Oct 31, 2009

Remove ShieldSafeness - Shield Safeness Removal Information

ShieldSafeness is a bogus security application form infamous Winisoft family. Parasite is promoted via Trojan horses. These Trojans impersonate falsh player or videocodecs updates. But be aware, these upadates are Trojan horses that will secretly download and install ShieldSafeness rogue onto your computer. Also thease Trojan will display fake security alerts on your computer and annoying pop-ups appearing from your Windows Taskbar. Moreover, Trojan will generate window that impersonate legitimate Windows Security Center which will suggest you to purchase licensed version of ShieldSafeness. ShieldSafeness will also bother you with different alerts, exaggerated scan results. Why exaggerated? Because all infections that ShieldSafeness will list after every scan was created by parasite itself and are absolutely harmless. Important to notice that for removing absolutely safe files ShieldSafeness will ask you to pay about a 50 $. That’s why we recommend you not to pay for ShieldSafeness license and remove it as soon as it is possible if there are any suspicion that your computer is infected.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:

How to remove ShieldSafeness manually:
It's possible to remove ShieldSafeness manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\ShieldSafeness.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\ShieldSafeness
c:\Documents and Settings\All Users\Start Menu\Programs\ShieldSafeness\1 ShieldSafeness.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\ShieldSafeness\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\ShieldSafeness\3 Uninstall.lnk
c:\Program Files\ShieldSafeness Software
c:\Program Files\ShieldSafeness Software\ShieldSafeness
c:\Program Files\ShieldSafeness Software\ShieldSafeness\ShieldSafeness.exe
c:\Program Files\ShieldSafeness Software\ShieldSafeness\uninstall.exe
c:\WINDOWS\10359virzs509.cpl
c:\WINDOWS\10380ha95tozl126.bin
c:\WINDOWS\10623spy65z9.bin
c:\WINDOWS\system32\2ed19pyz5re2156.bin
c:\WINDOWS\system32\2f53vir193z.bin
c:\WINDOWS\system32\2z075t59j48c.exe
%Temp%\unp4.tmp.exe


Remove registry entries:

HKEY_CURRENT_USER\Software\ShieldSafeness
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShieldSafeness
HKEY_LOCAL_MACHINE\SOFTWARE\ShieldSafeness
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ShieldSafeness"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "unp4.tmp.exe"


Please be careful because manual removal of ShieldSafeness may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 25, 2009

Remove Soft Stronghold - SoftStronghold Removal Information

Soft Stronghold is nothing more, but another rogue anti-spyware application, commonly known as fake security software. Soft Stronghold is a part of the one family of WiniBlue rogues. Its recent created predecessors are Soft Cop, Soft Soldier, Soft Veteran, Trust Warrior and Trust Soldier. All of these programs from the above are unreal security software and must not to be trusted. The tricking strategies they use are also identical for all. After being installed on your PC, Soft Stronghold, like its forerunner, will directly scan the whole Operation System and will send you alerts about tons of malicious files inside. Please note that Soft Stronghold is a simple rogue ant-virus program that is why everything it shows is nothing more but a fake. Such fake scan results are going to be sent to every user that put to use Soft Stronghold. So do not panic, and purchase the registered license of Soft Stronghold to fight the threats this scareware makes you believe in, because very probably you do not have any of them. Another interesting fact about rogue ant-spyware applications is that every time you log in your system, they begin their scare work. Soft Stronghold will modify Windows Security Center in such a way that it will send tons of annoying pop-ups, scare alerts that someone is trying to attack your computer, and security notifications about the importance of purchasing Soft Stronghold. All of this is just another simple attempt to scare you and make you believe that Soft Stronghold is the security application you can trust. Please remember that Soft Stronghold is nothing more but simple rogue ant-virus software and it should be removed from your computer directly at a time it has been detected.


Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Soft Stronghold manually:
It's possible to remove Soft Stronghold manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\Soft Stronghold.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Stronghold
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Stronghold\1 Soft Stronghold.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Stronghold\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Stronghold\3 Uninstall.lnk
c:\Program Files\Soft Stronghold Software
c:\Program Files\Soft Stronghold Software\Soft Stronghold
c:\Program Files\Soft Stronghold Software\Soft Stronghold\data.bin
c:\Program Files\Soft Stronghold Software\Soft Stronghold\license.txt
c:\Program Files\Soft Stronghold Software\Soft Stronghold\uninstall.exe
c:\Program Files\Soft Stronghold Software\Soft Stronghold\Soft Stronghold.exe
C:\Windows\System32\blocker.dll


Remove registry entries:

HKEY_CURRENT_USER\Software\Soft Stronghold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Soft Stronghold
HKEY_LOCAL_MACHINE\SOFTWARE\Soft Stronghold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Soft Stronghold"


Please be careful because manual removal of Soft Stronghold may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 22, 2009

Remove Soft Veteran - SoftVeteran Removal Information

Soft Veteran is the newest misleading application. It was created by the hackers, that is why this badware is not the protection you should trust in. The main aim for this software is to trick you and do everything to convince you to purchase their license. After been settled down on your PC, Soft Veteran will immediately start scanning the whole system. Very predictable that different scans are going to show the same result. Soft Veteran will always alert you about tons of malwares and viruses all over your computer. Interesting fact that all of the threats Soft Veteran tries to make you believe in probably do not even exist, because Soft Veteran created those files by itself. That is why, purchasing the “registered license” will not give you any profit. Soft Veteran is not going to stop only on fake system scans. It will always send you buzz notifications and pop-ups screaming about the need of license purchasing. Everything is just a simple spam and must be always ignored. Moreover, after some period of time, Soft Veteran will actually download the virus and that is the moment when you are getting into huge danger, because you will not be informed about anything, so infection will have tons of time to destroy all your system. To cut our report, we recommend you to get rid of Soft Veteran as soon as all the symptoms from the above were detected, even though you have already purchased its license.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Soft Veteran manually:
It's possible to remove Soft Veteran manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\Soft Veteran.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Veteran
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Veteran\1 Soft Veteran.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Veteran\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Soft Veteran\3 Uninstall.lnk
c:\Program Files\Soft Veteran Software
c:\Program Files\Soft Veteran Software\Soft Veteran
c:\Program Files\Soft Veteran Software\Soft Veteran\data.bin
c:\Program Files\Soft Veteran Software\Soft Veteran\license.txt
c:\Program Files\Soft Veteran Software\Soft Veteran\uninstall.exe
c:\Program Files\Soft Veteran Software\Soft Veteran\Soft Veteran.exe

Remove registry entries:

HKEY_CURRENT_USER\Software\Soft Veteran
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Soft Veteran
HKEY_LOCAL_MACHINE\SOFTWARE\Soft Veteran
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Soft Veteran"


Please be careful because manual removal of Soft Veteran may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Remove Soft Cop - SoftCop Removal Information

Nowadays the importance of having any sorts of protection on our computer is extremely high. There are tons of different antivirus applications, but unfortunately there are such security software that must not be trust. Soft Cop is one of these badwares that do any good, not for you and your computer. Soft Cop is a part of WiniSoft family. Soft Cop is produced by the same hackers created Soft Soldier. This rogue antispyware application is directed on tricking you and male you believe that your system is in high dangerous. The strategy Soft Cop uses is very simple and is the same for any programs of this type. Once inside your computer, Soft Cop creates different file all over your machine to present them as threats after every system scan. That was made to scare you and offer you to buy a registered license. Unfortunately this “license” is not going to help you. It will just pretend the work, but actually it does nothing, but sending false information about the security of your computer. Like many other rogue antivirus applications, Soft Cop gets inside your computer by using tojan downloader that is used on some web-sites to be able to watch movies and videos online. Soft Cop will also send you fake security alerts and different reports about the importance of license purchase. All these buzz pop-ups as well as scan reports must be ignored. Moreover, we highly recommend you to get rid of this badware if you want to keep your PC in safe, because the main danger on your computer is Soft Cop by itself.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:

How to remove Soft Cop manually:
It's possible to remove Soft Cop manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\SoftCop.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SoftCop
c:\Documents and Settings\All Users\Start Menu\Programs\SoftCop\1 SoftCop.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SoftCop\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SoftCop\3 Uninstall.lnk
c:\Program Files\SoftCop Software
c:\Program Files\SoftCop Software\SoftCop
c:\Program Files\SoftCop Software\SoftCop\SoftCop.exe
c:\Program Files\SoftCop Software\SoftCop\uninstall.exe
c:\WINDOWS\10345tr5j9z.dll
c:\WINDOWS\10b9backdoor1z95.ocx
c:\WINDOWS\10ez9parse1845.cpl
C:\WINDOWS\system32\ree5.tmp.exe
c:\WINDOWS\system32\1020zspambo55e39.exe
c:\WINDOWS\system32\10834w95z101.exe
c:\WINDOWS\system32\10z14tro9195.cpl


Remove registry entries:

HKEY_CURRENT_USER\Software\SoftCop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftCop
HKEY_LOCAL_MACHINE\SOFTWARE\SoftCop
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ree5.tmp.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SoftCop"


Please be careful because manual removal of Soft Cop may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 19, 2009

Remove Tre AntiVirus - TreAntiVirus Removal Information

Tre AntiVirus is a new creation in WiniSoft family of rogue antispyware programs. Tre AntiVirus was made by the same developers produced Soft Soldier, Trust Fighter and Trust Soldier. The difference between Tre AntiVirus and its predecessors is the usage of brand new GUI, commonly known as Graphical User Interface. However it works the same manner it’s elder brothers do. It is downloaded and installed by Trojan pretends to be the Flash player updates in order to watch video files. Without your concerning it will create numerous of files with different name all over your OS (Operating System). Every time you start Windows Tre AntiVirus starts scanning searching for malwares as well. Unfortunately, those scanning are not helpful as all files being created by Tre AntiVirus are presented as threats. Tre AntiVirus will not allow you then to remove these infections without further license purchasing. This tactic of fake scans and unreal infections detecting is how all rogue antivirus applications try to scare you and influence ordinary users to give their money away from their wallets. While Tre AntiVirus is working you are going to find tons of different alerts throughout your desktop. Each of these buzz pop-ups states that your computer is under malware attack and that your computer is in high dangerous without purchased license. Even though you have bought that license your problems are not going to stop at once. Even more, you are going to face new troubles until you got rid of Tre AntiVirus and all its products. That is why we highly recommend you to remove this rogue antispyware application as soon as it is possible.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:

How to remove Tre AntiVirus manually:
It's possible to remove Tre AntiVirus manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\TRE AntiVirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\TRE AntiVirus
c:\Documents and Settings\All Users\Start Menu\Programs\TRE AntiVirus\1 TRE AntiVirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\TRE AntiVirus\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\TRE AntiVirus\3 Uninstall.lnk
c:\Program Files\TRE AntiVirus Software
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\always_delete.xml
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\always_skip.xml
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\main_config.xml
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\treav.exe
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\uninstall.exe
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\quarantine
c:\Program Files\TRE AntiVirus Software\TRE AntiVirus\quarantine\quarantine.xml


Remove registry entries:

HKEY_CURRENT_USER\Software\TRE AntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TRE AntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\TRE AntiVirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "TRE AntiVirus"


Please be careful because manual removal of Tre AntiVirus may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 18, 2009

Remove PC Scout - PC Scout Removal Information

PC Scout is a creation of hackers who produced Active Security and Core Guard Antivirus 2009. Though it is brand new, PC Scout does not have a lot of differences in work from its predecessors. The main strategy for all rogue anti-spyware application is tricking you into buying absolutely worthless products. PC Scout is trying to create conditions for it’s save work by getting rid of all other security software on your computer. When being installed, PC Scout will run a fake scan of your OS and each scan will notify you about numerous threats inside your PC. However, PC Scout will give you the possibility to fight those threats only after you have purchase the registered license from the program’s web-site. Do not be disappointed and scared because all of those threats do not even exist and are harmless. Unfortunately, even after you have purchase the license all your troubles will not disappear. Furthermore, they might even double. While you are using your computer, PC Scout will spread tons of annoying notifications about license necessarity all over your work windows. Everything is made to make you trust PC Scout and to influence the user into giving your money to hackers, even though you don’t get any profits from that. After some time, PC Scout is going to download Trojans and that is the time when real problems begin. Everything is leading to loosing of all private documents and will cut down your PC life time. That is why we highly recommend you to remove PC Scout and all of its products out of your computer until it is not too late.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove PC Scout manually:
It's possible to remove PC Scout manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\PC Scout Support.lnk
c:\Documents and Settings\All Users\Desktop\PC Scout.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\PC Scout
c:\Documents and Settings\All Users\Start Menu\Programs\PC Scout\PC Scout Support.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\PC Scout\PC Scout.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\PC Scout\Uninstall PC Scout.lnk
c:\Program Files\PC Scout
c:\Program Files\PC Scout\core.cga
c:\Program Files\PC Scout\CoreExt.dll
c:\Program Files\PC Scout\help.ico
c:\Program Files\PC Scout\pcscout.exe
c:\Program Files\PC Scout\Uninstall.exe


Remove registry entries:

HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Scout
HKEY_LOCAL_MACHINE\SOFTWARE\PC Scout
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "PC Scout"


Please be careful because manual removal of PC Scout may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 13, 2009

Remove Trust Fighter - TrustFighter Removal Information

Trust Fighter is not the application you need to give your protection to. Moreover, it would be much better not to deal with this badware at all. The reason is that Trust Fighter is a simple rogue (fake) antispyware program that was created to steal as much money from ordinary users as it is possible. Being made by hackers, Trust Fighter is a powerful weapon to trick people into buying absolutely worthless products. Once inside your PC, Trust Fighter begins fake scanning of the whole system. Why it is fake? We will give you the answer. Interesting fact about Trust Fighter’s work is that this badware is just pretending to be working, but at the same time it is doing nothing but trying to make you believe that your computer is in absolute safe. Unfortunately, one of the most dangerous software on your computer is Trust Fighter itself. After each scan, this rogue antispyware application is going to alert you that computer is infected. Immediately it will give you a link with the imaginary help. Everything you have to do to get rid of those threats, Trust Fighter shows you, is to purchase for a not small amount of money (around 50$, if to be more specific) you can get the official license that might help you to fight all those malicious file. Believe us this license is absolutely worthless. Moreover, Trust Fighter will always bother you with annoying pop-ups reminding about necessarily of license purchasing. Hopefully, you have done your own opinion about Trust Fighter and will get rid of this rogue antispyware application as soon as possible.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Trust Fighter manually:
It's possible to remove Trust Fighter manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Start Menu\Programs\TrustFighter
c:\Documents and Settings\All Users\Start Menu\Programs\TrustFighter\1 TrustFighter.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\TrustFighter\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\TrustFighter\3 Uninstall.lnk
c:\Program Files\TrustFighter Software
c:\Program Files\TrustFighter Software\TrustFighter
c:\Program Files\TrustFighter Software\TrustFighter\TrustFighter.exe
c:\Program Files\TrustFighter Software\TrustFighter\uninstall.exe
c:\Documents and Settings\All Users\Desktop\TrustFighter.lnk
c:\WINDOWS\system32\d3d550c.dll
c:\WINDOWS\z9815spy765.dll
c:\WINDOWS\z9cfthreat4589.bin
c:\WINDOWS\za23d9wnload5r515.exe
c:\WINDOWS\system32\d98thi5f2122z.ocx
c:\WINDOWS\system32\f85a9dware256z.exe
c:\WINDOWS\system32\lil6.tmp.exe
c:\WINDOWS\system32\z105hackto5l709.cpl
%Temp%\lil6.tmp.exe


Remove registry entries:

HKEY_CURRENT_USER\Software\TrustFighter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TrustFighter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\TrustFighter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "lil6.tmp.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "TrustFighter"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe "GlobalFlag" "0x02000100"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe "VerifierDlls" = "d3d550c.dll"


Please be careful because manual removal of Trust Fighter may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 12, 2009

Remove WindowsEnterpriseDefender (Removal Instructions)

The modern world is created in a way where we have to pay for almost everything. There is nothing we cannot buy, and there is none we can get for free. Unfortunately, we cannot be sure in a quality of what we purchase. WindowsEnterpriseDefender is not the quality of protection you are looking for. The problem is that this badware is nothing more but fake or rogue antispyware application. It main clue is to steal as much money from ordinary users as possible and put them in hackers purse. That is why every time you use WindowsEnterpriseDefender and its products you promote hackers illegal activities. After been settled down in your PC, WindowsEnterpriseDefender begins scanning your system immediately. Though you might think this rogue antispyware program is searching for threats on your computer, WindowsEnterpriseDefender is only making you believe in this. Actually all of those malicious files WindowsEnterpriseDefender shows you were created by the badware itself. They are harmless, but you really don not even guess about it. That is why every user will always look for some help, after he sees so many threats on his PC. WindowsEnterpriseDefender is the fastest way of help, but unfortunately this help is absolutely worthless as you buy a license to fight troubles that do not exist. What is more WindowsEnterpriseDefender will download the viruses on your computer, but you are not going to know about it. That is why we highly recommend you to get rid of WindowsEnterpriseDefender and of all of its products as soon as possible, because it is very sure you might face really huge problems letting this badware play its game inside your own PC.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove WindowsEnterpriseDefender manually:
It's possible to remove WindowsEnterpriseDefender manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Application Data\c9ba
c:\Documents and Settings\All Users\Application Data\c9ba\83.mof
c:\Documents and Settings\All Users\Application Data\c9ba\mozcrt19.dll
c:\Documents and Settings\All Users\Application Data\c9ba\sqlite3.dll
c:\Documents and Settings\All Users\Application Data\c9ba\unins000.dat
c:\Documents and Settings\All Users\Application Data\c9ba\WED.ico
c:\Documents and Settings\All Users\Application Data\c9ba\WindowsEDefender.exe
c:\Documents and Settings\All Users\Application Data\c9ba\WEDDSys
c:\Documents and Settings\All Users\Application Data\c9ba\WEDDSys\vd952342.bd
c:\Documents and Settings\All Users\Application Data\WEDDSys
c:\Documents and Settings\All Users\Application Data\WEDDSys\wed.cfg
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Enterprise Defender.lnk
%UserProfile%\Application Data\Windows Enterprise Defender
%UserProfile%\Application Data\Windows Enterprise Defender\cookies.sqlite
%UserProfile%\Desktop\Windows Enterprise Defender.lnk
%UserProfile%\Recent\cb.sys
%UserProfile%\Recent\ddv.dll
%UserProfile%\Recent\eb.sys
%UserProfile%\Recent\energy.exe
%UserProfile%\Recent\pal.sys
%UserProfile%\Recent\PE.drv
%UserProfile%\Recent\ppal.exe
%UserProfile%\Recent\tempdoc.tmp
%UserProfile%\Start Menu\Windows Enterprise Defender.lnk
%UserProfile%\Start Menu\Programs\Windows Enterprise Defender.lnk
c:\Program Files\Mozilla Firefox\searchplugins\search.xml


Remove registry entries:

HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\WindowsEDefender.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => "http://search-gala.com/?&uid=7&q={searchTerms}"
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes "URL"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "[xSP_2:61a6083b6194a2314e3dd54cf9615e36_7]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "876902803"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Enterprise Defender"


Please be careful because manual removal of WindowsEnterpriseDefender may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Remove Windows Smart Security - WindowsSmartSecurity Removal Information

Without doubts, when an ordinary user hears about Windows Smart Security he thinks that it is the newest application that will protect his PC from numerous threats from the outside. Truly believing it so, he installs this software on the computer and follows all requests and offers. Unfortunately, Windows Smart Security is not the protection you really need. The problem is, this is a rogue or fake antispyware program that was created by hackers who’s the main strategy is to trick people and steal their money. After been installed Windows Smart Security is generated to start immediate scan. After this scan has finished it would state that your PC is infected. After that Windows Smart Security is going to offer you to follow the link it gives and purchase the official license, either way you will be not able to get rid of those threats on your PC. Calm down, and do not hurry up purchasing the license. Certainly, you don’t have any of those malicious files Windows Smart Security is trying to make you believe in. Probably, it is just a part of strategy to leave you little money to go around. What is more, Windows Smart Security is not going to stop that easy. It will always remind you about itself, by sending annoying pop-ups every time you log in the system, trying to make you purchase the license. All in all, Windows Smart Security is just a simple badware that you are not going to have any profits from. Moreover, after some period of time it would download more malware, but you are not going to find out about it till it is too late. So, be careful and don’t ever trust Windows Smart Security and its products.


Type: Rogue Anti-Spyware
Malware Author: Innovagest2000 SL

Threat Level: Critical
Screenshot:


How to remove Windows Smart Security manually:
It's possible to remove Windows Smart Security manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Application Data\hl11734594
c:\Documents and Settings\All Users\Application Data\hl11734594\hl11734594
c:\Documents and Settings\All Users\Application Data\hl11734594\hl11734594.exe
c:\Documents and Settings\All Users\Application Data\hl11734594\pchl11734594ins
%UserProfile%\Desktop\Windows Smart Security 2009.lnk
%UserProfile%\Start Menu\Programs\Windows Smart Security
%UserProfile%\Start Menu\Programs\Windows Smart Security\Windows Smart Security 2009.lnk


Remove registry entries:

HKEY_CURRENT_USER\Software\Windows Smart Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Smart Security
HKEY_LOCAL_MACHINE\SOFTWARE\Windows Smart Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Smart Security"


Please be careful because manual removal of Windows Smart Security may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 9, 2009

Remove Antivirus - Antivirus Removal Information

Nowadays, the need in good antispyware programs has grown up and become the most of every user who wants to keep his PC in safe. There tons of different applications that specialize on protecting our computers from the danger coming out the world-web, the Internet. Unfortunately, there are also such types of a antispyware programs that works like an ordinary antivirus, but will never help you. Those applications are called rogue or fake. Antivirus is such type of badwares that were created to steal money and any of privat information from the ordinary citizens. Once inside your machine, Antivirus starts scanning the system and will always give the same result: computer is infected and it is highly recommended to clean them up very soon. It also offers you to purchase the license from the official web-site Antivirus gives you, either way you will not be able to remove those threats with the help of Antivirus. Unfortunately, for a not cheap price you are going to have really cheap help. No profits at all, we would have say. That is why, using Antivirus as the computer protector, you risk to loose a lot of time and money. Moreover, after couple days being inside your PC, Antivirus will download more and more malware, and that is the time the big troubles begin. Everything has been said: don’t let Antivirus be your protection, because you are going to get none of help you need. We highly recommend you to get rid of Antivirus and all of its products and files on your beloved computer as soon as possible.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Antivirus manually:
It's possible to remove Antivirus manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus\Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus\Uninstall.lnk
%AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk
%Temp%\winupd64x.exe
c:\Program Files\Antivirus
c:\Program Files\Antivirus\Antivirus.exe
c:\Program Files\Antivirus\AvBho.dll
c:\Program Files\Antivirus\Uninstall.exe
c:\Program Files\Antivirus\wscsvc32.exe


Remove registry entries:

HKEY_CLASSES_ROOT\AvBho.AvBhoApp
HKEY_CLASSES_ROOT\AvBho.AvBhoApp.1
HKEY_CLASSES_ROOT\CLSID\{9d541c6a-573b-4888-b35e-6816e68c3620}
HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKEY_CLASSES_ROOT\TypeLib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d541c6a-573b-4888-b35e-6816e68c3620}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wscsvc32.exe"


Please be careful because manual removal of Antivirus may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 6, 2009

Remove Trust Cop - TrustCop Removal Information

This rogue or fake antispyware application appeared in the Internet not that long. It is a youngest member of the same family includes SaveDefense, SoftSafeness, SaveKeep and Secure Fighter. Trust Cop is not a good and sensitive policeman. It is not the software that is going to protect you from numerous malicious products from the world web. Trust Cop is an application that will steal your money and get rid of all private documents stored down on your PC. Once inside the system, Trust Cop starts an immediate scan of your computer. Unfortunately, you can always guess what the results would be. It is clear that Trust Cop will show that PC is infected and you need help. Trust Cop is going to give you the clue how to fight those threats. It will give you a link where you, for a not a small payment, can purchase the registered license of Trust Cop, either way you will not be able to get rid of those imaginary viruses. The interesting thing is that it is better not to buy the license than to do so, because for that money you will get none of help and Trust Cop will try to influence you to purchase the license after every scan. Moreover, Trust Cop will show annoying pop-ups upon all work windows, reminding that you need to purchase the license, every time you log in the system. That is why it has been highly recommended to get rid of Trust Cop until Trust Cop will get rid of everything important you have on your PC.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Trust Cop manually:
It's possible to remove Trust Cop manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Desktop\Trust Cop.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Trust Cop
c:\Documents and Settings\All Users\Start Menu\Programs\Trust Cop\1 Trust Cop.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Trust Cop\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Trust Cop\3 Uninstall.lnk
c:\Program Files\Trust Cop Software
c:\Program Files\Trust Cop Software\Trust Cop
c:\Program Files\Trust Cop Software\Trust Cop\data.bin
c:\Program Files\Trust Cop Software\Trust Cop\license.txt
c:\Program Files\Trust Cop Software\Trust Cop\uninstall.exe
c:\Program Files\Trust Cop Software\Trust Cop\Trust Cop.exe
C:\Windows\System32\blocker.dll

Remove registry entries:

HKEY_CURRENT_USER\Software\Trust Cop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trust Cop
HKEY_LOCAL_MACHINE\SOFTWARE\Trust Cop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Trust Cop"


Please be careful because manual removal of Trust Cop may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 4, 2009

Remove SecureWarrior - Secure Warrior Removal Information

SecureWarrior is the brand new product of numerous two-days SEO projects that was created to spread useless rogue antivirus applications around the world-web. SecureWarrioris a newborn member of the same family included Secure Veteran, Security Fighter, Security Soldier, Save Armor, Save Defender. All of these products are a simple fake that doesn’t make any profits to the victims who use them. The main aim for these badwares is to make as much money out of your wallet as possible. First thing, SecureWarriordoes after been installed on your PC, is running and immediate scan of the whole system. Unfortunately, the results of those scans are really predictable: computer has been infected. I’m absolutely sure that each of use, after have seen so many viruses on our beloved PC, would do his best to find any sorts of protection. SecureWarriorcounts on it, which is why it gives the victim an immediate and easy link where the full registered license could be downloaded and purchased. One interesting think about all of this is that for a not small payment you are going to get absolutely worthless product. Moreover, SecureWarriordoesn’t stop on it. It will offer you to purchase the license every time you scan the system. Very predictable that each scan will show the same threats, just to trick you into buying Secure Warrior’s products. Last but not least, SecureWarriorwill always remind you about itself. It will showered buzz pop-ups upon your work windows, screaming for purchasing the license, every time you log in the system. Everything has been said: be aware of SecureWarriorand all of its predecessors. We highly recommend you to get rid of SecureWarriorand all of its malicious files, since it is still not too late.


Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove SecureWarrior manually:
It's possible to remove SecureWarrior manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Program Files\SecureWarrior Software
c:\Program Files\SecureWarrior Software\SecureWarrior
c:\Program Files\SecureWarrior Software\SecureWarrior\SecureWarrior.exe
c:\Program Files\SecureWarrior Software\SecureWarrior\uninstall.exe
c:\WINDOWS\1025worm59bz.bin
c:\WINDOWS\10562spy9z1.cpl
c:\WINDOWS\109559dwarz959.dll
c:\WINDOWS\system32\2485z5p920a.cpl
c:\WINDOWS\system32\249069orm57cz.exe
c:\WINDOWS\system32\25059zorm4d9.dll
c:\Documents and Settings\All Users\Desktop\SecureWarrior.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SecureWarrior
c:\Documents and Settings\All Users\Start Menu\Programs\SecureWarrior\1 SecureWarrior.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SecureWarrior\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SecureWarrior\3 Uninstall.lnk
%Temp%\0urw56p0.exe


Remove registry entries:

HKEY_CURRENT_USER\Software\SecureWarrior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SecureWarrior
HKEY_LOCAL_MACHINE\SOFTWARE\SecureWarrior
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SECUREWARRIORSVC
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SecureWarriorSvc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "0urw56p0.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SecureWarrior"


Please be careful because manual removal of SecureWarrior may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

Oct 2, 2009

Remove Home Personal Antivirus - HomePersonalAntivirus Removal Information

Having antivirus on our computers is not something exotic, anymore. Nowadays it is a must for every user to able to protect the system from numerous malicious files that might destroy it. Home Personal Antivirus is probably not the protection you need. This is a simple rogue antispyware application which was made to trick ordinary people and steal their money. First thing Home Personal Antivirus does, after been settled down in your system, is creating numerous files all over the computer, without you concerning. After that it will start the system scan. The interesting thing, about all of these scans is that all of them have the same results: computer is infected. It is a real shock when you find out that so many viruses been stored down on your PC, and you never knew about them, isn’t it? That is why most of us will search for some tool that could remove all those threats. Home Personal Antivirus knows about it, and will offer you its help. It is going to give you a link where you can purchase and download the license, either way you would not be able to fight those viruses with Home Personal Antivirus help. Unfortunately, you will pay for nothing, because you probably don’t have any of those threats Home Personal Antivirus makes you believe in. Moreover, it is not going to stop. It will shower buzz pop-ups upon your work window every time you log into the system. All those pop-ups are the reminding that you must purchase the license. Everything has been said: think twice before using any products of Home Personal Antivirus and we highly recommend you to uninstall this malicious software as soon as possible, either way it might be too late.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Home Personal Antivirus manually:
It's possible to remove Home Personal Antivirus manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

%UserProfile%\Desktop\Home Personal Antivirus.LNK
%UserProfile%\Desktop\Home Personal Antivirus
%UserProfile%\Desktop\Home Personal Antivirus\BtCoreIf64.dll
%UserProfile%\Desktop\Home Personal Antivirus\homeav.exe
%UserProfile%\Desktop\Home Personal Antivirus\Microsoft.VC80.CRT.manifest
%UserProfile%\Desktop\Home Personal Antivirus\msvcm80.dll
%UserProfile%\Desktop\Home Personal Antivirus\msvcp80.dll
%UserProfile%\Desktop\Home Personal Antivirus\msvcr80.dll
%UserProfile%\Desktop\Home Personal Antivirus\null_antivirus.dll
%UserProfile%\Desktop\Home Personal Antivirus\pthreadVC2.dll
%UserProfile%\Desktop\Home Personal Antivirus\unistall.exe
%UserProfile%\Desktop\Home Personal Antivirus\vdb
%UserProfile%\Desktop\Home Personal Antivirus\vdb\daily.zvd
%UserProfile%\Start Menu\Home Personal Antivirus.LNK


Remove registry entries:

HKEY_CURRENT_USER\Software\Home Personal Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Home Personal Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "HomeAV"


Please be careful because manual removal of Home Personal Antivirus may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
/