Thursday, July 5, 2012

Windows Virus Hunter rogue. How to get rid of it?

Windows Virus Hunter is is nothing but a hoax which tries to trick users into thinking their PC is severely compromised and needs being cleaned with its “full” version. This is a lie. Do not purchase anything it offers because your money will be stolen..

As soon as it is inside of your machine it will initiate fake system scanning of your computer. The peculiarity of this scan is that the hoax would report plenty of viruses, malwares, infections and spywares present on your system. You should not trust all such reports, because they are all fake. Why then does it shown all of such fake reports? The answer is simple – the rogue tells that it is able to remove all detected fake infections if you pay for it. Thus, the only purpose of the developers of this program is to convince you to pay money for it. Therefore, this is a scam device that must be removed. In the section below you will find the step-by-step guide devoted to this parasite removal.

Windows Virus Hunter virus remover:

malware removal tool

Delete files:
%AppData%\NPSWF32.dll
%AppData%\Protector-[rnd].exe
%AppData%\result.db
Remove Windows Virus Hunter registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

No comments:

Post a Comment