Wednesday, October 12, 2011

Security Sphere 2012 - Rogue Fake AV - How to remove

Security Sphere 2012 - Fake AV. Removal Guide.



Files Created: 


C:\Documents and Settings\All Users\Application Data\kL05366HhJaC05366\kL05366HhJaC05366.exe


Registry edit:



HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Key: "kL05366HhJaC05366" = "C:\Documents and Settings\All Users\Application Data\kL05366HhJaC05366\kL05366HhJaC05366.exe"


How to remove Security Sphere 2012.
First of all you should download anti-trojan software Trojan-Killer.



Run and install it.



Upon completion of installation, uncheck the Launch GridinSoft Trojan Killer checkbox and click Finish.



Why we did not run Trojan-Killer after installation? Becouse Security Sphere 2012 block all application exlude explorer.exe.

Next step to delete Security Sphere 2012 will be rename of Trojan-Killer to explorer.exe :)
Go to the folder where Trojan-Killer installed and rename trojankiller.exe to explorer.exe.


Then you can run Trojan-Killer and scan your system.

When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.




I hope this guide helps you to kill Rogue Security Sphere 2012 :)

No comments: