Thursday, January 27, 2011

How to Remove Antivirus .NET (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
This summary is not available. Please click here to view the post.

Wednesday, January 26, 2011

How to Remove Windows Universal Tool (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows Universal Tool is classified as a rogue application that misleads users into paying for the simulated removal of viruses and system errors. This form of malware might be disguised as a video codec, flash player update or even spyware removal software. We found a Trojan downloader that impersonates Microsoft Security Essentials Alert and installs Windows Universal Tool scareware. The fake alert looks very convincing. This rogue program pretends to scan the computer for malicious software, registry and system errors. After the fake scan it reports hundreds of viruses and critical computer errors that of course do not exist. Windows Universal Tool will block other programs and system tools so that the removal of this rogue application becomes more complicated. Thankfully, we've got the removal instructions to help you to remove Windows Universal Tool and related malware for free. Please follow the removal instructions below.



Windows Universal Tool is from the same family as Windows Utility Tool malware. The Trojan changes Windows registry so that the fake scanner starts before your normal Windows desktop is shown. Just run a fake system scan and then close the program in order to get to your normal Windows desktop.

Fake Windows Universal Tool scan results:


Windows Universal Tool software description:


You will also get this web form where you can purchase a license of Windows Universal Tool. One year subscription + life time support will cost you $80.



If you have paid for Windows Universal Tool then you should contact your card supplier's fraud department and ask for the payment to be cancelled. Just tell them that this software is an infection. As you can see, this program gives a false sense of security and reports non-existent viruses. If you somehow got hit with this scareware, please follow the steps in the removal instructions below. Be advised that Windows Universal Tool may come bundled with other malware. That's why you should scan your computer with anti-malware software even if you managed to remove the rogue program manually. If you have any questions or help removing this virus, please leave a comment. Good luck and be safe online!


Windows Universal Tool removal instructions:

1. Rename the main executable of Windows Universal Tool:

In Windows XP:
C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe

In Windows Vista/7:
C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe



Look for htwlfy or similar file and rename it to malware. Then restart your computer. This should disable Windows Universal Tool. After reboot, please continue with the rest of the removal process. NOTE: By default, Application Data folder is hidden. If you can find it, please read Show Hidden Files and Folders in Windows.

OR you can download Process Explorer and end Windows Universal Tool process.



2. Download shell-fix.reg. Double-click to run it. Click "Yes" when it asks if you want to add the information to the registry. This file will fix the Windows Shell entry.
3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Alternate Windows Universal Tool removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Associated Windows Universal Tool files and registry values:

Files:

In Windows XP:
  • C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe
In Windows Vista/7:
  • C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%UserProfile%\Application Data\[SET OF RANDOM CHARACTERS]"
Share this information with other people:

Tuesday, January 25, 2011

How to Remove W32.Blaster.Worm (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
W32.Blaster.Worm is one of the most wide spread worms ever that was first noticed in August, 2003. It spreads by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (BID 8205). This vulnerability was fixed, a patch is available here: Microsoft Security Bulletin MS03-026. This computer worm targets machines running Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003. Apple, Unix and other platforms can not be infected. When executed, the Blaster worm attempts to retrieve a copy of the file msblast.exe, penis32.exe, teekids.exe, mspatch.exe, mslaugh.exe or enbiei.exe from the host that compromised the computer. Downloaded file is saved in the Windows system folder. The infected computer then scans the internet and local networks looking for vulnerable computers.

Other variants of Blaster Worm:
  • W32.Blaster.A.Worm
  • W32.Blaster.B.Worm
  • W32.Blaster.C.Worm
  • W32.Blaster.D.Worm
  • W32.Blaster.E.Worm
  • W32.Blaster.F.Worm
On Windows XP W32.Blaster.Worm can cause the remote RPC service to terminate displaying a message "Windows must now restart because the Remote Procedure Call (RPC) Terminated Unexpectedly". The infected computer might restart every few minutes.



In order to remove Blaster worm from the infected computer you need to install Microsoft patch and then run W32.Blaster.Worm removal tool or remove the worm manually. Accidental computer shut downs prevents the required patch and removal tools from being downloaded and installed. Thankfully, there is an easy way to stop this. Please follow W32.Blaster.Worm removal instructions below.

Important! If you've got the following notification, your computer is infected with a rogue antivirus program and not the original W32.Blaster.Worm.





To remove the rogue antivirus program from your computer, please follow there removal guide here or this removal guide.
However, if you believe that your computer is infected with the W32.Blaster.Worm, please follow the removal instructions below.

Download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.






W32.Blaster.Worm removal instructions:

1. Select Start -> Run (or press WinKey+R)
2. Type in: shutdown -a
3. Click OK or press Enter.



4. Download and install Microsoft patch MS03-039.
5. Then run W32.Blaster.Worm Removal Tool. You can choose one of these:
6. Restart the computer and re-connect to the internet. You should run Blaster Worm Removal Tool again to ensure that your computer is clean.

7. Download recommended anti-malware software (direct download) and run a full system scan to remove this worm from your computer.

The worm can download additional malware onto your computer. We have to make sure that your computer is not infected with other malicious software, specifically trojan downloaders.


W32.Blaster.Worm manual removal instructions:

1. Download and install Microsoft patch MS03-039.
2. Press Ctrl+Alt+Delete or Ctrl+Shift+Escape. You should now see the Windows Task Manager or a screen where you can select the Task Manager to be run.
3. Click on the Processes tab.
4. Look for a process(es) named msblast.exe, penis32.exe, teekids.exe, mspatch.exe, mslaugh.exe, enbiei.exe in the list
5. Click the process(es) to highlight it and then click the End Process button. Close Task Manager.
6. Open Windows Registry Editor (click Start -> Run. Type Regedit and click OK or press Enter).
7. Locate the HKLM\Software\Microsoft\Windows\CurrentVersion\Run entry.
8. In the right hand pane select windows auto update = msblast.exe and delete it.
9. Restart the computer and re-connect to the internet.

10. Download recommended anti-malware software (direct download) and run a full system scan to remove this worm from your computer.

The worm can download additional malware onto your computer. We have to make sure that your computer is not infected with other malicious software, specifically trojan downloaders.


W32.Blaster.Worm files and registry values:

Files:
  • C:\Windows\System32\msblast.exe
  • C:\Windows\System32\penis32.exe
  • C:\Windows\System32\teekids.exe
  • C:\Windows\System32\mspatch.exe
  • C:\Windows\System32\mslaugh.exe
  • C:\Windows\System32\enbiei.exe
Registry values:
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "windows auto update"="msblast.exe"
Share this information with other people:

Saturday, January 22, 2011

How to remove Windows Scan and Memory Scan (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows Scan, Windows Fix Disk, Memory Scan, System Diagnostic, Windows Safe Mode are new names of the fake disk defragmenter that reports false system security threats, registry errors and some other problems on your computer. It's a piece of malware that pretends to be a legitimate and useful Windows repair tool. It has many names, more than 20, but it uses the same graphical user interface (see the image below). There isn't much to say about this rogue called Windows Scan or Memory Scan. We've already posted numerous articles about this threat, e.g. How to Remove Disk Optimizer (Uninstall Guide) or How to Remove My Disk (Uninstall Guide). Quick facts about Windows Scan and Memory Scan: reports non-existent errors (the same 11 errors on different machines), displays fake security warnings, blocks other programs and gives a false sense of security. Windows Scan and Memory Scan is promoted through the use of fake online scanners, spam emails, infected/compromised websites and via social networks. You can active the rogue program by using these codes and any email: 0973467457475070215340537432225 or 8475082234984902023718742058948. This malware resides in C:\Documents and Settings\All Users\Application Data folder if you run Windows XP. If you have Windows Vista or Windows 7 then you can find the rogue program in C:\ProgramData\ folder. Look for randomly named folder with random file names inside that folder. Rename the main executable of Windows Scan or Memory Scan and then restart your computer. For more information, please follow the removal instructions below to remove Windows Scan and Memory Scan malware for free. If you need more help with this rogue program, you can always leave a comment. Good luck and be safe online!

Windows Repair GUI


Windows Tool GUI


Windows Scan GUI



Removal instructions:

1. Download Process Explorer. (click the link and wait for few seconds, download will begin automatically)
2. End malware processes, e.g. 254hdeJHdergfkse.exe or KHdrgeHQDSaw2rs.exe.



OR just rename/delete files related to Windows Scan or Memory Scan. Files are located in %AllUserProfile% folder. See the list at the end of this page for more details. Windows Scan or Memory Scan files in Windows XP: (note: by default, Application Data folder is hidden. If you can't see such folder/files, please read Show Hidden Files and Folders in Windows)



3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Alternate removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Windows Scan and Memory Scan associated files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\~[SET OF RANDOM CHARACTERS]
  • %UsersProfile%\Local Settings\Application Data\[SET OF RANDOM CHARACTERS].lic
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Windows Scan.lnk
  • %UsersProfile%\Start Menu\Programs\Windows Scan\
  • %UsersProfile%\Start Menu\Programs\Windows Scan\Windows Scan.lnk
  • %UsersProfile%\Start Menu\Programs\Windows Scan\Uninstall Windows Scan.lnk
%AllUsersProfile% refers to: C:\Documents and Settings\All Users
%UserProfile% refers to: C:\Documents and Settings\[User Name]

Windows Vista/7:
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\~[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].lic
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Windows Scan.lnk
  • %UsersProfile%\Start Menu\Programs\Windows Scan\
  • %UsersProfile%\Start Menu\Programs\Windows Scan\Windows Scan.lnk
  • %UsersProfile%\Start Menu\Programs\Windows Scan\Uninstall Windows Scan.lnk
%AllUsersProfile% refers to: C:\ProgramData
%UserProfile% refers to: C:\Users\[User Name]

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
Share this information with other people:

Friday, January 21, 2011

How to Remove Windows Utility Tool (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows Utility Tool is a rogue application that gives false reports about non-existent viruses and system errors on your computer. Usually, we encounter fake anti-virus or anti-spyware software but this rogue pretends to scan your computer for registry errors and even checks your Internet connection security, so it's more like a combination of anti-virus software and system optimization utility. It states that you can make your PC run faster. You just need to purchase a license of Windows Utility Tool and it will fix all the errors and remove viruses from your computer. The rogue program displays fake security warnings and pop-ups saying that your computer is infected with malware that may execute malcode, download additional malware on to your computer or even steal your sensitive information. What is more, Windows Utility Tool blocks task manager, registry editor, web browsers and other programs. As you can see, this rogue program uses misleading methods to scare you onto thinking that your computer is infected. Low system performance score and fake security alert may actually trick inexpierenced Internet users into paying for this bogus software. If you somehow ended up with this malware, please follow the removal instructions below to remove Windows Utility Tool and any related malware for free using legitimate anti-malware software.



Windows Utility Tool is from the same family as Windows Security & Control and Windows System Optimizator.
Here's an example of a fake Windows Utility Tool security notification that you will probably see if you got hit with this malware:
System Security warning!
Potentially harmful script execution is detected.
It is strongly recommended to run total System scanning.


The fake message that you will see when you attempt run a program is:



The main executable of Windows Utility Tool resides in C:\Documents and Settings\[UserName]\Application Data\ folder if you run Windows XP. If you have Windows Vista or Windows 7, then this file resides in C:\Users\[UserName]\AppData\Roaming\ folder. The file name is different in each case, we had "spkbqg.exe". This file was hidden. Change folder settings to view hidden files; otherwise you won't find it. Rename the rogue file to "malware.exe" and restart your computer. For more information, please read the removal instructions below. Last, but not least, if you have already purchased Windows Utility Tool malware, then you should definitely contact your credit card company and tell them that this program is an infection. Besides, scammers may charge your credit card again it won't so anything about it. Good luck and be safe online!


Windows Utility Tool removal instructions:

1. Rename the main executable of Windows Utility Tool:

In Windows XP:
C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe

In Windows Vista/7:
C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe



In our case, the file was spkbqg. Look for similar file and rename it to malware. Then restart your computer. This should disable Windows Utility Tool. After reboot, please continue with the rest of the removal process. NOTE: By default, Application Data folder is hidden. If you can find it, please read Show Hidden Files and Folders in Windows.

3. Download shell-fix.reg. Double-click to run it. Click "Yes" when it asks if you want to add the information to the registry. This file will fix the Windows Shell entry.
4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Alternate Windows Utility Tool removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus.


Windows Utility Tool associated files and registry values:

Files:

In Windows XP:
  • C:\Documents and Settings\[UserName]\Application Data\[SET OF RANDOM CHARACTERS].exe
In Windows Vista/7:
  • C:\Users\[UserName]\AppData\Roaming\[SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%UserProfile%\Application Data\[SET OF RANDOM CHARACTERS]"
Share this information with other people:

 
//PART 2