Pages

Tampilkan postingan dengan label remove. Tampilkan semua postingan
Tampilkan postingan dengan label remove. Tampilkan semua postingan

Jumat, 14 Februari 2014

Remove Home Security Solutions Uninstall Guide

Home Security Solutions is rogue anti-virus program (I really hope its the last one this year). Its pretty much an exact copy of the Microsoft Security Essentials. I mean the graphical user interface not the actual antivirus engine. Home Security Solutions is distributed through the use of infected websites, Trojan downloaders, and software vulnerabilities exploited by popular exploit kits. I think this time cyber crooks use the BlackHole exploit kit, which would cost $2000 for an annual licence. What makes this virus unique is that it fills up your computer with randomly named harmless files and then detect those files as Trojans, keyloggers, rootkits, etc. Home Security Solutions pretends to scan your computer for malicious code thus creating countless pop-ups about critical infections and claiming that your computer cant be fix unless you purchase the bogus program. We already dont want to pay full price for things, so paying for HomeSecuritySolutions is not a good idea folks. To remove Home Security Solutions malware from your computer, please follow the removal instructions below.



Home Security Solutions blocks the following anti-virus programs: Microsoft Security Essentials, ESET NOD32 and AVG. It does this buy modifying Windows Registry. Of course, it may block other legit AV products too. What is more, this scareware modifies Windows Hosts file and changes LAN settings. Thankfully, this scan be fixes very easily and we will show you how (see removal instructions below). Home Security Solutions runs from Application Data or PorgramData folders. Additional process runs from Windows Temporary folder.

Websites associated with this rogue antivirus program:
  • WWW5.THEBEST-AV-FORYOU.COM
  • SECURE1.SMARTWASUITE.COM
  • SECURE1.THEBEST-ARMYFYA.COM


OK, so the easiest way to remove Home Security Solutions from your PC is to use debugged registration keys and then run a full system scan with legitimate anti-malware software. In case the keys dont work, please follow the alternate removal guide outlined below. If you thought that Home Security Solutions was a real products and paid for it, please contact your credit card company immediately and dispute the charges. If you need extra help removing Home Security Solutions virus, please leave a comment below. Good luck and be safe online!


Quick removal guide:

1. Open Home Security Solutions. Click the "Activate full protection" button. Enter one of these debugged registration keys to register this rogue application. Dont worry, this is completely legal.

K7LY-R5GU-SI9D-EVFB
K7LY-H4KA-SI9D-U2FD
U2FD-S2LA-H4KA-UEPB

Once this is done, you are free to install anti-malware software and remove the rogue anti-virus program from your computer properly.

2. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.


Alternate Home Security Solutions removal instructions:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Launch Internet Explorer. In Internet Explorer go to: Tools->Internet Options->Connections tab. Click Lan Settings button and uncheck the checkbox labeled Use a proxy server for your LAN. Click OK. You may have to repeat steps 1-2 if you will have problems downloading malware removal programs.



3. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus from your computer.

4. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.


Associated Home Security Solutions files and registry values:

Files:

  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]Quarantine Items
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]HSSSys
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS] HSS.ico
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]mozcrt19.dll
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]sqlite3.dll
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]HS149.exe
  • %AllUsersProfile%Application DataHSMGPBWS
  • %AllUsersProfile%Application DataHSMGPBWSHSVNAS.cfg
  • %AppData%Home Security Solutions
  • %AppData%Home Security SolutionsInstructions.ini
  • %AppData%Home Security SolutionsScanDisk_.exe
  • %AppData%Home Security Solutionscookies.sqlite
  • %AppData%MicrosoftInternet ExplorerQuick LaunchHome Security Solutions.lnk
  • %UserProfile%DesktopHome Security Solutions.lnk
  • %UserProfile%Start MenuHome Security Solutions.lnk
  • %UserProfile%Start MenuProgramsHome Security Solutions.lnk
Registry values:
  • HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionRunHome Security Solutions = "%AllUsersProfile%Application Data82f49HS149.exe" /s /d
  • HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionRunOnceHSS = "%Temp%scandsk311f_9012.exe" /cs:1
  • HKEY_CURRENT_USERsoftware3
  • HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionImage File Execution Options[RANDOM].exeDebugger = svchost.exe
  • HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun = 01000000
  • HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun[1...15]
Share this information with your friends:
Read More..

Senin, 03 Februari 2014

Remove Chitka pop up ads removal instructions

Chitka pop up ads are truly annoying, lots of people have this issue, but the worse part is that these frequent intrusive pop-ups are caused by malicious software. What is Chitka? Honestly, Im not quite sure what it is. I mean I couldnt find anything, any clue about it. Google search suggested Chitika which is a perfectly legitimate online advertising network and obviously has nothing do to with this malware. It sounds almost the same, though. Actually, I think that those who run the malware campaign did this on purpose. They probably try to mislead users.

The primary reason behind the creation and use of this malware is that it enables one to generate profit by forcing hits to specific websites and advertisements. At the same time, it might be used as marketing and commercial strategy for publicity purposes. One way or another, infected users who are getting a bunch of Chitka pop ups and redirects are not happy at all. What is more, they cant remove the culprit of this infection. That’s why I wrote a step-by-step guide on how to remove Chitka pop up virus and other pop-ups from your computer. Please follow the removal instructions below.

Many people are clueless on how they become victims of this malware. They just keep getting popups on their web browsers, sometimes bottom right corner but very often both. Here’s a good example:



Chitka pop up ad appears in the lower right corner of the browser window. And at the same time, in the lower left corner theres another fake pop-up claiming that your Flash Player is outdated. It says: Please install Flash Player HD to continue. Obviously, its a scam. Ive said this many times before – download and install Flash layer from the official website only.

Here’s another example of Chitka pop up:



This time only one pop-up but highly targeted one, because the malware gathered enough information about victims interests and displayed the most relevant advertisement. Sometimes, it takes only a few minutes and keywords to select relevant enough ads and sometimes scammers simply display ads according to your location.

This last one shows the Facebook style pop up. That’s why some users say they got infected with Chitka/Facebook pop up ads.



Furthermore, this malware redirects users to malicious websites or web pages full of ads when they click links on the page they are browsing. Usually, Chitka pop ups cannot be closed. It simply doesnt have the small "X" to close it.

Chitka ads and redirect issue is not necessary the same for all users. From what Ive seen, these popups and redirects are caused by malicious browser helper object and modified Windows Hosts file. I got the malware for testing purposes from an adult site. However, Im pretty sure its promoted via infected websites and may even come bundled with freeware. The malware installed a web browser extension called Flash Player Update 11.0 and modified Windows Hosts will so that certain websites were redirected through servers controlled by scammers. It is worth mentioning that the malicious web browser extension was locked which makes the removal a little bit challenging, at least for less computer savvy users. Besides, the extension name itself may stop some people from removing it. It looks like a legitimate extension and most users know that web browser use Flash Player plugins to display interactive content and Flash documents.

But I also found another sample of this malware and it actually came packed with ZeroAccess rootkit. So far, I’ve seen to possible culprits of Chitka pop-ups – a rootkit and a malicious web browser extensions + Hosts file modification. Maybe there are even more combinations but I couldn’t find them at the time I was researching this malware.

Last but not least, this malware affects all major web browsers: Google Chrome, Mozilla Firefox and Internet Explorer. I’m not sure if it works on Macs and Safari. Cross platform malware became very popular, so I wouldn’t be very surprised. To get rid of this malware completely you should use the tools recommend below.

Do you have any additional information or questions on the Chitka pop up virus? Post your comment or question below. Good luck and be safe online!


Chitka pop up ads removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





2. Reset Windows HOSTS file.

Go to: C:WINDOWSsystem32driversetc.
Double-click "hosts" file to open it. Choose to open with Notepad or any other text editor.



The Windows hosts file should look the same as in the image below (Windows XP). There should be only one line:

127.0.0.1 localhost (Windows XP)

127.0.0.1 localhost ::1 (Windows Vista/7/8).

If there are more lines, then remove them and save changes. Read more about Windows Hosts file here: http://support.microsoft.com/kb/972034



Alternate method: to reset the Hosts file back to the default automatically, download and run Microsoft Fix it tool and follow the steps in the Fix it wizard.

3. Remove malicious extensions from your web browser.

Google Chrome:
1. Click on Chrome menu button. Go to Tools → Extensions.
2. Click on the trashcan icon and remove the extensions that might be causing Chitka pop ups. Basically, remove all extensions that you didnt install. Its perfectly OK to remove all extensions since by default Google Chrome comes without any extensions.

Mozilla Firefox:
1. Go to Tools → Add-ons.
2. Select Extensions. Remove all extensions that you didnt install. Please note, by default Firefox comes without any extensions.

Internet Explorer:
1. Go to Tools → Manage Add-ons. If you have the latest version, simply click on the Settings button.
2. Select Toolbars and Extensions. Remove all add-ons that you didnt install or you believe may cause those annoying pop-ups to show up.

4. Download CCleaner and tidy up your computer, remove temp files, etc.

5. If the problem persists, please read this web document and follow the steps carefully: http://deletemalware.blogspot.com/2010/02/remove-google-redirect-virus.html

Read More..

How to Remove Websteroids Uninstall Guide

Websteroids is an adware application that installs as a browser plugin across all the browsers and places ads randomly on pages or hyperlinks random words. Whenever you click somewhere on the web page, it will open popup windows as well with ads by Websteroids. Its not a virus as some users may describe but we could say its a web browser related malware. Anti-malware scanners will be usually detected as PUP.Optional.Websteroids, Adware.Websteroids or simply generic malware. This guide will walk you through removing Websteroids from your computer and web browsers.


Websteroids Chrome extension with current permissions to access your data on all websites and access your tabs and browsing activity too. You may also get a notification that Websteroids is running from Windows, even though you wont see any windows related to this program. It runs in the background and silently collects information about your browsing habits and interests.

Websteroidsapp.com is the official website of this adware program. However, its almost the same as any other web page created by Creative Island Media, LLC., except that this one is titled Websteroids and has a link to download the adware. You can also find a removal guide on that webpage however, its not very informative. To remove Websteroids adware and other potentially unwanted software that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Websteroids removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this infection. Hopefully you wont have to do that.





2. Remove Websteroids program from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove the following Websteroids.



If you are using Windows Vista, Windows 7 or Windows 8, click Uninstall up near the top of that window. When youre done, please close the Control Panel screen.


Remove Websteroids from Google Chrome:

1. Click on Chrome menu button. Go to Tools → Extensions.



2. Click on the trashcan icon to remove the Websteroids 2.6.49 extension.




Remove Websteroids from Mozilla Firefox:

1. Open Mozilla Firefox. Go to Tools → Add-ons.



2. Select Extensions. Click Remove button to the Websteroids 2.6.49 extension.




Remove Websteroids from Internet Explorer:

1. Open Internet Explorer. Go to Tools → Manage Add-ons. If you have the latest version, simply click on the Settings button.



2. Select Toolbars and Extensions. Click Remove/Disable button to remove the Websteroids browser add-on.


Associated Websteroids Files:
  • C:Documents and SettingsAll UsersApplication DataWebsteroids
  • C:Documents and SettingsAll UsersApplication DataWebsteroidsIEcommon.dll
Read More..