Showing posts with label AntiVirus. Show all posts
Showing posts with label AntiVirus. Show all posts

Friday, February 17, 2012

System Check Virus - How To Get Rid

System Check - It's Fake AV (Rogue, Virus, Malware). Just ransom money, nothing more.

System Check icon
Fake Errors
One more message
System Check main window
Effects of virus activity. All icons from Start menu and desktop are dissapeared.
HOW TO GET RID OF THE SYSTEM CHECK VIRUS

Step 1.

Press WinKey + R
Step 2.

In the opened command line type http://trojan-killer.net end press Enter
Step 3.

Download Trojan-Killer and run it.
Step 4.

Install Trojan-Killer
Step 5.

Run after installing
Step 6.

Wait while Trojan-Killer updade
Step 7.

After update scaning start automaticaly
Step 8.

Remove selected viruses
Step 9.

Run restore tool, and reset IE settings
Step 10.

Restart your PC

I HOPE THIS GUIDE HELPS YOU TO DELETE SYSTEM CHECK VIRUS :)

Additional Information.
System Check virus saved in hard disk with random named:
elXE7O7kJEBqT2.exe, HjLoCTYovD.exe, 6Hiyf0CT8BQuRB.exe, aSlILEXTGK87pa.exe, bR10hjnBB0Lpl.exe, ctsPWQNgCGxQAM.exe, dJfESasFBfaCsH.exe, fSTdkdZMtxFJkF.exe, ghxSJLETyoE.exe, GViAGAIDJIj.exe, hlBQa4E0touTaM.exe, IFEvuifXpHuouiv.exe, NjnSXj2tuRoKUS7.exe, rlETiIymYqlcUo6.exe, tauWkXtJMV9Db16.exe, ZQLvmgjdesHXTo2.exe, ZQLvmgjdesHXTo.exe, LoBoUYvVYw.exe, OgpDDLdaoq.exe, pBdLGFtTPyTq4K.exe, I97Lhx0Ur44APQ.exe, gVCMtk2aAKoij7.exe, vkYWHap0CdYhWW.exe, muNojdbroJgYEBX.exe, aPPhFOdsiSvcW7.exe, BHMmHjYKMAcfJ.exe, 0ewnDCcYZm4iD3.exe, gIknGA87xxJsXw.exe, PiGUNCilaeLmpu.exe, dpJPDS5zQXezbA.exe, xImULAUPBbuJP.exe, Jv4J8k9ZI2dNK6.exe, DeWkPGfSKxJfrv.exe, mPEEtw0FBFwhHE.exe, 9Zh9PqXYrplTPt.exe, 1O2o5Lb6LBhKTu.exe, FtY2mOkk7pve3M.exe, hhBUqpMjwRyef.exe, Wseuh3qsrMaNwj.exe, A1RX7zy8DgkpIQ.exe, 1MBJNfryNudaBx.exe, d2hl1WNdwFUQTx.exe, Y5Jt54B3tgxAhj.exe, 6sMTpXHIHIDMiu.exe, FNUpoBDe7Eh4nB.exe, oY80E0A3oE8428.exe, yiaYdRfrCjDkrP.exe, Q8Jj92og9IaiOP.exe, gnvI5aAHmNSLWb.exe, fPa6UdkhxeC6yN.exe, wbwILJy9bS5PBx.exe, LWhRvhHGnxlb4Z.exe, RhXKiTAQTdkfUsv.exe, D6nJ6QgLH4n7uj.exe, dAhFAvypmBDkGG.exe, MkZgT5YT24PhUu.exe, dwVTehTVyfVwUz.exe, wU4PAImT4vqv8b.exe, EBwohSmD2z5slH.exe, UeTjQalhkrwo31.exe, stTb6fzDOvR36S.exe, rZUjMC9UfwQjpi.exe, aKOdSYRlPw.exe, cwuKGCkVOILNu.exe, gvSR04lzAEFGnF.exe, zzlugUg198bjnN.exe, HtwXTICLskgoqa.exe, pgR68QKlA82AiX.exe, YSKyBGXKufhzjl.exe, 0Qnpcw6RN2fTfT.exe, l5Yvpgc7IHOvPG.exe, fFldlHRWjE.exe, xPjxtTsYl3qJDo.exe, dGjFaowmJSBwz3.exe, 5dav05veeegnfd.exe, 7bBESB2WJxbbog.exe, 1kAlMiG2Kb7FzP.exe, eu3fxtu7k.exe, 5dAv05veEEGnFD.exe, 11LgbhuIEemvEx.exe, yRXawHVrgFKjit.exe, E44VUIbrfRPsIe.exe, tK7RR9NkXHeupu.exe, 99WEo1VbBLlrIJ.exe, tDSwR0FVohJmhD.exe, zc24Lp02GXSZrk.exe, ey4oNJqwOgBclX.exe, OgpDDLdaoq.exe, QngLqBh4Uh1mgg.exe, n34qmiGOCOItaN.exe, D8opXeiXM6oZKx.exe, dAhFAvypmBDkGG.exe, fRWQFf1xHcKXXG.exe, CZ7L11beLoDUSv.exe, 7F6SrcE5kfgCsr.exe, YVg6j6ft7eFowM.exe, 0EoGlhpqfMk2xW.exe, E73VRiLGP6pkpb.exe, JG3U7FYhmzpZlA.exe, FB6Sx3NDGppDU6.exe, QXrnnZ0f2CPURj.exe, Njw6dU5SyvPhic.exe, NiEPAkXfDEhi.exe, BUYb1NLnpjLHYp.exe, vAYW5uxswcccap.exe, 9MVWHoNhOzAqZp.exe, DvhhCCFbLujqW.exe, MDpvuKDqT0HQQt.exe, aoJdsIXIjoqyd.exe, wpyigYDfWj.exe, KJLp67ulyEdtFU.exe, 9SMCCuIkakzNz5.exe, qLYEwoUwbT.exe, CdYe4VFba1YyaC.exe, pDCFmzrI4KSE4N.exe, p3efvXR0ndPmPU.exe, xP86UelhhDds5G.exe, ISj5jP7c6wL1pZ.exe, FEPXvquGMaIdUNF.exe, WzEjZgxQwuruPE.exe, om2V5ciGsylbbO.exe, FEPXvquGMaIdUNF.exe, i26UVs4aaKWhOj.exe, HxiSncYsv2876J.exe, 7BGJbkbrQmhgpf.exe, fA4nFAWTifUL9y.exe and other.

Thursday, November 17, 2011

AV Protection 2011 - FakeAV - REMOVAL GUIDE

AV Protection 2011 - it is fake antivirus. Only money ransom.


Files are created:

C:\Documents and Settings\<UserName>\Application Data\FCE03\0FD4B.exe
C:\Documents and Settings\<UserName>\Application Data\FCE03\3F0D.CE0
C:\Documents and Settings\<UserName>\Application Data\LUUJ1wscH0aTNzF\AV Protection 2011.ico
C:\Documents and Settings\<UserName>\Application Data\dwme.exe
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Desktop\AV Protection 2011.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\1.tmp
C:\Documents and Settings\<UserName>\Local Settings\Temp\dwme.exe
C:\Documents and Settings\<UserName>\Start Menu\Programs\AV Protection 2011\AV Protection 2011.lnk
C:\Program Files\03F0D\lvvm.exe
C:\Program Files\LP\4B7F\027.exe
C:\Program Files\LP\4B7F\2.tmp
C:\Program Files\LP\4B7F\3.tmp
C:\Program Files\LP\4B7F\4.tmp
C:\WINDOWS\system32\AV Protection 2011v121.exe





Registry edit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"027.exe" = "C:\Program Files\LP\4B7F\027.exe"
"ZikkWC6uQ" = "C:\Documents and Settings\<UserName>\Application Data\dwme.exe"
"wbbIK2edvJwcHqT8234A" = "C:\WINDOWS\system32\AV Protection 2011v121.exe"

Random key names.


To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.




Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.




When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



I hope this guide helps you :)

Thursday, November 10, 2011

Privacy Protection - Removal Guide ( FakeAV Rogue )

Privacy Protection - dangerous virus, also known as FakeAV or Rogue. It block most of all programs and you can't to do anything.

To remove this virus first of all you need kill them from memory.

Click "Start" menu and select "Run" option. Type-in the following text exactly as it is specified here:
taskkill.exe /F /IM privacy.exe


This will kill the process of Privacy Protection virus. (if you could not do it from the first attempt then try again)

When the virus outside of memory you can do something to remove it from you PC forever.

Go to the website www.Trojan-Killer.net and download Trojan-Killer.

Run and install it.


Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.


When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.




Files are created:
C:\Documents and Settings\<UserName>\Local Settings\Temp\1.tmp
C:\Documents and Settings\All Users\Application Data\privacy.exe
C:\Documents and Settings\All Users\Desktop\Privacy Protection.lnk


Register:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
Privacy Protection = C:\Documents and Settings\All Users\Application Data\privacy.exe

Wednesday, November 9, 2011

AV Security 2012 - How To Remove - FakeAV - Rogue

AV Security 2012 - it is fake antivirus. Only money ransom.





Files are created:
C:\Documents and Settings\<UserName>\Application Data\iEEDV8olEViWC\AV Security 2012.ico (It's random folder name)
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Desktop\AV Security 2012.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\1.tmp
C:\Documents and Settings\<UserName>\Start Menu\Programs\AV Security 2012\AV Security 2012.lnk
C:\WINDOWS\system32\AV Security 2012v121.exe
(Will be possible to meet such a file C:\WINDOWS\system32\virus.exe)




Registry edit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"qxxTGN9pR8234A"="C:\WINDOWS\system32\AV Security 2012v121.exe"

Random key names.


To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.




Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.




When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



I hope this guide helps you :)

Tuesday, November 8, 2011

System Security 2012 FakeAV How To Remove

System Security 2012 - it is fake antivirus. Only money ransom.



Files are created:
C:\Documents and Settings\<UserName>\Application Data\dwme.exe
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Application Data\rCC66jQAXymZtn3\System Security  2012.ico (It's random folder name)
C:\Documents and Settings\<UserName>\Desktop\System Security  2012.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\1.tmp
C:\Documents and Settings\<UserName>\Local Settings\Temp\dwme.exe
C:\Documents and Settings\<UserName>\Start Menu\Programs\System Security  2012\System Security  2012.lnk
C:\WINDOWS\system32\pttggOL3r.exe (It's random file name)
C:\WINDOWS\system32\System Security 2012v121.exe




Registry edit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"gXX5yhmP4tnLrI28234A" = "C:\WINDOWS\system32\D888oFB8lEViW6j.exe"
"PDVV8olDViWCuQh" = "C:\Documents and Settings\<UserName>\Application Data\dwme.exe"


Random key names.



To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.






Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.






When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



I hope this guide helps you :)

Monday, October 31, 2011

System Security 2011 - Fake AV - Rogue - Removal Guide


System Security 2011 - it is fake antivirus. Only money ransom.



Files are created:


C:\Documents and Settings\<UserName>\Application Data\GRRFB8olDViWCkC\System Security  2011.ico (It's random folder name)
C:\Documents and Settings\<UserName>\Application Data\dwme.exe
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Desktop\System Security  2011.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\1.tmp
C:\Documents and Settings\<UserName>\Local Settings\Temp\dwme.exe
C:\Documents and Settings\<UserName>\Start Menu\Programs\System Security  2011\System Security  2011.lnk
C:\WINDOWS\system32\D888oFB8lEViW6j.exe (It's random file name)




Registry edit:


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"gXX5yhmP4tnLrI28234A" = "C:\WINDOWS\system32\D888oFB8lEViW6j.exe"
"PDVV8olDViWCuQh" = "C:\Documents and Settings\<UserName>\Application Data\dwme.exe"


Random key names.



To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.






Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.






When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



I hope this guide helps you :)

Monday, October 10, 2011

Cloud Protection - Rogue, Fake Anti Virus, Ransomware. Delete Guide.

Cloud Protection - it is fake antivirus. Only money ransom.



Files are created:

C:\Documents and Settings\<UserName>\Application Data\g44tgnOLrfI2dJw\Cloud Protection.ico
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Desktop\Cloud Protection.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\2.tmp
C:\Documents and Settings\<UserName>\Local Settings\Temp\svhostu.exe
C:\Documents and Settings\<UserName>\Start Menu\Programs\Cloud Protection\Cloud Protection.lnk
C:\Documents and Settings\<UserName>\Start Menu\Programs\Startup\crss.exe
C:\Program Files\Internet Explorer\1.tmp
C:\WINDOWS\system32\D88olEDV7kS7kSu.exe



Registry edit:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tAAX5yhmP4gO3fK8234A" = "C:\WINDOWS\system32\D88olEDV7kS7kSu.exe"


To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.






Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.






When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



I hope this guide helps you :)

Thursday, October 6, 2011

Guard Online - Fake AV - removal guide - how to delete


AV Guard Online - it is fake antivirus. Only money ransom.












Files are created:

C:\Documents and Settings\<UserName>\Application Data\F33rfbIK2AV Guard Online.ico (it's random name)
C:\Documents and Settings\<UserName>\Application Data\ldr.ini
C:\Documents and Settings\<UserName>\Desktop\AV Guard Online.lnk
C:\Documents and Settings\<UserName>\Local Settings\Temp\1.tmp
C:\Documents and Settings\<UserName>\Start Menu\Programs\AV Guard Online\AV Guard Online.lnk
C:\WINDOWS\system32\vzRRFB8lEV.exe (it's random name)


Registry edit:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TiikWSV7kWCuQ5h8234A" = "C:\WINDOWS\system32\vzRRFB8lEV.exe"
(Random key and file names)



To remove this rogue go to the website www.Trojan-Killer.net and download Trojan-Killer.


Run and install it.






Upon completion of installation, select Launch GridinSoft Trojan Killer and click Finish.






When the Trojan Killer will look on your computer you will see a full list of detected malware.
Press the Remove Selected to remove them.



Good Luck :)