Most of the people don't realise that browser extensions might be dangerous .But why they download & installing it?.May be they are too lazy to download and install a software with the same functions as the extension, or it may save some time or it is a faster way to explore lots of features in a short time.After installation, the malicious extension can gain complete control of the victim’s profile and may have access to your data.By installing these extensions, you give your browser additional functionality unknowingly . So don’t install an app or extension unless you trust its creator.
ExtShield (formerly Chrome Protector)tells you that you need to download Google Chrome in order to run it. It keeps a more than 100s of blacklisted browser extensions known to contain adware, spyware or malware.It will scan your browser and alert you if any of these are installed.
ExtShield extension is a freeware available at Chrome webstore. Once installed, you can access the shield located at the right hand top corner of your webpage to know the status about your other installed extensions.
✔ Stops over 100 adware, spyware or malware extensions that are currently available in chrome web store and used by millions
✔ Monitors extensions and websites behavior to detect malicious patterns
✔ Shield code is protected to avoid bypassing by malware creators
Sometimes your web browser starts behaving strangely, it may be a sign your browser has been hijacked. Malicious software ( malware) can take control of your web browser and change your home page, redirect your search results to malicious sites, or you face with a barrage of popup ads.Malwares are often bundled with browser hijackers. A browser hijacker is a type of malware program that alters your computer's browser settings so that you are redirected to Web sites that you had no intention of visiting.It alter your default home pages and search pages. The hijacker can modify , control and redirect your search results and ultimately he can collect your personal information such as usernames, passwords, and credit card and banking information.
One of the easiest way is to block unwanted websites by modifying machine’s HOSTS file .What is a Host file? In a simple way Hosts file is like an address book.It is a common part of an operating system's Internet Protocol (IP) implementation, and serves the function of translating human-friendly hostnames into numeric protocol addresses, called IP addresses, that identify and locate a host in an IP network(Wikipedia).One of the feature of the HOSTS file is its ability to block other applications from connecting to the Internet, providing the entry exists.You can use HOSTS file to block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and hijackers
You can search the Host file in WINDOWS\system32\ directory.
Open the host file in notepad and to block a website input an entry in the host file.If you want to block ad.doubleclick.net just enter 127.0.0.1 as an IP address then type ad.doubleclick.net in the host file.Each entry should be placed on an individual line. The IP address and the hostname should be separated by a space or a tab. In this way, you can block any given website by just pointing it to the IP address
127.0.0.2 www.link-assistant.com
127.0.0.1 ad.doubleclick.net
When the browser hijacker or you will try to open the ad.doubleclick.net , you will see a blank page.
A newly discovered trojan is spreading fast , which is designed to damaging a victim's computer once it has harvested sensitive data.It's being called either Disttrack or the Shamoon . It steals the data from the 'Users', 'Documents and Settings', and 'System32/Drivers' and 'System32/Config' folders on Windows computers.It also overwrites files and the Master Boot Record of the machine and latter PC becomes unbootable.According to Kaspersky Labs this trojan consists of a 900KB folder that contains a number of "encrypted resources".The affected OS are Windows 95, Windows 98, Windows XP, Windows 200, Windows Vista, Windows NT, Windows ME, Windows 7, Windows Server 2003 and Windows Server 2008.
Symantec said it has updated its antivirus to protect against the malware.Seculert wrote in a blog post about Shamoon, you can read the post here
These days many viruses and malwares target your PC , rendering the computer unbootable. Microsoft Standalone System Sweeper is a recovery tool that can help you start an infected PC and perform an offline scan to help identify and remove viruses, trojans, rootkits and other forms of malware effectively.
It can also be used if you cannot install or start an antivirus solution on your PC, or if the installed solution can’t detect or remove malware on your PC.This tool installs itself to either a USB drive or a blank CD/DVD disc and creates a bootable media that can be used to recover your system in the event of a malware or virus infection.
please ensure that you have a blank CD, DVD, or USB drive with at least 250 MB of space, and an active Internet connection .To use Standalone System Sweeper ,users need to boot from the disc or USB device which in turn loads the tool that gives you the options to scan the PC and recover it.
It will load the Windows preinstall environment to run the Microsoft Standalone System Sweeper application for scanning .This will first scans your boot sector for any corrupted files or settings. It then scans your system for any known malware or infections.
Download 32 Bit Version | Download 64 Bit Version | Installation Help
IObit Uninstaller creates a restore image before every uninstall and you can view the uninstall details in the Log Manager. If any software is uninstalled by mistake, you can restore it with the created image.And the best thing of all, you need to install this tool in your PC.Through the sidebar you can filter the list of programs in various ways.You can view only the toolbars installed in your browser, recently installed programs, large programs, rarely used and Windows updates.
Key Benefits
- 1-Click Toolbars Removal
- Batch Uninstall
- Standard and Advanced Uninstall
- Without Installation
- Forced Uninstall
- Log Manager and Restoration
- Free and Easy-to-use
Other Tools worth to check
Whether your PC is slow? It may due to the malware infection. Malware is nothing but some malicious software.Norman Malware Cleaner is a Norman program that can be used to detect and remove specific malicious software.There is no need to install this one, just run the program.
Features
Download: Norman_Malware_Cleaner |Os:Windows 98, Me, NT, 2000, XP, 2003, Vista, 2008 and 7| 63.2MB|Freeware
To give Norman Malware Cleaner the best working conditions possible, it is better to start the computer in Safe mode before running the program.
Note: This program is not a substitute for running normal proactive antivirus protection, but it can be used as a reactive tool which can handle systems that are already infected.
Also Read
Looking for free Security Tools for you computer? Then visit .This is the right place for you! Here you will be able to find from Anti-virus, Anti-Spyware AntiRootkit Firewall and much more for free!
AndyManchesta is the developer of SDFix the famous tool that removes thousands of different types of trojans, worms, rootkits and other malwares
Visit :http://andymanchesta.com/
Security researchers found a new piece of ransomware that blocks an infected computer from accessing the Internet until a fee is paid via SMS.The ransomware file is bundled with a tool called uFast Download Manager. If your PC is infected, a message is posted in Russian demanding a ransom under the guise of activating the uFast Download Manager application.
Image courtesy: CA Community
Read full Article here:Ransomware Blocks Internet Access
System Security is a rogue anti-spyware that belongs to family WinwebSecurity. It uses Trojan or fake video codec to get into the . Once installed on a computer, SystemSecurity will start showing annoying pop-ups with false information about virus infections and serious system risks in order to sell itself.It starts generate fake security reports about infections. These false security warnings are intentioned to make people believe their computer is seriously infected with malicious viruses and force you to purchase their licensed version.
It affect your internet connection speed and slowdown the system.It also change your browser settings, leads to system crash.System Security 2009 is a PC parasite, an infection in itself, and should be avoided.
Manual Removal
Step 1 : By Using Windows Task Manager
%PROGRAMDATA%\11769284\11769284.exe
%PROGRAMDATA%\11846754\11846754.exe
%PROGRAMDATA%\13701144\13701144.exe
%ALLUSERSPROFILE%\Application Data\1597884464\83521271.exe
%PROGRAMDATA%\00184705\00184705.exe
%PROGRAMDATA%\90188702\90188702.exe
%ALLUSERSPROFILE%\Application Data\03380828\03380828.exe
%PROGRAMDATA%\29192498\29192498.exe
%PROGRAMDATA%\06837430\06837430.exe
%ALLUSERSPROFILE%\Application Data\14610250\14610250.exe
%ALLUSERSPROFILE%\Application Data\03326093\03326093.exe
%ALLUSERSPROFILE%\Application Data\13496218\13496218.exe
%ALLUSERSPROFILE%\Application Data\52796787\52796787.exe
%ALLUSERSPROFILE%\Application Data\96484328\96484328.exe
%ALLUSERSPROFILE%\Application Data\500153984\500153984.exe
%ALLUSERSPROFILE%\Application Data\00607031\00607031.exe
%ALLUSERSPROFILE%\Application Data\02686578\02686578.exe
%ALLUSERSPROFILE%\Application Data\01560265\01560265.exe
%ALLUSERSPROFILE%\Application Data\847809490\554845319.exe
%PROGRAMDATA%\991537388\1126514300.exe
%ALLUSERSPROFILE%\Application Data\947347721\1255330437.exe
%ALLUSERSPROFILE%\Application Data\646483980\2113272685.exe
%ALLUSERSPROFILE%\Application Data\1087856298\1725032906.exe
%ALLUSERSPROFILE%\Application Data\831600033\1354455340.exe
%ALLUSERSPROFILE%\application data\1838702514\380679599.exe
%ALLUSERSPROFILE%\Application Data\696273957\25238076.exe
%ALLUSERSPROFILE%\Application Data\1046175485\801085450.exe
%ALLUSERSPROFILE%\Application Data\281405228\2084498445.exe
%ALLUSERSPROFILE%\Application Data\383196232\14894324.exe
%ALLUSERSPROFILE%\Application Data\2002822718\2029503323.exe
%ALLUSERSPROFILE%\Application Data\1929861670\498278020.exe
%ALLUSERSPROFILE%\Application Data\914063820\1573468717.exe
%ALLUSERSPROFILE%\Application Data\1964289396\375534146.exe
%ALLUSERSPROFILE%\Application Data\1263973370\1743310514.exe
%ALLUSERSPROFILE%\Application Data\1340156489\202150970.exe
%ALLUSERSPROFILE%\Application Data\1217703993\1327825314.exe
%ALLUSERSPROFILE%\Application Data\568819996\1550536869.exe
%ALLUSERSPROFILE%\Application Data\771996059\695276073.exe
%ALLUSERSPROFILE%\Application Data\1095564415\650526885.exe
%ALLUSERSPROFILE%\Application Data\2018698794\1940874419.exe
%ALLUSERSPROFILE%\Application Data\1457297881\1947101902.exe
%ALLUSERSPROFILE%\Application Data\573251351\1431998300.exe
%ALLUSERSPROFILE%\Application Data\1655800406\2030350728.exe
%ALLUSERSPROFILE%\Application Data\1357783622\1977868703.exe
%ALLUSERSPROFILE%\Application Data\2068742222\438978017.exe
%PROGRAMDATA%\843824418\1591300478.exe
%ALLUSERSPROFILE%\Application Data\1993373367\613622941.exe
%ALLUSERSPROFILE%\Application Data\160465659\432632312.exe
%ALLUSERSPROFILE%\Application Data\988737293\931330021.exe
%USERPROFILE%\Application Data\1163524634\240844061.exe
%ALLUSERSPROFILE%\Application Data\194077280\172939276.exe
%ALLUSERSPROFILE%\Application Data\336546584\431192516.exe
%ALLUSERSPROFILE%\Application Data\114567299\800990911.exe
%ALLUSERSPROFILE%\Application Data\2014101429\1610380076.exe
%ALLUSERSPROFILE%\Application Data\1189037594\372561511.exe
%ALLUSERSPROFILE%\Application Data\278958024\124517242.exe
%ALLUSERSPROFILE%\Application Data\1926316989\1625593810.exe
%ALLUSERSPROFILE%\Application Data\2010372281\1462403437.exe
%ALLUSERSPROFILE%\Application Data\1193890671\9179499.exe
%ALLUSERSPROFILE%\Application Data\1256305888\1003720520.exe
%ALLUSERSPROFILE%\Application Data\1016589770\1714292029.exe
%ALLUSERSPROFILE%\Application Data\1398798156\788573529.exe
%ALLUSERSPROFILE%\Application Data\29046618\549344438.exe
SystemSecurity.exe
C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe
Step 2 : By Using Registry Editor
Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\System Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"
Step 3 : Remove these System Security files
System Security 2009 Support.lnk
System Security 2009.lnk
359F5809-00B8-4455-A73A-9EA62A51101B
SystemSecurity.exe
C:\Documents and Settings\All Users\Application Data\538654387\Languages\German.lng
C:\Documents and Settings\All Users\Application Data\538654387\Languages\English.lng
C:\Documents and Settings\All Users\Application Data\538654387\Languages\Spanish.lng
C:\Documents and Settings\All Users\Application Data\538654387\Languages
C:\Documents and Settings\All Users\Application Data\538654387\init.udb
C:\Documents and Settings\All Users\Application Data\538654387\config.udb
C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe
C:\Documents and Settings\All Users\Application Data\538654387
%UserProfile%\Start Menu\Programs\System Security\System Security.lnk
%UserProfile%\Start Menu\Programs\System Security
%UserProfile%\Desktop\System Security.lnk
%PROGRAMDATA%\11769284\11769284.exe
%PROGRAMDATA%\11846754\11846754.exe
%PROGRAMDATA%\13701144\13701144.exe
%ALLUSERSPROFILE%\Application Data\1597884464\83521271.exe
%PROGRAMDATA%\00184705\00184705.exe
%PROGRAMDATA%\90188702\90188702.exe
%ALLUSERSPROFILE%\Application Data\03380828\03380828.exe
%PROGRAMDATA%\29192498\29192498.exe
%PROGRAMDATA%\06837430\06837430.exe
%ALLUSERSPROFILE%\Application Data\14610250\14610250.exe
%ALLUSERSPROFILE%\Application Data\03326093\03326093.exe
%ALLUSERSPROFILE%\Application Data\13496218\13496218.exe
%ALLUSERSPROFILE%\Application Data\52796787\52796787.exe
%ALLUSERSPROFILE%\Application Data\96484328\96484328.exe
%ALLUSERSPROFILE%\Application Data\500153984\500153984.exe
%ALLUSERSPROFILE%\Application Data\00607031\00607031.exe
%ALLUSERSPROFILE%\Application Data\02686578\02686578.exe
%ALLUSERSPROFILE%\Application Data\01560265\01560265.exe
%ALLUSERSPROFILE%\Application Data\847809490\554845319.exe
%PROGRAMDATA%\991537388\1126514300.exe
%ALLUSERSPROFILE%\Application Data\947347721\1255330437.exe
%ALLUSERSPROFILE%\Application Data\646483980\2113272685.exe
%ALLUSERSPROFILE%\Application Data\1087856298\1725032906.exe
%ALLUSERSPROFILE%\Application Data\831600033\1354455340.exe
%ALLUSERSPROFILE%\application data\1838702514\380679599.exe
%ALLUSERSPROFILE%\Application Data\696273957\25238076.exe
%ALLUSERSPROFILE%\Application Data\1046175485\801085450.exe
%ALLUSERSPROFILE%\Application Data\281405228\2084498445.exe
%ALLUSERSPROFILE%\Application Data\383196232\14894324.exe
%ALLUSERSPROFILE%\Application Data\2002822718\2029503323.exe
%ALLUSERSPROFILE%\Application Data\1929861670\498278020.exe
%ALLUSERSPROFILE%\Application Data\914063820\1573468717.exe
%ALLUSERSPROFILE%\Application Data\1964289396\375534146.exe
%ALLUSERSPROFILE%\Application Data\1263973370\1743310514.exe
%ALLUSERSPROFILE%\Application Data\1340156489\202150970.exe
%ALLUSERSPROFILE%\Application Data\1217703993\1327825314.exe
%ALLUSERSPROFILE%\Application Data\568819996\1550536869.exe
%ALLUSERSPROFILE%\Application Data\771996059\695276073.exe
%ALLUSERSPROFILE%\Application Data\1095564415\650526885.exe
%ALLUSERSPROFILE%\Application Data\2018698794\1940874419.exe
%ALLUSERSPROFILE%\Application Data\1457297881\1947101902.exe
%ALLUSERSPROFILE%\Application Data\573251351\1431998300.exe
%ALLUSERSPROFILE%\Application Data\1655800406\2030350728.exe
%ALLUSERSPROFILE%\Application Data\1357783622\1977868703.exe
%ALLUSERSPROFILE%\Application Data\2068742222\438978017.exe
%PROGRAMDATA%\843824418\1591300478.exe
%ALLUSERSPROFILE%\Application Data\1993373367\613622941.exe
%ALLUSERSPROFILE%\Application Data\160465659\432632312.exe
%ALLUSERSPROFILE%\Application Data\988737293\931330021.exe
%USERPROFILE%\Application Data\1163524634\240844061.exe
%ALLUSERSPROFILE%\Application Data\194077280\172939276.exe
%ALLUSERSPROFILE%\Application Data\336546584\431192516.exe
%ALLUSERSPROFILE%\Application Data\114567299\800990911.exe
%ALLUSERSPROFILE%\Application Data\2014101429\1610380076.exe
%ALLUSERSPROFILE%\Application Data\1189037594\372561511.exe
%ALLUSERSPROFILE%\Application Data\278958024\124517242.exe
%ALLUSERSPROFILE%\Application Data\1926316989\1625593810.exe
%ALLUSERSPROFILE%\Application Data\2010372281\1462403437.exe
%ALLUSERSPROFILE%\Application Data\1193890671\9179499.exe
%ALLUSERSPROFILE%\Application Data\1256305888\1003720520.exe
%ALLUSERSPROFILE%\Application Data\1016589770\1714292029.exe
%ALLUSERSPROFILE%\Application Data\1398798156\788573529.exe
%ALLUSERSPROFILE%\Application Data\29046618\549344438.exe
Gumblar is currently targeting users of IE and Google search, delivering malware through compromised sites that infect a user's PC and subsequently intercepts traffic between the user and the visited sites. This means that once infected, anything the victim types could be monitored and used to commit identity theft, such as stealing credit card numbers, passwords or other sensitive data. Visitors encountering the compromised website also risk having their subsequent search results replaced with links that point to other malicious websites. The malware can also steal FTP credentials from the victim's computer and use them to infect more sites, thus increasing the spread of this threat.
Gumblar was first detected in March and has spread more quickly since then, against the expectations of security experts.The scripts attempt to exploit vulnerabilities in Adobe's Acrobat Reader and Flash Player to deliver code that injects malicious search results when a user searches Google on Internet Explorer
How to protect and remove?
If you are running ZoneAlarm® ForceField™ browser security technology you are already protected. If you are running ZoneAlarm Extreme Security, you must turn ON ForceField virtualization (Open ZoneAlarm Extreme and go to 'browser security', 'settings', 'advanced' and click 'enable virtualization'
Read more
How To Remove Any Malware Infection. A Step-By-Step How To. Part 1
How To Remove Any Malware Infection. A Step-By-Step How To. Part 2
How To Remove Any Malware Infection. A Step-By-Step How To. Part 3
How To Remove Any Malware Infection. A Step-By-Step How To. Part 4
How To Remove Any Malware Infection. A Step-By-Step How To. Part 5
Ad-Aware Anniversary Edition provides comprehensive malware protection without loading down your system’s resources, bringing you the core competence you need to stay safe online.Numerous changes in Ad-Aware Anniversary Edition include: Behavior-based heuristical detection; Ad-Watch Live! integrated real-time protection; Customizable Profile Scans and full integration with Windows Security Center.It provides advanced threat protection, and is significantly lighter and faster than our previous versions.
New and Improved Features:
- Malware Detect, Remove AND Clean
- Behavior-based Heuristical Detection
- Integrated Ad-Watch Live! Real-time Protection.
- Rootkit Removal
- Lavasoft AutoStart Manager
- Radically improved resource efficiency
- Lavasoft SmartSet
- Background Scan Mode
- Customizable Profile Scans
- External Drive Scanning
- Pin-Point Scanning
- Full integration with Windows Security Center
- Easy to Download, Install and Use
Ad-Aware is one of the must have program for protecting system against malware attacks. Ad-Aware will protect your system from spyware, keyloggers, trojans and other identity theft software. Ad-Aware has both free and paid versions, and the free version is enough for average user.
Antivirus 2009 is a rogue anti-spyware application.It is is an updated version of Antivirus 2008. Antivirus 2009 is usually promoted via a ZLOB/MediaAccess Codec installer found on adult websites.It floods the user with popups and fake system notifications.The user might click on one of the popups or notifications, all of which claim they will take him to a legitimate security tool, but try to make him purchase Antivirus2009's "licensed version" instead. It redirect web browser to antivirus-premium-scan.com, antivirus-best.com webscannertools.com, livesecurityinfo.com,antivirusonlivescan.com,bestantivirusscan.com
secureclick1.com or premiumlivescan.com and websites that sell the malware.
Symptoms
Manual Removal
Search the following files and delete
Antivirus2009.exe
av2009.exe
av2009[1].exe
AV2009Install.exe
Antivirus 2009.lnk
Uninstall Antivirus.lnk
- Go to Start > Search > All Files or Folders.
- In the "All or part of the the file name" section, type in "Antivirus 2009" file name(s).
- For better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button
Stop Antivirus 2009 Processes
Unregister and delete .dll files
shlwapi.dll
wininet.dll
Delete registry values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run\15358943642955870504508370025739
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Antivirus” = “%ProgramFiles%\Antivirus 2009\Antvrs.exe”
HKEY_CURRENT_USER\Software\Antivirus
Other programs to remove Antivirus 2009:
- Malwarebytes Anti Malware – Download | Malwarebytes' Anti-Malware 1.30
- Windows Defender – Download
- Spyhunter –Download | SpyHunter_Security_Suite_v3
Prevention
- Keep your Windows Security up-to-date
- Download and install a reliable anti-spyware software
Related Posts
A single computer virus, owned by one criminal gang, has compromised hundreds of thousands of online bank accounts worldwide, according to security experts at the RSA FraudAction Research Lab.
That's Sinowal, a super-Trojan that uses a technique called HTML injection to put ersatz information on your browser's screen. The bad info prompts you to type an account number and/or a password. Of course, Sinowal gathers all the information and sends it back home — over a fancy, secure, encrypted connection, no less.
Sinowal operates like many other viruses – injecting corrupt data into Web pages that are usually known and trusted by the victim, and which attack a computer through loopholes in a Web browser (media players are a popular way in). The virus can then prompt the victim to offer confidential information, such as bank account details. More than 2700 bank and e-commerce sites worldwide have been affected by this one Trojan.
Where it differs is not only is Sinowal being constantly updated with patches to beat security filters - it is also storing up user data on everyone its infects, which means it requires major data storage facilities.
Sinowal/Mebroot works by infecting Windows XP's Master Boot Record (MBR) — it takes over the tiny program that's used to boot Windows. MBR infections have existed since the dawn of DOS.
Once Sinowal/Mebroot is in your system, the Trojan runs stealthily, loading itself in true rootkit fashion before Windows starts. The worm flies under the radar by running inside the kernel, the lowest level of Windows, where it sets up its own network communication system, whose external data transmissions use 128-bit encryption. The people who run Sinowal/Mebroot have registered thousands of .com, .net, and .biz domains for use in the scheme.
Sinowal/Mebroot cloaks itself entirely and uses no executable files that you can see. The changes it makes to the Registry are very hard to find. Also, there's no driver module in the module list, and no Sinowal/Mebroot-related svchost.exe or rundll32.exe processes appear in the Task Manager's Processes list
Apparently Sinowal has been successful enough to compromise 270,000 bank accounts and 240,000 credit and debit cards across the US, UK, Australia and Poland.
The main method of delivery isn’t email spam, though, but instead through hacking websites to insert the malicious code onto visitors PC’s.Wordpress blogs have especially become a major target of attack, not least due to users failing to keep their software updated with patches.
Your firewall won't help: Sinowal/Mebroot bypasses Windows' normal communication routines, so it works outside your computer's firewall.
Your antivirus program may help, for a while. Time and time again, however, Sinowal/Mebroot's creators have modified the program well enough to escape detection. AV vendors scramble to catch the latest versions, but with one or two new Sinowal/Mebroot iterations being released every month, the vendors are trying to hit a very fleet — and intelligent — target.
You can't rely on rootkit scanners for protection. Even the best rootkit scanners miss some versions of Sinowal/Mebroot.
Source:BBC-News/Technology
PC Privacy Cleaner is a fake registry cleaner tool, which pretends to be able to clean your registry.PCPrivacyCleaner may spread with trojans, or you can get duped into downloading PCPrivacyCleaner from PCPrivacyCleaner.com. Once you’ve got PCPrivacyCleaner, it pops up annoying messages and runs fake scans.
Symptoms
Manual Removal Steps
1.Press Ctrl+Alt+Del to open Task Manager,check any process like pcpc.exe/PCPC_Setup_Free.exe running,kill that process
2.Open C:\Program Files (assuming windows installed in C drive) and delete the folder named PCPrivacyCleaner or To find PCPrivacyCleaner directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.Search and delete the following PCPrivacyCleaner directories:
C:\ProgramFiles\pcprivacycleaner
%common_programs%\pcprivacycleaner
%program_files%\pcprivacycleaner
3.Remove PC Privacy Cleaner short cuts from desktop, start menu and quick launch.Empty Recycle Bin
4.If PCPrivacyCleaner changed your homepage?Start menu > Control Panel > Internet Options. Next, under Home Page, select the General > Use Default. Type in the URL you want as your home page (e.g., “http://www.google.com”). Then select Apply > OK. You’ll want to open a fresh web page and make sure that your new default home page pops up.
5.How to remove PCPrivacyCleaner registry keys?
Start->Run-> type regedit and press enter.Remove following entries
HKEY_CURRENT_USER\software\pcprivacycleaner
HKEY_CURRENT_USER\software\pcprivacycleaner activationcode
HKEY_CURRENT_USER\software\pcprivacycleaner cookieparams
HKEY_CURRENT_USER\software\pcprivacycleaner installdate
HKEY_CURRENT_USER\software\pcprivacycleaner lastscantime
HKEY_CURRENT_USER\software\pcprivacycleaner totalscancount
HKEY_CURRENT_USER\software\pcprivacycleaner\schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run pcprivacycleaner HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}
6.How to remove PCPrivacyCleaner DLL files
To locate the PCPrivacyCleaner DLL path, go to Start > Search > All Files or Folders. Type PCPrivacyCleaner and in the Look in: select either My Computer or Local Hard Drives. Click the Search button.
Once you have the PCPrivacyCleaner DLL path,Start->Run->type cmd and click “OK.” To change your current directory, type “cd” in the command box, press your “Space” key, and enter the full directory where the PCPrivacyCleaner DLL file is located. (If you’re not sure if the PCPrivacyCleaner DLL file is located in a particular directory, enter “dir” in the command box to display a directory’s contents. To go one directory back, enter “cd ..” in the command box and press “Enter.”)
Here you type regsvr32 /u [dll_name] and press enter to unregister the DLL.If you accidentally do something wrong, you can register it again by using regsvr32 [dll_name].eg:regsvr32 /u pcpc.dll .(How to register/unregister a .dll file)
PCPrivacyCleaner Automatic Removal Instructions
Print these instructions because you’ll have to reboot into Safe Mode. Also back up your computer in case you make a mistake
- Download and save SmitFraudFix to your desktop.
- Restart your computer in Safe ModeOnce thedesktop appears, double click on the SmitfraudFix.exe on your desktop.
- After the credits screen, you’ll see a menu. Select the option number 2, which is ‘Clean (safe mode recommended)’, and thenpress Enter to delete infect files.
- SmitFraudFix will begin cleaning your computer and take a series of cleanup processes. When the process is over, it will automatically begin the Disk Cleanup program.
- Once the Disk Cleanup program is complete, you will be prompted with the message ‘Registry cleaning - Do you want to clean the registry’. Answer Y (Yes) and hit Enter. Reboot your computer.
- SmitFraudFix will now check if wininet.dll is infected. SmitFraudFix will ask you whether to replace the infected file (if there’s any) ‘Replace infected
file?’ Answer by typing Y (Yes) and hit Enter. - Reboot your computer to complete the cleaning process.
- After reboot, a Notepad screen may appear containing a log of all the filesremoved from your computer. If it doesn’t appear, a file will be created called rapport.txt in the root of your drive, (Local Disk C:).
- Restart your computer in Safe Mode .
- Go to C:\Windows\Temp, click Edit, click Select All, press DELETE, and thenclick Yes to confirm that you want all the items to go to the Recycle Bin.
- Go to C:\Documents and Settings\[LISTED USER]\Local Settings\Temp, click Edit, click Select All, press DELETE, and then click Yes to confirm that
you want all the items to go to the Recycle Bin. - Reboot your computer back to normal mode.
How to use SmitfraudFix ,detailed instructions here
McAfee SiteAdvisor helps protect you from all kinds of Web-based security threats including spyware, adware, spam, viruses, browser exploits, and online scams. Automated testers continually patrol the Web to browse sites, download files, and sign-up for things with e-mail addresses. As you search, browse, download, or register online, SiteAdvisor's safety ratings help you stay safe and in control.
When you do a google search or a yahoo search, a little symbol will appear next to each entry. A green check means it is a safe site to enter,no viruses or trojans there. A yellow question mark means it has questionable content.You might get something evil there. A red X means it is a site known for trojans and malicious software. Don't enter a site unless it shows a green check.
McAfee SiteAdvisor (Free Ver)
McAfeeSiteAdvisor +: McAfee SiteAdvisor Plus | Mcafee Siteadvisor Plus 2.1.2.25.
Also read :McAfee SiteAdvisor for Firefox
Malicious attackers are once again taking advantage of event-based social engineering attacks, and are currently mass mailing fake notifications for Microsoft’s Patch Tuesday, attaching a copy of Trojan.Backdoor.Haxdoor, next to a legitimately looking PGP signature which is, of course, fake too : “We received some questions from customers about an e-mail that´s circulating that claims to…..[Link: http://feeds.feedburner.com/~r/zdnet/security/~3/4...]
