Monday, October 10, 2011

Cloud Protection - Rogue, Fake Anti Virus, Ransomware. Delete Guide.

Cloud Protection - it is fake antivirus. Only money ransom.



Files are created:

C:\Documents and Settings\<UserName>\Application Data\g44tgnOLrfI2dJw\Cloud Protection.ico
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Desktop\Cloud Protection.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\2.tmp
C:\Documents and Settings\<UserName>\Local Settings\Temp\svhostu.exe
C:\Documents and Settings\<UserName>\Start Menu\Programs\Cloud Protection\Cloud Protection.lnk
C:\Documents and Settings\<UserName>\Start Menu\Programs\Startup\crss.exe
C:\Program Files\Internet Explorer\1.tmp
C:\WINDOWS\system32\D88olEDV7kS7kSu.exe



Registry edit:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tAAX5yhmP4gO3fK8234A" = "C:\WINDOWS\system32\D88olEDV7kS7kSu.exe"


To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.






Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.






When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



I hope this guide helps you :)

No comments: