Thursday, August 12, 2010

My Security Shield Removal Guide

My Security Shield Removal Guide
My Security Shield is a fake antivirus program which intend to urge the user whose computer is infected by My Security Shield to purchase the full version of My Security Shield. My Security Shield produces fake alert in order to cheat the user. My Security Shield installs into the computer without the confirmation of the user and configure itself to start automatically when windows boot. My Security Shield will then scan the computer and state that there are many malware in the computer and ask the user to purchase full version of My Security Shield to remove all the malwares.

My Security Shield ask the user to activate My Security Shield to get ultimate protection against Identify Theft, Malware and other threats! My Security Shield create a fake Windows Advanced Security Center and warn the user that the system is not cleaned yet! It show the users that the Firewall, Automatics Updates and Antivirus Protection are in the "OFF" state.

My Security Shield should be removed immediately!

My Security Shield Removal Guide
Kill Process
(How to kill a process effectively?)
MS345d_2129.exe
DBOLE.exe
kernel32.exe

Unregister DLL files
mozcrt19.dll
sqlite3.dll

Delete Registry
HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\MS345d_2129.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "control/7.02129"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "My Security Shield"
HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"

Remove Folders and Files
%AllUserProfile%\Application Data\345d567
%AllUserProfile%\Application Data\MSHBXRCOBWS
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\My Security Shield.lnk
%UserProfile%\Application Data\My Security Shield
%UserProfile%\Desktop\My Security Shield.lnk
%UserProfile%\Recent\cid.drv
%UserProfile%\Recent\CLSV.tmp
%UserProfile%\Recent\DBOLE.exe
%UserProfile%\Recent\delfile.sys
%UserProfile%\Recent\fan.dll
%UserProfile%\Recent\grid.sys
%UserProfile%\Recent\kernel32.exe
%UserProfile%\Recent\kernel32.sys
%UserProfile%\Recent\PE.dll
%UserProfile%\Recent\PE.tmp
%UserProfile%\Recent\runddlkey.drv
%UserProfile%\Recent\SICKBOY.drv
%UserProfile%\Recent\std.dll
%UserProfile%\Recent\tempdoc.tmp
%UserProfile%\Recent\tjd.sys
%UserProfile%\Start Menu\My Security Shield.lnk
%UserProfile%\Start Menu\Programs\My Security Shield.lnk

Thursday, August 5, 2010

WireShark Antivirus Removal Guide

WireShark Antivirus Removal Guide
WireShark Antivirus is a fake antivirus program same as Sysinternals Antivirus. WireShark Antivirus is not made by WireShark but by other people who try to confuse the user that the antivirus is legitimate and is able to remove malwares and even provide many antivirus features. WireShark Antivirus is created to earn a profit from the user who are cheated by them. WireShark Antivirus infect the computer and then scan the computer. WireShark Antivirus produce fake warnings that the computer is infected by many malwares and urge the user to purchase the full version of WireShark Antivirus in order to remove the malwares. Don't be cheated by the fake warnings.

WireShark Antivirus produce fake features like Firewall, System Scan, Update etc. It claims to help protect your PC and scares the user that "Windows is in danger". WireShark Antivirus also produce fake detection such as showing that the files are infected by Trojan.VBS.Qhost, Trojan-Downloader.JS.Remora and other malwares. It shows the computer status: "At Risk" and ask the user to Activate Protection by buying full version of WireShark Antivirus.

WireShark Antivirus should be removed immediately.

WireShark Antivirus Removal Guide
Kill Process
(How to kill a process effectively?)
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%Program Files%\Sysinternals Antivirus\Sysinternals Antivirus.exe
%Program Files%\scdata\dbsinit.exe
%Program Files%\svchost.exe
%Program Files%\alggui.exe
%Program Files%\Wireshark Antivirus\Wireshark Antivirus.exe
%Program Files%\wpp.exe

Unregister DLL files
%Program Files%\adc_w32.dll

Delete Registry
HKEY_CURRENT_USER\Software\Wireshark Antivirus
HKEY_CLASSES_ROOT\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdbUpd

Remove Folders and Files
%Program Files%\adc_w32.dll
%Program Files%\alggui.exe
%Program Files%\nuar.old
%Program Files%\skynet.dat
%Program Files%\svchost.exe
%Program Files%\wp3.dat
%Program Files%\wp4.dat
%Program Files%\wpp.exe
%Program Files%\Wireshark Antivirus

NetworkControl Removal Guide

NetworkControl Removal Guide
NetworkControl is a small program designed by a group of people in order to force the user to purchase one of their useless programs. NetworkControl is not a virus, but just a very small program which try to pretend like a firewall and produce fake system restore alert and a lot of advertisement. NetworkControl infects the computer through websites which provide free online scanner. The scanner will scare the user that the computer is infected by malwares and ask the user to download a program and install it to kill the virus. When the user install the program, NetworkControl will automatically be installed into the computer. Thus, don't be cheated by the free online scanner unless it has been promoted by many people in the world.

NetworkControl will create a folder named NetworkControl in C: drive to store its files. NetworkControl will start automatically when windows boot. NetworkControl produce fake system restore alert ("Critical System Notification") and tell the user that the Remote Administrator Adam1 has changed some system files of Windows OS. Checking will take several minutes. Please do not turn off the computer - it can lead to system crash." Don't trust what it has stated. NetworkControl just want to scare the user. All is just a lie!

NetworkControl constantly ask the user if he wish to block or allow Adam1 to modify the system. NetworkControl should be removed immediately!

NetworkControl Removal Guide
Kill Process
(How to kill a process effectively?)
checker.exe
nc.exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnPostRedirect" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "NetworkControl"

Remove Folders and Files
c:\NetworkControl
%WINDOWS%\Fonts\segoeui.ttf
%UserProfile%\Local Settings\Temp\abc
%UserProfile%\Local Settings\Temp\i.bat