Most of the people don't realise that browser extensions might  be dangerous .But why they download & installing it?.May be  they are too lazy to download and install a software with the same functions as the extension, or  it may  save some time or it is a faster way to explore lots of features in a short time.After installation, the malicious extension can gain complete control of the victim’s profile and  may have access to your data.By installing these extensions, you give your browser additional functionality unknowingly . So  don’t install an app or extension unless you trust its creator.

ExtShield (formerly Chrome Protector)tells you that you need to download Google Chrome in order to run it. It keeps a more than  100s of blacklisted  browser extensions known to contain adware, spyware or malware.It  will scan your browser and alert you if any of these are installed.

1-26-2014 8-46-12 PM

ExtShield extension is a freeware  available  at Chrome webstore. Once installed, you can access the shield located at the right hand top corner of your webpage to know the status about your other installed extensions.

1-26-2014 9-11-26 PM

✔ Stops over 100 adware, spyware or malware extensions that are currently available in chrome web store and used by millions
✔ Monitors extensions and websites behavior to detect malicious patterns
✔ Shield code is protected to avoid bypassing by malware creators
dl21-26-2014 9-21-07 PM
 


Sometimes your web browser starts behaving strangely, it may be a sign your browser has been hijacked. Malicious software    ( malware) can take control of your web browser and change your home page, redirect your search results to malicious sites, or  you face  with a barrage of popup ads.Malwares are often bundled with browser hijackers. A browser hijacker  is a type of malware program that alters your computer's browser settings so that you are redirected to Web sites that you had no intention of visiting.It  alter your  default home pages and search pages. The hijacker can modify  , control  and redirect  your search results and ultimately  he can collect  your personal information such as usernames, passwords, and credit card and banking information.

One of the easiest way is to   block unwanted websites by modifying machine’s HOSTS file .What is a Host file? In a simple  way  Hosts file is like an address book.It is a common part of an operating system's Internet Protocol (IP) implementation, and serves the function of translating human-friendly hostnames into numeric protocol addresses, called IP addresses, that identify and locate a host in an IP network(Wikipedia).One of the  feature of the HOSTS file is its ability to block other applications from connecting to the Internet, providing the entry exists.You can use  HOSTS file to block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and   hijackers

You can search the Host file in  WINDOWS\system32\  directory.

13-01-2013 10-02-30

Open the host file in notepad  and to block a website  input an entry  in the host file.If you want to block ad.doubleclick.net just enter 127.0.0.1 as an IP address then type ad.doubleclick.net  in the host file.Each entry should be placed on an individual line. The IP address and the hostname should be separated by a space or a tab. In this way, you can block any given website by just pointing it to the IP address
127.0.0.2 www.link-assistant.com

127.0.0.1 ad.doubleclick.net

13-01-2013 10-31-21

When the  browser hijacker or you will try to open the ad.doubleclick.net  , you will see a blank page.

CBSA newly discovered  trojan   is spreading   fast  , which is designed to damaging a victim's computer once it has harvested sensitive data.It's being called either Disttrack  or the Shamoon    . It  steals the data  from the 'Users', 'Documents and Settings', and 'System32/Drivers' and 'System32/Config' folders on Windows computers.It also  overwrites files and the Master Boot Record  of the machine and  latter  PC becomes unbootable.According to Kaspersky Labs this   trojan  consists of a 900KB folder that contains a number of "encrypted resources".The affected OS are  Windows 95, Windows 98, Windows XP, Windows 200, Windows Vista, Windows NT, Windows ME, Windows 7, Windows Server 2003 and Windows Server 2008.

Symantec said it has updated its antivirus to protect against the malware.Seculert wrote in a blog post about Shamoon, you can read the post here

These days many viruses and malwares  target  your PC , rendering the computer unbootable. Microsoft Standalone System Sweeper is a recovery tool that can help you start an infected PC and perform an offline scan to help identify and remove viruses, trojans, rootkits and other forms of malware effectively.

06-08-2011 20-20-38 

It can also be used if you cannot install or start an antivirus solution on your PC, or if the installed solution can’t detect or remove malware on your PC.This tool installs itself to either a USB drive or a blank CD/DVD disc and creates a bootable media that can be used to recover your system in the event of a malware or virus infection.

06-08-2011 20-21-27

please ensure  that you have a blank CD, DVD, or USB drive with at least 250 MB of space, and an active Internet connection .To use Standalone System Sweeper ,users need to boot from the disc or USB device which in turn loads the tool that gives you the options to scan the PC and recover it.

06-08-2011 20-25-33

It will load the Windows preinstall environment to run the Microsoft Standalone System Sweeper application for scanning .This  will first scans your boot sector for any corrupted files or settings. It then scans your system for any known malware or infections.

06-08-2011 20-49-2306-08-2011 20-5-45 

Download 32 Bit Version | Download 64 Bit Version | Installation Help

You may feel  toolbars for browsers are handy, but sometimes spammers use their crappy toolbars to infect your browser spywares, which in return will enable to do malicious stuff on your computer.It not only eat some of your system6-1-2010 06-27-55 resource but also hijack your search engine.Most of the browser tool bars are rogue software that you don’t know when you installed and how to uninstall.
IObit Uninstaller is a free tool that lets you uninstall programs and toolbars of the browser in a complete, removing all traces left on computer.It  uninstall browser tool bars which are hard to be detected in control panel.Windows inbuilt Add/Remove programs doesn't loads quickly and also not uninstalls applications properly.Where as IObit uninstaller provides simple, powerful and easy to use program helps to uninstall software .It can help you force removal of stubborn programs from your PC.
6-1-2010 06-35-19
IObit Uninstaller creates a restore image before every uninstall and you can view the uninstall details in the Log Manager. If any software is uninstalled by mistake, you can restore it with the created image.And the best thing of all,  you need to install this tool in your PC.Through the sidebar you can filter the list of programs in various ways.You can view only the toolbars installed in your browser, recently installed programs, large programs, rarely used and Windows updates.
Key Benefits
  • 1-Click Toolbars Removal
  • Batch Uninstall
  • Standard and Advanced Uninstall
  • Without Installation
  • Forced Uninstall
  • Log Manager and Restoration
  • Free and Easy-to-use
Download
Other Tools worth to check

Whether your PC is slow? It may  due to the  malware infection. Malware is nothing but some malicious software.Norman Malware Cleaner is a Norman program that can be used to detect and remove specific malicious software.There is no need to install this one, just run the program.

5-8-2010 05-58-06

Features

  • Kill running processes that are infected
  • Remove infections from disk (including ActiveX components and browser helper objects)
  • Reveal and remove rootkits
  • Restore correct registry values
  • Remove references created by malware in hosts file
  • Remove windows firewall rules for malicious programs
  • Download: Norman_Malware_Cleaner |Os:Windows 98, Me, NT, 2000, XP, 2003, Vista, 2008 and 7| 63.2MB|Freeware

    To give Norman Malware Cleaner the best working conditions possible, it is better to  start the computer in Safe mode before running the program.

    Note: This program is not a substitute for running normal proactive antivirus protection, but it can be used as a reactive tool which can handle systems that are already infected.

    Also Read

    Looking for free Security Tools for you computer? Then visit andymanchesta .This is the right place for you! Here you will be able to find from Anti-virus, Anti-Spyware AntiRootkit Firewall and much more for free! 

    AndyManchesta  is the developer of SDFix  the famous tool that removes thousands of different types of trojans, worms, rootkits and other malwares

    3-6-2010 08-29-59

    Visit :http://andymanchesta.com/

    Security researchers  found a new piece of ransomware that blocks an infected computer from accessing the Internet until a fee is paid via SMS.The ransomware file is bundled with a tool called uFast Download Manager.  If your PC is infected, a message is posted in Russian  demanding a ransom under the guise of activating the uFast Download Manager application.

    12-5-2009 21-42-52

    Image courtesy: CA Community

    Read full Article here:Ransomware Blocks Internet Access

    System Security is a rogue anti-spyware that belongs to family WinwebSecurity. It  uses Trojan or fake video codec to get into the . Once installed on a computer, SystemSecurity will start showing annoying pop-ups with false information about virus infections and serious system risks in order to sell itself.It  starts generate fake security reports about infections. These false security warnings  are intentioned to make people believe  their computer is seriously infected with malicious viruses and  force you to  purchase their  licensed version.

     

    8-6-2009 7-45-34 AM

     

    It affect your internet connection speed and  slowdown the system.It also change your browser settings, leads to system crash.System Security 2009 is a PC parasite, an infection in itself, and should be avoided.

     

    Manual Removal

    Step 1 : By  Using  Windows Task Manager

     

    %PROGRAMDATA%\11769284\11769284.exe
    %PROGRAMDATA%\11846754\11846754.exe
    %PROGRAMDATA%\13701144\13701144.exe
    %ALLUSERSPROFILE%\Application Data\1597884464\83521271.exe
    %PROGRAMDATA%\00184705\00184705.exe
    %PROGRAMDATA%\90188702\90188702.exe
    %ALLUSERSPROFILE%\Application Data\03380828\03380828.exe
    %PROGRAMDATA%\29192498\29192498.exe
    %PROGRAMDATA%\06837430\06837430.exe
    %ALLUSERSPROFILE%\Application Data\14610250\14610250.exe
    %ALLUSERSPROFILE%\Application Data\03326093\03326093.exe
    %ALLUSERSPROFILE%\Application Data\13496218\13496218.exe
    %ALLUSERSPROFILE%\Application Data\52796787\52796787.exe
    %ALLUSERSPROFILE%\Application Data\96484328\96484328.exe
    %ALLUSERSPROFILE%\Application Data\500153984\500153984.exe
    %ALLUSERSPROFILE%\Application Data\00607031\00607031.exe
    %ALLUSERSPROFILE%\Application Data\02686578\02686578.exe
    %ALLUSERSPROFILE%\Application Data\01560265\01560265.exe
    %ALLUSERSPROFILE%\Application Data\847809490\554845319.exe
    %PROGRAMDATA%\991537388\1126514300.exe
    %ALLUSERSPROFILE%\Application Data\947347721\1255330437.exe
    %ALLUSERSPROFILE%\Application Data\646483980\2113272685.exe
    %ALLUSERSPROFILE%\Application Data\1087856298\1725032906.exe
    %ALLUSERSPROFILE%\Application Data\831600033\1354455340.exe
    %ALLUSERSPROFILE%\application data\1838702514\380679599.exe
    %ALLUSERSPROFILE%\Application Data\696273957\25238076.exe
    %ALLUSERSPROFILE%\Application Data\1046175485\801085450.exe
    %ALLUSERSPROFILE%\Application Data\281405228\2084498445.exe
    %ALLUSERSPROFILE%\Application Data\383196232\14894324.exe
    %ALLUSERSPROFILE%\Application Data\2002822718\2029503323.exe
    %ALLUSERSPROFILE%\Application Data\1929861670\498278020.exe
    %ALLUSERSPROFILE%\Application Data\914063820\1573468717.exe
    %ALLUSERSPROFILE%\Application Data\1964289396\375534146.exe
    %ALLUSERSPROFILE%\Application Data\1263973370\1743310514.exe
    %ALLUSERSPROFILE%\Application Data\1340156489\202150970.exe
    %ALLUSERSPROFILE%\Application Data\1217703993\1327825314.exe
    %ALLUSERSPROFILE%\Application Data\568819996\1550536869.exe
    %ALLUSERSPROFILE%\Application Data\771996059\695276073.exe
    %ALLUSERSPROFILE%\Application Data\1095564415\650526885.exe
    %ALLUSERSPROFILE%\Application Data\2018698794\1940874419.exe
    %ALLUSERSPROFILE%\Application Data\1457297881\1947101902.exe
    %ALLUSERSPROFILE%\Application Data\573251351\1431998300.exe
    %ALLUSERSPROFILE%\Application Data\1655800406\2030350728.exe
    %ALLUSERSPROFILE%\Application Data\1357783622\1977868703.exe
    %ALLUSERSPROFILE%\Application Data\2068742222\438978017.exe
    %PROGRAMDATA%\843824418\1591300478.exe
    %ALLUSERSPROFILE%\Application Data\1993373367\613622941.exe
    %ALLUSERSPROFILE%\Application Data\160465659\432632312.exe
    %ALLUSERSPROFILE%\Application Data\988737293\931330021.exe
    %USERPROFILE%\Application Data\1163524634\240844061.exe
    %ALLUSERSPROFILE%\Application Data\194077280\172939276.exe
    %ALLUSERSPROFILE%\Application Data\336546584\431192516.exe
    %ALLUSERSPROFILE%\Application Data\114567299\800990911.exe
    %ALLUSERSPROFILE%\Application Data\2014101429\1610380076.exe
    %ALLUSERSPROFILE%\Application Data\1189037594\372561511.exe
    %ALLUSERSPROFILE%\Application Data\278958024\124517242.exe
    %ALLUSERSPROFILE%\Application Data\1926316989\1625593810.exe
    %ALLUSERSPROFILE%\Application Data\2010372281\1462403437.exe
    %ALLUSERSPROFILE%\Application Data\1193890671\9179499.exe
    %ALLUSERSPROFILE%\Application Data\1256305888\1003720520.exe
    %ALLUSERSPROFILE%\Application Data\1016589770\1714292029.exe
    %ALLUSERSPROFILE%\Application Data\1398798156\788573529.exe
    %ALLUSERSPROFILE%\Application Data\29046618\549344438.exe
    SystemSecurity.exe
    C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe


    Step 2 : By Using  Registry Editor

    Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\System Security
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"

     

    Step 3 : Remove these System Security files

    System Security 2009 Support.lnk
    System Security 2009.lnk
    359F5809-00B8-4455-A73A-9EA62A51101B
    SystemSecurity.exe
    C:\Documents and Settings\All Users\Application Data\538654387\Languages\German.lng
    C:\Documents and Settings\All Users\Application Data\538654387\Languages\English.lng
    C:\Documents and Settings\All Users\Application Data\538654387\Languages\Spanish.lng
    C:\Documents and Settings\All Users\Application Data\538654387\Languages
    C:\Documents and Settings\All Users\Application Data\538654387\init.udb
    C:\Documents and Settings\All Users\Application Data\538654387\config.udb
    C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe
    C:\Documents and Settings\All Users\Application Data\538654387
    %UserProfile%\Start Menu\Programs\System Security\System Security.lnk
    %UserProfile%\Start Menu\Programs\System Security
    %UserProfile%\Desktop\System Security.lnk
    %PROGRAMDATA%\11769284\11769284.exe
    %PROGRAMDATA%\11846754\11846754.exe
    %PROGRAMDATA%\13701144\13701144.exe
    %ALLUSERSPROFILE%\Application Data\1597884464\83521271.exe
    %PROGRAMDATA%\00184705\00184705.exe
    %PROGRAMDATA%\90188702\90188702.exe
    %ALLUSERSPROFILE%\Application Data\03380828\03380828.exe
    %PROGRAMDATA%\29192498\29192498.exe
    %PROGRAMDATA%\06837430\06837430.exe
    %ALLUSERSPROFILE%\Application Data\14610250\14610250.exe
    %ALLUSERSPROFILE%\Application Data\03326093\03326093.exe
    %ALLUSERSPROFILE%\Application Data\13496218\13496218.exe
    %ALLUSERSPROFILE%\Application Data\52796787\52796787.exe
    %ALLUSERSPROFILE%\Application Data\96484328\96484328.exe
    %ALLUSERSPROFILE%\Application Data\500153984\500153984.exe
    %ALLUSERSPROFILE%\Application Data\00607031\00607031.exe
    %ALLUSERSPROFILE%\Application Data\02686578\02686578.exe
    %ALLUSERSPROFILE%\Application Data\01560265\01560265.exe
    %ALLUSERSPROFILE%\Application Data\847809490\554845319.exe
    %PROGRAMDATA%\991537388\1126514300.exe
    %ALLUSERSPROFILE%\Application Data\947347721\1255330437.exe
    %ALLUSERSPROFILE%\Application Data\646483980\2113272685.exe
    %ALLUSERSPROFILE%\Application Data\1087856298\1725032906.exe
    %ALLUSERSPROFILE%\Application Data\831600033\1354455340.exe
    %ALLUSERSPROFILE%\application data\1838702514\380679599.exe
    %ALLUSERSPROFILE%\Application Data\696273957\25238076.exe
    %ALLUSERSPROFILE%\Application Data\1046175485\801085450.exe
    %ALLUSERSPROFILE%\Application Data\281405228\2084498445.exe
    %ALLUSERSPROFILE%\Application Data\383196232\14894324.exe
    %ALLUSERSPROFILE%\Application Data\2002822718\2029503323.exe
    %ALLUSERSPROFILE%\Application Data\1929861670\498278020.exe
    %ALLUSERSPROFILE%\Application Data\914063820\1573468717.exe
    %ALLUSERSPROFILE%\Application Data\1964289396\375534146.exe
    %ALLUSERSPROFILE%\Application Data\1263973370\1743310514.exe
    %ALLUSERSPROFILE%\Application Data\1340156489\202150970.exe
    %ALLUSERSPROFILE%\Application Data\1217703993\1327825314.exe
    %ALLUSERSPROFILE%\Application Data\568819996\1550536869.exe
    %ALLUSERSPROFILE%\Application Data\771996059\695276073.exe
    %ALLUSERSPROFILE%\Application Data\1095564415\650526885.exe
    %ALLUSERSPROFILE%\Application Data\2018698794\1940874419.exe
    %ALLUSERSPROFILE%\Application Data\1457297881\1947101902.exe
    %ALLUSERSPROFILE%\Application Data\573251351\1431998300.exe
    %ALLUSERSPROFILE%\Application Data\1655800406\2030350728.exe
    %ALLUSERSPROFILE%\Application Data\1357783622\1977868703.exe
    %ALLUSERSPROFILE%\Application Data\2068742222\438978017.exe
    %PROGRAMDATA%\843824418\1591300478.exe
    %ALLUSERSPROFILE%\Application Data\1993373367\613622941.exe
    %ALLUSERSPROFILE%\Application Data\160465659\432632312.exe
    %ALLUSERSPROFILE%\Application Data\988737293\931330021.exe
    %USERPROFILE%\Application Data\1163524634\240844061.exe
    %ALLUSERSPROFILE%\Application Data\194077280\172939276.exe
    %ALLUSERSPROFILE%\Application Data\336546584\431192516.exe
    %ALLUSERSPROFILE%\Application Data\114567299\800990911.exe
    %ALLUSERSPROFILE%\Application Data\2014101429\1610380076.exe
    %ALLUSERSPROFILE%\Application Data\1189037594\372561511.exe
    %ALLUSERSPROFILE%\Application Data\278958024\124517242.exe
    %ALLUSERSPROFILE%\Application Data\1926316989\1625593810.exe
    %ALLUSERSPROFILE%\Application Data\2010372281\1462403437.exe
    %ALLUSERSPROFILE%\Application Data\1193890671\9179499.exe
    %ALLUSERSPROFILE%\Application Data\1256305888\1003720520.exe
    %ALLUSERSPROFILE%\Application Data\1016589770\1714292029.exe
    %ALLUSERSPROFILE%\Application Data\1398798156\788573529.exe
    %ALLUSERSPROFILE%\Application Data\29046618\549344438.exe

    Softwares

    Gumblar is currently targeting users of IE and Google search, delivering malware through compromised sites that infect a user's PC and subsequently intercepts traffic between the user and the visited sites. This means that once infected, anything the victim types could be monitored and used to commit identity theft, such as stealing credit card numbers, passwords or other sensitive data. Visitors encountering the compromised website also risk having their subsequent search results replaced with links that point to other malicious websites. The malware can also steal FTP credentials from the victim's computer and use them to infect more sites, thus increasing the spread of this threat.

     

    Gumblar was first detected in March and has spread more quickly since then, against the expectations of security experts.The scripts attempt to exploit vulnerabilities in Adobe's Acrobat Reader and Flash Player to deliver code that injects malicious search results when a user searches Google on Internet Explorer

     

    6-5-2009 5-53-28 AM

     

    How to protect and remove?

    If you are running ZoneAlarm® ForceField™ browser security technology you are already protected. If you are running ZoneAlarm Extreme Security, you must turn ON ForceField virtualization (Open ZoneAlarm Extreme and go to 'browser security', 'settings', 'advanced' and click 'enable virtualization'

    Read more

    Gumblar .cn Exploit

    Removal and Prevention of Gumblar.cn Infections

    How To Remove Any Malware Infection. A Step-By-Step How To. Part 1

     

     

    How To Remove Any Malware Infection. A Step-By-Step How To. Part 2

     

     

    How To Remove Any Malware Infection. A Step-By-Step How To. Part 3

     

     

    How To Remove Any Malware Infection. A Step-By-Step How To. Part 4

     

     

    How To Remove Any Malware Infection. A Step-By-Step How To. Part 5

     

    Ad-Aware Anniversary Edition provides comprehensive malware protection without loading down your system’s resources, bringing you the core competence you need to stay safe online.Numerous changes in Ad-Aware Anniversary Edition include: Behavior-based heuristical detection; Ad-Watch Live! integrated real-time protection; Customizable Profile Scans and full integration with Windows Security Center.It provides advanced threat protection, and is significantly lighter and faster than our previous versions.

     

    1-21-2009 8-51-19 PM

    New and Improved Features:

    • Malware Detect, Remove AND Clean
    • Behavior-based Heuristical Detection
    • Integrated Ad-Watch Live! Real-time Protection.
    • Rootkit Removal
    • Lavasoft AutoStart Manager
    • Radically improved resource efficiency
    • Lavasoft SmartSet
    • Background Scan Mode
    • Customizable Profile Scans
    • External Drive Scanning
    • Pin-Point Scanning
    • Full integration with Windows Security Center
    • Easy to Download, Install and Use

     

    Ad-Aware is one of the must have program for protecting system against malware attacks. Ad-Aware will protect your system from spyware, keyloggers, trojans and other identity theft software. Ad-Aware has both free and paid versions, and the free version is enough for average user.

    download_thumb[1] Free version

     

    Uploadbox |Uploading.com|Rapidshare

    Antivirus  2009 is a rogue anti-spyware application.It is is an updated version of Antivirus 2008. Antivirus 2009 is usually promoted via a ZLOB/MediaAccess Codec installer found on adult websites.It floods the user with popups and fake system notifications.The user might click on one of the popups or notifications, all of which claim they will take him to a legitimate security tool, but try to make him purchase Antivirus2009's "licensed version" instead. It    redirect web browser to antivirus-premium-scan.com, antivirus-best.com webscannertools.com, livesecurityinfo.com,antivirusonlivescan.com,bestantivirusscan.com

    secureclick1.com   or  premiumlivescan.com and websites that sell the malware.

     

    antivirus2009

     

     

    Symptoms

     

  • "Critical System Error",
  • "Your computer is infected",
  • Hijacked homepage to obscure webpage.
  • Flashing icons appear on your system tray (Near of your system clock).

     

    Manual Removal

     

    Search the following files and delete

    Antivirus2009.exe
    av2009.exe
    av2009[1].exe
    AV2009Install.exe
    Antivirus 2009.lnk
    Uninstall Antivirus.lnk

    1. Go to Start > Search > All Files or Folders.
    2. In the "All or part of the the file name" section, type in "Antivirus 2009" file name(s).
    3. For better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button

     

    Stop  Antivirus 2009 Processes

     

  • Click the Start menu, select Run.
  • Type taskmgr.exe into the the Run command box, and click “OK.” You can also launch the Task Manager by pressing keys ALT + CTRL + DELETE or CTRL + Shift + ESC.
  • Click Processes tab, and find Express Antivirus 2009 processes.
  • Once you’ve found the Express Antivirus 2009 processes, right-click them and select “End Process” to kill Express Antivirus 2009.

     

    Unregister and delete .dll files


    shlwapi.dll
    wininet.dll

     

  • Start” and then click on “Run
  • Now in the Run command box, type “cmd“, and then click on “OK
  • Type “regsvr32 /u filename.dll” where “filename” is the name of the file that you like to Unregister

    1-14-2009 6-22-53 AM

     

    Delete registry values:

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run\15358943642955870504508370025739
    HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Antivirus” = “%ProgramFiles%\Antivirus 2009\Antvrs.exe”
    HKEY_CURRENT_USER\Software\Antivirus

                                                                                                                                         Other programs to remove Antivirus 2009:

     

    Prevention

    • Keep your Windows Security up-to-date
    • Download and install a reliable anti-spyware software

    Related Posts

  • A single computer virus, owned by one criminal gang, has compromised hundreds of thousands of online bank accounts worldwide, according to security experts at the RSA FraudAction Research Lab.

    That's Sinowal, a super-Trojan that uses a technique called HTML injection to put ersatz information on your browser's screen. The bad info prompts you to type an account number and/or a password. Of course, Sinowal gathers all the information and sends it back home — over a fancy, secure, encrypted connection, no less.

    Sinowal operates like many other viruses – injecting corrupt data into Web pages that are usually known and trusted by the victim, and which attack a computer through loopholes in a Web browser (media players are a popular way in). The virus can then prompt the victim to offer confidential information, such as bank account details. More than 2700 bank and e-commerce sites worldwide have been affected by this one Trojan.

    Where it differs is not only is Sinowal being constantly updated with patches to beat security filters - it is also storing up user data on everyone its infects, which means it requires major data storage facilities.

    Sinowal/Mebroot works by infecting Windows XP's Master Boot Record (MBR) — it takes over the tiny program that's used to boot Windows. MBR infections have existed since the dawn of DOS.

    Once Sinowal/Mebroot is in your system, the Trojan runs stealthily, loading itself in true rootkit fashion before Windows starts. The worm flies under the radar by running inside the kernel, the lowest level of Windows, where it sets up its own network communication system, whose external data transmissions use 128-bit encryption. The people who run Sinowal/Mebroot have registered thousands of .com, .net, and .biz domains for use in the scheme.

    Sinowal/Mebroot cloaks itself entirely and uses no executable files that you can see. The changes it makes to the Registry are very hard to find. Also, there's no driver module in the module list, and no Sinowal/Mebroot-related svchost.exe or rundll32.exe processes appear in the Task Manager's Processes list

    Apparently Sinowal has been successful enough to compromise 270,000 bank accounts and 240,000 credit and debit cards across the US, UK, Australia and Poland.

    The main method of delivery isn’t email spam, though, but instead through hacking websites to insert the malicious code onto visitors PC’s.Wordpress blogs have especially become a major target of attack, not least due to users failing to keep their software updated with patches.

    Your firewall won't help: Sinowal/Mebroot bypasses Windows' normal communication routines, so it works outside your computer's firewall.

    Your antivirus program may help, for a while. Time and time again, however, Sinowal/Mebroot's creators have modified the program well enough to escape detection. AV vendors scramble to catch the latest versions, but with one or two new Sinowal/Mebroot iterations being released every month, the vendors are trying to hit a very fleet — and intelligent — target.

    You can't rely on rootkit scanners for protection. Even the best rootkit scanners miss some versions of Sinowal/Mebroot.

    Source:BBC-News/Technology

    PC Privacy Cleaner is a fake registry cleaner tool, which pretends to be able to clean your registry.PCPrivacyCleaner may spread with trojans, or you can get duped into downloading PCPrivacyCleaner from PCPrivacyCleaner.com. Once you’ve got PCPrivacyCleaner, it pops up annoying messages and runs fake scans.

    sparks021

    sparks022 sparks023

    Symptoms

  • "Critical System Error",
  • "Your computer is infected",
  • Hijacked homepage to obscure webpage.
  • Flashing icons appear on your system tray (Near of your system clock).
  • Manual Removal Steps

    1.Press Ctrl+Alt+Del to open Task Manager,check any process like pcpc.exe/PCPC_Setup_Free.exe running,kill that process

    sparks024

    2.Open C:\Program Files (assuming windows installed in C drive) and delete the folder named PCPrivacyCleaner or To find PCPrivacyCleaner directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.Search and delete the following PCPrivacyCleaner directories:
    C:\ProgramFiles\pcprivacycleaner
    %common_programs%\pcprivacycleaner
    %program_files%\pcprivacycleaner

    3.Remove  PC Privacy Cleaner  short cuts from desktop, start menu and quick launch.Empty Recycle Bin

    4.If PCPrivacyCleaner changed your homepage?Start menu > Control Panel > Internet Options. Next, under Home Page, select the General > Use Default. Type in the URL you want as your home page (e.g., “http://www.google.com”). Then select Apply > OK. You’ll want to open a fresh web page and make sure that your new default home page pops up.

    5.How to remove PCPrivacyCleaner registry keys?

    Start->Run-> type regedit and press enter.Remove following entries

    HKEY_CURRENT_USER\software\pcprivacycleaner
    HKEY_CURRENT_USER\software\pcprivacycleaner activationcode
    HKEY_CURRENT_USER\software\pcprivacycleaner cookieparams
    HKEY_CURRENT_USER\software\pcprivacycleaner installdate
    HKEY_CURRENT_USER\software\pcprivacycleaner lastscantime
    HKEY_CURRENT_USER\software\pcprivacycleaner totalscancount
    HKEY_CURRENT_USER\software\pcprivacycleaner\schedule
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run pcprivacycleaner                                                                                                 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}

    6.How to remove PCPrivacyCleaner DLL files

    To locate the PCPrivacyCleaner DLL path, go to Start > Search > All Files or Folders. Type PCPrivacyCleaner and in the Look in: select either My Computer or Local Hard Drives. Click the Search button.

    Once you have the PCPrivacyCleaner DLL path,Start->Run->type cmd and click “OK.” To change your current directory, type “cd” in the command box, press your “Space” key, and enter the full directory where the PCPrivacyCleaner DLL file is located. (If you’re not sure if the PCPrivacyCleaner DLL file is located in a particular directory, enter “dir” in the command box to display a directory’s contents. To go one directory back, enter “cd ..” in the command box and press “Enter.”)

    Here you type regsvr32 /u [dll_name] and press enter to unregister the DLL.If you accidentally do something wrong, you can register it again by using regsvr32 [dll_name].eg:regsvr32 /u pcpc.dll  .(How to register/unregister a .dll file)

    PCPrivacyCleaner Automatic Removal Instructions

    Print these instructions because you’ll have to reboot into Safe Mode. Also back up your computer in case you make a mistake

    1. Download and save SmitFraudFix to your desktop.
    2. Restart your computer in Safe ModeOnce thedesktop appears, double click on the SmitfraudFix.exe on your desktop.
    3. After the credits screen, you’ll see a menu. Select the option number 2, which is ‘Clean (safe mode recommended)’, and thenpress Enter to delete infect files.
    4. SmitFraudFix will begin cleaning your computer and take a series of cleanup processes. When the process is over, it will automatically begin the Disk Cleanup program.
    5. Once the Disk Cleanup program is complete, you will be prompted with the message ‘Registry cleaning - Do you want to clean the registry’. Answer Y (Yes) and hit Enter. Reboot your computer.
    6. SmitFraudFix will now check if wininet.dll is infected. SmitFraudFix will ask you whether to replace the infected file (if there’s any) ‘Replace infected
      file?’
      Answer by typing Y (Yes) and hit Enter.
    7. Reboot your computer to complete the cleaning process.
    8. After reboot, a Notepad screen may appear containing a log of all the filesremoved from your computer. If it doesn’t appear, a file will be created called rapport.txt in the root of your drive, (Local Disk C:).
    9. Restart your computer in Safe Mode .
    10. Go to C:\Windows\Temp, click Edit, click Select All, press DELETE, and thenclick Yes to confirm that you want all the items to go to the Recycle Bin.
    11. Go to C:\Documents and Settings\[LISTED USER]\Local Settings\Temp, click Edit, click Select All, press DELETE, and then click Yes to confirm that
      you want all the items to go to the Recycle Bin.
    12. Reboot your computer back to normal mode.

    How to use  SmitfraudFix ,detailed instructions here

    McAfee SiteAdvisor helps protect you from all kinds of Web-based security threats including spyware, adware, spam, viruses, browser exploits, and online scams. Automated testers continually patrol the Web to browse sites, download files, and sign-up for things with e-mail addresses. As you search, browse, download, or register online, SiteAdvisor's safety ratings help you stay safe and in control.

    slide_2_1 slide_2_2

    When you do a google search or a yahoo search, a little symbol will appear next to each entry. A green check means it is a safe site to enter,no viruses or trojans there. A yellow question mark means it has questionable content.You might get something evil there. A red X means it is a site known for trojans and malicious software. Don't enter a site unless it shows a green check.

  • Protects you from adware, spyware, spam, viruses and online scams.
  • Advises you about the safety of sites using a colored button in your browser toolbar.
  • Enhances your online search by placing safety ratings next to search results.
  • Warns you about dangerous sites and search results with clear messages.
  • Provides you with all the details about a site's safety rating on request.
  • Updates automatically to protect against new threats
  • Download icon  McAfee SiteAdvisor (Free Ver)

    McAfeeSiteAdvisor +: McAfee SiteAdvisor Plus | Mcafee Siteadvisor Plus 2.1.2.25.

    Also read :McAfee SiteAdvisor for Firefox

    Malicious attackers are once again taking advantage of event-based social engineering attacks, and are currently mass mailing fake notifications for Microsoft’s Patch Tuesday, attaching a copy of Trojan.Backdoor.Haxdoor, next to a legitimately looking PGP signature which is, of course, fake too : “We received some questions from customers about an e-mail that´s circulating that claims to…..[Link: http://feeds.feedburner.com/~r/zdnet/security/~3/4...]

    sparksspace