ultra Defragger.lnk
  • %UserProfile%\Start Menu\Programs\Ultra Defragger\Uninstall Ultra Defragger.lnk
%Temp% refers to:
C:\Documents and Settings\[UserName]\Local Settings\Temp (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Local\Temp (in Windows Vista & Windows 7)

%UserProfile% refers to:
C:\Documents and Settings\[UserName]\ (in Windows 2000/XP)
C:\Users\[UserName]\ (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

Saturday, November 13, 2010

Remove Vista Antispyware 2011 and Vista Security 2011 (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Vista Antispyware 2011, Vista Security 2011 and Vista Antimalware 2011 are a few names of the same rogue security program that intentionally misrepresents the security status of your computer, pretends to scan your computer for malicious software and blocks certain executable files (.exe) from running. The scam is intended to frighten you into purchasing the fake program. Please do not purchase Vista Antispyware 2011, Vista Antimalware 2011 or any other rogue program from the list below. This rogue program is downloaded mostly by trojans that come from fake online scanners, infected websites or spam emails. The bad guys may also distribute their bogus products on Facebook, Twitter and other social networks. If you got hit by this rogue security program please follow the removal instructions below.

This rogue program goes by many different program names listed below.
  • Vista Antispyware
  • Vista Antispyware 2011
  • Vista Anti-Virus 
  • Vista Anti-Virus 2011
  • Vista Home Security
  • Vista Home Security 2011
  • Vista Security
  • Vista Security 2011
  • Vista Internet Security
  • Vista Internet Security 2011
  • Vista Antimalware
  • Vista Antimalware 2011
  • Vista Guard
  • Vista Total Security
  • Vista Total Security 2011
A screen shot of Vista Security 2011
Vista Antispyware 2011, Vista Security 2011 or Vista Antimalware 2011 pretends to be a security update for Windows. The fake Windows update looks quite convincing. Once the rogue program is installed, it will inform you that you are infected with new threats. The misleading application will then present itself and run a scan of the system. Of course, it will find numerous infections on your computer and then will ask you to pay for a full version of the program. Furthermore, the rogue program will block legitimate anti-malware software. The main process of this rogue program pw.exe and several newly added Windows registry values will launch the rogue program instead of the requested executable, e.g. Task Manager or MS Paint. While Vista Antispyware 2011 or Vista Guard is running, it will display numerous security alerts and "balloon messages" that appear in the lower right-hand side of the system. The rogue program will claim that Internet Explorer is infected with keylogger or that private data can be stolen by third parties. Some of the fake alerts read:
Vista Antispyware 2011 Firewall Alert
Vista Antispyware 2011 has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.
Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.
The scan results and security warnings produced by the misleading application are entirely false and should be ignored. Last, but not least, this fake program will hijack Internet Explorer and Mozilla Firefox. It will display a fake alert message and block nearly all websites you attempt to visit. The message that you will see is:
Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
- Dangerous code found in this site's pages which installed unwanted software into your system.
- Suspicious and potentially unsafe network activity detected.
- Spyware infections in your system
- Complaints from other users about this site.
- Port and system scans performed by the site being visited.


Things you can do:
- Get a copy of Vista Antispyware 2011 to safeguard your PC while surfing the web (RECOMMENDED)
- Run a spyware, virus and malware scan
- Continue surfing without any security measures (DANGEROUS)


It goes without saying that you should remove this rogue program from your computer as soon as possible. It exaggerates the problems on the system and refuse to fix them until the vendor is paid. Please do not pay for a program that doesn't work. It will give you a false sense of security and may eve leads to potentially greater risks from more aggressive threats. If you have already purchased this bogus program then you should contact your credit card company and dispute the charges. We also recommend you to cancel your credit card. Finally, please follow the removal instructions below to remove Vista Antispyware 2011, Vista Security 2011 or Vista Antimalware 2011 from your computer for free using legitimate anti-malware applications. If you have any questions or additional information about this malware, please leave a comment. Good luck and be safe online!


Vista Antispyware 2011, Vista Security 2011 or Vista Antimalware 2011 removal instructions:

1. Click Start->Run or press WinKey+R. Type in "command" and press Enter key.


2. In the command prompt window type "notepad" and press Enter key. Notepad will come up.


3. Copy all the text in blue color below and paste to Notepad.

Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[-HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[-HKEY_CLASSES_ROOT\secfile]

4. Save file as fix.reg to your Desktop. NOTE: (Save as type: All files)


5. Double-click on the fix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.
6. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

7. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus 4.


Associated Vista Antispyware 2011, Vista Security 2011 or Vista Antimalware 2011 files and registry values:

Files:
  • C:\ProgramData\[SET OF RANDOM CHARACTERS]
  • C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe
  • C:\Users\AppData\Local\[SET OF RANDOM CHARACTERS]
  • C:\Users\AppData\Roaming\Microsoft\Windows\Templates\[SET OF RANDOM CHARACTERS]
  • C:\Users\[Username]\AppData\Local\Temp\[SET OF RANDOM CHARACTERS]
For example:
[SET OF RANDOM CHARACTERS] = d6e3porotq7359g8rm1q286zx
[3 RANDOM CHARACTERS].exe = hyf.exe

Registry values:
  • HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'
  • HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1' = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe.exe" /START "%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'
  • HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'
  • HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" - '"%1" %*'
  • HKEY_CLASSES_ROOT\.exe\DefaultIcon "(Default)" = '%1'
  • HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\runas\command "(Default)" = '"%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\exefile "Content Type" = 'application/x-msdownload'
  • HKEY_CLASSES_ROOT\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\exefile\shell\runas\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"C:\Users\AppData\Local\[3 RANDOM CHARACTERS].exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"'
Share this information with other people:

Remove XP Antispyware 2011 and XP Guard (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
XP Antispyware 2011, XP Guard or XP Internet Security 2011 are only a few names of the same fake security program. Basically, it's a name changing rip-off rogue application that deliberately reports false system security threats. Some other names of this misleading program are listed below. This fake program (XP Antispyware 2011, XP Guard or any other name from the list) is quite aggressive. It comes from fake online scanners, infected websites or bundled with other malware and masquerades as the security update for Windows. The rogue program drops an executable on the computer which blocks legitimate anti-virus and anti-spyware programs and causes some other problems. XP Internet Security 2011 or XP Antimalware 2011 also modifies Windows registry and makes the removal process even more complicated. Thankfully, we've got the remove instructions to help you to remove XP Antispyware 2011, XP Guard or XP Internet Security 2011 from your computer. Please follow the instructions below carefully.

This rogue program goes by many different program names listed below.
  • XP Antispyware
  • XP Antispyware 2011
  • XP Anti-Virus
  • XP Anti-Virus 2011
  • XP Total Security
  • XP Total Security 2011
  • XP Security
  • XP Security 2011
  • XP Internet Security
  • XP Internet Security 2011
  • XP Antimalware
  • XP Antimalware 2011
  • XP Guard
  • XP Home Security 2011




While XP Antispyware 2011 is running, it will pretend to scan your computer for malicious code. Obviously, it will find numerous infections, e.g. e-mail worms, trojans, spyware and other malicious software on your computer. Then it will ask you to pay for a full version of the program to remove the infections which do not even exist. Please do not fall victim to this scam. As a typical rogue, XP Antispyware 2011, XP Security or any other other name, will display fake security warnings and notification from your Windows taskbar. The text of some of the fake alerts is:
System danger!
Your system security is in danger. Privacy threats detected. Spyware, keyloggers or Trojans may be working the background right now. Perform an in-depth scan and removal now, click here.
Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.

Privacy threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.






So, as you can see, the rogue program does all its best to scare you into thinking that your computer is infected with spyware, trojans and other viruses. It will even claim that your sensitive information will be stolen and sold. Don't worry, all these alerts are fake. You just need to remove the rogue program and maybe some related malware from your computer and you will be good to go. XP Antispyware 2011 or XP Guard will also hijack Intenet Explorer and Mozilla Firefox. The problem is that you won't be able to download malware removal software. The rogue program will display a fake alert that the site you are visiting is dangerous. Of course, that’s not true. The fake message reads:
Internet Explorer alert. Visiting this site may pose a security threat to your system!
Possible reasons include:
- Dangerous code found in this site's pages which installed unwanted software into your system.
- Suspicious and potentially unsafe network activity detected.
- Spyware infections in your system
- Complaints from other users about this site.
- Port and system scans performed by the site being visited.


Things you can do:
- Get a copy of XP Antispyware 2011 to safeguard your PC while surfing the web (RECOMMENDED)
- Run a spyware, virus and malware scan
- Continue surfing without any security measures (DANGEROUS)


Last, but not least, XP Antispyware 2011 will block certain programs on your computer. So, first of all you will have to stop the rogue program and fix the registry. If your PC is heavily you will need to use a different computer than the infected one to download and transfer all the necessary files required to remove the rogue program. By the way, if you have already purchased this bogus program then you should contact your credit card company and dispute the charges or even cancel your credit card. Then please follow the removal instructions below. If you have any questions or additional information about XP Antispyware 2011, XP Guard or XP Internet Security 2011, please leave a comment. Good luck and be safe online!


XP Antispyware 2011, XP Guard, XP Internet Security 2011 removal instructions:

1. Click Start->Run or press WinKey+R. Type in "command" and press Enter key.


2. In the command prompt window type "notepad" and press Enter key. Notepad will come up.


3. Copy all the text in blue color below and paste to Notepad.

Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe]
[-HKEY_CURRENT_USER\Software\Classes\secfile]
[-HKEY_CLASSES_ROOT\secfile]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

4. Save file as fix.reg to your Desktop. NOTE: (Save as type: All files)


5. Double-click on fix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.

6. Download recommended anti-malware software (direct download) from the list below and run a full system scan.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

7. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32.


Alternate removal instructions:

Make sure that you can see hidden and operating system protected files in Windows. For more in formation, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmarks from the checkboxes labeled:
  • Hide extensions for know file types
  • Hide protected operating system files
Click OK to save the changes.


1. Go into C:\Documents and Settings\[UserName]\Local Settings\Application Data\ folder.

For example: C:\Documents and Settings\Michael\Local Settings\Application Data\


2. Find hidden executable file in this folder. In our case it was called wmi.exe, but I'm sure that the file name will be different in your case. Rename wmi.exe to wmi.dl_ and click Yes to confirm file rename. Then restart your computer.





3. After a restart, open Internet Explorer. Download xp_exe_fix.reg and save it to your Desktop. Double-click on xp_exe_fix.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.



4. Download recommended anti-malware software (direct download) from the list below and run a full system scan.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe. With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32.



Associated XP Antispyware 2011, XP Guard, XP Internet Security 2011 files and registry values:

Files:
  • C:\Documents and Settings\All Users\[SET OF RANDOM CHARACTERS]
  • C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS]
  • C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe
  • C:\Documents and Settings\[UserName]\Templates\[SET OF RANDOM CHARACTERS]
  • C:\Documents And Settings\[UserName]\Local Settings\Temp\[SET OF RANDOM CHARACTERS]
For example: [SET OF RANDOM CHARACTERS] = d5a8krfpei0913mt2ts3px3c78qw

Registry values:
  • HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'
  • HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1' = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'
  • HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'
  • HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)" = '"%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" - '"%1" %*'
  • HKEY_CLASSES_ROOT\.exe\DefaultIcon "(Default)" = '%1'
  • HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\runas\command "(Default)" = '"%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\exefile "Content Type" = 'application/x-msdownload'
  • HKEY_CLASSES_ROOT\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\exefile\shell\runas\command "IsolatedCommand" = '"%1" %*'
  • HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "%1" %*'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"C:\Documents and Settings\[UserName]\Local Settings\Application Data\[3 RANDOM CHARACTERS].exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"'
Share this information with other people:

Friday, November 12, 2010

How to remove Internet Security Suite (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Internet Security Suite is a fake security program that pretends to scan the computer for malicious software and reports false system security threats. Once installed, the rogue program will report that your computer is infected with all sorts of malware, e.g. trojans, worms, spyware and other viruses. Internet Security Suite will try to frighten you into paying for a full version of the program. Do not fall victim to this rogue application. You should remove it from your computer as soon as possible. We've got the removal instructions to help you to remove Internet Security Suite from your computer for free using legitimate anti-malware software. Please follow the removal instructions below.

A screen shot of the Internet Security Suite malware
This rogue program is from the same family as Smart Engine. It's a typical rip-off rogue. Internet Security Suite is promoted mostly through the use of fake online scanners, infected websites and other malicious software. The bad guys also use various other misleading methods to distribute their bogus software, e.g. social engineering and spam emails. If you somehow ended up with this rogue program then you will be greeted with the misleading Internet Security Suite screen every time you login to Windows. Typically, such rogue programs are not very dangerous. They cannot delete your files or steal sensitive information. However, Internet Security Suite and other similar rogues can come bundled with Trojans and rootkits. You may even become a part of a botnet. That's why you should remove Internet Security Suite and any related malware from your computer using reputable anti-malware software.

While Internet Security Suite is running, it will display fake security alerts and notifications from your Windows taskbar. The rogue program will claim that your computer is infected with trojans and that your sensitive information can be stolen.







Please ignore such fake alerts. Just like the false scan results, these fake security alerts were made to scare you into thinking that your computer is infected when the only real infection is Internet Security Suite itself. What is more, the rogue will block some executables and may even hijack Internet Explorer. It goes without saying that you should get rid of Internet Security Suite. Most importantly, do not purchase it. If you have already bought this rogue program then please contact your credit card company, dispute the charges and cancel your credit card. Then please follow Internet Security Suite removal instructions below. When the rogue program is gone, please install reliable anti-virus software to protect your computer against malicious software. We recommend ESET NOD32. If you have any questions or additional information about Internet Security Suite, please leave a comment. Good luck and be safe online!


Internet Security Suite removal instructions using Process Explorer (in Normal mode):

1. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK.



2. Download Process Explorer.
3. Rename procexp.exe (Process Explorer) to winlogon.exe and run it. Stop the Internet Security process(es).

4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus 4.


Internet Security Suite removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab.
Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK.



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus 4.


Share this information with other people:

 
//PART 2