Sunday, 14 April 2013

Remove Win32.downloader.gen, removal instructions

This page contains removal instructions for the Win32.downloader.gen virus. Please use this guide to remove Win32.downloader.gen and any associated malware from your computer. Ok, so, most of us have heard of the term ‘Trojan Horse’ in relation to computer viruses but if you are not sure what exactly a Trojan horse is and how it infects your PC you might be want to know a little more about it. In this article we will take a look at what exactly a Trojan downloader is and, more importantly, how you can protect yourself and your data from being infected and corrupted.

Firstly, how does a Trojan horse infect your computer? Well it may be hard to believe but you actually play a part in the infection yourself because for a Trojan horse to do its damage, you actually need to install the client part of the application yourself. Sounds crazy, doesn’t it? Why would you physically take steps to infect your own computer, you ask, and quite rightly so. Well this is where the malicious intent behind the Trojan comes in to play as the creator of it needs to somehow convince you to download the application.

Typically this is done by social engineering – what this means is that the author of the Win32.downloader.gen will manipulate and convince you to perform an action or to divulge personal information somewhat unwittingly or against your will. Another way of getting you to install the Trojan horse on your computer system is to send you it in an email, with the hope that you will open the attachment. And this is precisely why it is called a Trojan horse; because you have to run the .exe file in order to install the program on your computer. Whether you do this knowingly or unknowingly is irrelevant, but the end result will be a nasty infected PC or laptop.

Although people often call it such, it is precisely because of this that a Trojan horse cannot be classed as a virus; because viruses reproduce on their own. As soon as you have executed the program, the application belonging to the Trojan will be installed and will immediately start running automatically every time you log on to your computer.

Win32.downloader.gen can quite literally spread like online wildfire as the majority of their developers like to spread them via email. They will send out possibly hundreds, or maybe even thousands of emails to a random selection of people via spam email and anyone who opens the email and is then unlucky or incautious enough to download the attachment will end up with an infected computer system.

Did you know that your computer can become a zombie? And no, we’re not talking about one of the walking dead from a TV show or movie. It doesn’t even have to be a person sitting at their computer and maliciously emailing their Trojan horses to unsuspecting users. It could actually be your very own computer that is at fault! If your computer system has already been infected, the person responsible for the Trojan horse in the first place may have sent you, amongst other victims, a Trojan that has turned your PC into a so-called ‘zombie computer’, meaning that they are actually in control of your system! As its name suggests, this particular Trojan will download and install additional malware onto your computer, that's why it's called downloader. Of course, it can easily install spyware or DDos modules or even Bitcoin mining trojan. This type of Trojan horse is particularly nasty because you will very likely be completely unaware that you are being remotely controlled by a hacker who will in turn be using your computer to send out more Trojans or viruses. This will eventually create an entire network of zombie computers, all at the mercy of the malicious hacker. These networks are called botnets.

If all of this sounds like something from a science fiction horror movie, don’t panic because there are steps you can take to protect yourself from becoming the victim of Win32.downloader.gen – or becoming the owner of a zombie computer. First of all, you should never even open an email from a sender that is unknown to you, and you should most definitely not download any attachments included in an email from an unknown sender either. Most spam messages will probably find their way directly to your junk email folder anyway, but don’t be fooled if one does slip through the net and make it to your inbox. If it doesn’t come from someone you know, if in the slightest bit of doubt, delete it.

Another thing to do is to make sure you have reputable – and up-to-date antivirus software installed on your computer as this will scan all of the files that you download, even ones from someone in your contact list. Furthermore, make sure your software and OS is up-to-date as well. This can be easily done using Personal Software Inspector from Secunia. If you do suspect that you’ve been infected with Win32.downloader.gen, you should download recommend antimalware software and run full system scan. Very often users say that their antivirus found the infection but can't remove Win32.downloader.gen, in such case please follow the removal instructions below. If you need help, leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Win32.downloader.gen removal instructions:

1. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



2. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



3. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of this virus from your computer.

Friday, 12 April 2013

Qvo6 Removal, How To Uninstall

This page contains step by step removal instructions for the Qvo6 browser hijacker/adware. At first glance it may look like a typical browser hijacker and technically it is but I think we shouldn't forget the main goal of browser hijacking - advertising. It's not a secret that scammers hijack web browsers in order to promote their search engines or other services as well as display ads. In this day and age we are all used to advertising being part and parcel of our everyday lives but it’s not only billboards and TV advertising that aim to influence the things we buy as now even our computers are used to target us and try and tempt us to click and spend. So, browser hijacking is not only unethical practice but also potentially malicious.

Qvo6 is promoted mainly through software download websites and freeware. Once installed, this browser hijacker will make http://www.Qvo6.com your homepage. It will also come up when you open new tab. Searching directly from omnibox in Google Chrome or from address bar will load results from entirely different search engine search.globososo.com. If you will use Qvo6 custom search it will surprisingly redirect you to Google search engine.



You most probably know these adverts as pop-up boxes, and let’s be honest, most of us find them pretty annoying. Do you actually pay any attention to pop-ups or do you just close them instantly? However they must be effective in some way as they are increasingly used and show no signs of abating. So what is the point of browser hijacking and adware? Basically its function is to generate revenue for its creator or author and whilst adware alone does not do any damage to your computer.

The spyware, which is software that is intended to gather information about the way you use your computer; which websites you visit and so forth, is designed so that you don’t know it is there and it will be integrated with the adware. Qvo6 may track your web surfing habits, so I guess we can safely assume that it it's spyware at some point. At least it doesn't collect personally identifiable information.

So, as we can see, some of those innocent, if somewhat annoying, little pop-up adverts can have a dangerous side to them too. If software which has been designed to monitor and detect which websites we are visiting has been integrated in with the advert it will most likely to be used to then present us with advertising which is relevant to the sites that we are looking at. For example, if you often spend time looking at websites which sell lady’s shoes and clothing, you may well get advertising pop-ups that display female fashion. This means that that particular advert has software monitoring integrated and has therefore been noting which websites you have been recently viewing.

As well as some adware being spyware or privacy invasion software, it may also be what is called shareware (or trialware or demoware). This is software which is provided to the end user, i.e. you or me, for a trial period only. Shareware will normally only give us a ‘taster’ of the full package and will have limited functionality, and it will be provided with a view to getting us to then purchase the full package.

The difference between adware and other types of shareware is that it is mainly supported by the advertising function. We may even be offered the option of a ‘registered’ or ‘licensed’ version of the software that doesn’t feature any advertising – but of course this will come at a price! Some software does it in reverse however. For example some email clients have what is called an adware mode embedded in their programming. You will be able to use the email account with full functionality and able to access all the features for a trial period and when that has expired you’ll be offered a choice of whether to continue using it for free, but with less functions than before, or you can continue using it for free with all functions but with adverts or finally – and you can probably see this one coming! – you can either pay a fee to continue using your account with all of its functions and no adverts.

All in all, Qvo6 browser hijacker may come bundled with freeware and shareware. Read installation details very carefully and especially pay attention to such annoying "offers" as Qvo6.com. Some people find it really difficult to remove this infection from their computers mainly because of two reasons: it's not listed in Control Panel (not the exact name) and it also uses this really nasty trick to add additional line to web browsers' shortcuts forcing them to load the Qvo6 search page.

Without a doubt, this application has a malware behaviour. It downloads and installs additional applications in background without user knowledge. Some components are actually detected as either adware or even Trojan. Guys who created this software did all they could to protect the software from debugging and quick analysis. What is more, Qvo6 creates a new Windows service named eSafeSvc and starts it. Please note that they configure Windows registry so that this service and the pseudo search engines are loaded automatically when Windows starts.

To completely uninstall Qvo6 from your computer please use the guide below. If you have any questions, feel free to ask. Comments and useful suggestions are welcome too. Simply leave a comment below. Good luck and be safe online!



Qvo6 removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Uninstall Qvo6 and related programs from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control PanelAdd/Remove Programs.
If you are using Windows Vista or Windows 7, select Control PanelUninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove eSave Security Control, Qvo6 toolbar, New Tabs Uninstall, Desk 365, BrowserProtect and any other recently installed application. As I said earlier, this application is rarely listed as Qvo6 in the currently installed programs list. So, either look for applications mentioned here or try to remember what software you installed recently. It's probably the culprit.



Simply select the application and click Remove. If you are using Windows Vista, Windows 7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove Qvo6 from Google Chrome:

1. Click on Customize and control Google Chrome icon. Select Settings.




2. Click Set pages under the On startup.


Remove Qvo6.com by clicking the "X" mark as shown in the image below.



3. Click Show Home button under Appearance. Then click Change.



Select Use the New Tab page and click OK to save changes.



4. Click Manager search engines button under Search.



Select Google or any other search engine you like from the list and make it your default search engine provider.



Select Qvo6 from the list and remove it by clicking the "X" mark as shown in the image below.



5. Right-click the Google Chrome shortcut you are using to open your web browser and select Properties.

6. Select Shortcut tab and remove "http://www.qvo6.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Chrome executable file. Nothing more.




Remove Qvo6 from Mozilla Firefox:

1. Click on the Qvo6 search icon as shown in the image below and select Manage Search Engines....



2. Select Qvo6 from the list and click Remove to remove it. Click OK to save changes.



3. In the URL address bar, type about:config and hit Enter.



Click I'll be careful, I promise! to continue.



In the search filter at the top, type: Qvo6



Now, you should see all the preferences that were changed by Qvo6. Right-click on the preference and select Reset to restore default value. Reset all found preferences!





4. Right-click the Mozilla Firefox shortcut you are using to open your web browser and select Properties.

5. Select Shortcut tab and remove "http://www.qvo6.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Firefox executable file.




Remove Qvo6 in Internet Explorer:

1. Open Internet Explorer. Go to ToolsManage Add-ons.



2. Select Search Providers. First of all, choose Live Search search engine and make it your default web search provider (Set as default).



3. Select Qvo6 and click Remove to remove it. Close the window.



4. Right-click the Internet Explorer shortcut you are using to open your web browser and select Properties.

5. Select Shortcut tab and remove "http://www.qvo6.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Internet Explorer executable file.



6. Finally, go to ToolsInternet Options and restore your home page to default. That's it!

Thursday, 11 April 2013

XP Security Cleaner Pro Removal, How To Get Rid Of It Completely

This page contains step by step removal instructions for the XP Security Cleaner Pro computer virus. These days scareware can still pose a very real and serious threat with victims suffering a great deal of upset and stress as a result. This particular scareware example belongs to infamous Rogue.FakeRean-Braviax malware family. It's not dead yet, cyber crooks register new domains, improve the rogue software and even offer affiliate system for those who would like to distribute this malware.

So what is XP Security Cleaner Pro, how can you tell if you’ve been affected by it and how can you protect yourself from falling prey to it?


XP Security Cleaner Pro is a cleverly designed scareware which has been designed to look just like real antivirus software. When the rogue AV is running on your computer, pop up boxes will start appearing on your screen, asking you if you like to have your computer scanned for viruses or telling you that it’s running slowly and needs cleaning.

It is distributed mostly through hacked websites and fake online virus scanners claiming that your computer is infected with spyware. Social engineering have an important role too.

Once your computer is infected with this malware, a fake Windows Security Center notification will pop up on your computer screen claiming that your antivirus software is turned off.


Then a GUI (a graphical user interface) will be launched and will show you a fake scanning procedure allegedly running through your system and finding so-called viruses. Once the false scan is ‘complete’ the software will normally tell you that your PC or laptop is riddled with viruses and has malicious software downloaded. It will then usually display a window asking you whether you want to continue using your computer without protection or if you would like the software to get rid of ‘the viruses’ for you. DO NOT pay for rogue antivirus products! Never.

Unfortunately, the majority of us will probably decide to get rid of all those nasty viruses that we now think are affecting our PC and we’ll click the corresponding button. Next we’ll be told that to do this we’ll need to pay for the service and be asked to enter our credit card details. Again, it's one thing when you have to pay for genuine security software that will remove found threats and protect your PC from other malware but XP Security Cleaner Pro virus is not one of them. So, once again, DO NOT pay for it.

Placing our faith in our new antivirus software friend, we’ll enter our credit card details and just like that we’ll not only be charged for having had our computer fake-scanned and absolutely no viruses or malware removed but we’ll also be leaving ourselves wide open to identity theft. And that’s not all: XP Security Cleaner Pro may also log how many keys we’re hitting on our keyboards, actually install further malicious software packages and viruses, corrupt documents and even steal our personal files - which naturally further exacerbates the identity theft issue. I've testes at least ten or maybe even more different variants of this rogue security program and what I've noticed is that it rarely comes separately from other malware, mostly rootkits and generic Trojans.
Just like any other fake AV out there, it displays fake security alerts to further scare you into believing that your computer is infected. Less computer savvy users can hardly see the diference because cyber crooks use well designed fake notifications that look like a real thing. Here are a few examples:

XP Security Cleaner Pro Firewall Alert
Chrome is infected with Trojan-BNK.Win32.Keylogger.gen.



Virus infection!
System Security was found to be compromised. Your computer is now infected. Attention, irreversible changes may occur. Private data may get stolen. Click here now for an instant anti-virus scan.



So how can we protect ourselves against rogue antiviruses and what do we need to look out for? One of the most important things you can do in the fight against fake AV is to already have reputable antivirus software running on your machine. If you don’t already have it installed, check online for honest providers of AV and download a suitable one. There are many free versions so you don’t even have to pay if you want a basic package. From my experience however, free antivirus program rarely protect from such infections. You should really consider purchasing a decent and reliable antimalware product.

Now you’ve got antivirus protection make sure you familiarize yourself with your provider’s name, their logo and also the way they design their pop-up boxes. If you do get a pop up box from a different company claiming that your system is slow or needs cleaning, it is very likely to be a rogue imposter. Another thing to set alarm bells ringing is credit card payment screens. If you’re using a genuine antivirus software company and your download is up to date or you’re on a basic free package, they will not be asking you to make payment for the basic function of scanning and cleaning your PC or laptop. The rule of thumb is to not enter your credit card or other personal information anywhere that you are not 100% sure is completely safe.

If you have entered your credit card number and have any kind of doubts about the company you’ve just paid, get in touch with your bank or credit card company as soon as possible and ask them to run through the transactions made on that day. However be aware that just because nothing else has been charged to your card yet, you are not completely safe and you should ask for a new card to be issued and then destroy your current one as the criminals behind the fraudulent software may have collected your details with a view to selling them on to a third party.

To get rid of XP Security Cleaner Pro and related malware please use the guide below. If you have any questions, feel free to ask. Simply leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Method 1: XP Security Cleaner Pro removal using activation key:

1. Use any of the keys listed below to register this infection and stop the fake security alerts.

9443-077673-5028
3425-814615-3990
2233-298080-3424
1147-175591-6550

Just click the Registration button (top right corner of the fake scanner).



Select Manual Activation.



Enter XP Security Cleaner Pro activation key and then select Activate Now. Don't worry, this is completely legal. If the activation keys do not work anymore, please follow the alternate removal instructions below.



Once this is done, you are free to install recommended anti-malware software and run a full system scan to remove the rogue program from your computer completely.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.






Method 2: XP Security Cleaner Pro removal instructions in Safe Mode with Networking:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Open Internet Explorer. In the Address bar type: http://goo.gl/AXIrU (this is a download link for FixNCR.reg) and click hit Enter or click Go to download the file.



3. Save FixNCR.reg to your Desktop. Double-click on FixNCR.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.



4. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





NOTE: don't forget to update anti-malware software before scanning your computer.

Wednesday, 10 April 2013

System Care Antivirus Removal, How To Uninstall

This page contains step-by-step instructions on how to remove System Care Antivirus from your computer. System Care Antivirus is both an annoying issue and one that can have a far-reaching knock on effect – even going so far as to leave you financially out of pocket. It's yet another rogue security application from the Rogue.WinWebSec scareware family, currently being distributed through infected websites and spam.

How does it find its way onto your PC in the first place, how do you know if you've been affected – and most importantly; how do you prevent it from happening?

Rogue antivirus software, including this one, is normally extremely professional looking and to the untrained eye it is virtually impossible to distinguish between a legitimate version and a fake one. Unless you are familiar with scareware families or did some sort of investigation or research yourself. The criminals behind this fake AV are clever – in fact the industry is worth over a billion dollars per year! At least it was so profitable a fee years a ago. They design a graphical user interface (or GUI for short) that looks just like a genuine antivirus application and once this rogue version is running on your PC, the GUI is launched which in turn displays a bogus scanning procedure on your screen. However it is completely false and no scan will be occurring.


Once the fake scan has been ‘completed’, System Care Antivirus will then tell you that your PC is infected and that you have unwittingly installed malicious software or fallen victim to a virus. Usually it lists at least twenty supposedly detected infections on your computer ranging from low severity to extremely dangerous. What happens next is that the fake antivirus software will normally offer you two choices: one to clean your computer system for you, thus getting rid of the viruses or two it will ask if you want to continue using your computer without protection. Most of us will of course take the software up on its kind offer to remove the viruses. DO NOT pay for it!

So, not only are we now making payment and handing over our hard earned cash for something unnecessary that doesn’t actually exist, but we’re leaving ourselves wide open to identity theft, fraud and bank account hacking too. And it’s not just about the money and the ID, the fake antivirus application is often also able to log your key strokes, steal documents from your files, and actually do the one thing that it is claiming to assist with: it will infect your other files, your networks and even install more malicious malware. Very often this rogue AV program comes in the same package with trojan droppers and rootkits, for instance Sirefef.

So let’s just sum that up: you are paying for the privilege of letting supposed antivirus software install actual viruses onto your computer or laptop!

So how does System Care Antivirus find its way on to your PC? Well there are in fact a few different methods that the creators of rogue antiviruses use – all of them designed to catch you off guard and leave you none the wiser that you’re a victim. Firstly, it can come through your inbox. You see that attachment to an email or that link embedded into correspondence? Stop before you open it or click on it as it may be malicious. If you don’t know the sender it’s wise to ignore the mail, although having said that anyone can fall victim to viruses so there’s no guarantee that a friend isn’t unknowingly sending you an infected attachment.

Furthermore, this scareware may also be found and accidently downloaded via a social media site such as Twitter or Facebook, with a link taking you to a website that will automatically download the rogue AV on to your computer. The software can also be downloaded by malware (short for malicious or malevolent software) that is already present on the PC’s system. Although very unlikely, but this application may be downloaded from its official website hxxp://systemcare-antivirus.org. Once the software is on your system, pop up boxes will start appearing asking you if you want to scan and clean your computer.

Warning: Your computer is infected
Detected spyware infection! Click this message to install the last update of security software...


Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs.
Click here to remove it immediately with System Care Antivirus.


So what are the warning signs and when should you be on your guard? The first thing to do is to make sure you know what genuine antivirus software you already have installed on your computer: know its name, its logo and familiarise yourself with what its design looks like. That way if any other so-called antivirus software pops up on your screen you’ll know that it’s most probably fake. If you don’t already have antivirus software running on your system, you should take steps to protect yourself as soon as possible and download one from a reputable antivirus software manufacturer’s website.

These days thanks to identity theft becoming an increasing problem, fake AV’s can present a very real risk, so take steps to protect yourself, make sure you have antivirus software installed and that you know who your provider is.

If your computer is already infected, you will have to use recommend anti-malware software to remove System Care Antivirus virus and any other malware that could have been installed on your computer. Of course, the rogue application may be removed manually, but even if you are lucky enough to get rid of it manually, I still highly recommend scanning your computer with anti-malware software.

If you need help with remove this malware, please post your comment or question below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Method 1: System Care Antivirus removal guide using activation key:

1. Open System Care Antivirus. Click the "Registration" button.



Enter the System Care Antivirus activation key given below and click "Activate" to activate the rogue antivirus program. Don't worry, this is completely legal since it's not genuine software.

AA39754E-715219CE




Once this is done, you are free to install recommended anti-malware software and remove System Care Antivirus from your computer.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this malware from your computer.





NOTE: if you can't run anti-malware software, rename the installer to iexplore.exe and try again.


Method 2: System Care Antivirus removal in Safe Mode with Networking:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this malware from your computer.





NOTE: if you can't run anti-malware software, rename the installer to iexplore.exe and try again.


Method 3: System Care Antivirus manual removal guide:

1. First of all, go to your Desktop and right click the System Care Antivirus.lnk shortcut file and select Properties.



2. Select Shortcut tab. Find the location of System Care Antivirus executable file (target location). It should be a randomly named file. Simply click the Find Target button.



3. Browser to the executable file. Rename it, for instance to virus.exe. Restart Windows.



4. Download recommended anti-malware software (direct download) and run a full system scan to remove this malware from your computer.





NOTE: if you can't run anti-malware software, rename the installer to iexplore.exe and try again.