Thursday, January 13, 2011

How to Remove Windows System Optimizator (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows System Optimizator is a piece of malware that gives false threat reports on your computer and then ask you to purchase a registered version to remove those reported threats. It pretends to be computer optimization and security software. The rogue performs a fake system scan and reports non-existent Windows registry errors, viruses, privacy issues and network security problems. It also checks system performance, media tools and etc. After the fake scan it gives total system "efficiency score" which is of course very low, between 30-40%, to scare you into thinking that your computer has some serious problems. Windows System Optimizator performs no useful function other than to enrich the scammers. You shouldn't trust it. If you are reading this article, then your computer is probably infected with this malware. Thankfully, we've got the removal instructions to help you to remove Windows System Optimizator from your computer for free. Please follow the steps in the removal guide below.



Windows System Optimizator is promoted via Trojans that impersonate Microsoft Security Essentials alert. Trojans displays a fake security warning saying that Microsoft Security Essentials has detected a potential threat. It pretends to scan the suspicious file with online scanner. Then it will display another fake window saying that you should install malware removal tool to remove the threat. When you click OK, your computer will restart.



After reboot, you will see Windows System Optimizator installation wizard.



When the installation is finished, Windows System Optimizator fake scanner will show up on your computer screen. By the way, this rogue program changes Windows registry so that Windows System Optimizator scanner runs every time Windows starts. You won't be able to access your desktop so please allow it to perform its fake scan. After the fake scan, close the program by clicking on the X at the top right of the Windows System Optimizator Window. Now your Windows Desktop should be available and can continue with the removal process.

Windows System Optimizator blocks other programs on the infected computer and displays its fake message saying "Application that seems to be a key-logger is detected."
Warning!
Name: taskmgr.exe
Name: C:\WINDOWS\system32
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.


It also displays fake security notifications from Windows task bar.
Critical vulnerability!
System information security is at risk.
Total System scanning is recommended to remove PC works errors.


Windows System Optimizator purchase page:



Windows System Optimizator is from the same family as Windows Optimization Center and Privacy Corrector.
If you choose to purchase this rogue program you will lose at least $50 with a special discount. Besides, scammers will have your credit card details and may steal even more money from you. If you have already purchased this bogus program, please contact your credit card company and dispute the charges stating that Windows System Optimizator is a computer infection. Then please follow then removal instructions below to remove Windows System Optimizator. You can remove it manually but we strongly recommend you to scan your computer with anti-malware software because this rogue can come bundled with other malicious software. Please inform your friends and associate about this threat. If you have any questions, please do not hesitate to contact us. Good luck and be safe online!


Windows System Optimizator removal instructions:

1. Rename the main executable of Windows System Optimizator malware:

In Windows XP:
C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe

In Windows Vista/7:
C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe

Here's an example in Windows XP:


In our case, the file was bkjgka. Look for similar file and rename it to malware. Then restart your computer. This should disable Windows System Optimizator. After reboot, please continue with the rest of the removal process. NOTE: By default, Application Data folder is hidden. If you can find it, please read Show Hidden Files and Folders in Windows.

3. Download shell-fix.reg. Double-click to run it. Click "Yes" when it asks if you want to add the information to the registry. This file will fix the Windows Shell entry.
4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Alternate Windows System Optimizator removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Windows System Optimizator associated files and registry values:

Files:

In Windows XP:
  • C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe
In Windows Vista/7:
  • C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%UserProfile%\Application Data\[SET OF RANDOM CHARACTERS]"
Share this information with other people:

Wednesday, January 12, 2011

How to Remove Good Memory (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Good Memory is a rogue disk defragmenter, computer optimization and system protection program that reports false system threats, critical errors and performance issues. It's classified as a rogue application for several reasons. First of all, it detects the same errors and issues (11) on different computers. Some of the fake problems you may see:
  • Read time of hard drive clusters less than 500 ms
  • 32% of HDD space is unreadable
  • Bad sectors on hard drive or damaged file allocation table
  • Drive C initializing error
  • Hard drive doesn't respond to system commands
  • Data Safety Problem. System integrity is at risk.
  • Registry Error - Critical Error
Secondly, Good Memory doesn't scan your computer. It reports premeditated hard drive errors and Windows registry problems. Thirdly, the rogue program gives a false sense of overall system stability, performance and even protection by displaying fake error messages and warnings. This piece of malware states that all these errors are critical. It may even state that your hard drive is missing. It will block other programs on your computer for the same reasons - critical hard drive errors and system stability issues.



Good Memory has to be manually installed most of the time but it can come bundled with other malware. If you got hit with a Trojan virus then there is also a chance that you will end up with this fake application on your computer. Scammers distribute this bogus software via e-mails, malicious or hacked web pages, social networks, peer-to-peer networks, etc. Good Memory won't show up in add/remove programs list. Uninstall option that doesn't work either. You will have to remove Good Memory manually or with anti-malware software. We prefer second option because there can be more malware installed on your computer that are not included in the malware removal guide outlined below. When Good Memory is running, it may hide and desktop icons, task bar and change desktop background image/color. The rogue application may display even more fake security and system alerts saying that you can lose your files or that your computer may crash.
Critical Error
Damaged hard drive clusters detected. Private data is at risk

Low Disk Space
You are running very low disk space on Local Disk (C:).

Critical Error
A critical error has occurred while indexing data stored on hard drive. System restart required.


Good Memory is from the same family as Fast Disk and My Disk scareware.

Without a doubt, Good Memory is a scam. It doesn't do anything and asks money for fake malware/error removal. The problem is that Good Memory looks quite legitimate. Inexperienced Internet users may easily fall victim to this rogue program. If you have already purchased it, please contact your credit card company and dispute the charges. Be advised, that scammers may steal more money from your bank account if you gave them your credit card details. If you somehow ended up this bogus application on your computer, please follow the removal instructions below to remove Good Memory and related malware for free. Please inform your friends and associates about this threat. If you need additional help removing Good Memory, please leave a comment. Good luck and be sage online!


Good Memory removal instructions:

1. Download Process Explorer. (click the link and wait for few seconds, download will begin automatically)
2. End Good Memory processes, e.g. 2Hdgr52HdfrGH.exe or 2MfCCjX5Pv1fkr.exe.



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Good Memory removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Good Memory associated files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\~[SET OF RANDOM CHARACTERS]
  • %UsersProfile%\Local Settings\Application Data\[SET OF RANDOM CHARACTERS].DAT
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Good Memory.lnk
  • %UsersProfile%\Start Menu\Programs\Good Memory\
  • %UsersProfile%\Start Menu\Programs\Good Memory\Good Memory.lnk
  • %UsersProfile%\Start Menu\Programs\Good Memory\Uninstall Good Memory.lnk
%AllUsersProfile% refers to: C:\Documents and Settings\All Users
%UserProfile% refers to: C:\Documents and Settings\[User Name]

Windows Vista/7:
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\~[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Good Memory.lnk
  • %UsersProfile%\Start Menu\Programs\Good Memory\
  • %UsersProfile%\Start Menu\Programs\Good Memory\Good Memory.lnk
  • %UsersProfile%\Start Menu\Programs\Good Memory\Uninstall Good Memory.lnk
%AllUsersProfile% refers to: C:\ProgramData
%UserProfile% refers to: C:\Users\[User Name]

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes"='.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
Share this information with other people:

Tuesday, January 11, 2011

How to Remove Fast Disk (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Fast Disk is a rogue defrag utility that displays convincing hard drive and system error messages to make you think that your computer has some serious stability and performance problems. It reports non-existent performance issues, critical hard drive and Windows registry errors and some other problems. Basically it's just another Trojan that looks legitimate and tries to steal money from inexperienced Internet users. Fast Disk malware is distributed through poisoned search results and fake online scanners as a codec or flash player that is required to view online videos. Fast Disk or a trojan downloader can also masquerade as malware removal tool, e.g. Windows Defender. If you somehow ended up with this scareware, please do not pay for simulated removal of malware or other computer problems. Fast Disk will state that you need to install advanced module to fix certain hard drive and system errors. Do not fall victim to this scam. Instead, please follow the removal instructions below to remove Fast Disk malware from your computer.



Once the rogue program is installed, it will display a fake Fix Disk Windows diagnostic utility which will supposedly check hard drive sectors and registry integrity.



After the fake scan it will prompt you to run Fast Disk malware in order to fix computer errors. Fast Disk will perform another fake system scan and display eleven computer errors. It will pretend to fix six errors. If you want to fix the remaining errors you need to buy the "advanced module". Furthermore, Fast Disk will block other programs on your computer saying that there is a critical hard drive error which prevents the execution of certain applications and system utilities.
Critical Error
Damaged hard drive clusters detected. Private data is at risk.




To make things even worse, Fast Disk will change your desktop background and hide all desktop icons. Here are some of the fake warnings that you may see if you have this rogue program on your computer:
Critical Error
Hard Drive not found. Missing hard drive.
Critical Error
RAM memory usage is critically high. RAM memory failure.
Critical Error
Windows can't find hard disk space. Hard drive error
If the rogue program blocks everything and you can't download anti-malware software then you can use this code to activate Fast Disk: 0973467457475070215340537432225. If it works, the rogue program shouldn't bother you any more.





Fast Disk is from the same family as My Disk, Disk OK and Memory Fixer.

Fast Disk is a piece of malware that uses misleading methods to trick you into paying for a full version of the program. If you thought that this program was real and bought it then you should contact your credit card company and dispute the charges. Scammers may steal even more money from you if you won't inform your credit card company about this fraud. To remove Fast Disk and related malware, please follow the steps in the instructions below. If you have any questions about this malware, please let me know. Just use the comment form below. Please inform your friends and associates about this threat. Good luck and be safe online!


Fast Disk removal instructions:

1. Download Process Explorer. (click the link and wait for few seconds, download will begin automatically)
2. End Fast Disk processes, e.g. hfdGdeghsGDjke.exe or HdfrgdherGFdsaz.exe.



3. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Fast Disk removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Fast Disk associated files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Fast Disk.lnk
  • %UsersProfile%\Start Menu\Programs\Fast Disk\
  • %UsersProfile%\Start Menu\Programs\Fast Disk\Fast Disk.lnk
  • %UsersProfile%\Start Menu\Programs\Fast Disk\Uninstall Fast Disk.lnk
%AllUsersProfile% refers to: C:\Documents and Settings\All Users

Windows Vista/7:
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Fast Disk.lnk
  • %UsersProfile%\Start Menu\Programs\Fast Disk\
  • %UsersProfile%\Start Menu\Programs\Fast Disk\Fast Disk.lnk
  • %UsersProfile%\Start Menu\Programs\Fast Disk\Uninstall Fast Disk.lnk
%AllUsersProfile% refers to: C:\ProgramData

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes"='.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
Share this information with other people:

Monday, January 10, 2011

Antispyis.com and other Antivirus Scan related domains

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
New additions of misleading websites which promote a rogue security application called Antivirus Scan.
  • antispyis.com
  • afantispy.net
  • softwareea.com
  • softwarear.com
  • marezer.com
These website use a single web template and provide false information, comments, reviews and awards about Antivirus Scan scareware. This program is not legitimate and it obviously won't protect your computer against any type of malicious software. If you somehow ended up with this rogue antivirus or you are constantly redirected to one of the rogue websites listed above then please scan your computer with trusted anti-malware software. For more information please read how to remove Antivirus Scan and related malware from. If you have any questions regarding the bogus web sites or the rogue program, please leave a comment. Useful insights on this threat are welcome too. Good luck and be safe online!

A screenshot of antispyis.com:

How to Remove Disk OK and HDD OK (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Disk OK and HDD OK are the names of basically the same piece of malware that poses as the Windows disk defragmenter utility. The rogue program proceeds to scan your computer, finds eleven critical errors and gives you two options; purchase advanced module license to fix the problems or to stay unprotected. If you choose to stay unprotected it will display disturbing hard drive errors messages and block other programs so that you will not be able to use them properly. Disk OK is very annoying scareware. It not only gives you a false sense of system status and performance but also interrupts your work. Disk OK or HDD OK, no matter how it's called, reports the same hard drive, Windows registry and other computer problems on different machines. It comes with an uninstall feature but unfortunately it doesn't work. You shouldn't trust Disk OK and HDD OK. It's a typical rip-off rogue that does nothing and uses misleading methods to trick users into paying for bogus software. If you somehow picked up this rogue program then please follow the removal instructions below to remove Disk OK and HDD OK from your computer using reliable and free malware removal applications.



Disk OK and HDD OK are from the same family as My Disk and Memory Fixer. Scammers often use re-branded versions of the same piece of malware. Such rogue programs are typically distributed through the use of Trojans and other malicious software. The rogue program may be downloaded and installed without your knowledge or you may be prompted to install it from some place that you obviously should not have been visiting. One way or another, this is not the right way to distribute any software. Here are some of the fake error messages that you will probably see if your computer gets infected with Disk OK or HDD OK:
Critical Error
Damaged hard drive clusters detected. Private data is at risk.

Critical Error
A critical error has occurred while indexing data stored on hard drive. System restart required.

System Restore
The system has been restored after a critical error. Data integrity and hard drive integrity verification required.
Activation Reminder
Disk OK Activation
Advanced module activation required to fix detected errors and performance issues. Please purchase Advanced Module license to activate this software and enable all features.
You should also know that Disk OK or HDD OK won't delete your files or steal sensitive information. It's not that type of program. However, when your computer is infected with any type of malware there is a chance that you may end up with even more malware on your computer. That's why you should scan your computer with recommend anti-malware software just to make sure that there are no other viruses on your computer. Last, but not least, if you have already purchased this or any other rogue program, please contact your credit card company and dispute the charges. To remove Disk OK or HDD OK, please follow the steps in the instructions below. If you need help removing this rogue, please leave a comment. Helpful comments and related questions are also welcome. Please inform your friends and associates about this threat. Good luck and be safe online!


Disk OK removal instructions:

1. Download Process Explorer. (click the link and wait for few seconds, download will begin automatically)
2. End Disk OK or HDD OK processes, e.g. ifgHrdhftGndke.exe or HfgrK34HdnfHGe.exe.



3. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Disk OK removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Disk OK associated files and registry values:

Files:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Disk OK.lnk
  • %UsersProfile%\Start Menu\Programs\Disk OK\
  • %UsersProfile%\Start Menu\Programs\Disk OK\Disk OK.lnk
  • %UsersProfile%\Start Menu\Programs\Disk OK\Uninstall Disk OK.lnk
%AllUsersProfile% refers to:
C:\Documents and Settings\All Users (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Roaming (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes"='.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
Share this information with other people:

 
//PART 2