Archive for the 'Malware Removal Guide' Category

How to remove TROJ_POPHOT.O and the svchosd.exe infection.

Wednesday, July 30th, 2008

The TROJ_POPHOT.O Trojan is installed form other malware downloaded off of the Internet.  When run, this Trojan will install the following files on your computer:

  • C:\Windows\System32\inf\scsys16_080725.dll
  • C:\Windows\System32\inf\sppdcrs080725.scr
  • C:\Windows\System32\inf\svchosd.exe
  • C:\Windows\dcbdcatys32_080725a.dll
  • C:\Windows\system\sgcxcxxaspf080725.exe
  • C:\Windows\tawisys.ini
  • C:\Windows\wftadfi16_080725a.dll

The Trojan will also add a registry entry to start itself every time you restart this computer. This registry entry will start C:\Windows\System32\inf\svchosd.exe, which is actually a renamed rundll32.exe, which will be used to load the code found in the wftadfi16_080725a.dll DLL file.

Automatic Removal Method

If you are infected with this malware, then we suggest you use Trend Micro antivirus to remove this infection. It is know to be able to remove this malware and it is included in its current virus definitions.  A big thumbs up for Trend Micro for being able to remove this infection so quickly.

DownloadDownload Trend Micro Antivirus to scan your computer

Manual Removal Instructions for

End these processes:

Learn how to end processes

svchosd.exe


Delete these files:

Lean how to remove files

C:\Windows\System32\inf\scsys16_080725.dll
C:\Windows\System32\inf\sppdcrs080725.scr
C:\Windows\System32\inf\svchosd.exe
C:\Windows\dcbdcatys32_080725a.dll
C:\Windows\system\sgcxcxxaspf080725.exe
C:\Windows\tawisys.ini
C:\Windows\wftadfi16_080725a.dll

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\policies\Explorer\run
initnyuser = “%System%\inf\svchosd.exe %WINDOWS%\wftadfi16_080725a.dll tanlt88″

How to remove the Trojan.Proscks.C Malware

Tuesday, July 29th, 2008

The Proscks Trojan modifies files on the compromised computer and connects to a remote server. Once infected you will be shown pop-up advertisements on your computer.

When infected the Trojan.Proscks.C malware will create the following files:

  • %Temp%\RarSFX0\IPHOST.DLL
  • %Temp%\RarSFX0\iphy.dll
  • %Temp%\RarSFX0\xExe.dll
  • %Temp%\RarSFX0\loaderSvc.exe
  • %System%\IPHOST.DLL
  • %System%\_proxy.dll
  • %System%\iphy.dll
  • %System%\fhpatch.dll
  • %System%\fiplock.dll
  • %System%\IpSvchostF.dll

Next, the Trojan copies the file %System%\svchost.exe to the following location:

%System%\[EIGHT RANDOM CHARACTERS]

It then modifies %System%\svchost.exe so that the following file is executed every time Windows starts:

%System%\IPHOST.DLL

The Trojan then downloads a .dll file from a remote location and saves it as %System%\IPHACTION.dll.

Automatic Removal Method

If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. The current definitions for Symantec Antivirus contains methods of removing this virus.

DownloadDownload Symantec Antivirus to scan your computer for free

Manual Removal Instructions for

End these processes:

Learn how to end processes

loaderSvc.exe

Delete these files:


Lean how to remove files

%Temp%\RarSFX0\IPHOST.DLL
%Temp%\RarSFX0\iphy.dll
%Temp%\RarSFX0\xExe.dll
%Temp%\RarSFX0\loaderSvc.exe
%System%\IPHOST.DLL
%System%\_proxy.dll
%System%\iphy.dll
%System%\fhpatch.dll
%System%\fiplock.dll
%System%\IpSvchostF.dll

How to remove Secure Expert Cleaner

Tuesday, July 29th, 2008

Secure Expert Cleaner is a program that states it can make your computer secure by cleaning it of security risks.  Unfortunately, this program does not live up to its name.  Secure Expert Cleaner will scan your computer and list legitimate programs as risks and state that they are dangerous.  Then, in order to remove them, you need to first purchase the software.

This software is a scam and should be avoided as you will only be wasting your money and not actually cleaning your computer.

Secure Expert Cleaner

Secure Expert Cleaner

Automatic Removal Method

We recommend that you install Spyware Doctor from PCTools in order to remove Secure Expert Cleaner from your computer. Spyware Doctor has an incredible track record for removing and detecting the latest malware.

DownloadDownload Spyware Doctor to scan your computer for free

Manual Removal Instructions

End these processes:

Learn how to end processes

SEC.exe


Delete these files:

Lean how to remove files

c:\Documents and Settings\All Users\Application Data\SEC
c:\Documents and Settings\All Users\Start Menu\Programs\SecureExpertCleaner
<userprofile>\Local Settings\Temp\is-ROV72.tmp
c:\Program Files\SecureExpertCleaner
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT
c:\Documents and Settings\All Users\Desktop\Launch SecureExpertCleaner.lnk
c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db
c:\Documents and Settings\All Users\Start Menu\Programs\SecureExpertCleaner\Launch SecureExpertCleaner.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SecureExpertCleaner\Uninstall SecureExpertCleaner.lnk
<userprofile>\Application Data\Microsoft\Internet Explorer\Quick Launch\SecureExpertCleaner.lnk
c:\Program Files\SecureExpertCleaner\mfc80.dll
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.MFC.manifest
c:\Program Files\SecureExpertCleaner\Reminder.exe
c:\Program Files\SecureExpertCleaner\SEC.exe
c:\Program Files\SecureExpertCleaner\SEC.ico
c:\Program Files\SecureExpertCleaner\SEC.xml
c:\Program Files\SecureExpertCleaner\unins.ico
c:\Program Files\SecureExpertCleaner\unins000.dat
c:\Program Files\SecureExpertCleaner\unins000.exe
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT\msvcp80.dll
c:\Program Files\SecureExpertCleaner\Microsoft.VC80.CRT\msvcr80.dll

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_CURRENT_USER\Software\SEC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3P_USEC_is1
HKEY_LOCAL_MACHINE\SOFTWARE\SEC

How to remove the desktop.sysm or W32.Azero.A infection

Friday, July 25th, 2008

The W32.Azero.A infection is virus that infects .exe files so that when they are run they further infect other .exe files. When a .exe file is run the virus will create the following files:

  • %System%\Windows 3d.scr
  • %System%\commandprompt.sysm
  • %System%\desktop.sysm
  • %UserProfile%\application data\Microsoft\[4 RANDOM LETTERS].exe

It will then create the following folders:

It also creates the following folders:

  • %UserProfile%\applications data\excel
  • %UserProfile%\applications data\media player
  • %UserProfile%\applications data\Microsoft
  • %UserProfile%\applications data\office
  • %UserProfile%\applications data\Windows
  • %UserProfile%\applications data\word

It then creates the following Windows Registry entry so that it starts automatically when the computer boots up:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”VisualStyle” = “%System%\desktop.sysm”

When a computer is infected with this virus they will find that their computer runs slower than normal and tends to crash.

Automatic Removal Method

If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. The current definitions for Symantec Antivirus contains methods of removing this virus.

DownloadDownload Symantec Antivirus to scan your computer for free

Manual Removal Instructions for

End these processes:

Learn how to end processes

desktop.sysm


Delete these files:

Lean how to remove files

  • %System%\Windows 3d.scr
  • %System%\commandprompt.sysm
  • %System%\desktop.sysm
  • %UserProfile%\application data\Microsoft\[4 RANDOM LETTERS].exe

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”VisualStyle” = “%System%\desktop.sysm”

How to remove the Troj_Renos.ACO or lphc3pgj0e3ct.exe infection.

Thursday, July 24th, 2008

A new variant of the Troj_Renos.ACO infection was discovered that installs a file called lphc3pgj0e3ct.exe into your C:WindowsSystem32folder. This infection is installed on your computer by one of the following three methods:

  • This Trojan may be downloaded from remote site(s) by other malware.
  • It may be dropped by other malware.
  • It may be downloaded unknowingly by a user when visiting malicious Web site(s).

When started, the infection will connect to a remote web site to download and run another file that is also detected as Troj_Renos.ACO.  It then copies itself to C:WindowsSystem32lphc3pgj0e3ct.exe and adds a entry into the Windows Registry to start the file everytime you boot your computer.

This infection will also change your Windows desktop wallpaper to look like:

Trojan Renos Wallpaper

Trojan Renos Wallpaper

Automatic Removal Method

If you are infected with this malware, then we suggest you use Trend Micro antivirus to remove this infection. It is know to be able to remove this malware and it is included in its current virus definitions.  A big thumbs up for Trend Micro for being able to remove this infection so quickly.

DownloadDownload Trend Micro Antivirus to scan your computer

Manual Removal Instructions for

End these processes:

Learn how to end processes

lphc3pgj0e3ct.exe


Delete these files:

Lean how to remove files

C:WindowsSystem32lphc3pgj0e3ct.exe
C:WindowsSystem32phc3pgj0e3ct.bmp
C:WindowsSystem32blphc3pgj0e3ct.scr

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_LOCAL_MACHINESOFTWAREMicrosoft
WindowsCurrentVersionRun
lphc3pgj0e3ct = “%System%lphc3pgj0e3ct.exe”

How to remove XLGuarder or XLG Security Center

Thursday, July 24th, 2008

XLGuarder, or XLG Security Center, is a rogue anti-spyware program that displays deliberate false information about infections found on your computer.  This malware is typical for its type:

  • Shows false results
  • Won’t let you remove any supposed infections unless you first purchase the software.
  • Hijacks the Internet Explorer Start page.
  • Makes your computer slower.
  • Provides no way of contacting the developers of the software.

Overall, this software is a scam and should be avoided at all cost.  Please use the automated or manual removal instructions below to remove this infection.

XLGuarder or XLG Security Center image

XLGuarder or XLG Security Center image

Automatic Removal Method

If you are infected with this malware, then we suggest you use Symantec Antivirus to remove this infection. It is know to be able to remove this malware and XLG Security Center is included in its current virus definitions.  A big thumbs up for Symantec adding this to removal definitions so quickly!

DownloadDownload Symantec Antivirus to scan your computer for free

Manual Removal Instructions for

End these processes:

Learn how to end processes

sysutil.exe


Delete these files:

Lean how to remove files

<userprofile>Start MenuProgramsProtection
c:windowssysutils
c:windowssysutilswarning
c:windowssysutilssounds
c:windowssysutilssettings.ini
c:windowssysutilssysutil.exe
c:windowssysutilssysutil_s.exe
c:windowssysutilsuninstall.exe
c:windowssysutilswinsystip.exe
c:windowssysutilssounds�1.wav
c:windowssysutilssounds�2.wav
c:windowssysutilssounds�3.wav
c:windowssysutilswarningalertpage.jpg
c:windowssysutilswarningspacer.gif
c:windowssysutilswarningwarningpage.html
<userprofile>Start MenuProgramsProtectionUninstall XLG.lnk
c:windowsiebho.dll

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_CLASSES_ROOTCLSID{D032570A-5F63-4812-A094-87D007C23012}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{D032570A-5F63-4812-A094-87D007C23012}
HKEY_CURRENT_USERSoftwaresysutils
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallsysutils

How to remove the USS.exe Trojan

Thursday, July 17th, 2008

THe USS.exe Trojan is an executable that gets installed on your computer along with other malware.  This infection will also install a service called wasfsd that uses the filename C:\Windows\System32\drivers\System32. When running, this Trojan will display fake alerts that state your computer is being attacked or is infected with particular infections.  It will then ask if you would like to block or fix these infections, and if you specify yes, will open up an Internet Explorer window where it prompts you to buy Trusted Antivirus.

alert2 alert
Fake alerts from USS.exe

Automatic Removal Method

We recommend that you install Spyware Doctor from PCTools in order to remove USS.exe Trojan from your computer. Spyware Doctor has an incredible track record for removing and detecting the latest malware.

DownloadDownload Spyware Doctor to scan your computer for free

Manual Removal Instructions for

End these processes:

Learn how to end processes

USS.exe


Delete these files:

Lean how to remove files

c:\END
c:\Program Files\USS
c:\Program Files\USS\unins000.dat
c:\Program Files\USS\unins000.exe
c:\Program Files\USS\USS.exe
c:\Program Files\USS\#agents
c:\Program Files\USS\#agents\53
c:\Program Files\USS\#agents\53\#startup
c:\Program Files\USS\#monitors
c:\Program Files\USS\#monitors\DirMonitor
c:\Program Files\USS\#monitors\FileMonitor
c:\Program Files\USS\#monitors\RegMonitor
c:\Program Files\USS\{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}
c:\Program Files\USS\{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}\GESPlugin.dll
c:\Program Files\USS\{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}\GESPlugin.xml
c:\Program Files\USS\{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}\kernel.dll
c:\Program Files\USS\{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}\unins000.dat
c:\Program Files\USS\{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}\unins000.exe
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\AMPlugin.dll
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\AMPlugin.xml
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\AsAgents.dll
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\AsAgents.xml
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\msvcp71.dll
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\msvcr71.dll
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\unins000.dat
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\unins000.exe
c:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\wasffNT.exe
c:\Program Files\USS\{EC572088-91C7-4293-93F9-93D40B0E0B36}
c:\Program Files\USS\{EC572088-91C7-4293-93F9-93D40B0E0B36}\GSCRPlugin.dll
c:\Program Files\USS\{EC572088-91C7-4293-93F9-93D40B0E0B36}\unins000.dat
c:\Program Files\USS\{EC572088-91C7-4293-93F9-93D40B0E0B36}\unins000.exe
c:\WINDOWS\system32\drivers\wasfsd.sys

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_CURRENT_USER\Software\USLst
HKEY_CURRENT_USER\Software\USS
HKEY_CLASSES_ROOT\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B22}
HKEY_CLASSES_ROOT\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95422}
HKEY_CLASSES_ROOT\Interface\{ABCD4567-D8E8-4DF1-A3EA-D0AA72F42622}
HKEY_CLASSES_ROOT\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37422}
HKEY_CLASSES_ROOT\wasfsd.CreationNotifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\USS_{826F15BF-1A4C-4290-BFD1-794AF7A2CB8F}_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\USS_{D1957FF4-EA22-4b4a-81A1-C62068479DED}_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\USS_{EC572088-91C7-4293-93F9-93D40B0E0B36}_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\USS_is1
HKEY_LOCAL_MACHINE\SOFTWARE\USS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wasfsd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wasfsd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run => USS

How to uninstall and remove InternetSecurityDeluxe

Thursday, July 17th, 2008

InternetSecurityDeluxe is a very deceptive and misleading anti-spyware program. It proclaims that is a top pick of some made-up magazines and had high reviews on sites that don’t have any listing of this.  Then when you run the software, it states you have infections but will not tell you what they are.  To remove these infections, you would then have to purchase the software.

From initial tests and research on the Internet, this rogue does not appear to have any malware bundled with it.  It does though occasionally popup messages through its popuper.exe application.

When you uninstall the application it will also leave behind most of the files associated with this application as well as a program that will continue to start.  This program is popuper.exe.  Due to this, it is advised that you use Spyware Doctor to scan your computer for this infection so that your computer is not only clean of infection, but running better.

InternetSecurityDeluxe
InternetSecurityDeluxe

vague-results
Vague Results

Automatic Removal Method

We recommend that you install Spyware Doctor from PCTools in order to remove InternetSecurityDeluxe from your computer. Spyware Doctor has an incredible track record for removing and detecting the latest malware.

DownloadDownload Spyware Doctor to scan your computer for free

Manual Removal Instructions for

End these processes:

Learn how to end processes

popuper.exe
SystemService.exe
InternetSecurityDeluxe.exe
InternetSecurityDeluxeSetup[1].exe


Delete these files:

Lean how to remove files

<userprofile>\Local Settings\Temp\{463F3580-9041-400d-BAA6-1118D3570D41}
<userprofile>\Local Settings\Temp\{629CB163-22C0-41F7-BD7E-997B4F3B2C95}
c:\Program Files\InternetSecurityDeluxe
c:\Documents and Settings\All Users\Start Menu\Programs\InternetSecurityDeluxe.lnk
c:\Program Files\InternetSecurityDeluxe\Controls.dll
c:\Program Files\InternetSecurityDeluxe\InternetSecurityDeluxe.application
c:\Program Files\InternetSecurityDeluxe\InternetSecurityDeluxe.exe
c:\Program Files\InternetSecurityDeluxe\InternetSecurityDeluxe.exe.manifest
c:\Program Files\InternetSecurityDeluxe\ScanEngine.dll
c:\Program Files\InternetSecurityDeluxe\ServiceInterface.dll
c:\WINDOWS\Installer\27a127.msi
c:\WINDOWS\system32\Controls.dll
c:\WINDOWS\system32\InstallUtil.InstallLog
c:\WINDOWS\system32\Popuper.exe
c:\WINDOWS\system32\ScanEngine.dll
c:\WINDOWS\system32\ServiceInterface.dll
c:\WINDOWS\system32\ServiceObject.dll
c:\WINDOWS\system32\SystemService.application
c:\WINDOWS\system32\SystemService.exe
c:\WINDOWS\system32\SystemService.exe.manifest
c:\WINDOWS\system32\SystemService.InstallLog
c:\WINDOWS\system32\SystemService.InstallState

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.


HKEY_CLASSES_ROOT\Installer\Assemblies\C:|Program Files|InternetSecurityDeluxe|Controls.dll
HKEY_CLASSES_ROOT\Installer\Assemblies\C:|Program Files|InternetSecurityDeluxe|InternetSecurityDeluxe.exe
HKEY_CLASSES_ROOT\Installer\Assemblies\C:|Program Files|InternetSecurityDeluxe|ScanEngine.dll
HKEY_CLASSES_ROOT\Installer\Assemblies\C:|Program Files|InternetSecurityDeluxe|ServiceInterface.dll
HKEY_CLASSES_ROOT\Installer\Features\0BEB3C9987A437848BFC0744983750CD
HKEY_CLASSES_ROOT\Installer\Products\0BEB3C9987A437848BFC0744983750CD
HKEY_CLASSES_ROOT\Installer\Products\0BEB3C9987A437848BFC0744983750CD\SourceList
HKEY_CLASSES_ROOT\Installer\Products\0BEB3C9987A437848BFC0744983750CD\SourceList\Media
HKEY_CLASSES_ROOT\Installer\Products\0BEB3C9987A437848BFC0744983750CD\SourceList\Net
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\D2FB1F8FCC9FA1543AF0066D3BBB86BB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\D2FB1F8FCC9FA1543AF0066D3BBB86BB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C3BEB0-4A78-4873-B8CF-7044897305DC}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYSTEMSERVICE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SystemService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SystemService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYSTEMSERVICE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SystemService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run => InternetSecurityDeluxe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run => Notifications

How to uninstall and remove AntiSpyCheck

Thursday, July 17th, 2008

AntiSpyCheck is a rogue anti-spyware program installed through the Zlob Trojan.  The Zlob Trojan is an infection which pretends to be a program required to watch a video online.  When you install it, though, it instead installs AntiSpyCheck on to your computer.

AntiSpyCheck works just like all of the rest.  It scans your computer, displays fake findings, and then asks you to purchase it before you can remove anything.  To make matters worse, it’s constant registration requests can bring your computer to a crawl.

It is advised that you use Spyware Doctor to scan your computer for this infection so that your computer is not only clean of infection, but running better.

antispycheck

Automatic Removal Method

We recommend that you install Spyware Doctor from PCTools in order to remove AntiSpyCheck from your computer. Spyware Doctor has an incredible track record for removing and detecting the latest malware.

DownloadDownload Spyware Doctor to scan your computer for free

Manual Removal Instructions

End these processes:

Learn how to end processes

AntiSpyCheck.exe


Delete these files:

Lean how to remove files

<userprofile>\Start Menu\Programs\AntiSpyCheck 2.1.0
c:\Program Files\AntiSpyCheck
<userprofile>\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpyCheck 2.1.0.lnk
<userprofile>\Desktop\AntiSpyCheck 2.1.0.lnk
<userprofile>\Local Settings\Temp\~DF6B1B.tmp
<userprofile>\Start Menu\AntiSpyCheck 2.1.0.lnk
<userprofile>\Start Menu\Programs\AntiSpyCheck 2.1.0\AntiSpyCheck 2.1.0.lnk
c:\Program Files\AntiSpyCheck\AntiSpyCheck.exe
c:\Program Files\AntiSpyCheck\IEWarning.dll
c:\Program Files\AntiSpyCheck\uninst.exe

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_CURRENT_USER\Software\AntiSpyCheck
HKEY_CURRENT_USER\Software\AntiSpyCheck\Update
HKEY_CLASSES_ROOT\CLSID\{56FA7933-DC3E-403b-8D47-BB5E3F345A21}
HKEY_CLASSES_ROOT\CLSID\{D2608046-DD09-A225-01BF-70C1EDD8B2E8}
HKEY_CLASSES_ROOT\IEWarning.WarningBHO
HKEY_CLASSES_ROOT\IEWarning.WarningBHO.1
HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiSpyCheck.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56FA7933-DC3E-403b-8D47-BB5E3F345A21}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiSpyCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run => AntiSpyCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run => AntiSpyCheck 2.1.0

How to uninstall Antivirus Master (Removal Instructions)

Tuesday, July 15th, 2008

Antivirus Master is a new rogue anti-spyware program that is a master of nothing.  This program proclaims itself as a master of removing malware from your computer.  In reality, though, this program is the actual infection.  When Antivirus Master scans your computer it will list infections that do not exist.  Then, in order to remove these infections, you must first purchase the software in order to do so.  As we did not purchase it, I am sure once it was purchased those threats would immediately be gone.

It is advised that you use Spyware Doctor to scan your computer for this infection.  If left on your computer, this infection will slow it down and make it harder to use.

pcbsq-antivirus-master

Automatic Removal Method

We recommend that you install Spyware Doctor from PCTools in order to remove Antivirus Master from your computer. Spyware Doctor has an incredible track record for removing and detecting the latest malware and is known to remove Antivirus Master as shown by the screen shot below.

DownloadDownload Spyware Doctor to scan your computer for free


Click to see a screen shot of Spyware Doctor Detecting
Antivirus Master

Manual Removal Instructions

End these processes:

Learn how to end processes

avm.exe


Delete these files:

Lean how to remove files

c:\Program Files\AVM
<userprofile>\Desktop\Antivirus Master.lnk
<userprofile>\Recent\antivirus-master.lnk
c:\Program Files\AVM\avm.cpl
c:\Program Files\AVM\avm.exe
c:\Program Files\AVM\avm0.dat
c:\Program Files\AVM\avm1.dat
c:\WINDOWS\system32\avm.cpl

Remove these Registry keys:

Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.  Otherwise, please use the automated removal method above.

HKEY_CURRENT_USER\Software\AntiVirus
HKEY_CURRENT_USER\Software\AVM
HKEY_CLASSES_ROOT\.keyHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Antivirus”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Antivirus”