Thursday, 24 January 2013

Livesearchnow redirect virus - removal guide

Livesearchnow redirect has been a topic of conversation in technical support forums and security related websites recently. The problem isn't new but unfortunately it seems that more and more computers become plagued by this pesky redirect malware. So, I thought I would shed a little light on this topic as well.

Here's the problem, when clicking on Google or other search results, users get redirected through http://click.livesearchnow.com to random landing pages, sponsored search results or simply web pages filled with ads. This happens regardless of a web browser or search engine. While it can be a very persistent infection, most of the time, redirects happen at random. Sometimes users get the right websites and sometimes they get the http://click.livesearchnow.com. Landing pages are rarely the same as well. Please note that the click.livesearchnow domain itself is not malicious. From a technical point of view, it's a tracking domain. It is used to identify and qualify traffic sent by an advertising network partners. It's a very common practice, tracking domains are used by all big internet players and there's nothing wrong about that.



While most users use Google to find information on the internet, some of them blame Google, saying that they are infected with the Google redirect virus rather then livesearchnow virus. Of course, Google has nothing to do with those redirects and can’t be held responsible because it yields correct results.

Livesearchnow redirect virus is not the same for everyone. If you get sent to click.livesearchnow.com and then to random web pages, then your computer may be infected with Pihar, ZeroAccess/Sirefef rootkit, Tracur, DNS changing malware or even potentially unwanted programs (PUPs). Any of these can be the culprit. That's why removal procedures are usually slightly different. For example, let's say your computer is infected with Pihar or ZeroAccess rootkits. These rootkits maliciously intercepts HTTP requests and redirects victims to spammy or malicious websites that are controlled by cyber crooks. Or if they do not have their own advertising platforms, cyber crooks tend to abuse existing ones, such as http://click.livesearchnow.com.

Pretty much the same can be said about DNS changing malware, except that normally cyber criminals using DNS changer virus have to maintain their own ad networks in order to effectively monetize traffic. Typically, a few web servers would be enough to run a medium size ad network and fulfill their customers' needs. Needless to say, ad networks that are controlled either by malware authors themselves or cyber crooks who simply rent malware are very dangerous. They can serve malware without any problems only if they get paid for that. No ethics, no ad control.

Potentially unwanted programs, including malicious web browser extensions are also used to redirect victims to http://click.livesearchnow.com. Actually, they become very popular lately, due to their low cost and detection rates. PUPs, malicious web browser extensions and browser helper objects can be very difficult to remove and they may even hide behind more obvious infections, such as Trojan horses and computer worms.

Removing Livesearchnow redirect virus isn't that difficult; some people recommend letting a security expert to do it. However, I'm pretty sure guys that you will be able to remove it yourselves, using the right tools. If you your machine is infected with a rootkit, you will have to use anti-rookit utility because some anti-malware products can't handle certain rootkits, for example ZeroAccess. If it's the DNS changer, Spyware Doctor or any other popular malware removal tool will definitely remove it. You may have to restore certain system settings manually after the removal, though. And finally, if it's a malicious add-on, you will have to remove it yourself. Antivirus programs rarely detect and remove potentially harmful add-ons. So, to remove this virus from your computer, please follow the removal instructions below.

Going forward, avoid warez software, unknown adult sites and other sketchy websites. Keep your anti-malware software up to date and fully active at all times. Do you have something to say about removing the Livesearchnow virus? Post your comment or question below. Good luck and be safe online!


Livesearchnow redirect virus removal instructions:

1. First of all, scan your computer for malicious software. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





2. Reset the Hosts file back to the default. To reset the Hosts file back to the default automatically, download Microsoft Fix it utility, run the file and then follow the steps in the Fix it wizard.

3. Flush DNS cache.

A. Go to Start->Run (or WinKey+R) and type in "cmd" without quotes.


B. At the command prompt, please type "ipconfig /flushdns" without quotes and hit Enter.


4. If the problem persists, please read this web document and follow the steps carefully: http://deletemalware.blogspot.com/2010/02/remove-google-redirect-virus.html

Share this information with your friends:

Friday, 18 January 2013

Text Enhance Removal Guide

Text Enhance is an intext advertising platform that allows publishers to monetize their content. At first glance, it's no different than any other advertising platform, except for one thing – publishers can use "plugins" to display intext ads. Broadly speaking, this term "plugin" is used to describe a web browser extension or an add-on. The idea is not necessarily bad and it might even work but it seems that the platform is already being abused a lot. Image how hard it would be to convince your visitors to voluntarily install such Firefox or Chrome extensions that highlight certain words on nearly every site you visit and turn them into tiny little ads. I think that's almost impossible. That's why cyber crooks use social engineering, fake alerts and notifications to convince users into installing such web browser extensions. Besides, publishers can bundle Text Enhance extensions and add-ons with other software.

Text Enhance shows up as links in websites you view. This can be a very irritating situation because malicious web browser extensions use the same hyperlink style as the website you view. When you hover over Text Enhance link, it says "Powered by Text-Enhance" and then displays an advertisement that is not necessarily relevant to the topic you are reading on that particular website.

Here’s an example of a "work at home" advertisement displayed by Text Enhance on a very popular gaming forum.



Another example, "Win an iPad" ad showed up when I hovered over a word "your" in the middle of the text. The ad is completely irrelevant.



Dating ads are very popular as well. Hovering over "girlfriend" will probably display ads similar to this one.



What is more, very often these ads lead users to spammy and even dangerous websites. Who can guaranty you that cyber crooks are not using this platform to distribute Trojans, spyware and other malicious software? I guess no one. So, if you think that your computer might be or almost certainly is infected with Text Enhance virus, I highly recommend you to remove it. By the way, you can follow the opt-out procedure which is available on the official Text Enhance website to bock ads, but I'm afraid it might not work in case you got infected with this malware.

Text Enhance malware is distributed mostly through the use of warez and online video streaming websites. Usually, scammers display fake notifications that your Flash player is not updated or that you need to install a "special" plugin in order to watch requested video or download files.

Here's how the fake "Error: missing plugin" warning looks like (Mozilla Firefox).



The same warning message displayed in Google Chrome.



Both warnings are very misleading and unfortunately may trick users into installing malicious web browser extensions. I've said this many times before: install web browser extensions and add-ons only from the official stores or websites you trust.

Here's another very popular notification claiming that "Your system doesn't support this video file". Needless to say it's completely false because all you need to watch videos online is Flash player. Sometimes it's enough to use a modern web browser, HTML5 compatible to watch videos. Stay away from extra plugins and codecs!



Antivirus programs may detect and block misleading error warnings but they rarely detect potentially harmful web browser extensions. Most of the time, they do not pose direct threats to users but they are still potentially harmful, not to mention how annoying they are. I think antivirus companies should check browser extensions, add-ons and browser helper object more carefully.

If you are infected with Text Enhance, please follow the steps in the removal guide below. It will show you how to remove Text Enhance virus in Mozilla Firefox, Google Chrome, Internet Explorer and Apple Safari.  I'm sure it will be listed as completely different program and web browser extensions. I made a list of programs and web browser extensions that are related to Text Enhance and may cause "Powered by Text-Enhance" ads to show up on your computer screen. I will update this list as often as I can. In case I missed something, please leave a comment below. One more thing, when you remove the culprit of Text Enhance ads, I recommend you to uninstall Flash player as well. Uninstall it completely and install the latest version. Text Enhance may interact with Flash Player to display ads. I noticed that when Flash Player is disabled Text Enhance ads do not show up. Last, but not least, if you have any questions or additional information about this virus, please leave a comment. Good luck and be safe online!

Source: http://deletemalware.blogspot.com


Text Enhance removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Remove Text Enhance and/or related programs from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control PanelAdd/Remove Programs.
If you are using Windows Vista or Windows 7, select Control PanelUninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove the following entries (if exist):
  • Bandicam
  • BCool
  • BeCool
  • Better Links
  • Bflix1.0
  • Browser Enhancements 1.0
  • Click 2 Save
  • CodecC
  • CodecM
  • Crossrider
  • Dealply
  • Deals Plugin
  • Downloadnsave
  • Extension
  • Facebook Dislike
  • Facetheme
  • Fantapper
  • Fast save
  • Freemind
  • Game Play Labs
  • I-livid
  • I Want That
  • I Want This
  • Iminent
  • Installed Class
  • With Java plug-ins
  • Jlmp3
  • Media Plugin
  • Pando Media Enhancer
  • Premiumplay Codec
  • Privacy SafeGuard
  • Protector by IB
  • Rewardsarcade
  • RewardsArcadeSuite
  • Splashtop Inc
  • Startnow Toolbar
  • TheBflix
  • TheBflix5.0
  • TheBflix Class
  • Toad
  • Vid-Saver
  • Video File Download
  • Vuze
  • Widgi
  • wxDfast
  • Yontoo
  • YouTube Plus
  • ZoomEx
  • ZoomIt


Simply select each application and click Remove. If you are using Windows Vista, Windows7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove Text Enhance in Mozilla Firefox:

1. Open Mozilla Firefox. Go to ToolsAdd-ons.



2. Select Extensions. If any of the extensions listed below exist, click on the Remove button next to each one. If you can't find the Remove button, then simply click on the Disable button.
  • Bandicam
  • BCool
  • BeCool
  • Better Links
  • Bflix1.0
  • Browser Enhancements 1.0
  • Click 2 Save
  • CodecC
  • CodecM
  • Crossrider
  • Dealply
  • Deals Plugin
  • Downloadnsave
  • Extension
  • Facebook Dislike
  • Facetheme
  • Fantapper
  • Fast save
  • Freemind
  • Game Play Labs
  • I-livid
  • I Want That
  • I Want This
  • Iminent
  • Installed Class
  • With Java plug-ins
  • Jlmp3
  • Media Plugin
  • Pando Media Enhancer
  • Premiumplay Codec
  • Privacy SafeGuard
  • Protector by IB
  • Rewardsarcade
  • RewardsArcadeSuite
  • Splashtop Inc
  • Startnow Toolbar
  • TheBflix
  • TheBflix5.0
  • TheBflix Class
  • Toad
  • Vid-Saver
  • Video File Download
  • Vuze
  • Widgi
  • wxDfast
  • Yontoo
  • YouTube Plus
  • ZoomEx
  • ZoomIt


Once you have found and removed all of the above extensions that were installed on your computer, you can close Mozilla Firefox. Disabling a web browser extension might also help, however, it still exists on your PC. Some extensions might be blocked or only have an option to disable them. In such case, I recommend you to delete extensions manually.


Remove CouponDropDown in Google Chrome:

1. Click on Chrome menu button. Go to ToolsExtensions.



2. Click on the trashcan icon and remove the extensions listed below if they are present:
  • Bandicam
  • BCool
  • BeCool
  • Better Links
  • Bflix1.0
  • Browser Enhancements 1.0
  • Click 2 Save
  • CodecC
  • CodecM
  • Crossrider
  • Dealply
  • Deals Plugin
  • Downloadnsave
  • Extension
  • Facebook Dislike
  • Facetheme
  • Fantapper
  • Fast save
  • Freemind
  • Game Play Labs
  • I-livid
  • I Want That
  • I Want This
  • Iminent
  • Installed Class
  • With Java plug-ins
  • Jlmp3
  • Media Plugin
  • Pando Media Enhancer
  • Premiumplay Codec
  • Privacy SafeGuard
  • Protector by IB
  • Rewardsarcade
  • RewardsArcadeSuite
  • Splashtop Inc
  • Startnow Toolbar
  • TheBflix
  • TheBflix5.0
  • TheBflix Class
  • Toad
  • Vid-Saver
  • Video File Download
  • Vuze
  • Widgi
  • wxDfast
  • Yontoo
  • YouTube Plus
  • ZoomEx
  • ZoomIt


Once you have found and removed all of the above extensions that were installed on your computer, you can close Google Chrome. Please note, that some extensions might be locked (remove option is disabled). In such case, you have to remove those extensions manually. Enable Developer Mode to find extension's name that go to Google Chrome extension folder and delete it. Google Chrome extension folder placed in the following directory:

Windows 7 → C:\Users\[UserName]\AppData\Local\Google\Chrome\User Data\Default\Extensions

Windows XP → C:\Documents and Settings\[UserName]\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions


Remove Text Enhance in Internet Explorer:

1. Open Internet Explorer. Go to ToolsManage Add-ons. If you have the latest version, simply click on the Settings button.



2. Select Toolbars and Extensions. If any of the extensions listed below exist, select it and then click on the Remove/Disable button to remove it from Internet Explorer.
  • Bandicam
  • BCool
  • BeCool
  • Better Links
  • Bflix1.0
  • Browser Enhancements 1.0
  • Click 2 Save
  • CodecC
  • CodecM
  • Crossrider
  • Dealply
  • Deals Plugin
  • Downloadnsave
  • Extension
  • Facebook Dislike
  • Facetheme
  • Fantapper
  • Fast save
  • Freemind
  • Game Play Labs
  • I-livid
  • I Want That
  • I Want This
  • Iminent
  • Installed Class
  • With Java plug-ins
  • Jlmp3
  • Media Plugin
  • Pando Media Enhancer
  • Premiumplay Codec
  • Privacy SafeGuard
  • Protector by IB
  • Rewardsarcade
  • RewardsArcadeSuite
  • Splashtop Inc
  • Startnow Toolbar
  • TheBflix
  • TheBflix5.0
  • TheBflix Class
  • Toad
  • Vid-Saver
  • Video File Download
  • Vuze
  • Widgi
  • wxDfast
  • Yontoo
  • YouTube Plus
  • ZoomEx
  • ZoomIt


Once you have removed/disabled all of the above extensions (if existed), you can close Internet Explorer.


Remove Text Enhance in Apple Safari:

1. Open Safari. Go to Preferences.



2. Select the Extensions tab. If any of the extensions listed below exist, select it and then click on the Uninstall button to remove it from Apple Safari.
  • Bandicam
  • BCool
  • BeCool
  • Better Links
  • Bflix1.0
  • Browser Enhancements 1.0
  • Click 2 Save
  • CodecC
  • CodecM
  • Crossrider
  • Dealply
  • Deals Plugin
  • Downloadnsave
  • Extension
  • Facebook Dislike
  • Facetheme
  • Fantapper
  • Fast save
  • Freemind
  • Game Play Labs
  • I-livid
  • I Want That
  • I Want This
  • Iminent
  • Installed Class
  • With Java plug-ins
  • Jlmp3
  • Media Plugin
  • Pando Media Enhancer
  • Premiumplay Codec
  • Privacy SafeGuard
  • Protector by IB
  • Rewardsarcade
  • RewardsArcadeSuite
  • Splashtop Inc
  • Startnow Toolbar
  • TheBflix
  • TheBflix5.0
  • TheBflix Class
  • Toad
  • Vid-Saver
  • Video File Download
  • Vuze
  • Widgi
  • wxDfast
  • Yontoo
  • YouTube Plus
  • ZoomEx
  • ZoomIt


Once you have removed all of the above extensions (if existed), you can close Apple Safari.


Optional steps:

1. Opt-out of text-enhance.com advertisements → http://text-enhance.com/optout.php

3. Uninstall Flash Player. Please follow this uninstall guide.

3. Download and install the latest version of Flash Player. Download is available here.

Tell your friends:

Thursday, 10 January 2013

Remove CouponDropDown Pop-ups (Uninstall Guide)

CouponDropDown is an ad supported application that will automatically display available coupons for the website you're browsing. It might be useful for some of you since this application offers valid (they were valid at the time I checked them) coupons and it's available on some well know online merchants. Even though it might be useful, it's still an ad supported application so it will definitely display ads on your computer as you browse the web. It might be pop-up windows in various forms, pop-unders, in-text advertisements an so on.

That's how a typical CouponDropDown pop-up looks like:



There are many forum threads and blog posts about this application or associated web browser extensions and most of them are negative. Most people take up the position that Coupon DropDown is almost certainly some kind of malware. Others say it's simply a virus. From what I've seen it's definitely not a virus, Trojan horse or spyware. It's adware and that's not a secret, you can find this information on their website. You can use command line malware scanner such as Virus Total or Jotti to scan CouponDropDown files and you will see that only three security products detect it as either adware or potentially unwanted application. Of course, these are just command line scanners without advanced features, behavioral analysis, etc. The actual detection ratio may be different.

The real problem with CouponDropDown is that too many users tried to remove it and couldn't succeed. This is especially true if Coupon Drop Down came bundled with other applications. Users do not know where the ads are coming from because they inadvertently installed this application with some other software. I know for sure that some apps use very aggressive distribution methods and may indeed install web browser add-ons or certain parts of this application without users' knowledge. "Coupons" market is very competitive and it might be extremely difficult for new players to successfully enter it. I think that's the main reason why CouponDropDown adware comes bundled with suspicious or shady video players, downloaders and toolbars.

No wonder why people are not happy with Ads by CouponDropDown offers from different products, highlighted words and pop-ups that are pushing the real content away from them. Besides, some ads are really random and they appear on pretty much every page you visit which is very annoying. What is more, CouponDropDown might not be even listed under web browser extensions. Or it might be listed as completely different program, for example Yontoo, StartNow toolbar, 1ClickDownloader, FBPhotoZoom, Incredibar, SweetIM and many others. Sometimes users have to remove four or even more extensions that are causing the problem to completely remove the CouponDropDown adware. But how to know which one is the culprit? The official uninstall guide available on their website is useless. It only works when you install CouponDropDown directly from their website.

It’s up to you whether you want to keep it or not but if you wasn't planning to install in the first place then I highly recommend you to remove it. In order to remove CouponDropDown adware and associated files, please follow the removal instructions below. If you need any help removing this adware, please leave a comment below. Good luck and be safe online!

Source: http://deletemalware.blogspot.com


CouponDropDown removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Remove CouponDropDown and/or related programs from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control PanelAdd/Remove Programs.
If you are using Windows Vista or Windows 7, select Control PanelUninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove the following entries:
  • CouponDropDown
  • Yontoo
  • 1ClickDown
  • IB Updater
  • TornTV
  • 1ClickDownloader
  • FB Photo Zoom
  • SweetPacks Toolbar
  • GoPhoto.it
  • HDvid Codec
  • PutLockerDownload
  • Incredibar Toolbar
  • OneClickDownload
  • OneClickDownloader
  • Online HD TV StartNow
Simply select each application and click Remove. If you are using Windows Vista, Windows7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove CouponDropDown in Internet Explorer:

1. Open Internet Explorer. Go to ToolsManage Add-ons. If you have the latest version, simply click on the Settings button.



2. Select Toolbars and Extensions. If any of the extensions listed below exist, select it and then click on the Remove/Disable button that will then appear to remove it from Internet Explorer.
  • CouponDropDown
  • FBPhotoZoom
  • Yontoo
  • Yontoo API
  • GoPhoto.it
  • Online HD TV
  • HDvid Codec
  • TornTV
  • Incredibar Toolbar
  • TorrentHandler
  • Incredibar Helper Object
  • IB Updater
  • OneClickDownload
  • OneClickDownloader
  • PutLockerDownloader
  • Smartdownloader class
  • StartNow


That's it! Once you have removed/disabled all of the above extensions (if existed), you can close Internet Explorer.


Remove CouponDropDown in Mozilla Firefox:

1. Open Mozilla Firefox. Go to ToolsAdd-ons.



2. Select Extensions. If any of the extensions listed below exist, click on the Remove button next to each one. If you can't find the Remove button, then simply click on the Disable button.
  • CouponDropDown
  • IB Updater
  • HDvid Codec
  • GoPhoto.it
  • Yontoo
  • Incredibar
  • FBPhotoZoom
  • OneClickDownload
  • SweetPacks Toolbar
  • OneClickDownloader
  • TornTV
  • Online HD TV
  • PutLockerDownloader
  • StartNow Toolbar
  • TorrentHandler


That's it! Once you have removed or disabled all of the above extensions, you can close Mozilla Firefox.


Remove CouponDropDown in Google Chrome:

1. Click on Chrome menu button. Go to ToolsExtensions.



2. Click on the trashcan icon and remove the extensions listed below if they are present:
  • CouponDropDown
  • FBPhotoZoom
  • GoPhoto.it
  • HDvid Codec
  • IB Updater
  • OneClickDownload
  • OneClickDownloader
  • Online HD TV
  • PutLockerDownloader
  • StartNow
  • TornTV
  • TorrentHandler
  • Yontoo
  • ZoomIt


That's it! Once you have removed all of the above extensions (if existed), you can close Google Chrome.


Associated CouponDropDown adware files and registry values:

Files:
  • C:\Program Files\CouponDropDown\
  • C:\Program Files\CouponDropDown\CouponDropDown.dll
  • C:\Program Files\CouponDropDown\CouponDropDown.exe
  • C:\Program Files\CouponDropDown\CouponDropDown.ico
  • C:\Program Files\CouponDropDown\CouponDropDown.ini
  • C:\Program Files\CouponDropDown\CouponDropDownGui.exe
  • C:\Program Files\CouponDropDown\CouponDropDownInstaller.log
  • C:\Program Files\CouponDropDown\Uninstall.exe
  • C:\Program Files\CouponDropDown\Chrome\
  • C:\Program Files\CouponDropDown\Chrome\CouponDropDown.crx
Registry values:
  • HKCU\Software\AppDataLow\Software\CouponDropDown\
  • HKCU\Software\AppDataLow\Software\Crossrider
  • HKCU\Software\Cr_Installer
  • HKLM\SOFTWARE\Classes\CrossriderApp0004352.BHO
  • HKLM\SOFTWARE\Classes\CrossriderApp0004352.FBApi
  • HKLM\SOFTWARE\Classes\CrossriderApp0004352.Sandbox
  • HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055435552}
  • HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066436652}
  • HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077437752}
  • HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044434452}
  • HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\New
  • Windows\Allow\*.crossrider.com
  • HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011431152}
  • HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CouponDropDown
  • HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011431152}
Tell your friends:

Tuesday, 6 November 2012

How to Remove Win 7 Antivirus Pro 2013, Win 7 Antispyware Pro 2013 (Uninstall Guide)

Win 7 Antivirus Pro 2013 is a fake application that reports false system security threats on the computer. This scareware may also appear as Win 7 Antispyware Pro 2013 or use any other application name that would make it look as if it was a genuine Microsoft product. The overall graphical user interface does not change, only the application name. It seems that the rogue application changes its name randomly. Once you know how it actually looks, you can easily identify other versions of this malicious software.



Win 7 Antivirus Pro 2013 or Win 7 Antispyware Pro 2013 distribution: actually it could be and probably is distributed in many ways. Very often, such fake security applications are promoted via infected websites. I'm sure you've heard that adult sites that could be among 50 most visited sites on the net sometimes spread malware, including fake security applications. It remains unclear whether they distribute malware intentionally to earn extra cash or become victims of cyber criminals who manage to find software vulnerabilities and infect high profile websites. And I'm talking not only about adult sites. I mean any website can be used to infect PCs. Even your all time favorite blog that isn't even popular or not so popular comparing to other sites. You should also be aware of misleading emails that may contain malicious attachments or lead to potentially harmful sites.

What Win 7 Antivirus Pro 2013 is capable of? Well, first of all, it may and I'm sure it will block or disable your antivirus protection software. Once installed, this rogue application will modify Windows registry and add itself to the list of apps that start automatically when you restart your computer. Win 7 Antivirus Pro 2013 or Win 7 Antispyware Pro 2013 makes rather advanced Windows registry modifications that can be hardly restored manually, but don't worry I got a one-click fix for that. What is more, any attempt to run system tools will be interrupted by fake security notifications claiming that pretty much all the applications and tools you're trying to open are either damaged or infected by Trojans, spyware, rootkits or some other malicious software. Of course, that's far from the truth. Some false statements and security alerts you may see when your computer is infected by Win 7 Antivirus Pro 2013:
Privacy alert!Rogue malware detected in your system. Data leaks and system damage are possible. Click here for a free security scan and spyware deletion.
Tracking software found!Your PC activity is being monitored. Possible spyware infection. Your data security may be compromised. Sensitive data can be stolen. Prevent damage now by completing a security scan.
These are pretty common and typical for scareware. Especially the second one about supposedly found tracking software on your computer. I didn't count them but there were like four or five different pop-ups reporting 'critical' malware infections. When running, Win 7 Antivirus Pro 2013 will also block your web browser and display false security message:

Visiting this site may pose a security threat to your system!

Possible reasons include:
  • Dangerous code found in this site's pages which installs unwanted software into your system.
  • Suspicious and potentially unsafe network activity detected.
  • Spyware infection in your system.
  • Complaints from other users about this site.
  • Port and system scans performed by the site being visited
Once again, scammers who made this fake application will make sure that they've done everything to convince you that your computer is infected. This isn't surprising but rather interesting because they the use the same scheme for the fifth or so time in just a few years. It probably works.

What's the main goal of Win 7 Antivirus Pro 2013, Win 7 Antispyware Pro 2013 or whatever the name of this malware is? It tries to trick you into paying for a full license of the rogue application in order to remove the threats. Supposedly found threats because it only pretends to scan your computer for malware. If I were to buy this application it would cost me about 100 dollars which makes it rather expensive PC security product. On the other hand, it's a lifetime license ;)



I'm just kidding. DO NOT pay for it. Win 7 Antivirus Pro 2013 is a scam. If you thought it was a real thing and paid for it, then I think you should contact your credit card company and dispute the charges while it's not too late. That’s the only way to get your money back.

It goes without saying that Win 7 Antivirus Pro 2013 has to be removed from the system upon detection. To do so, please follow the instructions below. Questions and comments are welcome and appreciated. Good luck and be safe online!


Quick Win 7 Antivirus Pro 2013 removal:

1. Use this key: 3425-814615-3990 to register the fake security application in order to stop the fake security alerts.

Just click the Registration button and then select Activate Now. Don't worry, this is completely legal. If the debugged serial keys do not work anymore, please follow the alternate removal instructions below.



Once this is done, you are free to install recommended anti-malware software and run a full system scan to remove Win 7 Antivirus Pro 2013 from your computer properly.

2. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this malware from your computer.


Win 7 Antivirus Pro 2013, Win 7 Antispyware Pro 2013 removal instructions in Safe Mode with Networking:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Open Internet Explorer. In the Address bar type: http://goo.gl/AXIrU (this is a download link for FixNCR.reg) and click hit Enter or click Go to download the file.

3. Save FixNCR.reg to your Desktop. Double-click on FixNCR.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.



4. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus from your computer.

NOTE: don't forget to update anti-malware software before scanning your computer.


Manual Win 7 Antivirus Pro 2013, Win 7 Antispyware Pro 2013 removal instructions:

Make sure that you can see hidden and operating system protected files in Windows. For more in formation, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmarks from the checkboxes labeled:
  • Hide extensions for know file types
  • Hide protected operating system files
Click OK to save the changes.


1. Go into C:\Users\[UserName]\AppData\Local\ folder.

For example: C:\Users\Michael\AppData\Local\


2. Find hidden executable file(s) in this folder. In our case it was called vkl.exe, but I'm sure that the file name will be different in your case. Rename vkl.exe to vkl.vir and click "Yes" to confirm file rename. Then restart your computer.



3. After a restart, copy all the text in bold below and paste to Notepad.

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

4. Save file as fix.reg to your Desktop. NOTE: (Save as type: All files)


5. Double-click on fix.reg file to run it. Click "Yes" for Registry Editor prompt window. Then click OK.

6. Open Internet Explorer. Download exefix.reg and save it to your Desktop. Double-click on exefix.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.

7. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.


Associated Win 7 Antivirus Pro 2013, Win 7 Antispyware Pro 2013 files and registry values:

Files:
  • %CommonAppData%\[SET OF RANDOM CHARACTERS]
  • %LocalAppData%\[SET OF RANDOM CHARACTERS]
  • %LocalAppData%\[3 RANDOM CHARACTERS]
  • %Temp%\[SET OF RANDOM CHARACTERS]
Registry values:
  • HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = ''
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
  • HKEY_CLASSES_ROOT\[SET OF RANDOM CHARACTERS]
  • HKEY_CURRENT_USER\Software\Classes\[SET OF RANDOM CHARACTERS] "(Default)" = 'Application'
  • HKEY_CURRENT_USER\Software\Classes\[SET OF RANDOM CHARACTERS]\DefaultIcon "(Default)" = '%1'
  • HKEY_CURRENT_USER\Software\Classes\[SET OF RANDOM CHARACTERS]\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
  • HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
  • HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
  • HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = ""%LocalAppData%\[3 RANDOM CHARACTERS].exe -a "C:\Program Files\Mozilla Firefox\firefox.exe""
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = ""%LocalAppData%\[3 RANDOM CHARACTERS].exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = ""%LocalAppData%\[3 RANDOM CHARACTERS].exe" -a "C:\Program Files\Internet Explorer\iexplore.exe""
Tell your friends:

Thursday, 1 November 2012

Oficina Virtual de Denuncias virus removal

Oficina Virtual de Denuncias virus is a Spanish variant of a ransomware infection that masquerades as local law enforcement agency and tells you that you've been caught accessing illicit material online. It's a clever decision that already works perfectly fine in most English speaking countries, so obviously it should work just fine in other countries as well. In such way the ransom becomes a fine. Infected computer becomes unusable until you pay the ransom, and we’re speaking about 100 euros or even more. It depends, but usually scammers ask to pay either 100 euros in Europe and 100 dollars in the United States and also Canada.



Oficina Virtual de Denuncias virus is distributed in various ways. Recently, we've got numerous PCs infected with the TrojanDownloader:Win32/Dofoil.R malware. It's a Trojan horse that silently downloads malicious applications without consent. This could include the installation of additional malware components to an affected computer according to Microsoft. This could be anything, ransomware, spyware or even rootkits. This Trojan horse was first detected this year, back in June or July if I'm not mistaken. I couldn't say it was used to distributed ransomware until recent months. Now, cyber criminals use this Trojan horse to distribute Oficina Virtual de Denuncias virus and similar ransomware as well.

Once this Trojan horse executes additional Spanish ransom ware components, affected users' computers become unusable. The ransomware component displays completely false notification about illicit material found on your computer. It uses Spanish police logo as a part of the scam to add more trustworthiness. Cyber crooks have also implemented a flash component that can access your web camera, if you have one of course, and display either your face or part of your room. I'm sure that this web cam component rarely works but when it does it can scare the living hell out of someone. The fake Oficina Virtual de Denuncias message says:
El ordenador suyo está bloqueado por el sistema d control informativo automatizado q está relacionado con la policía.
The ransom can be paid using either Pay Safe Card or Ukash. El ordenador suyo está bloqueado ukash is usually what users of an infected computers search for when trying to remove this virus. Both Ukash and Pay Safe Card vouchers are available to buy on various stores around the country. Nevertheless, DO NOT pay the ransom. The fake notification has nothing to do with the local authorities and besides, you've probably didn't do anything wrong whatsoever. What is more, Ukash and Pay Safe Card cannot dispute the charges. This is one of the reasons why scammers are using these services instead of Master Card and Visa payments processors.

Some variants of Oficina Virtual de Denuncias virus work in Safe Mode with Networking while others don't. First, reboot your computer in Safe Mode with Networking or Comman Prompt and try to restore your computer to an earlier date when the system was clean. If you can't do this or the virus blocks any attempts to remove it, use Kaspersky Rescue Disk or similar software if you like. Please follow detailed Oficina Virtual de Denuncias virus removal instructions below.


Oficina Virtual de Denuncias virus removal instructions (System Restore, may not work for all users):

1. Unplug your network cable and manually turn your computer off. Reboot your computer is Safe Mode with Command Prompt. As the computer is booting tap the F8 key continuously which should bring up the Windows Advanced Options Menu as shown below. Use your arrow keys to move to Safe Mode with Command Prompt and press Enter key.



2. Make sure you log in to an account with administrative privileges (login as admin).

3. Once the Command Prompt appears you have few seconds to type in explorer and hit Enter. If you fail to do it within 2-3 seconds, the Oficina Virtual de Denuncias virus will take over and will not let you type anymore.

4. If you managed to bring up Windows Explorer you can now browse into:
  • Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
  • Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter
5. Follow the steps to restore your computer into an earlier day.

6. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove Oficina Virtual de Denuncias virus and associated malware.


Oficina Virtual de Denuncias virus removal using Kaspersky Rescue Disk:

1. Download the Kaspersky Rescue Disk iso image from the Kaspersky Lab server. (Direct download link)
Please note that this is a large downloaded, so please be patient while it downloads.

2. Record the Kaspersky Rescue Disk iso image to a CD/DVD. You can use any CD/DVD record software you like. If you don't have any, please download and install ImgBurn. Small download, great software. You won't regret it, we promise.

For demonstration purposes we will use ImgBurn.

So, open up ImgBurn and choose Write image file to disc.



Click on the small Browse for file icon as show in the image. Browse into your download folder and select kav_rescue_10.iso as your source file.



OK, so know we are ready to burn the .iso file. Simply click the Write image file to disc button below and after a few minutes you will have a bootable Kaspersky Rescue Disk 10.



3. Configure your computer to boot from CD/DVD. Use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.



The keys F1, F8, F10, F12 might be used for some motherboards, as well as the following key combinations:
  • Ctrl+Esc
  • Ctrl+Ins
  • Ctrl+Alt
  • Ctrl+Alt+Esc
  • Ctrl+Alt+Enter
  • Ctrl+Alt+Del
  • Ctrl+Alt+Ins
  • Ctrl+Alt+S
If you can enter Boot Menu directly then simply select your CD/DVD-ROM as your 1st boot device.

If you can't enter Boot Menu directly then simply use Delete key to enter BIOS menu. Select Boot from the main BIOS menu and then select Boot Device Priority.



Set CD/DVD-ROM as your 1st Boot Device. Save changes and exist BIOS menu.



4. Let's boot your computer from Kaspersky Rescue Disk.

Restart your computer. After restart, a message will appear on the screen: Press any key to enter the menu. So, press Enter or any other key to load the Kaspersky Rescue Disk.



5. Select your language and press Enter to continue.



6. Press 1 to accept the End User License Agreement.



7. Select Kaspersky Rescue Disk. Graphic Mode as your startup method. Press Enter. Once the actions described above have been performed, the operating system starts.



8. Click on the Start button located in the left bottom corner of the screen. Run Kaspersky WindowsUnlocker to remove Windows system and registry changes made by Oficina Virtual de Denuncias virus. It won't take very long.



9. Click on the Start button once again and fire up the Kaspersky Rescue Disk utility. First, select My Update Center tab and press Start update to get the latest malware definitions. Don't worry if you can't download the updates. Just proceed to the next step.



10. Select Object Scan tab. Place a check mark next to your local drive C:\. If you have two or more local drives make sure to check those as well. Then click Start Objects Scan to scan your computer for malicious software.



11. Quarantine (recommended) or delete every piece of malicious code detected during the system scan.



12. You can now close the Kaspersky Rescue Disk utility. Click on the Start button and select Restart computer.



13. Please restart your computer into the normal Windows mode. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove Oficina Virtual de Denuncias virus and associated malware.


Associated Oficina Virtual de Denuncias virus files and registry values:

Files:
  • [SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "[SET OF RANDOM CHARACTERS].exe"
Tell your friends: