Monday, June 14, 2010

Defense Center Removal Guide

Defense Center Removal Guide
Defense Center is a fake antivirus program that try to trick the user to buy the full version of Defense Center by using fake scan results. Defense Center installs itself into the computer without confirmation of the user unless the user set the UAC level to the highest level. Defense Center start itself when the computer boot and scan the computer automatically and produce fake scan result and keep on warning the users to buy the full version of Defense Center.

Defense Center also disable Windows Task Manager so that the user cannot stop its process. However, we can stop the process by using a-squared HiJackFree. It also uninstall several antivirus program such as Malwarebytes', F-Secure, Trend Micro, and Symantec Antivirus.

Defense Center provide fake features such as Antivirus and Antispyware protection (DEMO version), Network Shield (Firewall)(DEMO version), Automatics Updates(DEMO version), Scheduled Scans, RAM Protection. It urge the user to buy the full version so that the user can have the full active Antivirus and Antispyware protection, Network shield and Automatic Updates. It always show the user that the computer is not protected! It asks the user to activate the protection.

Defense Center should be removed immediately.


Defense Center Removal Guide
Kill Process
(How to kill a process effectively?)
defcnt.exe
Uninstall.exe
spam001.exe
spam002.exe
spam003.exe
troj000.exe

Unregister DLL files
%Program Files%\Defense Center\defext.dll
%Program Files%\Defense Center\defhook.dll

Delete Registry
HKEY_USERS\S-1-5-21-861567501-152049171-1708537768-1003_Classes\secfile
HKEY_CURRENT_USER\Software\Classes\secfile
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CLASSES_ROOT\secfile
HKEY_LOCAL_MACHINE\SOFTWARE\Defense Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Defense Center
HKEY_LOCAL_MACHINE\SOFTWARE\Program Groups
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Defense Center"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5E2121EE-0300-11D4-8D3B-444553540000}"

Remove Folders and Files
%Documents and Settings%\All Users\Favorites\_favdata.dat
%Program Files%\Defense Center
%UserProfile%\Desktop\Defense Center Support.lnk
%UserProfile%\Desktop\Defense Center.lnk
%UserProfile%\Desktop\nudetube.com.lnk
%UserProfile%\Desktop\pornotube.com.lnk
%UserProfile%\Desktop\spam001.exe
%UserProfile%\Desktop\spam003.exe
%UserProfile%\Desktop\troj000.exe
%UserProfile%\Desktop\youporn.com.lnk
%UserProfile%\Start Menu\Programs\Defense Center
%appdata%\microsoft\internet explorer\quick launch\Defense Center.lnk
%commonprograms%\Defense Center

Friday, June 4, 2010

Sysinternals Antivirus Removal Guide

Sysinternals Antivirus Removal Guide
Sysinternals Antivirus is a fake antivirus which is a fake security application. Sysinternals Antivirus install into computer through malwares without any permission of the user unless UAC is set to the highest level (for Windows 7 users). Sysinternals Antivirus will automatically run when windows boot. Sysinternals Antivirus produce false scan result and urge the user to activate the protection by purchasing the full version of Sysinternals Antivirus.

Sysinternals Antivirus once is installed in the computer, it will tell the user that the Windows is in danger! It will scan the computer and show that there are n Infection Found. It even state the malwares that infect the files such as Email-Worm.Win32.Meronda and in fact, it is a fake result. It provide fake features like System Scan, Firewall, Update etc.

Sysinternals Antivirus should be removed immediately!


Sysinternals Antivirus Removal Guide
Kill Process
(How to kill a process effectively?)
alggui.exe
%Program Files%\svchost.exe
dbsinit.exe
Sysinternals Antivirus.exe
ccsmn.exe
ccsrr.exe

Unregister DLL files
%Program Files%\adc_w32.dll

Delete Registry
HKEY_CURRENT_USER\Software\Sysinternals Antivirus
HKEY_USERS\.DEFAULT\Software\Sysinternals Antivirus
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adbupd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256d5-e103-4523-bb43-2cfb066839d6}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{149256d5-e103-4523-bb43-2cfb066839d6}
HKEY_CLASSES_ROOT\CLSID\{149256d5-e103-4523-bb43-2cfb066839d6}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavapp"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavappr"

Remove Folders and Files
%Program Files%\adc_w32.dll
%Program Files%\alggui.exe
%Program Files%\extra1.dat
%Program Files%\extra2.dat
%Program Files%\nuar.old
%Program Files%\skynet.dat
%Program Files%\svchost.exe
%Program Files%\wp3.dat
%Program Files%\wp4.dat
%Program Files%\scdata
%Program Files%\Sysinternals Antivirus
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.acf
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.ltd
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.lti
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.acb
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.aci
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.mt
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\lleod150
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmharun.log
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmrun.log
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus

Wednesday, June 2, 2010

Protection Center Removal Guide

Protection Center Removal Guide
Protection Center is a fake antivirus program which try to trick the user to purchase the full version of fake antivirus. It infects the computer through installing trojans and start it when computer boot. Protection Center use false scan result to make the users to purchase the fake antivirus. It may also stop the user from using anti-malware programs or antivirus.

Protection Center provide fake features like Antivirus and Antispyware protection, Network shield (Firewall), Automatic Updates, Scheduled Scans and even RAM protection. It acts live a real and good antivirus. Protection Center is installed as unregistered version. It shows the users that the computer is not protected and ask the user to upgrade to full version.

Protection Center must be removed immediately!


Protection Center Removal Guide
Kill Process
(How to kill a process effectively?)
wscsvc32.exe
mswinsck.exe
uninstall.exe
protcen.exe
cntprot.exe

Unregister DLL files
%Program Files%\Protection Center\cntext.dll
%Program Files%\Protection Center\cnthook.dll
%Documents and Settings%\All Users\Application Data\fiosejgfse.dll
%Program Files%\Protection Center\prothook.dll
%Program Files%\Protection Center\protext.dll

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Protection Center"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
HKEY_LOCAL_MACHINE\SOFTWARE\Protection Center
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Protection Center
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense
HKEY_CLASSES_ROOT\secfile
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CURRENT_USER\Software\Paladin Antivirus
HKEY_CURRENT_USER\Software\Malware Defense
HKEY_CURRENT_USER\Software\Classes\secfile

Remove Folders and Files
%Documents and Settings%\All Users\Application Data\fiosejgfse.dll
%Temp%\wscsvc32.exe
%Temp%\mswinsck.exe
%Temp%\4otjesjty.mof
%Program Files%\Protection Center
%Documents and Settings%\[UserName]\Application Data\Microsoft\Internet Explorer\Quick Launch\Protection Center.lnk
%Documents and Settings%\[UserName]\Start Menu\Programs\Protection Center
%Documents and Settings%\[UserName]\Desktop\Protection Center.lnk
%Documents and Settings%\[UserName]\Desktop\Protection Center Support.lnk