Friday, September 28, 2012

How to remove File Recovery Virus

File Recovery is a serious computer infection that originates from the group of fake hard drive defragmenters. This software is categorized as a typical rogue. We have published a lot about viruses like this. The are Data Recovery, Smart HDD and lots of other rogues that are alike. When this malware comes to your system it launches fake system scan of your computer and reports various system, hard drive and memory errors. The fake report is summarized in the following fake hard drives diagnostic report that tells as follows:

Friday, July 20, 2012

Windows Security Renewal is categorized as a fake software

Windows Security Renewal is a money-oriented fake anti-virus that aims aim to gain a commercial profit by taking advantage of users’ credulity.

Thursday, July 19, 2012

What is Windows Home Patron? How to deal with it?

Windows Home Patron represents itself as an anti-virus engine, effective at fight with Trojans, rogues, viruses and other types of infections. It creates the impression of being decent utility and it does it so persuasive that it is difficult to determine its authenticity at first glimpse

Tuesday, July 17, 2012

WALKTOOLS.EXE is malicious one

GridinSoft Trojan Killer anti-malware Lab has discovered the next hazardous file WALKTOOLS.EXE We confidently state that it is harmful one and is worth immediate removal. It is implanted on the vulnerable computer by cyber criminnals as a tool for evil plot implementation.
Make sure to regularly check your PC for unknown files presence because they sneak to the targeted PCs invisibly. All PC holders are at the risk group. Be careful of it.

Windows Virtual Firewall rogue. How to get rid of this scam

FakeVimes has released one more fake antivirus program called Windows Virtual Firewall. Computer threat infiltrates into the system through malicious Internet websites that offer system scanners online and with a a help of Trojan viruses which ensure that the infiltration would be completely secret. No matter how the program reaches the system, it will make it completely unnoticeably and without asking authorization of the user. Windows Virtual Firewall will be configured to start automatically after each login to Windows. The program will launch its scanner and imitate looking for infections. Beware that this process is fabricated. However, it will generate professionally looking scan results and it may really seem that your system is at risk. After that, the program will ask to purchase its full version so it could remove infections that have been detected. You have to understand that the files displayed by Windows Virtual Firewall are not even close to real infections. The program is only trying to convince you into purchasing its license because it wants to get your money this way.


malware removal tool

Delete Windows Virtual Firewall files:
%AppData%\NPSWF32.dll
%AppData%\Protector-[rnd].exe
%AppData%\result.db
Delete Windows Virtual Firewall registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

Friday, July 6, 2012

WVRSS.EXE file is identified as hazardous

WVRSS.EXE file is Adware Kraddare. This file is categorized as malicious one so be careful of it. Take removal measures at once if you notice it on your private territory. It is implanted on the vulnerable computer by cyber crooks as a tool for evil plot implementation.
Make sure to regularly check your PC for unknown files presence because they sneak to the targeted PCs invisibly. No one is 100% safe. All PC holders are at the risk group.

Thursday, July 5, 2012

Windows Virus Hunter rogue. How to get rid of it?

Windows Virus Hunter is is nothing but a hoax which tries to trick users into thinking their PC is severely compromised and needs being cleaned with its “full” version. This is a lie. Do not purchase anything it offers because your money will be stolen..