Wednesday, October 8, 2008

Antivirus 2010 manual removal guide [updated]

Yesterday we wrote about Antivirus 2010 (Antivirus2010) rogue antispyware. Now you can provide manual removal process using our instructions. Also you can remove Antivirus 2010 using Spyware Doctor with antivirus (free scan).

Antivirus 2010 manual removal guide:
Delete Antivirus 2010 files:
AV2010.exe
svchost.exe
IEDefender.dll
wingamma.exe
AV2010.lnk
AV2010.lnk
Uninstall.lnk
Delete Antivirus 2010 registry entries:
HKEY_CURRENT_USER\Software\AV2010
HKEY_CLASSES_ROOT\AppID\
{3C40236D-990B-443C-90E8-B1C07BCD4A68}
HKEY_CLASSES_ROOT\AppID\IEDefender.DLL
HKEY_CLASSES_ROOT\CLSID\
{FC8A493F-D236-4653-9A03-2BF4FD94F643}
HKEY_CLASSES_ROOT\IEDefender.IEDefenderBHO
HKEY_CLASSES_ROOT\IEDefender.IEDefenderBHO.1
HKEY_CLASSES_ROOT\Interface\
{7BC7565C-5062-43CE-8797-DC2C271140A9}
HKEY_CLASSES_ROOT\TypeLib\
{705FD64B-2B7B-4856-9337-44CA1DA86849}
HKEY_LOCAL_MACHINE\SOFTWARE\
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC8A493F-D236-4653-9A03-2BF4FD94F643}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run “Windows Gamma Display”

ContentEraser - will erase system files and damage your PC

ContentEraser or Content Eraser is a rogue software that looks like a legitimate and trusted application. This software produces false positives in attempt to make users purchase "licensed version" of ContentEraser. Download SpywareDoctor + antispyware to remove this scamware from your PC because it may damage system files and cause slowdowns and data loss.

ContentEraser web-site screenshots:


ContentEraser removal tool:


ContentEraser manual removal instructions:

Delete ContentEraser files:

IH.exe
GDCW.exe
GDC.exe
GDCPatch.exe
InstantSCNS.exe
Delete ContentEraser registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Uninstall\Content Eraser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run\ContentEraser
HKEY_LOCAL_MACHINE\SOFTWARE\ContentEraser
HKEY_LOCAL_MACHINE\SOFTWARE\ContentEraserDownloader
Content Eraser

Tuesday, October 7, 2008

Antivirus 2010 is when antyspware is malware

Antivirus 2010 is marketed from web-site identified by all malware observers as malicious. Stay away both from this site and from Antivirus 2010. Remove Antivirus 2010 if infected. Early detection of Antivirus 2010 is preferable as timely removal obviates any considerable damage. Of course, you would better get rid of Antivirus 2010 before its installation, i.e. during the period between its download and installation. Pay attention to any deviations in your system run, unless you have already noted its presence by more clear signals. Antivirus 2010 generates free scan after installation to scare a victim with its results (totally fake). That is why its late identifying should not embarrass you at all.

Antivirus 2010 screenshots:


Antivirus 2010 removal tool:

How to remove XPAntispyware 2009 (XP Antispyware 2009)

XPAntispyware 2009 (XP Antispyware 2009) is not the malware that relies on its web-site impression. However, this rogue has another advantage, namely, very efficient technique of propagation and quite well-planned behavior of trial version. There millions of traps, especially for credulous users, it is easy to become another victim of the rascals.
Stay away from web-site and pop-ups generated by this malware online, as they result in trial version installation. Remove XPAntispyware 2009 trial immediately, though the same suggestion is applicable also for its full version. We hope you have not purchased it yet and have not such intention. It is easy and convenient to get rid of XPAntispyware 2009 by the remover offered below. Click here for free scan using Spyware Doctor and to perform XPAntispyware 2009 removal immediately.

XPAntispyware 2009 screenshot:




XPAntispyware 2009 automatical remover:

Monday, October 6, 2008

Get rid of eKerbros to suspend slow destruction of your machine

eKerbros, malicious application with a bit strange denomination as for malware, is a product released by notorious malware developing group with head-quarter in Ukraine and affiliates around the globe. Some experts forewarn against its purchase not only because this is useless money spending and feeding of rascals’ business, but first of all because they are not sure in reliability of billing service used by eKerbros. By the other words, once you have purchased eKerbros, your credit card details may become a hackers’ prey and safety of your financial accounts can not be ensured any more until you invalidate your credit card.
Do you still need proofs that eKerbros can enter your computer without invitation and all its scans are false?
At the same time, detection of this rogue is relatively hard, especially at the background of hardly annoying malware. It is good to remove eKerbros before its installation (right after its download). Use the best scanner free of charge (Spyware Doctor) by clicking here. The same reference is applicable for eKerbros removal.

eKerbros screenshot:



eKerbros automatical remover:

eKerbros manual removal instructions:
Delete eKerbros files:

uninstall.exe
ekerberos.exe
skinactive.xml
hook.dll
eKerberos.exe
eKerberosInstaller[1].exe
Start eKerberos.lnk
Register eKerberos.lnk
eKerberos.lnk
Delete eKerbros registry entries:
eKerberos
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\
uninstall\ekerberos displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\
uninstall\ekerberos uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\
uninstall\ekerberos
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\
run ekerberos
HKEY_LOCAL_MACHINE\software\ekerberos versioninfo
HKEY_LOCAL_MACHINE\software\ekerberos regshortcut
HKEY_LOCAL_MACHINE\software\ekerberos programdirectory
HKEY_LOCAL_MACHINE\software\ekerberos isstartatstartup
HKEY_LOCAL_MACHINE\software\ekerberos registrationurl
HKEY_LOCAL_MACHINE\software\ekerberos isproblem6
HKEY_LOCAL_MACHINE\software\ekerberos isproblem5
HKEY_LOCAL_MACHINE\software\ekerberos isproblem4
HKEY_LOCAL_MACHINE\software\ekerberos isproblem3
HKEY_LOCAL_MACHINE\software\ekerberos isproblem2
HKEY_LOCAL_MACHINE\software\ekerberos isproblem1
HKEY_LOCAL_MACHINE\software\ekerberos

HeX 2.0R Released!

After much adeau, HeX 2.0R is out... the improvements are numerous and include:


1. FreeBSD 7 Stable
2. Unionfs
3. NSM Console updates
4. Tons of analysis alias and scripts
5. Tons of NSM tools' signatures
6. Firefox - Useful websites bookmark
7. Liferea - Security rss feeds


For more info: http://us.rawpacket.org

Thanks to the rest of the HeX team for diligent and hard work on this.... more to come!

J

Friday, October 3, 2008

How to remove "You have a security problem!" message

"You have a security problem!" alerts are now widely applied by a group of fake removers to the purpose of theirs propagation. If you see such message arising from your desktop toolbar (left bottom corner of your monitor, as a rule), do not hesitate to start scanning your PC. If you have a reliable timely updated scanner, some rogues should be certainly detected. It is likely be Antivirus 2009 or another malware from its group that generated "You have a security problem!" alert. Failure to get rid of "You have a security problem!" message means to let malware do anything; as a result, your privacy and your machine are in danger. Click here to download Spyware Doctor and detect free of charge malware responsible for screening of the above alert and to remove "You have a security problem!" related malware (and, of course, elimination of "You have a security problem!" alert is guaranteed after malware removal)

"You have a security problem!" message screenshot:


"You have a security problem!" message automatical remover: