Posts Tagged ‘manual’

System Security 2009 fake virus program removal guide

Monday, July 27th, 2009



Remove System Security 2009 fake rogue spyware
System Security, also known as System Security 2009, (Fake anti virus program / Rogue spyware) is another deadly counterfeit antispyware application that developed to invade our Internet life. (Do not confuse System Security, which is fake softeware, to AE Software Technologies’ System Security 2009 which indeed a legit software). Presumably, System Security is a new verion of Winweb Security, with different name but same destruction. Just like most fake antispywares, System Security simulates the Windows system security alert interface, then issues misleading and exaggerated results to distract and scare the internet users.

System Security 2009 usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. System Security will display fake system alerts or fake security alerts to trick user to buy the paid version of System Security, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.

And Once installed, Security 2009 will be set to start automatically when Windows starts. Once started, the program will scan your computer and list a variety of infections, which cannot be removed unless you first purchase the program. These infections, though, are actually legitimate programs that could cause problems with the proper operation of your computer if deleted. While running, Security 2009 will also display fake security alerts in your Windows taskbar. These security alerts will contain messages stating that Security 2009 detected malware or an attack on your system and that you should register the software to protect yourself. These fake alerts and the false positives found in the scan are just a tactic to scare you into purchasing the software.



Manual System Security Removal Instructions:

Stop System Security Processes:
SystemSecurity.exe
05643921.exe
install.exe

Find and Delete these System Security Files:
systemsecurity.exe
SystemSecurity.lnk
SystemSecurity on the Web.lnk
Uninstall SystemSecurity.lnk
%desktopdirectory%\system security.lnk
%desktopdirectory%\ws\config.udb
%desktopdirectory%\ws\init.udb
%desktopdirectory%\ws\languages\english.lng
%desktopdirectory%\ws\languages\german.lng
%desktopdirectory%\ws\languages\spanish.lng
%desktopdirectory%\ws\systemsecurity.exe
%programs%\system security\system security.lnk
%desktopdirectory%\ws\systemsecurity.exe
05643921.exe
install.exe
%desktopdirectory%\system security 2009.lnk
%programs%\system security\system security 2009 support.lnk
%programs%\system security\system security 2009.lnk

Remove System Security Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run systemsecurity
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 displayicon
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 shortcutpath
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 uninstallstring
=======================
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

=======================

Win Blue Soft Spyware popup removal

Monday, July 27th, 2009



Remove WiniBlueSoft rogue spyware
WiniBlueSoft removal should not be executed through Add / Remove Programs of Windows Start menu, since that will be a signal for WiniBlueSoft, which is rather a crushware, to start its destructive activities. At the same time, removal of WiniBlueSoft through Add / Remove Programs is unlikely to remove pop-ups and repeating scan which are normally the reason why users seek to get rid of WiniBlueSoft. WiniBlueSoft is a fake security application distributed with trojans and through websites pretending to be online scanners, as well as through more moderate websites that seem to be WiniBlueSoft homepage. Distribution of WiniBlueSoft is to be understood as installation of its trial version that frightens and tricks users as hackers expect some of them pay for registration after such a treatment. If infected, remove WiniBlueSoft instead of donating the hackers fund and stimulating the development of other misleading tools.



WiniBlueSoft manual removal instructions:

Delete WiniBlueSoft files:
always_skip.xml
data.bin
License.txt
main_config.xml
uninstall.exe
WiniBlueSoft.exe
c:Homepage.lnk
c:Uninstall.lnk
c:WiniBlueSoft.lnk
102959roz2b45.ocx
10325virusz955.ocx
10355h9eat227z2.cpl
111znot-a-v5rus998.dll
115z1vi9us3e85.ocx
11797tzoj595.dll
1197addwaze16915.ocx
127b95ief305z.ocx
12946sz5mbot79c.dll
129cvir1z58.dll
12bbszy5ar91941.dll
13323w95mz1b.ocx
135zvir1929.cpl
1393z5or9df.ocx
13951spzmb9t5a2.exe
14041hackt5zl99.exe
19199hackt5zl7a1.bin
19524spyze9.exe
19544spy6fbz.ocx
19945hzcktool65b.dll
19991not-a-v5rzs1c9.exe
19z43hacktoo965f.exe
1a59dow9lozder1735.ocx
1b20z9a5se2186.bin

Delete WiniBlueSoft registry entries:
HKEY_CURRENT_USER\Software\WiniBlueSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\WiniBlueSoft
HKEY_LOCAL_MACHINE\SOFTWARE\WiniBlueSoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run “setup2.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run “WiniBlueSoft”
=======================
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

=======================