Archive for May, 2011

May 28

Windows Risks Preventions Adware Removal Instructions

The Emsisoft malware research team has discovered a new outbreak of the Windows Risks Preventions adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRisksPreventions.

Windows Risks Preventions is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Another variants:

Create new file:

  • %UserProfile%\Application Data\Microsoft\%random%.exe

Create/modify registry entries:

  • HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
    (String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore
    (DWORD) DisableSR = 0×00000001 (1)
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System
    (DWORD) EnableLUA = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe
    (String) Debugger = svchost.exe

Screenshots:

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

Adware.Win32.WindowsRisksPreventions

How to remove the infection of Windows Risks Preventions (Adware.Win32.WindowsRisksPreventions)?

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

May 28

Windows Custom Settings Adware Removal Instructions

The Emsisoft malware research team has discovered a new outbreak of the Windows Custom Settings adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsCustomSettings.

Windows Custom Settings is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Another variants:

Create new file:

  • %UserProfile%\Application Data\Microsoft\%random%.exe

Create/modify registry entries:

  • HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
    (String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore
    (DWORD) DisableSR = 0×00000001 (1)
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System
    (DWORD) EnableLUA = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe
    (String) Debugger = svchost.exe

Screenshots:

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

Adware.Win32.WindowsCustomSettings

How to remove the infection of Windows Custom Settings (Adware.Win32.WindowsCustomSettings)?

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

May 27

Windows Firewall Unit Adware Removal Instructions

The Emsisoft malware research team has discovered a new outbreak of the Windows Firewall Unit adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsFirewallUnit.

Windows Firewall Unit is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Another variants:

Create new file:

  • %UserProfile%\Application Data\Microsoft\%random%.exe

Create/modify registry entries:

  • HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
    (String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore
    (DWORD) DisableSR = 0×00000001 (1)
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System
    (DWORD) EnableLUA = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe
    (String) Debugger = svchost.exe

Screenshots:

Adware.Win32.WindowsFirewallUnit

Adware.Win32.WindowsFirewallUnit

Adware.Win32.WindowsFirewallUnit

Adware.Win32.WindowsFirewallUnit

Adware.Win32.WindowsFirewallUnit

Adware.Win32.WindowsFirewallUnit

Adware.Win32.WindowsFirewallUnit

How to remove the infection of Windows Firewall Unit (Adware.Win32.WindowsFirewallUnit)?

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

May 24

Windows Safeguard Utility Adware Removal Instructions

The Emsisoft malware research team has discovered a new outbreak of the Windows Safeguard Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSafeguardUtility.

Windows Safeguard Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Another variants:

Create new file:

  • %UserProfile%\Application Data\Microsoft\%random%.exe

Create/modify registry entries:

  • HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
    (String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore
    (DWORD) DisableSR = 0×00000001 (1)
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System
    (DWORD) EnableLUA = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe
    (String) Debugger = svchost.exe

Screenshots:

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

Adware.Win32.WindowsSafeguardUtility

How to remove the infection of Windows Safeguard Utility (Adware.Win32.WindowsSafeguardUtility)?

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

May 24

Windows Repairing System Adware Removal Instructions

The Emsisoft malware research team has discovered a new outbreak of the Windows Repairing System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRepairingSystem.

Windows Repairing System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Another variants:

Create new file:

  • %UserProfile%\Application Data\Microsoft\%random%.exe

Create/modify registry entries:

  • HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon
    (String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe
  • HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore
    (DWORD) DisableSR = 0×00000001 (1)
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System
    (DWORD) EnableLUA = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)
    (DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe
    (String) Debugger = svchost.exe
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe
    (String) Debugger = svchost.exe

Screenshots:

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

Adware.Win32.WindowsRepairingSystem

How to remove the infection of Windows Repairing System (Adware.Win32.WindowsRepairingSystem)?

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.