Posts Tagged ‘system’

Remove Antivirus System Pro fake program manually

Monday, July 27th, 2009



Antivirus System Pro is classified as a rogue anti-spyware application because it uses misleading methods in order to scare you into purchasing this program. Usually, the rogue uses false scan results and fake security warnings. It states that your computer is infected with Trojans, adware or malware and that you should purchase Antivirus System Pro to remove these infections. Of course, these infections are all fake and don’t actually exist on your computer.

This parasite is advertised through the use of Trojans, such as notorious Zlob or Vundo. It might be also promoted on various malicious websites. Once active, AntivirusSystem Pro will ostensibly scan your computer and list various fake infections or security issues. It will also flood your computer with very annoying pop-ups and security alerts. Here’s an example of a fake Antivirus System Pro alert:
“Windows Security alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan you computer. Your system might be at risk now.”

Obviously, these alerts are also fake. If your computer is infected with Antivirus System Pro, please use the removal guide shown below to remove it immediately. Removal delay will only worsen the situation, because Antivirus System Pro will download even more malware onto your computer.

Antivirus System Pro properties:
• Changes browser settings
• Shows commercial adverts
• Stays resident in background



Antivirus System Pro manual removal:
Kill processes:
sysguard.exe

Delete registry values:
HKEY_CURRENT_USER\Software\AvScan

HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “system tool”

Unregister DLLs:
iehelper.dll

Delete files:
sysguard.exe iehelper.dll
=======================
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

=======================

System Security 2009 fake virus program removal guide

Monday, July 27th, 2009



Remove System Security 2009 fake rogue spyware
System Security, also known as System Security 2009, (Fake anti virus program / Rogue spyware) is another deadly counterfeit antispyware application that developed to invade our Internet life. (Do not confuse System Security, which is fake softeware, to AE Software Technologies’ System Security 2009 which indeed a legit software). Presumably, System Security is a new verion of Winweb Security, with different name but same destruction. Just like most fake antispywares, System Security simulates the Windows system security alert interface, then issues misleading and exaggerated results to distract and scare the internet users.

System Security 2009 usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. System Security will display fake system alerts or fake security alerts to trick user to buy the paid version of System Security, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.

And Once installed, Security 2009 will be set to start automatically when Windows starts. Once started, the program will scan your computer and list a variety of infections, which cannot be removed unless you first purchase the program. These infections, though, are actually legitimate programs that could cause problems with the proper operation of your computer if deleted. While running, Security 2009 will also display fake security alerts in your Windows taskbar. These security alerts will contain messages stating that Security 2009 detected malware or an attack on your system and that you should register the software to protect yourself. These fake alerts and the false positives found in the scan are just a tactic to scare you into purchasing the software.



Manual System Security Removal Instructions:

Stop System Security Processes:
SystemSecurity.exe
05643921.exe
install.exe

Find and Delete these System Security Files:
systemsecurity.exe
SystemSecurity.lnk
SystemSecurity on the Web.lnk
Uninstall SystemSecurity.lnk
%desktopdirectory%\system security.lnk
%desktopdirectory%\ws\config.udb
%desktopdirectory%\ws\init.udb
%desktopdirectory%\ws\languages\english.lng
%desktopdirectory%\ws\languages\german.lng
%desktopdirectory%\ws\languages\spanish.lng
%desktopdirectory%\ws\systemsecurity.exe
%programs%\system security\system security.lnk
%desktopdirectory%\ws\systemsecurity.exe
05643921.exe
install.exe
%desktopdirectory%\system security 2009.lnk
%programs%\system security\system security 2009 support.lnk
%programs%\system security\system security 2009.lnk

Remove System Security Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run systemsecurity
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 displayicon
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 shortcutpath
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 uninstallstring
=======================
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

=======================