Thursday, 16 June 2011

Remove ShopperReports (Uninstall Guide)

ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser. It's not a virus. Whenever you search for something, it may give you a list of related products on the left-hand side of your computer screen.



ShopperReports may occasionally display pop-up windows with advertisements. This adware is usually integrated into or bundled with a other programs, e.g., freeware or shareware. Adware does not make a product free of charge; it comes with a price - advertisements.



Most of the time, users have the option to not install it. On the other hand, some users are not having problems with adware at all. It's up to you whether or not to remove ShopperReports. But we think that if you didn't go looking for it, you should uninstall it. Besides, some users believe that Shopper Reports causing the major problems with they web browsers or even makes their computers run slower. You can uninstall ShopperReports by going to the "Add or Remove Programs (Windows XP)" or "Uninstall a Program (Windows Vista/7)" section in your Control Panel. But what if its not listed? Please follow the steps in the removal guide below to remove ShopperReports from your computer completely. If you have any questions, please leave a comment below. Good luck and be safe online!


Scan your computer with recommended anti-malware and clean-up software:

First of all, download recommended anti-malware and clean-up software and run a full system scan to make sure that your computer is not infected with malicious or potentially unwanted applications and that your files are not corrupted before proceeding with the uninstall process.


ShopperReports removal instructions:

1. Go to the Start Menu. Select Control PanelAdd/Remove Programs.
If you are using Windows Vista or Windows 7, select Control PanelUninstall a Program.



2. Search for ShopperReports in the list. Select the program and click Remove button.
If you are using Windows Vista/7, click Uninstall up near the top of that window.



3. Restart your computer.

4. Download free anti-malware software and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.


ShopperReports should be gone. If it's still on your computer, please follow the removal instructions bellow to remove the remains.


Remove ShopperReports in Internet Explorer:

1. Open Internet Explorer. Go to ToolsManage Add-ons.



2. Select Toolbars and Extensions. Uninstall/disable everything related to ShopperReports from the list.




Remove ShopperReports in Mozilla Firefox:

1. Open Mozilla Firefox. Go to ToolsAdd-ons.



2. Select Extensions. Choose ShopperReports and click Uninstall button.


Associated ShopperReports files and registry values:

Files:
  • C:\Program Files\ShoppingReport2\Uninst.exe
  • C:\Program Files\ShoppingReport2\Bin\2.7.34\ShoppingReport.dll
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\Config.xml
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\db\Aliases.dbs
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\db\Sites.dbs
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\dwld\WhiteList.xip
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\report\aggr_storage.xml
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\report\send_storage.xml
  • C:\Documents and Settings\[UserName]\Application Data\ShoppingReport2\cs\res1\WhiteList.dbs
Registry values:
  • HKEY_CURRENT_USER\Software\ShoppingReport2
  • HKEY_CLASSES_ROOT\ShoppingReport2.HbAx
  • HKEY_CLASSES_ROOT\ShoppingReport2.HbAx.1
  • HKEY_CLASSES_ROOT\ShoppingReport2.HbInfoBand
  • HKEY_CLASSES_ROOT\ShoppingReport2.HbInfoBand.1
  • HKEY_CLASSES_ROOT\ShoppingReport2.IEButton
  • HKEY_CLASSES_ROOT\ShoppingReport2.IEButton.1
  • HKEY_CLASSES_ROOT\ShoppingReport2.RprtCtrl
Share the knowledge:

Tuesday, 14 June 2011

Remove Windows XP Restore (Uninstall Guide)

Windows XP Restore is a fake computer optimization tool that pretends to scan your computer for registry and system errors. It may look like legitimate computer analysis and optimization software, but it actually gives you fabricated reports of threats on the computer. This fake program, which also goes by the name of Windows XP Recovery, began circulating in early May and has steadily racked up victims. I have to admit that Windows XP Restore is probably the most annoying scareware I've encountered this year so far. There are two primary factors that make such malware profitable: fear and annoyance. Windows XP Restore not only urges users to pay for the "full version" of the rogue application to fix non-existent Windows registry and other errors, but it also hides your files, folders, desktop shortcuts and icons. It changes file attributes and disables Windows tools, e.g., Task Manager. So if you are grappling with this malware, please follow the removal instructions below to remove Windows XP Restore and to make your files visible again.



While Windows XP Restore is running, it displays fake hard drive error warnings to make you think that your computer is really going to explode. Here's an example of the fake Windows XP Restore security alert:
Critical Error
Damaged hard drive clusters detected. Private data is at risk.

Critical Error
Hard drive critical error. Run a system diagnostic utility to
check your hard disk drive for errors.


As I said, it blocks Task Manager and other Windows utilities. Windows XP Restore claims that it was disabled by your administrator; that's bloody rude.
Task Manager has been disabled by your admininstrator.


You can remove Windows XP Restore manually but honestly this is not something that novice computer users may be able to deal with on their own. Instead of that, you should scan your computer with anti-malware software. Additionally, you can activate the rogue program by entering this registration code 8475082234984902023718742058948 and any email as shown in the image below.



Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly. Besides, Windows XP Restore makes your files visible again automatically. This will save you a lot of time, trust me. If you have any further questions, please leave a comment below. Good luck and be safe online!


Windows XP Restore removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



If you still can't see any of your files, Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter explorer and hit Enter or click OK.



2. Open Internet Explorer. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Alertane Windows XP Restore removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



2. The rogue application places an icon or your desktop. Right click on the icon, click Properties in the drop-down menu, then click the Shortcut tab.



The location of the malware is in the Target box.



On computers running Windows XP, malware hides in:
C:\Documents and Settings\All Users\Application Data\

NOTE: by default, Application Data folder is hidden. Malware files are hidden as well. To see hidden files and folders, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmark from the checkbox labeled:

- Hide extensions for known file types
- Hide protected operating system files

Click OK to save the changes. Now you will be able to see all files and folders in the Application Data directory.

On computers running Windows Vista/7, malware hides in:
C:\ProgramData\

3. Look for suspect ".exe" files in the given directories depending on the Windows version you have.

Example Windows XP:
C:\Documents and Settings\All Users\Application Data\16506660.exe
C:\Documents and Settings\All Users\Application Data\nmqkFApeDId.exe

Example Windows Vista/7:
C:\ProgramData\16506660.exe
C:\ProgramData\nmqkFApeDId.exe

Basically, there will be a couple of ".exe" file named with a series of numbers or letters.



Rename those files to 16506660.vir, nmqkFApeDId.vir etc. For example:



It should be: C:\Documents and Settings\All Users\Application Data\16506660.vir

Instead of: C:\Documents and Settings\All Users\Application Data\16506660.exe

4. Restart your computer. The malware should be inactive after the restart.

5. Open Internet Explorer and download TDSSKiller. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller and remove the rootkit.



6. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

7. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated Windows XP Restore files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\~[SET OF RANDOM CHARACTERS]
  • %UsersProfile%\Local Settings\Application Data\[SET OF RANDOM CHARACTERS].lic
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Windows XP Restore.lnk
  • %UsersProfile%\Start Menu\Programs\Windows XP Restore\
  • %UsersProfile%\Start Menu\Programs\Windows XP Restore\Windows XP Restore.lnk
  • %UsersProfile%\Start Menu\Programs\Windows XP Restore\Uninstall Windows XP Recovery.lnk
%AllUsersProfile% refers to: C:\Documents and Settings\All Users
%UserProfile% refers to: C:\Documents and Settings\[User Name]

Windows Vista/7:
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\~[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].lic
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Windows XP Restore.lnk
  • %UsersProfile%\Start Menu\Programs\Windows XP Restore\
  • %UsersProfile%\Start Menu\Programs\Windows XP Restore\Windows XP Restore.lnk
  • %UsersProfile%\Start Menu\Programs\Windows XP Restore\Uninstall Windows XP Restore.lnk
%AllUsersProfile% refers to: C:\ProgramData
%UserProfile% refers to: C:\Users\[User Name]

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
Share this information with other people:

How to Remove "Security Protection" (Uninstall Guide)

Security Protection is a fake antivirus program that pretends to scan your computer for security problems. This malware, often called scareware, fabricates a list of security threats it has found on your machine. It also generates false or misleading security alerts to make you think that your computer is infected with malicious software. To remove the non-existent infections and protect your self from malware, you will be prompted to buy the "full-version" of Security Protection designed to protect. That's one of the most common ways for cybercriminals to steal money from people. It's very important to remember that by purchasing such rogue security software you are submitting your credit card details and personal information to cyber-crooks. As a result, you may become a victim of credit card scam or even identity theft. So, if you thought that Security Protection was a legitimate software and have already purchased it, please contact your credit card company and dispute the charges. To remove Security Protection from your computer, please follow the removal instructions below.



Security Protection is distributed though the use of fake online scanners; that's probably the most popular malware distribution mechanism. For example, if you search for something on Google and then click on a search result or image you are taken to a webpage which serves up a fake online scanner. It claims to detect a large number of nonexistent threats and urges you to install malware removal tool or anti-virus software. Once downloaded to your computer, Security Protection runs a fake system scan. It displays fake security alerts, pop-up windows and notifications like very one or two minutes saying that your computer is infected.

Fake Security Protection alerts:







What is more, Security Protection blocks other programs on your computer, including your web browser and takes you to a web page where you can purchase it. It displays fake notification saying that Internet Explorer or any other program is infected with W32/Blaster.worm.
iexplore.exe can not start
File iexplore.exe is infected by W32/Blaster.worm
Please activate Malware Protection to protect your computer.


The good news is that your computer is not infected with W32/Blaster worm and other viruses as this rogue programs claims. However, you should remove Security Protection from your computer as soon as possible. Just restart your computer in Safe Mode with Networking, download anti-malware software and run a full system scan.

OPTIONAL: In case you can't boot your PC in Safe Mode with Networking or you can't delete the malicious files manually, you can use this code SL55J-T54YHJ61-YHG88 and any email to register the rogue application in order to stop the fake security alerts.



Once this is done, you are free to install recommended anti-malware software (direct download) to remove the rogue anti-virus program from your computer properly. If you need help in removing Security Protection from your computer, please leave a comment below. Additional information about this malware and comments are welcome too. Good luck and be safe online.

Related malware:

Security Protection removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this rogue anti-virus program from your computer.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.


Security Protection associated files and registry values:

Files:

Windows XP:
  • C:\Documents and Settings\All Users\Application Data\defender.exe
Windows Vista/7:
  • C:\ProgramData\defender.exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Security Protection"
Share this information with other people:

Thursday, 9 June 2011

How to Remove Milestone Antivirus (Uninstall Guide)

Milestone Antivirus is a rogue security program that will pretend to scan your computer for viruses and report threats that do not really exist to scare you into believing your system is infected. It's designed to mimic real anti-virus software and it's pretty much useless. It will display fake security alerts about viruses, spyware or other malware found on your computer and it won't stop until a payment is made. Milestone Antivirus will take you to a very well crafted, bogus online store where you can buy a full version of this program for $50. The cyber crooks behind rogue anti-virus software are continuing to improve their social engineering attacks to be more successful so you should really think twice before installing software without doing some basic research about it. Fortunately, Milestone Antivirus is easy to remove if you know what to look for. If you have a PC infected with this rogue anti-virus application, please follow the steps in the removal guide.



Milestone Antivirus video:


While running, Milestone Antivirus will gives you loads of fake security alerts and error messages that just seem to pop up constantly. It claims that your computer is infected by spyware.


Security warning:
The file C:\WINDOWS\regedit.exe is infected.
Running of application is impossible.


Here's an example of a very well designed svchost.exe error message that may trick novice Windows users.



And worse, it may block you from running anti-malware tools. Milestone Antivirus also hijacks a file association for executable files, that's why you will probably see the "Open with..." dialog box when you try to open a program. Thankfully, there's an easy fix for this problem. Just follow the removal instructions below.

A screen shot of what the Milestone Antivirus online store looks like:



As you can see, Milestone Antivirus is a threat that comes under the guise of a genuine antivirus program. It's pure malware. Our recommendations: remove Milestone Antivirus from the system as soon as possible and install a solid antivirus software. Better safe than sorry. If you need help removing this pesky malware from your computer, please leave a comment below. Good luck and be safe online!

Related malware:
Optional: you can use this serial significantother to uninstall the rogue application.



Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly.


Milestone Antivirus removal instructions:

1. Go to StartRun or press WinKey+R. Type in "command" and press Enter key.


2. In the command prompt window type "notepad". Notepad will come up.


3. Copy all the text in blue color below and paste into Notepad.

Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

4. Save file as regfix.reg to your Desktop. NOTE: (Save as type: All files)


regfix.reg is available for download here, in case you can't make your own or it doesn't work.

5. Double-click on regfix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.
6. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe, explorer.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

7. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated Milestone Antivirus files and registry values:

Files:
  • C:\Program Files\conhost.exe
  • C:\Program Files\csrss.exe
  • C:\Program Files\Milestone Antivirus.ico
  • C:\Program Files\Milestone Antivirus\
  • C:\Program Files\Milestone Antivirus\Milestone Antivirus.exe
  • C:\Program Files\scdata\
  • C:\Program Files\scdata\wispex.html
  • C:\Program Files\scdata\wskinn.exe
  • C:\Program Files\scdata\images\
  • %UserProfile%\Desktop\Milestone Antivirus.exe.txt
  • %UserProfile%\Desktop\Milestone Antivirus.lnk
  • %UserProfile%\Start Menu\Programs\Milestone Antivirus\
  • %UserProfile%\Start Menu\Programs\Milestone Antivirus\Milestone Antivirus.lnk
Registry values:
  • HKEY_CURRENT_USER\Software\Milestone Antivirus
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QTUpdate
  • HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = 'C:\Program Files\conhost.exe "%1" %*'
Share this information with other people:

Wednesday, 8 June 2011

Remove Vista Antispyware 2012, Win 7 Internet Security 2012 (Uninstall Guide)

Vista Antispyware 2012, Win 7 Internet Security 2012, Win 7 Security 2012 are only a few names of the rogue security program that pretends to scan your computer for viruses and then claims to find a bunch of malicious files that aren’t really there. It will prompt you to register the fake antivirus application for a fee in order to remove the non-existent threats and to make the incessant malware warnings disappear. It can be quite persistent in its attempts to convince you into buying the full version of the program. If you have accidentally installed this fake antivirus, go ahead and uninstall it. To remove Vista Antispyware 2012, Win 7 Internet Security 2012 and other variants of this scareware from your computer, please follow the steps in the removal guide below.

This rogue security application goes by many different program names listed below.

Windows Vista rogue names:
  Windows 7 rogue names:
Vista Antispyware 2012   Win 7 Antispyware 2012
Vista Antivirus 2012   Win 7 Antivirus 2012
Vista Security 2012   Win 7 Security 2012
Vista Home Security 2012   Win 7 Home Security 2012
Vista Internet Security 2012   Win 7 Internet Security 2012
Vista Total Security 2012   Win 7 Total Security 2012



Vista Antispyware 2012, Win 7 Internet Security 2012, Win 7 Security 2012 is one of many fake antivirus applications just like the '11 version of this malware described on this page Vista Antispyware 2011, Vista Security 2011 and Vista Antimalware 2011. If you take a closer look at these fake antivirus applications you'll see that they are almost identical. While running, the fake antivirus will launch pop-up windows with false or misleading alerts. It states that your computer is under attack from a remote server and that there is a piece of malware running on your computer that may steal your sensitive information.





It also displays this fake Windows Security Center which looks quite convincing and professional.



Vista Antispyware 2012, Win 7 Internet Security 2012 prevents you from visiting antivirus vendor websites, it may disable certain Windows utilities and block legitimate software. Actually, it hijacks Internet Explorer and other browsers and it might be that you won't be able to visit any website. The fake alert states: Visiting this site may pose a security threat to your system!



Here's another fake security alert which is displayed every time you attempt to run legitimate software:
Vista Antivirus 2012 Firewall Alert
Vista Antivirus 2012 has blocked a program from accessing the
internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen


And probably the most annoying thing about this malware, is that Vista Antispyware 2012, Win 7 Internet Security 2012, Win 7 Security 2012 hijacks a file association for executable (.EXE) files.


Quick removal:

1. In the worst case scenario, if can't reboot your computer in safe mode and install anti-malware software to remove Vista Antispyware 2012, Win 7 Internet Security 2012, Win 7 Security 2012, you can use this debugged serial key 9443-077673-5028 or 3425-814615-3990 to register the rogue application in order to stop the fake security alerts. Just click the Registration button and then select "Activate manually". Don't worry, this is completely legal. If the reg keys do not work anymore, please follow the removal instructions below.



Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.

Without a doubt, this security application is nothing more but a scam. Don't end up handing your credit card information over to the people most likely to defraud you. If you need help in removing this annoying malware from your computer, please leave a comment below or follow the alternate removal instructions. Good luck and be safe online.


Alternate Vista Antispyware 2012, Win 7 Internet Security 2012, Win 7 Security 2012 removal instructions:

Make sure that you can see hidden and operating system protected files in Windows. For more in formation, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmarks from the checkboxes labeled:
  • Hide extensions for know file types
  • Hide protected operating system files
Click OK to save the changes.


1. Go into C:\Users\[UserName]\AppData\Local\ folder.

For example: C:\Users\Michael\AppData\Local\


2. Find hidden executable file(s) in this folder. In our case it was called vkl.exe, but I'm sure that the file name will be different in your case. Rename vkl.exe to vkl.vir and click "Yes" to confirm file rename. Then restart your computer.



3. After a restart, copy all the text in bold below and paste to Notepad.

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

4. Save file as fix.reg to your Desktop. NOTE: (Save as type: All files)


5. Double-click on fix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.

6. Open Internet Explorer. Download exefix.reg and save it to your Desktop. Double-click on exefix.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.

7. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.


Associated Vista Antispyware 2012, Win 7 Internet Security 2012, Win 7 Security 2012 and registry values:

Files:
  • C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe
  • C:\Users\[UserName]\AppData\Local\[SET OF RANDOM CHARACTERS]
  • C:\Users\[UserName]\AppData\Local\[SET OF RANDOM CHARACTERS]
  • C:\Users\[UserName]\AppData\Local\Temp\[SET OF RANDOM CHARACTERS]
Registry values:
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe" -a "%1" %*'
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe" -a "%1" %*'
  • HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe" -a "%1" %*'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"C:\Users\[UserName]\AppData\Local\[3 RANDOM CHARACTERS].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'
Share this information with other people: