Archive for December, 2009

Malware Defense virus removal guide

Saturday, December 26th, 2009



Malware Defense is a fake antivirus program from the same family as AntiMalware virus. Please read the removal instructions carefully and remove this infection from your computer as soon as possible. MalwareDefense is promoted through the use of Trojans, mostly Trojan.FakeAlert. Most of the time, Trojans come from fake online scanners, misleading websites or masquerading as a fake video codec. Please note that Trojans can come bundled with other illegitimate software. Once installed, Malware Defense will generate fake alerts or notifications and report false detections in order to convince you to purchase this bogus anti-virus software. Please don’t purchase it. Otherwise, you will simply lose your money.

When running, Malware Defense will simulate a system scan and display a list of infections that can’t be removed with a trial version of this program. In order to remove found infections you have to buy a full version of it. However, this is nothing more but a scam. Let’s see why. First of all, MalwareDefense reports non-existing or legitimate Windows files as infections. Do not remove those files manually because you can seriously damage your computer. Some of the infections will be shown with the following names: Backdoor.Win32.Agent.ich, Rootkit.Win32.Agent.pp, Trojan.Dropper, Virus.Win32.Gpcode.ak, Email-Worm.Win32.NetSky.q, Net-Worm.Win32.Mytob.t and etc. Usually, Malware Defense detects those infections in main Windows OS directories. Of course, this malicious software detects the same infections on every infected computer.

While running, Malware Defense will also display fake security alerts, notifications and error messages. This is a part of MalwareDefense scam. This virus will block particular software and display fake warning that states:

There is unauthorized antivirus software detected on your computer. It is recommend you to remove it, otherwise it could conflict with Malware Defense. Press ‘OK’ to terminate [Program name]


Malware Defense manual removal:
Kill processes:
mdefense.exe uninstall.exe

Delete registry values:
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Malware Defense”

Unregister DLLs:
mdext.dll

Delete files:
mdefense.exe mdext.dll uninstall.exe help.ico md.db Malware Defense Support.lnk Malware Defense.lnk Uninstall Malware Defense.lnk

Delete directories:
C:\Program Files\Malware Defense
%UserProfile%\Start Menu\Programs\Malware Defense


Download
Super Anti Spyware
OR

Download
Malware Bytes Anti-Malware


Personal Security virus removal guide

Saturday, December 26th, 2009



Remove Fake PersonalSecurity center rogue spyware
Personal Security is a rogue anti-spyware program from the same family as Cyber Security. This program is promoted through the use of malware that will install it on your computer without your permission. In order to protect itself, this program will automatically attempt to terminate security programs that may help to remove it. When installed, Personal Security will be configured to start automatically when Windows starts. Once started, it will scan your computer and display a variety of infections, but will state that it will not remove them unless you first purchase the program. In reality, the infections it finds are either fake or legitimate programs that if deleted could cause problems with the proper operation of Windows. Therefore, please do not act upon any of the files it states are infections.

Personal Security reports regular programs as infections and requires buying full version for deleting the „threats“. It uses aggressive tactics to indimidate victims and gain a purchase. PersonalSecurity hijacks web browser and loads the following notification:

Privacy violation alert!
Personal Security has detected numerous privacy violations. Some programs may send your private data to an untrusted internet host. Click here to permanently block this activity and remove the possible threat (Recommended)

System files modification alert!
Important system files of your computer may be modified by malicious program. It may cause system instability and data loss. Click here to block unauthorized modification and remove potential threats (Recommended).

Internal conflict alert!
Personal Security has detected internal software conflict. Some application endeavors to access system kernel (such behavior is typical for spyware/malware). Click here to prevent system crash and remove potential threats (Recommended)

Spyware activity alert!
Spyware.IEMonster is a popular spyware that attempts to steal passwords from Web browsers, e-mail clients and other programs, including login information from online banking sessions, billing pages, CC transactions, etc. It may also create special tracking files to log your activity and compromise your Internet privacy. It is strongly recommended to prevent this threat immediately. Click here to get protection against Spyware.IEMonster.

Privacy Violation alert!
Personal Security detected a Privacy Violation. A program is secretly sending your private data to an untrusted internet host. Click here to block this activity by removing the threat (Recommended).

System files modification alert!
Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss. Click here to block unauthorized modification by removing threats (Recommended).

System files modification alert!
Personal Security detected internal software conflict. Some application tries to get access to system kernel (such behavior is typical to Spyware/Malware). It may cause crash of your computer. Click here to prevent system crash by removing threats (Recommended).

Spyware activity alert!
Spyware.IEMonster activity detected. It is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs, including logins and passwords from online banking sessions, eBay, PayPal. It may also create special tracking files to log your activity and compromise your Internet privacy. It’s strongly recommended to remove this threat as soon as possible. Click here to remove Spyware.IEMonster.

How to Manually remove Personal Security Center 2010

To remove Personal Security spyware you must block Personal Security sites, stop and remove processes, unregister DLL files, search and delete all other Personal Security files and registry utility. Follow the Personal Security detection and removal instructions below.

The most typical software removal method is to remove Personal Security by using “Add or Remove Programs” service. However there may be hidden Personal Security files, running processes and registries in your computer, so Personal Security may recreate all other files after reboot.

Personal Security manual removal instructions
Block Personal Security sites:
browsersecessentials.com
protection-estore.com

Stop and remove Personal Security processes:
psecurity.exe

Locate and delete Personal Security registry entries:
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\5FFB10D58FFCF482208906E6A889FD56
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “PSecurity”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform “WinTSI 01.12.2009″

Search and unregister Personal Security DLL libraries:
win32extension.dll

Detect and delete other Personal Security files:
c:\Program Files\PSecurity
c:\Program Files\PSecurity\psecurity.exe
c:\Program Files\Common Files\PSecurityUninstall
c:\Program Files\Common Files\PSecurityUninstall\Uninstall.lnk
c:\WINDOWS\system32\win32extension.dll
c:\Documents and Settings\All Users\Start Menu\PSecurity
c:\Documents and Settings\All Users\Start Menu\PSecurity\Computer Scan.lnk
c:\Documents and Settings\All Users\Start Menu\PSecurity\Help.lnk
c:\Documents and Settings\All Users\Start Menu\PSecurity\Personal Security.lnk
c:\Documents and Settings\All Users\Start Menu\PSecurity\Registration.lnk
c:\Documents and Settings\All Users\Start Menu\PSecurity\Security Center.lnk
c:\Documents and Settings\All Users\Start Menu\PSecurity\Settings.lnk
c:\Documents and Settings\All Users\Start Menu\PSecurity\Update.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSecurity.lnk
%UserProfile%\Desktop\Personal Security.lnk


Download
Super Anti Spyware
OR

Download
Malware Bytes Anti-Malware


Internet security 2010 virus removal

Saturday, December 12th, 2009



Remove Fake Internet security 2010 rogue spyware
Internet Security 2010 is a rogue antivirus program. Please read the removal instructions and get rid of this fake program from your computer as soon as possible. InternetSecurity2010 is a clone of Advanced Virus Remover malware. If you take a closer look, you will see that both programs use the same graphical user interface. This rogue application is promoted through the user of Trojans. Most of the time, Trojans have to be manually installed and come from various misleading websites, for example fake online anti-malware scanners. Once installed, Internet Security 2010 will imitate a system scan and report many false system security threats. Then it will ask you to pay for a full version of the program to remove those security threats or infections. However, do not buy it – this is a scam.

When running, Internet Security 2010 will also display fake security alerts. Those alerts will state that IS2010 has found critical vulnerabilities on your computer. The rogue program displays these infections:
Rogue:W32/XPAntivirus.gen! AdWare.Win32.Zwangi Trojan-Spy.HTML.Visafraud.a
Worm:W32/Agent
Trojan-PSW.W32/Steam
Net-Worm.Win32.DipNet.d
Trojan-Dropper:W32/Trojan-Dropper
Worm:W32/Downadup.gen
Trojan-Downlaoder:W32/Fakerean.gen!A
Net-Worm.Win32.Mytob.t
Trojan-Spy.Win32.Hookit.11
Trojan-Clicker.HTML.IFrame.g
Virus:W32/Alman.b
Trojan-Dropper.Win32.Agent.sd
Email-Worm.Win32NetSky.q
riskware.Win32
Rootkit.win32.agent
internet-security-2010

Internet Security 2010 will also display fake notifications from Windows Taskbar. The fake notifications state:

System warning!
Intercepting programs that may compromise your privacy and harm your system has been detected on your PC. It’s highly recommended you scan your PC right now.

System warning!
Continue working in unprotected mode is very dangerous. Virus can damage your confidential data and work on your computer. Click here to protect your computer.



How to Manually remove Internet Security 2010

How to remove Internet Security 2010 manually:
Manual removal of Internet Security 2010 is a feasible objective if you have sufficient expertise in dealing with program files, processes, .dll files and registry entries.

The files and folders to be deleted are listed below:
•%Program Files%\InternetSecurity2010
•%Program Files%\InternetSecurity2010\IS2010.exe
•%Documents and Settings%\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk

•%Documents and Settings%\[USER]\Cookies\user@buy[1].txt
•%Documents and Settings%\[USER]\Desktop\Internet Security 2010.lnk
•%Documents and Settings%\[USER]\Desktop\SetupIS2010.exe
•%Documents and Settings%\[USER]\Start Menu\Internet Security 2010.lnk

The registry entries that need to be removed are as follows:
•HKEY_CURRENT_USER\Software\Internet Security 2010
•HKEY_LOCAL_MACHINE\SOFTWARE\Internet Security 2010
•HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “IS2010.exe”
Please, be aware that manual removal of Internet Security 2010 is a cumbersome process and does not always ensure complete deletion of the malware, due to the fact that some files might be hidden or may get reanimated automatically afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal Internet Security 2010, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.

Auto Removal tools to remove this virus:

Download
Super Anti Spyware
OR

Download
Malware Bytes Anti-Malware