Sunday, May 30, 2010

How to remove Security Master AV (Uninstall Instructions)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Security Master AV is a fake anti-virus program that uses misleading methods to make you think that your computer is infected with malicious software. First, it displays fake security warnings and claims that malicious software has been detected on your computer. Then, it runs a fake system scan and displays a list of infected files. Of course, the scan results are false. Security Master AV flags harmless files as malware. It may also list Windows system files in its scan report, so don't manually delete any of those files. Finally, the rogue program will prompt you to pay for a full version of the program to remove the infections. It goes without saying that you shouldn't purchase it. Instead, please remove Security Master AV from your computer as soon as possible using the removal instructions below.



You may ask, where did it come from? Usually, such bogus programs come from fake online scanners and fake video websites sites or you may simply click an infected advertisement. Security Master AV can come bundled with other malware, but this is less common situation. By the way, the rogue program has to be manually installed, but the problem is that it pretends to be a legitimate program, that's why some users don't understand that it's actually a Trojan or other malware. Once installed, Security Master AV will display fake security alerts. Some of those alerts or pop-ups read:

"System alert
Potentially harmful programs have been detected in your
system and need to be dealt with immediately. Click here to
remove them using Security Master AV."


"System alert
Suspicious software which may be malicious has been detected on your PC. Click here to remove this threat immediately using Security Master AV."



Furthermore, this fake program hijacks Internet Explorer and changes default search engine to findgala.com. It blocks security related websites, modifies Windows Hosts file and blocks legitimate anti-malware programs. Thankfully, we've got remove instructions to help you. It's possible to remove Security Master AV manually, but we strongly recommend you to scan your PC with reputable and legitimate anti-malware software. Please follow the removal instructions below. And by the way, if you have already purchased SecurityMasterAV, then you should contact your credit card company and dispute the charges. Also, if you have any questions or additional information about this virus, please leave a comment. Good luck and be safe!


Security Master AV removal instructions using HijackThis (in Normal mode):

1. Download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it.

2. Search for similar entries in the scan results:
O4 - HKCU\..\Run: [Security Master AV] "C:\Documents and Settings\All Users\Application Data\345d567\SM345d.exe" /s /d
Select all similar entries and click once on the "Fix checked" button. Close HijackThis tool.

3. Download at least one anti-malware program from the list below and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to winlogon.exe or iexplore.exe. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.


Security Master AV removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

3. Download at least one anti-malware program from the list below and run a full system scan.
NOTE: before saving the selected program onto your computer, please rename the installer to winlogon.exe or iexplore.exe. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.
4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Security Master AV associated files and registry values:

Files:
  • C:\Documents and Settings\All Users\Application Data\345d567\
  • C:\Documents and Settings\All Users\Application Data\345d567\16.mof
  • C:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll
  • C:\Documents and Settings\All Users\Application Data\345d567\SM345d.exe
  • C:\Documents and Settings\All Users\Application Data\345d567\SMAV.ico
  • C:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll
  • C:\Documents and Settings\All Users\Application Data\345d567\Quarantine Items\
  • C:\Documents and Settings\All Users\Application Data\345d567\SMAVSys\
  • C:\Documents and Settings\All Users\Application Data\345d567\SMAVSys\vd952342.bd
  • C:\Documents and Settings\All Users\Application Data\SMNPCTCAV\
  • %UserProfile%\Start Menu\Security Master AV.lnk
  • %UserProfile%\Start Menu\Programs\Security Master AV.lnk
Registry values:
  • HKEY_CURRENT_USER\Software\3
  • HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKEY_CLASSES_ROOT\SM345d.DocHostUIHandler
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}"
  • HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Security Master AV"
  • HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
Share this information with other people: 

Tuesday, May 25, 2010

How to remove XJR Antivirus (Uninstall Instructions)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
XJR Antivirus is a fake anti-virus program from the same family as AKM Antivirus 2010 Pro. Once installed, it will give false or exaggerated reports of threats on your computer and then will prompt you to pay for a full version of the program to remove the infections and to protect your PC from other malware. The rogue program is promoted through the use of Trojan Horses and other malicious software. Very often, Internet users download such bogus programs from fake online anti-malware scanners and misleading video websites. If you are reading this article, then your computer is probably infected with this fake and very annoying antivirus program. The good news is that it can be completely removed from your computer using legit anti-malware software. Please follow the removal instructions below to remove XJR Antivirus and any related malware for free.



While running, XJRAntivirus will display fake security warnings claiming that somebody is trying to attack your PC or that malicious software may steal your passwords and other sensitive information. Moreover, this scareware will block legit anti-virus and anti-malware programs. It will state that your antivirus program is infected and should be uninstalled or cleaned. Besides, the rogue program blocks other tools and programs as well, such as notepad, task manager, MS Word and etc.



It also displays fake svchost.exe error screen and impersonates Windows Security Center.



Some of the fake security alerts read:

"Security Warning
Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer.
Clear here to clean your PC immediately."


"svchost.exe
svchost.exe has encountered a problem and needs to
close. We are sorry for inconvenience."


"Warning!
Running of application is impossible.
The file C:\Windows\System32\notepad.exe is infected.
Please activate your antivirus program."



As you can see, XJR Antivirus is absolutely needless software that should be removed from your computer as soon as possible. It's nothing more but a scam, so obviously you shouldn't buy it. If you have already bought this fake program, then contact your credit card company and dispute the charges. If you have any questions or additional information about this virus please leave a comment. Good luck and be safe!


XJR Antivirus removal instructions:

Method #1
1. Go to Start->Run or press WinKey+R. Type in "command" and press Enter key.


2. In the command prompt window type "notepad". Notepad will come up.


3. Copy all the text in blue color below and paste into Notepad.

Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

4. Save file as regfix.reg to your Desktop. NOTE: (Save as type: All files)


5. Double-click on regfix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.
6. Download one of the following anti-malware applications:
7. Install the selected application, update it an run a system scan.
8. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.

Method #2
1. Use another computer and download one of the anti-malware applications listed above (Method #1, step 6),
2. Create fix.reg file as said in Method #1 (steps 1-4). Copy an anti-malware application and fix.reg file to USB flash drive or any other removable device and transfer those files to the infected computer.
3. First of all run the fix.reg file. Then install the anti-malware application, update it and run a full system scan.
4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Manual removal:

Associated XJR Antivirus files:
  • C:\Program Files\XJR Antivirus
  • C:\Program Files\XJR Antivirus\XJR Antivirus.exe
  • C:\Program Files\adc_w32.dll
  • C:\Program Files\alggui.exe
  • C:\Program Files\nuar.old
  • C:\Program Files\skynet.dat
  • C:\Program Files\svchost.exe
  • C:\Program Files\wp3.dat
  • C:\Program Files\wp4.dat
  • C:\Program Files\wpp.exe
  • %UserProfile%\Local Settings\Temp\win1.tmp
  • %UserProfile%\Local Settings\Temp\win2.tmp
Associated XJR Antivirus registry values:
  • HKEY_CURRENT_USER\Software\XJR Antivirus
  • HKEY_CLASSES_ROOT\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
Share this information with other people: 

Saturday, May 22, 2010

How to remove Windows activation ransomware (Uninstall guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Today we want to draw you attention to a new piece of Windows activation ransomware that locks up your system and prompts you to enter your billing details and credit card information to re-activate your copy of Windows. Basically, it's a Trojan virus that displays a fake pop-up (which looks quite legitimately by the way) and claims that you are running a pirated version of Windows. Of course that's not true. If you choose to activate Windows later, your computer reboots. Thankfully, we've got removal instructions to help you. This Windows activation ransomware can be removed from your computer for free using legit anti-malware programs. Please follow the removal instructions below.



The text of the fake Windows activation pop-up:
"Microsoft Windows Activation
Microsoft Piracy Control


Your copy of Windows was activated by another user. To help reduce software piracy, please re-activate your copy of Windows now. We will ask for your billing details, but your credit card will NOT be charged. You must activate Windows before you can continue to use it. Microsoft is committed to your privacy. For more information, www.microsoft.com/privacy.


Do you want to activate Windows now?"

And it should be obvious that you shouldn't submit your credit card information because it can be used for identity theft or your credit card can be charged for an unknown amount of money. Either way, that sounds bad, right? In order to remove the Fake Windows Activation or Microsoft Piracy Control screen you need to reboot your computer is Safe Mode with Networking and either remove the ransomware manually or download and scan your PC with reputable and legit anti-malware software. Most importantly, don't submit your credit card information! If you have any questions or additional information about this ransomware, please leave a comment. Good luck and be safe!


Windows activation ransomware removal instructions:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download and scan your computer with at least one anti-malware program listed below:
NOTE: before saving the selected program onto your computer, please rename the installer to winlogon.exe or iexplore.exe. Launch the program and follow the prompts. Don't forget to update the installed program before scanning. Then reboot your computer in "Normal Mode" and run  a system scan again. That's it!


Windows activation ransomware associated files and registry values:

Files:
  • C:\WINDOWS\system32\.exe
  • %UserProfile%\Application Data\mtl.dll
Registry:

  • HKEY_CURRENT_USER\Software\AntiPiracy
  • HKEY_CURRENT_USER\Software\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
Please share this information with other people:

Avoid Livesecsuite.com, live-sec-suite.com(Free removal)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Yesterday we posted a quick note about livesecuritysuite.com scam. Today we came with even more misleading websites that promote the rogue anti-spyware program called Live Security Suite. here they are:
  • livesecsuite.com (62.122.73.76)
  • live-sec-suite.com (62.122.74.249)
  • live-security-suite.com (193.169.235.61)
Please add the websites (IPs) listed above the the list of potentially harmful and risky websites. All those websites use the same web template and provide false information with fake awards. Livesecsuite.com, live-sec-suite.com and live-security-suite.com may host malicious software. If you find that your computer is infected with Live Security Suite, please follow Live Security Suite removal instructions. If you are being constantly redirected to one of those websites, then you should scan your computer with reputable and legit anti-malware programs. If you have any questions or additional information about this infection, please leave a comment. Good luck and be safe!



Share this information with other people:

Sunday, May 16, 2010

Remove Livesecuritysuite.com (Free removal)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Livesecuritysuite.com is a misleading website that provides false information and displays fake awards related to Live Security Suite scareware. It hosts the rogue program as well, but the download link isn't active if you visit livesecuritysuite.com directly. Anyway, it's a risky website and it should be added to the list of potentially harmful sites. As you can see in the image below, the scammers use well known Microsoft Windows logo, colors and overall design of Microsoft websites to make it look more reputable.

Most importantly, don't install anything from livesecuritysuite.com. Just don't trust it. However, if you find that your computer is already infected with livesecuritysuite.com hijacker or Live Security Suite malware, then you should scan your computer with reputable anti-malware program as soon as possible. For more information please read Live Security Suite removal instructions. You will find out how to remove livesecuritysuite.com and Live Security Suite from your computer for free using legitimate anti-malware programs. If you have any questions or additional information about this malware, please don't hesitate and leave a comment. Good luck and be safe!

Screenshot of Livesecuritysuite.com


Share this information with other people:

 
//PART 2