Thursday, April 12, 2012

Fake Windows Antivirus 2012 (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Windows Antivirus 2012 has found critical process activity on your PC and will perform fast scan of system files! -- if a dialog box comes up with something similar, please do not click on anything and leave the web page immediately. It's a part of blackhat SEO attack that leads users to fake virus scanners. Social engineering and black hat SEO attacks are still very popular even though the volume of successfully executed attacks has decreased significantly during the last six months. Reputable security products use URL filtering and generic detections for certain components of well thought search engine optimization attacks, but it seems that cyber crooks have found other ways to game the search engines (anti-spam teams). Fake online virus scanners are back and kickin'.





Rogue anti-virus programs from the FakeVimes family are being installed at the time of writing. It's one of the most widely spread scareware for a couple of months now. The problem with fake virus scanners is that only few AV programs will actually catch them. Very often such attacks defeat even the most determined users, who will allow rogueware to be installed on their machines no matter how much you teach them. Besides, cyber crooks are constantly looking for improvements that will increase conversion rates. A security message from Windows Antivirus 2012 seems quite legit and confusing at the same time, isn't it? People might think is a genuine Windows warning. Also, most of us tend to trust search engines results. When we get a security warning from a web page that is listed on the first page of results, we think that something is definitely not right because Google or any other popular search engine wouldn't allow misleading websites to show up in the search results in the first place. Unfortunately, this is not always the case.

Fake Windows Antivirus 2012 scanner claims that your computer is infected with malicious software. It randomly displays infections supposedly found during the scan, which is by the super fast :) The truth be told, it doesn't scan your PC for malware. It's just a simple javascript file that displays nice graphics and scan animation to scare you. Don't download or install anything from such websites. Close the fake scanner immediately and run a full system scan with up to date antivirus software to be sure that your computer is clean. If you have any questions, please leave a comment below. Good luck and be safe online!

Tell your friends:

Wednesday, April 11, 2012

Remove Happili Redirect Virus (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Although the growth of browser (search results) redirects associated with rootkits and orther malware has been declining quite rapidly since the middle of last year (except for a few spikes during holidays) many people are still having issues with the 'redirect virus'. That's how many of you would call it. It's an evergreen niche, sort of... Recently, my aunt contracted a virus that was redirecting every search she did to Happili.com. Obviously, she wasn't happy about that :) She had it among other redirect and ads. This is a very common problem faced by thousands of pc users every day. Occasionally when you search on Google or any other web search engine for that matter and then click a search result you get redirected to a website full of ads or even worse - malicious code. Sometimes, you may get the 404 not found web server error when you click a search result. This happens when malware authors add new domains but their malicious code still redirects users to old websites. Most of the incidents reported by our readers during the last couple of weeks were one way or another associated with websites called Gimmeanswer and Happili.



Happili redirect virus or whatever you may call it, is just another domain/site involved in malicious scheme when cyber criminals earn more every time affected user clicks the ad or installs affiliated software. Usually, cyber crooks change domain names every few weeks or so but I've seen some domains that are used to distribute malware for at least a couple of months and they are still active. It might be that these domains are accepted by certain companies that monetize parked domains. Cyber crooks increase traffic using malicious software and infected computers and at the same time earn some nice money while displaying paid ads. However, this is probably not the case.



Even thought, the URL says happili.com, the rootkit loads content from entirely different website - x2838954xc(dot)com.



ZAccess/Sirefef rootkit creates a new Windows services called DCamUSBDXGT [symmpi].



Removing Happili virus is not an easy task, unfortunately. It has nothing to do with your web browser. Happili.com as well as many other redirects are very often caused by rather sophisticated malware called ZeroAccess or Sirefef. The problem is that this rootkit cannot be removed with popular anti-spyware software, e.g. Malwarebytes' Anti-malware. It may however remove associated malware from the infected computer, trojan droppers, etc. If you want to get rid of ZeroAccess rootkit and stop annoying redirects you need to use removal tools designed to remove this specific infection.

TDSSKiller by Kaspersly is probably the most popular but other antivirus software companies have ZAccess removal tools as well. Besides, sometimes TDSSKiller fails to remove infected files from the system, so it's always a good idea to use alternate removal tools just to be sure that your PC is perfectly clean and the that virus was successfully removed. AVG Win32/ZeroAccess remover removes most of the ZAccess/Sirefef variants but very often fails to remove newly released samples. Symantec offers ZeroAccess Fix Tool 1.0.0 which detects and removes this infection but may not work with the latest variants of the roorkit. It cleans the .sys file but not the malicious module, so once you restart your computer, the rootkit patches new drivers. I'm not saying that these utilities are useless but Panda, BitDefender and Webroot offer removal tools that worked for me almost every single time when I was dealing with the ZeroAccess rootkit. So, I definitely recommend scanning your computer with these great utilities before running your favorite anti-malware software. Please note that certain variants of this rootkit blocks legit anti-malware software and security related websites.

Panda ZeroAccess/Sirefef remover: http://www.pandasecurity.com/usa/homeusers/support/card?id=1672&idIdioma=2

BitDefender ZeroAccess removal tool: http://www.malwarecity.com/community/index.php?app=downloads&showfile=34

To remove the remnants of Happili virus from your computer you should run a full system scan with updated anti-malware software. Also, you should check your LAN settings, make sure that your internet settings are set up correctly, flush DNS cache and make sure that Windows Hosts file was not modified. For more more details, please read this removal guide. If you have any questions or need assistance removing this malware from your computer, please leave a comment below. Good luck and be safe online!


Happili virus removal instructions:

1. First of all, download and run TDSSKiller by Kaspersky. This utility will remove malicious .dlls and infected memory modules.

2. Then download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove the remnants of this virus from your computer. Don't forget to update anti-malware software before scanning.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts.


Happili virus removal instructions for Mac users:

1. Update Java to remove the most common variants of the Flashback malware which causes Happili.com redirection. Learn more: http://support.apple.com/kb/HT5242

2. Download and run Flashback Removal Tool to remove the remnants of Flashback malware.

3. Reset Safari settings. Click on the Reset Safari option under the Safari menu.


Tell your friends:

Wednesday, April 4, 2012

Removing Advanced Antispyware Solution (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
If you are a regular visitor to our blog you probably noticed that the last few weeks had been a bit slow compared to the previous months. This is mostly due that we have been working on other projects. Besides, the volume of actively spread rogue security products has decreased significantly over the past few weeks, at least in some regions, which is a good thing after all. However, malware authors will probably exploit Easter just like any other special event to send out rogue security programs and other malicious software. Malware may show up in Easter greeting cards and images, so please be very cautious when downloading and opening Easter greeting cards, especially this weekend. Cyber crooks are already distributing new rogue security programs and will probably double the number of new malware samples this weekend.



Ok, so today we are looking at a new rogue security program called Advanced Antispyware Solution. As far as we can tell, this rogue security program is being delivered through Twitter spam messages that lead to fake Windows Antivirus 2012 online scanners. All the domains that were found distributing this malware had .info TLDs. Some of the popular registrars offered .info domains for under $5 or less, so cyber crooks apparently bought lots of .info domains as well.

Advanced Antispyware Solution reports non-existent malware infections and displays lost of fake and very annoying security alerts to make you think that your computer is infected. All the rogue applications from the FakeVimes family, we've seen more than ten this year so far, share common characteristics. Once installed, Advanced Antispyware Solution drops several absolutely harmless files on the compromised computer. The rogue program later pretends to scan the compromised computer for malware and once the 'scan' is finished, it flags those files as dangerous. A funny things is that this rogue anti-spyware drops and detects exactly the same files on each and every compromised machine.

Fake security alerts are rather well designed and may look like a real thing for unsuspecting computer users despite the fact people are being exposed to technology like never before. Here are some of the fake security alerts you may see when your computer is infected with Advanced Antispyware Solution scareware:





What is more, this malware may block Windows system utilities and genuine malware removal tools. Some variants of this malware may modify Windows host file and redirect users to misleading websites. We will show you how to restore the Windows Host file in the removal guide below. You should scan your computer for rootkits as well, because removing Advanced Antispyware Solution won't help you much if you won't get rid of rootkits. You can remove this rogue anti-spyware program using legit anti-malware software recommended in the removal guide below. Follow the steps in the removal guide very carefully. If you need help removing this malware from your computer, please leave a comment. Good luck and be safe online!


Advanced Antispyware Solution removal guide:

1. Click on Help and select Activate Now.



2. Enter one the following debugged registration keys and click Activate to register the rogue antivirus program. Don't worry, this is completely legal since it's not genuine software.

U2FD-S2LA-H4KA-UEPB
K7LY-H4KA-SI9D-U2FD
K7LY-R5GU-SI9D-EVFB



2. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this malware from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.

Source: http://spywareremovalx.blogspot.com


Associated Advanced Antispyware Solution files and registry values:

Files:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]\
  • %AppData%\Advanced Antispyware Solution\
  • %AppData%\Microsoft\Internet Explorer\Quick Launch\Advanced Antispyware Solution.lnk
  • %UserProfile%\Desktop\Advanced Antispyware Solution\
  • %UserProfile%\Start Menu\Advanced Antispyware Solution\
  • %UserProfile%\Start Menu\Programs\Advanced Antispyware Solution.lnk
Registry values:
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\Advanced Antispyware Solution = "%AllUsersProfile%\Application Data\34g561\AV62c_8538.exe" /s /d
  • HKEY_CURRENT_USER\software\3
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\[RANDOM].exe\Debugger = svchost.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun = 01000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\[1...15]
Tell your friends:

Thursday, March 29, 2012

Emsisoft Giveaways And Deals

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Emsisoft Easter Offer: 3 licenses for the price of 1

The Easter Bunny comes to town and brings some great presents for you: two additional free licenses with every purchase of an Emsisoft full version license. Even of you don't need additional licenses, you can share them with your family and friends. Help them to fully secure their computers and save some extra bucks. Who knows, maybe they will buy you a chocolate rabbit in return ;)

Emsisoft Internet Security Pack: https://shop.emsisoft.com/34/?scope=checkout&product=40106

Emsisoft Anti-Malware: https://shop.emsisoft.com/34/?scope=checkout&product=2414

Emsisoft Online Armor Firewall: https://shop.emsisoft.com/34/?scope=checkout&product=36640

This offers lasts until April 9th, 2012 and only applies to new purchases of 1-year licenses. No renewals. Besides, you need to you those free licenses within two months after date of purchasel otherwise, they will expire.

Tell your friends:

GFI VIPRE Giveaways And Deals

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
50% Off VIPRE Antivirus 2012 and VIPRE Internet Security 2012

Receive a 50% discount on VIPRE Antivirus 2012 or VIPRE Internet Security 2012 license (expired trial). Hurry up because this is a limited-time offer, valid until April 15th, 2012. If your trial license is about to expire and you're planning to extend it, this is a great chance to save some extra bucks. Personally, I don't use any of their products but I can assure you that GFI does a great job protecting computers from the latest malware attacks.

For more details, please visit http://www.vipreantivirus.com/promos/expired-trial-offer/

Tell your friends:

 
//PART 2