Saturday, January 1, 2011

Show Hidden Files and Folders in Windows

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
By default Microsoft Windows hides important files from being seen with Windows Explorer in order to protect these files from being modified or deleted by the user. Unfortunately viruses, rogue programs and other type of malicious software may hide files making it hard to find and delete them. Please follow the step-by-step directions below to show all hidden files in Windows.

Table of Contents:


Windows XP

1. Go to Start → Control Panel and choose Folder Options.



2. Double-click on the Folder Options icon. Click on the View tab.



3. Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmark from the checkbox labeled Hide protected operating system files. Click OK.




Windows Vista

1. Click on the Start button and then click on the Control Panel menu option.



2. In Control Panel, click Appearance and Personalization, and then click Folder Options.



3. Click the View tab. Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmark from the checkbox labeled Hide protected operating system files. Click OK.




Windows 7

1. Click on the Start button, then type in "folder options" into the search box. You will now see the search results. Just click on the Folder Options to open it.



2. Under the Hidden files and folders section, click Show hidden files, folders, and drives. Then remove the checkmark from the checkbox labeled Hide protected operating system files. Click OK.



Now your computer is configured to show all hidden files and folders. Hidden files will appear as if they are faint (slightly grayed out).

Friday, December 31, 2010

How to Remove Easy Scan (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Easy Scan is a rogue application that pretends to be legitimate software, in this case registry cleaner and hard drive optimization program. This rogue program can be installed either manually by a user or unknowingly through the use of other malware and software vulnerabilities, e.g. pdf exploits. Once installed on your computer, Easy Scan will deliberately misrepresent your computer's security status by displaying fake hard drive error message and notifications saying that Windows registry is corrupted or your hard drive is missing. It will also pretend to scan your computer for errors and malcode and. After the fake scan, it will state that it has found 11 critical errors on your computer. Then Easy Scan will state that you need to purchase a full version or register for an annual subscription of the program in order to fix the reported errors. Profit is a primary motivation for creators of this rogue program. Please do not fall victim to Easy Scan. If it has infected your computer then please use the removal instructions below to remove Easy Scan using legitimate anti-malware software and hopefully you should be ok.



Easy Scan is from the same family as HDD Low and Scanner scareware. When running, it will block other applications on your computer. You won't be able to use Task Manager, Registry Editor and some other useful tools as well. If you attempt to launch malware removal programs it will display a fake error message with the following text:
Windows detected a hard drive problem.
A hard drive error occurred while starting the application.
Some examples of the fake problems Easy Scan detects are:
  • Read time of hard drive clusters less than 500 ms
  • 32% of HDD space is unreadable
  • Bad sectors on hard drive or damaged file allocation table
  • Drive C initializing error
  • Data Safety Problem. System integrity is at risk.
  • Registry Error - Critical Error
Easy Scan may come bundled with other malicious software, usually rootkits. Though the rogue program can be removed manually yet there might be other malware installed on your computer. That's why we strongly recommend you to use anti-malware software to remove EasyScan and any related malware from the system. By the way, if you have already purchased this fake program then please contact your credit card company and state that you would like to dispute the charge because Easy Scan is a scam. To remove Easy Scan and related malware, please follow the removal instructions below. If you have any questions, please feel free to ask. Good luck and be safe online!


Easy Scan removal instructions:

1. Open Task Manager (Ctrl+Alt+Delete) or use Process Explorer.
2. Click on the Processes tab.
3. End Easy Scan process, e.g. tGlvsSfrDrd.exe or 158736954.exe.



4. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



5. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

6. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Easy Scan removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Easy Scan associated files and registry values:

Files:
  • %Temp%\[SET OF RANDOM CHARACTERS].exe
  • %Temp%\dfrg
  • %Temp%\dfrgr
  • %Temp%\~[SET OF RANDOM CHARACTERS]
  • %Temp%\
  • %Temp%\[SET OF RANDOM CHARACTERS].dll
  • %UserProfile%\Desktop\Easy Scan.lnk
  • %UserProfile%\Start Menu\Programs\Easy Scan\
  • %UserProfile%\Start Menu\Programs\Easy Scan\Easy Scan.lnk
  • %UserProfile%\Start Menu\Programs\Easy Scan\Uninstall Easy Scan.lnk
%Temp% refers to:
C:\Documents and Settings\[UserName]\Local Settings\Temp (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Local\Temp (in Windows Vista & Windows 7)

%UserProfile% refers to:
C:\Documents and Settings\[UserName]\ (in Windows 2000/XP)
C:\Users\[UserName]\ (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

Tuesday, December 28, 2010

How to Remove Full Scan (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Full Scan pretends to be a disk defragmenter program but actually it's a piece of malware that reports fake infections and hard drive errors. This rogue program is promoted via trojan downloaders and it is similar to the HDD Low malware in appearance. It uses deceiving methods to trick users into paying for the fake or simulated removal of malware and system errors. Once installed, Full Scan will alert you with the fake or simulated detection of hard drive and Windows registry problems. It finds the same hard drive problems (11) on different computers. Some examples of the fake problems it detects are:
  • Read time of hard drive clusters less than 500 ms
  • 32% of HDD space is unreadable
  • Bad sectors on hard drive or damaged file allocation table
  • Drive C initializing error
  • Data Safety Problem. System integrity is at risk.
  • Registry Error - Critical Error
What is more, it will block nearly all programs on your computer and display an error message saying, "Windows detected a hard drive problem. A hard drive error occurred while starting the application." It will display fake notifications from your Windows task bar as well. As you can see, Full Scan is nothing more but a scam. Besides, this program pops up on the computer screen and stars scanning the system without user's permission. And some of the fake alerts you may see while your PC is infected with this malware are ridiculous, let's say the one saying that your hard drive is missing. It sounds bad but it can't be true; otherwise your PC wouldn't work. Just like the fake errors messages, these alerts were designed to scare you into purchasing the program and should be ignored. If you find that your computer is infected with a program called "Full Scan" then you should follow the removal instructions below to remove Full Scan and any related malware from your computer as soon as possible. You can remove it manually but it would be a lot better idea to use anti-malware software because Full Scan rogue may come bundled with rootkits and other malware. Last, but not least, if you have already purchased it, then you should contact your credit card company and dispute the charges. Good luck and be safe online!


Full Scan removal instructions:

1. Open Task Manager (Ctrl+Alt+Delete) or use Process Explorer.
2. Click on the Processes tab.
3. End Full Scan process, e.g. jhGdrgHsr.exe or 18428423.exe.



4. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



5. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

6. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Full Scan removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Full Scan associated files and registry values:

Files:
  • %Temp%\[SET OF RANDOM CHARACTERS].exe
  • %Temp%\dfrg
  • %Temp%\dfrgr
  • %Temp%\~[SET OF RANDOM CHARACTERS]
  • %Temp%\
  • %Temp%\[SET OF RANDOM CHARACTERS].dll
  • %UserProfile%\Desktop\Full Scan.lnk
  • %UserProfile%\Start Menu\Programs\Full Scan\
  • %UserProfile%\Start Menu\Programs\Full Scan\Full Scan.lnk
  • %UserProfile%\Start Menu\Programs\Full Scan\Uninstall Full Scan.lnk
%Temp% refers to:
C:\Documents and Settings\[UserName]\Local Settings\Temp (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Local\Temp (in Windows Vista & Windows 7)

%UserProfile% refers to:
C:\Documents and Settings\[UserName]\ (in Windows 2000/XP)
C:\Users\[UserName]\ (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

Monday, December 27, 2010

How to Remove HDD Low (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
HDD Low is a rogue disk defragmenter and PC optimization program. It reports false system security threats, hard drive problems, and Windows registry errors to make you think that there is something wrong with your computer. The rogue program initiates a fake scan of your computer and reports 11 errors: Drive C initializing error, Registry Error - Critical Error, 32% of HDD space is unreadable and some other problems. HDD Low displays fake error messages and notifications saying that your hard drive is corrupted or missing. It blocks other programs on your computer and may even hijack your web browser. In some cases, HDD Low comes bundled with rootkit which makes the removal procedure even more complicated. You will have to use several malware removal tools to remove HDD Low from your computer so that it won't hide deep in the system and won't come back after a few days. If you have this virus on your computer, please follow the removal instructions below to remove HDD Low and any related malware from your computer for free using legitimate anti-malware programs. Also, if you have any questions about HDDLow, please leave a comment below. Good luck and be safe online!



HDD Low is from the same family as Win Scanner, Smart HDD, and Disk Repair.


HDD Low removal instructions:

1. Open Task Manager (Ctrl+Alt+Delete) or use Process Explorer.
2. Click on the Processes tab.
3. End HDD Low proces, e.g. GslHrwOfr.exe or 14835202.exe.



4. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



5. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

6. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


HDD Low removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


HDD Low associated files and registry values:

Files:
  • %Temp%\[SET OF RANDOM CHARACTERS].exe
  • %Temp%\dfrg
  • %Temp%\dfrgr
  • %Temp%\~[SET OF RANDOM CHARACTERS]
  • %Temp%\
  • %Temp%\[SET OF RANDOM CHARACTERS].dll
  • %UserProfile%\Desktop\HDD Low.lnk
  • %UserProfile%\Start Menu\Programs\HDD Low\
  • %UserProfile%\Start Menu\Programs\HDD Low\HDD Low.lnk
  • %UserProfile%\Start Menu\Programs\HDD Low\Uninstall HDD Low.lnk
%Temp% refers to:
C:\Documents and Settings\[UserName]\Local Settings\Temp (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Local\Temp (in Windows Vista & Windows 7)

%UserProfile% refers to:
C:\Documents and Settings\[UserName]\ (in Windows 2000/XP)
C:\Users\[UserName]\ (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

Sunday, December 26, 2010

How to Remove Personal Internet Security 2011 (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Personal Internet Security 2011 is classified as a rogue antivirus program which means that it doesn't provide proven anti-virus protection or reports false system security threats. This fake security program uses deceptive sales tactics to scare up sales from confused users. It performs a fake scan on your computer and states that you are infected with spyware, trojans and other malicious software, e.g. Packed.Win32.PolyCrypt, Trojan-PSW.Win32.Dripper, Trojan-Spy.HTML.Bankfraud.ix. After the fake scan, Personal Internet Security 2011 will prompt you to pay for a full version of the program to remove viruses from your computer and to ensure full system protection against malware. You need to remove Personal Internet Security 2011 from your computer. Do not purchase it. If need help removing this rogue program from your computer then please follow the steps in the removal guide below.



Personal Internet Security 2011 is from the same family as Internet Antivirus 2011 and My Security Shield, so its behavior is well known. This rogue program may be downloaded by trojan downloaders or installed when the fake alert is clicked. Usually, it has to be manually installed but in some cases installation occurs without user knowledge or consent. While Personal Internet Security 2011 is running, it will display numerous fake security warnings about imaginary threats and infections on your computer.


Warning! Identity theft attempt detected
Target: Microsoft Corporation keys




Just like the fake scan results, these fake warnings are only being used to make you think that your computer in infected with malicious software. The rogue program changes Windows Hosts file and your LAN settings to use a proxy server that will not allow you to browse any pages on the Internet with Internet Explorer and update your antivirus software. Furthermore, it may block legitimate programs on your computer as well.

The main executable of Personal Internet Security 2011 is located under C:\Documents and Settings\All Users\Application Data\[randomly named folder]\, e.g. "sqhdr5". The main exe should be "WKsra_249.exe" or similar. The easiest way to remove the main executable of this rogue program is to use Task Manager while logged in as another user, track down the file and deleted it. Then go back to normal mode and use malware scanner to remove the remains of Personal Internet Security 2011. Another way to remove Personal Internet Security 2011 is to restart your computer in safe mode with networking, disable proxy server for LAN in Internet Explorer and download anti-malware software. For more information, please follow the removal instructions below. Last, but not least, if you have purchased Personal Internet Security then contact your credit card company and dispute the charges. And, of course, if you have any questions about this malware, please leave a comment. Good luck and be safe online!


Personal Internet Security 2011 removal instructions:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK. You may have to repeat steps 1-2 if you will have problems downloading malware removal programs.



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Alternate Personal Internet Security 2011 removal instructions using HijackThis or Process Explorer (in Normal mode):

1. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK.



2. Download Process Explorer.
3. Rename procexp.exe to iexplore.exe and run it. Look for similar process in the list and end it:
  • WKsra_249.exe
OR download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it. Search for similar entries in the scan results:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:25520
O4 - HKCU\..\Run: [Personal Internet Security 2011] "C:\Documents and Settings\All Users\Application Data\sqhdr5\WKsra_249.exe" /s /d
Select all similar entries and click once on the "Fix checked" button. Close HijackThis tool.

4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Personal Internet Security 2011 associated files and registry values:

Files:
  • C:\Documents and Settings\All Users\Application Data\sqhdr5\
  • C:\Documents and Settings\All Users\Application Data\sqhdr5\WKsra_249.exe
  • C:\Documents and Settings\All Users\Application Data\sqhdr5\35.mof
  • C:\Documents and Settings\All Users\Application Data\sqhdr5\[SET OF RANDOM CHARACTERS].dll
  • C:\Documents and Settings\All Users\Application Data\sqhdr5\[SET OF RANDOM CHARACTERS].ocx
  • C:\Documents and Settings\All Users\Application Data\sqhdr5\MSSSys\
  • C:\Documents and Settings\All Users\Application Data\SMEYFE
  • %UserProfile%\Application Data\Personal Internet Security 2011\
  • %UserProfile%\Application Data\Personal Internet Security 2011\cookies.sqlite
  • %UserProfile%\Application Data\Personal Internet Security 2011\Instructions.ini
%UserProfile% refers to:
C:\Documents and Settings\ (for Windows 2000/XP)
C:\Users\[User Name]\AppData (for Windows Vista & Windows 7)

Registry values:
  • HKEY_CLASSES_ROOT\PersonalIS.DocHostUIHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:25553"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Internet Security 2011"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
Share this information with other people:

 
//PART 2