Saturday, March 16, 2013

Remove Win 7 Security Cleaner Pro, removal instructions

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Win 7 Security Cleaner Pro rogue security software can do a tremendous amount of damage on your computer. Especially when it comes bundled with rootkits, for instance ZeroAccess. It may be also packed with spyware or generic Trojan downloaders that can later download and install pretty much any piece of malicious software on your machine. The rogue security program itself isn't very very dangerous if speaking about technical capabilities of infecting and spreading malicious code but it tries to trick victims into paying for a fake antivirus program in order to remove non-existent virus threats. However, if it comes packed with spyware, and sometimes it really does, this combination is able to steal your passwords, personal information, or even your credit card information. It can hack into your email account and send spam messages using your account, especially true if you're using Outlook. It can corrupt the files saved and installed on your computer, causing your PC system to slow down or even crash. It is even able to infect other computers on a local network. Note: only possible if the rogue program comes bundled with additional malware. The rogue program alone doesn't have such capabilities. One way or another, should definitely remove it from your machine. If you are infected, you're in the right place because this page contains comprehensive instructions on how to remove Win 7 Security Cleaner Pro virus from your computer.



But first of all, do not let yourself become one of the millions of people who fall victim to rogue security software. The most commonly used form of rogue security software is depicting itself as an anti-virus scanner, complete with non-existent virus threats that it claims to be on the computer. Another scheme used by fake antivirus software is to make itself appear as a Windows Security Center, reminding computer users that their antivirus is out of date. Pop-up windows and alerts are the most common scheme used to get computer users to download the software or pay for it. As such, be wary of pop-up windows and alerts warning you that your computer has been infected and instructing you to download the fake software to get rid of the non-existent virus. In this case, Win 7 Security Cleaner Pro actually displays a fake Windows Action center pop-up claiming that your antivirus software is outdated.

Scareware makes them sound legitimate programs to easier trick computer users to trust the contents and download the application or but the so-called "full" version to remove supposedly found infections. You may check this websites for a complete list of the different names of programs used by rogue antivirus software.

Win 7 Security Cleaner Pro is promoted via fake online virus scanners and infected websites. Cyber crooks do not choose sites by categories, they normally infect any website that has bugs and so can be infected hoping that it will drive a significant amount of traffic to fake online scanners. After detecting that a certain web page is actually rogue virus scanner, what do you do next?

Never click on the web page elements, for example "Scan", "Download", etc. Do not click on OK or CANCEL or CLOSE, as the software can easily install itself into your system just by one click. I'm not kidding. Immediately close and quit the web browser if you have sensed that the alert or pop-up is actually rogue software. Another safe way to close the program or pop-up is to use keyboard shortcuts (press Ctrl+Esc). You can also close it by right-clicking on the program in the taskbar and then selecting the close option. Install legitimate security, which can provide real-time protection for your computer. Check on the options and make sure your firewall, anti-malware and antivirus applications are active and fully updated. Remember to keep it up to date!!!

Be sure that you have enabled the phishing protection of your web browser settings. Remember to avoid using file sharing programs to download files such as games, music, shows as most of shared files are infected.

Also, do not click on advertisements, especially on shady websites. Choose the automatic updating option to keep your operating system up to date. Never click on links in email from unknown senders. Read on phishing scams to know what to avoid and how to avoid falling victim to it. Make it a habit of checking the list of rogue security software available online so you could always be on your guard. Avoid visiting unsecured websites, wherein malware may be found.

When installed, Win 7 Security Cleaner Pro pretends to scan your computer for malicious software. Of course, it finds at least twenty possible infections that need you attention and quick actions. The rogue program is designed to scare you into thinking that your computer is infected with unbelievably sophisticated viruses that can delete your files and steal your sensitive information. Of course, that's a complete BS. Do not trust it and do not follow the on screen instructions because if you do then you will probably spend like $100 or so for completely useless antivirus software. And you don't want that, right? :) Oh, and one more thing, Win 7 Security Cleaner Pro blocks genuine malware removal tools. It may also block your web browser and claim that even your local newspaper's website is infected. I mean seriously, it claims that everything is infected, do not do this, don't click there and so on, just buy the freaking full version of this superb antivirus software. What is more, the rogue application displays fake security alerts to further scare you into believing that your machine is infected. Simply ignore them.
Win 7 Security Cleaner Pro Firewall Alert
Win 7 Security Cleaner Pro has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.
OK, so if your computer is infected with this rogue antivirus program things may become a little tricky. If you can, restore your system. First, turn off your computer. Then turn it on in safe mode. Click the START button and go to Programs. Click Accessories. Then click System Tools and select System Restore. Click on the option ‘Restore computer to an earlier time’ and click ‘Next’. Click on a date prior to the time your computer has been infected by the Win 7 Security Cleaner Pro and then click ‘Next’. This procedure will restore your system and should efficiently get rid of the rogue software. Very important! if you choose to remove the scareware this way, download recommend anti-malware software and run a full system scan even if the rogue application seems to be gone. System restore is not the best way to remove malware but it may be the fastest.

However, in case you still encounter troubles removing Win 7 Security Cleaner Pro, please follow the removal instructions below. In short, you can enter one of debugged keys to register the rogue application and then scan your computer with anti-malware software. Why you should register it? When registered, it doesn't block anti-malware software and security related websites. Makes removal a lot easier. If that's not an option for you, you can simply reboot your computer in safe mode with networking and download recommend anti-malware software. It will detect and remove this infection. Finally, you can remove the rogue application manually. For some of you, it actually may be the only working solution.

Do you have any additional information or questions on the Win 7 Security Cleaner Pro virus? Post your comment or question below. Good luck and be safe online!


Method 1: Win 7 Antivirus Pro 2013 removal using debugged activation keys:

1. Use any of the keys listed below to register this malware and stop the fake security alerts.

9443-077673-5028
3425-814615-3990
2233-298080-3424
1147-175591-6550

Just click the Registration button (top right corner of the fake scanner), enter the reg key and then select Activate Now. Don't worry, this is completely legal. If the debugged activation keys do not work anymore, please follow the alternate removal instructions below.

Once this is done, you are free to install recommended anti-malware software and run a full system scan to remove Win 7 Security Cleaner Pro from your computer properly.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.


Method 2: Win 7 Security Cleaner Pro removal instructions in Safe Mode with Networking:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Open Internet Explorer. In the Address bar type: http://goo.gl/AXIrU (this is a download link for FixNCR.reg) and click hit Enter or click Go to download the file.

3. Save FixNCR.reg to your Desktop. Double-click on FixNCR.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.



4. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.

NOTE: don't forget to update anti-malware software before scanning your computer.


Method 3: Manual Win 7 Security Cleaner Pro removal instructions:

Make sure that you can see hidden and operating system protected files in Windows. For more in formation, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmarks from the checkboxes labeled:
  • Hide extensions for know file types
  • Hide protected operating system files
Click OK to save the changes.


1. Go into C:\Users\[UserName]\AppData\Local\ folder.

For example: C:\Users\Michael\AppData\Local\


2. Find hidden executable file(s) in this folder. In our case it was called vkl.exe, but I'm sure that the file name will be different in your case. Rename vkl.exe to vkl.vir and click "Yes" to confirm file rename. Then restart your computer.



3. After a restart, copy all the text in bold below and paste to Notepad.

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

4. Save file as fix.reg to your Desktop. NOTE: (Save as type: All files)


5. Double-click on fix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.

6. Open Internet Explorer. Download exefix.reg and save it to your Desktop. Double-click on exefix.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.

7. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.

Thursday, March 14, 2013

How to Remove 22find

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Not all people are as tech-savvy as those working in Microsoft or Google, and chances are some people don't even understand the difference between an incognito window and a new tab. Unfortunately, some individuals or groups take advantage of this and create malicious or potentially unwanted software that can invade and infect the computers of those who don't know anything about PUPs, browser helper objects and adware, for example 22find. At its core, 22find.com isn't malware. It’s not even adware, but you can easily find many references on the internet, for instance "22find redirect" or "22find browser hijacker", basically claming that it's either a virus or a web browser hijacker. What is 22find?



Think of it this way – imagine yourself as an everyday-kind-of-person who just happens to have a laptop and needs to go online every once and a while to check on emails, post pictures, or chat with people. Now imagine that you saw this advertisement on some website saying that a particular add-on or toolbar would further increase the speed of your Internet browser. Not knowing any better, you have a go at it and download the file anyway. Suddenly on your next internet surf, you notice more and more pop-ups opening on your browser, links leading to paid advertisements and even adult websites suddenly get displayed, and you suddenly notice that you find it difficult to open your frequently visited websites. These are key signs that your browser has already been hijacked.

In case of 22find, it doesn't actually display any ads, at least it didn't at the time I was investigating this software. 22find portal site simply lists the most popular web destinations in one place and also offers Google custom search. I don't really know whether it's convenient or not. Maybe some of you guys think it's convenient but what I know for sure is that many users can't fully remove 22find from their computers. Even though, the core elements can be uninstalled through Control panel, some of its components remain and have to be uninstalled manually. Of course, it's not very difficult but only if you know where to look for the remnant traces. Otherwise, it can be rather challenging. That's why I wrote a comprehensive guide on how to completely uninstall 22find from Chrome, Firefox and Internet Explorer. I really hope it will help you to solve this problem.

Of course, this doesn't mean that all downloadable toolbars for your browser are dangerous—only those being advertised on rarely visited websites and shady-looking pop-ups. PUPs like these browser hijackers often make use of the flaws of a particular web browser’s programming by looking for kinks in the encoding of the program and inserting its own code into the set-up. This allows the hijacker to manipulate what happens on the browser without any manual input from the actual user.

Usually, such browser hijackers comes bundled with freeware, for example this "high performance video player":



The most common signal that tells you your Internet browser has been hijacked is when your homepage suddenly gets changed to something else without you knowing it. In this case it's 22find.com This might not be much of a hassle for most people, but if for example the infected computer is in an office setting, more often than not the time it takes to change the homepage to the desired website every time you go online will decrease worker productivity, and worse, may lead to serious consequences once your boss finds you visiting adult websites at work, even if you never intended to.

Homepage dilemmas are actually the least of your troubles once a browser hijacker infects your computer. Latest versions of the malware, and I'm not talking specifically about 22find, have the ability to analyze your surfing trends and commonly visited websites. Malware then usually block your access to these websites for a time, causing major inconvenience especially when your frequently visited websites are work-related.

Browser hijackers even have the capacity to remove some search results when you look something up using a search engine. This greatly reduces productivity if a certain amount of information is sorely needed. The gravest consequence of getting infected by browser hijackers is definitely stolen information, since some viruses can actually steal some personal information like passwords and credit card numbers from some websites. In the hands of criminals, this information may lead to identity theft, account hacking, fraudulent activity, or worse, financial theft.

It's bad enough if it was just your personal computer affected by this virus, but what more if this had happened in an industrial setting? Think of the inconvenience it would cause to the people involved and how minimal the productivity would be; not to mention the kind of company secrets that could possibly be leaked if information such as passwords were to be obtained by the virus?

There are certain steps to be followed once you feel that your browser has been infected.

First, immediately shut down your browser; this would at least curb the spread of the hijacking somewhat since it doesn’t have enough time to analyze your surfing patter and access valuable information.

Second, download recommend anti-malware program of your choice. Anti-malware programs have the ability to remove the 22find hijacker from your computer when you get the chance to actually scan your entire system for malware.

Third, once the scan is complete and it detects some software toolbars or add-ons that do not look familiar to you, delete them at once. This can prevent further spread of the virus to other clean browsers that you may have on your computer.

Lastly, and this is for preventive purposes, make sure to invest in commercial anti-virus software that come with anti-malware or anti-spyware capabilities. These commercial - to industrial - grade anti-viruses may come as very expensive and actually have expiration dates that usually lasts for just a year, but these are investments that are definitely worth the extra time and effort, since these can prevent future attacks, not just by browser hijackers, but also by other malicious content scattered throughout the internet. But of course, the cheapest kind of protection would always be vigilance, never open shady websites and pop-ups, and make it a habit to regularly scan your computer for possible viruses and parasites.

22find removal instructions are outlined below. Please follow them very carefully. Do you have any additional information or questions on the 22find.com? Post your comment or question below. Good luck and be safe online!


22find removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Remove 22find and related programs from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove CheckRun22find_uninstaller:



Simply select the application and click Remove. If you are using Windows Vista, Windows 7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove 22find from Google Chrome:

1. Click on Customize and control Google Chrome icon. Go to Tools → Settings.




2. Click Set pages under the On startup.


Remove 22Find Portal Site by clicking the "X" mark as shown in the image below.



3. Click Show Home button under Appearance. Then click Change.



Select Use the New Tab page and click OK to save changes.



4. Click Manager search engines button under Search.



Select Google or any other search engine you like from the list and make it your default search engine provider.



Select 22find from the list and remove it by clicking the "X" mark as shown in the image below.



5. Click on Customize and control Google Chrome icon. Go to Tools → Extensions.

6. Select 22find and click on the small recycle bin icon to remove the extension.



7. Right-click the Google Chrome shortcut you are using to open your web browser and select Properties.

8. Select Shortcut tab and remove "22find.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Chrome executable file. Nothing more.




Remove 22find from Mozilla Firefox:

1. Open Mozilla Firefox. Go to Tools → Add-ons.



2. Select Extensions. Remove 22find extension. Close the window.



3. Click on the 22find search icon as shown in the image below and select Manage Search Engines....



4. Choose 22find from the list and click Remove to remove it. Click OK to save changes.



5. In the URL address bar, type about:config and hit Enter.



Click I'll be careful, I promise! to continue.



In the search filter at the top, type: 22find



Now, you should see all the preferences that were changed by 22find. Right-click on the preference and select Reset to restore default value. Reset all found preferences!




6. Right-click the Mozilla Firefox shortcut you are using to open your web browser and select Properties.

7. Select Shortcut tab and remove "22find.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Firefox executable file.




Remove 22find in Internet Explorer:

1. Open Internet Explorer. Go to Tools → Manage Add-ons.



2. Select Search Providers. First of all, choose Live Search search engine and make it your default web search provider (Set as default).



3. Select 22find and click Remove to remove it. Close the window.



4. Right-click the Internet Explorershortcut you are using to open your web browser and select Properties.

5. Select Shortcut tab and remove "22find.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Internet Explorer executable file.


Share this information:

Sunday, March 10, 2013

How to Remove Disk Antivirus Professional (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Disk Antivirus Professional is a rogue application that passes itself as real and top-notch antivirus software. Most computer users are aware of the importance of real security software. A good one, which can prevent hackers from stealing important information and protecting against viruses and malicious software. This one, however, won't make your computer safer and it's far far away from what you could call a decent security product. It mainly targets computer users in the United States and UK. However, over the past 6 years or so, rogueware attacks have been reported in many countries around the word and this particular malware isn't different - it may be and probably is promoted in other countries as well.



Due to the necessity of security software for every user, cyber crooks have attempted to utilize that for their own benefit. By offering consumers fake security software that is faulty or carrying malware, cyber crooks are able to make money. This lucrative scam commonly targets less computer savvy users who willingly spend hundreds of dollars for programs that report non-existent infections and literally do nothing to protect your computer.

In addition to charging money, the software can also infect computers with more sophisticated malware, for instance, rootkits and Trojans. A Google study in 2010 suggested that rogue security software is responsible for 15 percent of the total malware detected that year. The good news is, the numbers are going down third year in a row but rogue security applications are still overwhelming genuine malware scanners.

Disk Antivirus Professional is promoted mostly through fake online malware scanners, infected websites and weakly protected ad networks that serve malicious advertisements. Pop-ups stating that your computeris infected with viruses, encouraging you to "clean" the system using their software. Also, scammers manipulate online rankings putting infected websites on top hits when you visit search engines. The link then redirects victims to fake online scanners, later claiming that your machine is infected and suggest a free trial of their anti-virus rouge security program or a quick fix. Of course, we shouldn't forget spam. Spam emails offer fake security programs, suggesting people to click on the link to download antivirus software.

Once installed, the rogue application will pretend to scan your computer for malware. Obviously, it will detect at least 20 or 30 Trojans and other malware on your computer, even if you know for sure that the system was perfectly clean before this darn thing showed up. On the other hand, it might fail to detect real viruses in case your PC gets infected. So, one way or another, Disk Antivirus Professional is nothing more but a scam. You may already know, that sometimes upon downloading rogue security software, it Trojan droppers install viruses or other forms of malicious software on your PC so that the rogue security program will have something to detect. This isn't the case, though.

When running, Disk Antivirus Professional will display fake security alerts and pop-ups to further scare you into thinking that your computer is infected. Remember, its goal is to trick you into paying for rogue software. There are at lease 5 or 6 nicely designed but totally fake security alerts that may indeed trick less computer savvy users.




Disk Antivirus Professional Warning
Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs.
Click here to remove it immediately with Disk Antivirus Professional.


What is more, the rogue application will block pretty much everything on the infected computer. You can't download malware removal tools and you can't use your own antivirus software. You can't even use Task Manager to close rogue application.


Warning!
Application cannot be executed. The file taskmgr.exe infected.
Please activate your antivirus software.
But there's one thing that puts a huge smile on my face - for some strange reasons it blocks everything except Internet Explorer. Seriously, scammers probably think that IE so insignificant that it's not even worth blocking it. Of course, I'm just kidding. The rogue application doesn't work that way, but still it's kinda funny to see such mistakes.

One of the best ways to protect yourself the ability to know the difference between legitimate and fake security warnings. If you receive a shady pop-up, immediately close the browser window. Note, there are erroneous ways of closing the browser window. Sometimes, a fraudulent security warning could present a button or hyperlink labeled "Close", when clicked, executes another function instead of closing the browser window.

Make sure that your computer software is always up to date. Other rogue security software might not present itself as a fake security warning, but instead try to exploit vulnerabilities in common software. Adobe Flash, Adobe Reader, and Java are usual targets in these scenarios. A web-based tool developed by the Information Security Office allows people to check their browser version, ensuring that they are kept up to date.

Be mindful of phishing scams. There are times when a phishing email or site may be utilized to lure you into installing rogue security software.

Be alert with unexpected prompts of software download during website visits. A majority of software providers such as Adobe, Microsoft, Mozilla, and Symantec among others include the functional update within their products. If you feel in doubt, close the unexpected prompt. Check for updates via software built-in functionality.

Always buy original software. Security software is an important program, so make sure that you are buying from a legitimate source or even better, official site. Please note that this is an investment. Verify that you are purchasing the product from their authentic website. In addition, contact the customer service in case you have any questions.

Last but not the least, avoid phishing scams that encourage people to click on links from unauthorized senders in emails. Do not attempt to download from popups that tell you to download a certain program, no matter how scary and convincing they look. From now on, be more aware about possible malware that can hit your computer. Remember, prevention is always better than cure!

Ok, so you know the basic principles how to protect your computer from possible rogueware attacks. If you are reading this article, your computer might be already infected. But don't worry, bellow you will find a step-by-step guide on how to remove Disk Antivirus Professional from your computer. Three possible methods that hopefully will help you remove this malware for good.

Do you have any additional information or questions on the Disk Antivirus Professional virus removal? Post your comment or question below. Good luck and be safe online!


Disk Antivirus Professional removal in Safe Mode with Networking:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





NOTE: if you can't run anti-malware software, rename the installer to iexplore.exe and try again.


Disk Antivirus Professional removal guide using debugged registration key:

1. Open Disk Antivirus Professional scanner. Click the "Registration" button (top right corner).



Enter the following debugged registration key and click "Activate" to register the rogue antivirus program. Don't worry, this is completely legal since it's not genuine software.

AA39754E-715219CE




Once this is done, you are free to install recommended anti-malware software and remove Disk Antivirus Professional from your computer properly.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





NOTE: if you can't run anti-malware software, rename the installer to iexplore.exe and try again.


Disk Antivirus Professional manual removal guide:

1. First of all, go to your Desktop and right click the Disk Antivirus Professional.lnk shortcut file and select Properties.



2. Select Shortcut tab. Find the location of Disk Antivirus Professional executable file (target location). It should be a randomly named file. Simply click the Find Target button.



3. Browser to the executable file. Rename it, for instance to virus.exe. Restart Windows.



4. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





NOTE: if you can't run anti-malware software, rename the installer to iexplore.exe and try again.


Associated Disk Antivirus Professional files and registry values:

Files:

Windows XP:
  • C:\Documents and Settings\All Users\Application Data\[SET OF RANDOM CHARACTERS]\
  • %UserProfile%\Desktop\Disk Antivirus Professional.lnk
  • %UserProfile%\Start Menu\Programs\Disk Antivirus Professional\
Windows Vista/7:
  • C:\ProgramData\[SET OF RANDOM CHARACTERS]\
  • %UserProfile%\Desktop\Disk Antivirus Professional.lnk
  • %UserProfile%\Start Menu\Programs\Disk Antivirus Professional\
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Disk Antivirus Professional\

Wednesday, March 6, 2013

Know the Enemy – Identifying & Removing the FBI Virus

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
What is the FBI Virus?

Also known as Reveton ransomware, the FBI virus is a form of malware - malicious software that criminals install on your computer without your consent. It provides criminals with the ability to freeze your computer from a remote location. Your computer screen is then filled with a pop-up window displaying a warning that your computer is locked by a local law enforcement agency, such as the FBI or Metropolitan Police, please read how to remove FBI Moneypak virus.

It demands that you pay a fine, claiming that you and your computer have been involved in illegal activities, such as the downloading and sharing of copyrighted files. New versions of the virus can activate your webcam and take a picture of you to display alongside the warning. Some versions now contain a dynamic configuration module which allows the hacker real time control of your browser. They can use this to create interactive pop-up boxes and responsive forms that request further personal information, such as your bank details and date of birth.




How does the FBI Virus work?

The main strategy behind the FBI virus is scare tactics and holding the victim’s computer to ransom. By persuading the victim that they are in serious trouble with the authorities the attackers hope to gain not just a one off payment but also intimidate the victim into providing payment details and other personal information. If the victim does comply and pays the fine as requested, this does not mean that the virus will be removed– the lock out screen may remain or the virus may appear to be removed but instead go into hiding and exploit other vulnerabilities using a wide range of malicious tactics.

It may be easy to assume as a knowledgeable, and security conscious, computer user that you would immediately identify this as a virus and not fall prey to ransomware. However the screenshots and tales circulating the internet show this to be convincing and threatening. By displaying an image of the victim on their screen or creating responsive pop-up boxes it becomes even more intrusive and damaging than simply locking the victim out of their computer. Even if the victim is aware that this was a scam, and not actually the FBI, the feeling of a hacker having control of your computer, capturing an image of you using your own technology and live communicating with you through a pop-up box could be considered akin to a burglar physically breaking into your home.

Detecting Infection

The FBI virus is usually installed when you click on a malicious attachment in an email or when you click on a malicious link in an instant message, email or a message on a social networking site. It could even be installed when you unknowingly pay a visit to a malicious website. When your computer becomes infected with the virus, your personal material and computer system’s functionality are put at risk. If your infected computer is switched on and connected to the Internet, the virus will have complete control over your computer and all of the data stored on it.

In addition to presenting you with an “official” warning on your frozen computer system, the FBI virus is likely to bring less obvious malware. It has been reported by the, genuine, FBI that Reveton malware is being combined with Citadel, an advanced and powerful malware that is particularly difficult to remove. If you believe that your computer has been infected by a malicious program, you should run a full system scan using trusted antivirus software.

Removing the FBI Virus

To remove the FBI virus and other types of malicious software that may be installed on your computer, you will need to have an up-to-date antivirus program on your computer. While it may be possible for you to manually remove the FBI virus, and there are several sites including this one which provide instructions on how to do this, this could result in permanent damage to your system, particularly if you are not completely confident in how to go about this.

Thus, manually removing the FBI virus is only recommended if you are confident in your ability and willing to sacrifice everything should it go wrong. For the majority of cases total removal of the FBI virus, and possibly Citadel malware, requires reinstalling your operating system from a rescue disc or master boot record. Hopefully you will be have been vigilant in your scheduled data backups and won’t suffer too much loss. It is important to remember that this virus, or any form of ransomware or malware, could have gained access to your passwords. Once you have successfully cleared your computer of infection you should ensure your accounts have not been compromised and change all passwords to something completely new, unique and, hopefully, uncrack-able. If you don't know how to create a strong password, please read this article.

Preventing FBI Virus Infection

As we all know the best cure for anything is prevention. In order to prevent infection from the FBI virus or any other form of malware, it is advised to avoid clicking on links to suspicious websites, opening spam email messages, visiting adult websites or downloading and using pirated software. It is also strongly recommended to install a reputable antivirus program, such as Kaspersky, on all your internet-enabled devices. Take the time to make a rescue disc or USB drive; you never know when you might need it.

 
//PART 2