<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/" 
	xmlns:wfw="http://wellformedweb.org/CommentAPI/" 
	xmlns:dc="http://purl.org/dc/elements/1.1/" 
	xmlns:atom="http://www.w3.org/2005/Atom" 
	>

<channel>
	<title>Virus, Spyware, and Malware Removal Guides</title>

	<link>http://www.bleepingcomputer.com/virus-removal/</link>
	<description>The latest information about current virus, spyware, and malware threats to your computer.  Use these guides and tutorials to remove or uninstall various malware and infections from your comptuer. All removal instructions are free to use and do not cost any money to remove any of the malware listed in these guides. The content in this RSS feed is to be used by news aggregators and informational purposes.  It is not to be used to add as content on a web site.</description>
	<pubDate>Fri, 20 Nov 2009 17:37:08 EST</pubDate>
	<generator>http://www.bleepingcomputer.com/</generator>
	<language>en</language>

 <item>
	<title>Remove Enterprise Suite (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-enterprise-suite</link>
	<pubDate>Wed, 18 Nov 2009 13:04:51 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Enterprise Suite]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-enterprise-suite</guid>
	<description><![CDATA[Enterprise Suite is a rogue anti-spyware program that is promoted through the use of fake online scanner sites and misleading advertisements. When this program is installed it will be configured to start automatically. The installer will also create numerous files on your computer that will then be detected as malware by Enterprise Suite when it scans your computer. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Enterprise Suite (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 18 Nov 2009 13:04:51 EST &middot; Views: 362</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-enterprise-suite', 'Remove Enterprise Suite (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-enterprise-suite', 'Remove Enterprise Suite (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Enterprise Suite</strong> is a rogue anti-spyware program that is promoted 
  through the use of fake online scanner sites and misleading advertisements. 
  When this program is installed it will be configured to start automatically. 
  The installer will also create numerous files on your computer that will then 
  be detected as malware by Enterprise Suite when it scans your computer. The files 
  that this rogue creates are:</p>
<blockquote>
  <p><font color="#0000FF">%UserProfile%\Recent\ANTIGEN.dll<br>
    %UserProfile%\Recent\ANTIGEN.sys<br>
    %UserProfile%\Recent\ANTIGEN.tmp<br>
    %UserProfile%\Recent\cid.dll<br>
    %UserProfile%\Recent\CLSV.dll<br>
    %UserProfile%\Recent\ddv.tmp<br>
    %UserProfile%\Recent\PE.dll<br>
    %UserProfile%\Recent\PE.drv<br>
    %UserProfile%\Recent\PE.sys<br>
    %UserProfile%\Recent\ppal.exe<br>
    %UserProfile%\Recent\runddlkey.drv<br>
    %UserProfile%\Recent\std.sys<br>
    %UserProfile%\Recent\tempdoc.dll<br>
    %UserProfile%\Recent\tjd.exe<br>
    %UserProfile%\Recent\tjd.sys</font></p>
</blockquote>
<p>This method of creating the files that will be detected by the same program 
  is becoming more and more common with rogues. They do this to substantiate the 
  existence of supposed malware files even on machines that are completely clean. 
  Therefore, please do not believe any of the scan results presented by this program.</p>
<p>
  
</p>
<p>While Enterprise Suite is running you will also see a constant barrage of fake 
  security alerts and warnings appear on your desktop. These warnings will state 
  that a virus has been detected or that active malware is sending data on the 
  Internet. Just like the scan results, these fake security alerts are just another 
  method where the program is trying to trick you into thinking that you have 
  a security problem.</p>
<p>Without a doubt, Enterprise Suite is a scam designed to trick you into purchasing 
  the program to remove fake infections. It goes without saying that you should 
  not purchase this program and if you already have, we suggest you contact your 
  credit card company to dispute the charges. Finally, to remove this infection 
  and any related malware, please use the removal guide below.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [Enterprise Suite] "C:\Documents and Settings\All Users\Application Data\345d567\WE345d.exe" /s /d<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/18/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Enterprise Suite using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Enterprise Suite</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Enterprise Suite</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/e/enterprise-suite/mbam-enterprise-suite.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Enterprise Suite</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=enterprise-suite" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Enterprise Suite Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\345d567<br />
c:\Documents and Settings\All Users\Application Data\345d567\752.mof<br />
c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll<br />
c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll<br />
c:\Documents and Settings\All Users\Application Data\345d567\WE345d.exe<br />
c:\Documents and Settings\All Users\Application Data\345d567\WES.ico<br />
c:\Documents and Settings\All Users\Application Data\345d567\WESSys<br />
c:\Documents and Settings\All Users\Application Data\345d567\WESSys\vd952342.bd<br />
c:\Documents and Settings\All Users\Application Data\WESSys<br />
c:\Documents and Settings\All Users\Application Data\WESSys\wes.cfg<br />
%UserProfile%\Application Data\Enterprise Suite<br />
%UserProfile%\Application Data\Enterprise Suite\cookies.sqlite<br />
%UserProfile%\Application Data\Enterprise Suite\Instructions.ini<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Enterprise Suite.lnk<br />
%UserProfile%\Desktop\Enterprise Suite.lnk<br />
%UserProfile%\Recent\ANTIGEN.dll<br />
%UserProfile%\Recent\cb.exe<br />
%UserProfile%\Recent\cid.dll<br />
%UserProfile%\Recent\CLSV.tmp<br />
%UserProfile%\Recent\DBOLE.sys<br />
%UserProfile%\Recent\ddv.sys<br />
%UserProfile%\Recent\eb.exe<br />
%UserProfile%\Recent\energy.sys<br />
%UserProfile%\Recent\exec.tmp<br />
%UserProfile%\Recent\FS.exe<br />
%UserProfile%\Recent\grid.drv<br />
%UserProfile%\Recent\runddlkey.drv<br />
%UserProfile%\Recent\sld.drv<br />
%UserProfile%\Recent\SM.drv<br />
%UserProfile%\Recent\tempdoc.dll<br />
%UserProfile%\Recent\tempdoc.tmp<br />
%UserProfile%\Recent\tjd.sys<br />
%UserProfile%\Start Menu\Enterprise Suite.lnk<br />
%UserProfile%\Start Menu\Programs\Enterprise Suite.lnk<br />
c:\Program Files\Mozilla Firefox\searchplugins\search.xml
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Enterprise Suite Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\3<br />
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
HKEY_CLASSES_ROOT\WE345d.DocHostUIHandler<br />
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=162&q={searchTerms}"<br />
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "[xSP_2:117fc3395e69e29f71abba93a68c4181_162]"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "887805703"<br />
HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=162&q={searchTerms}"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Enterprise Suite"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove SecureKeeper (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-securekeeper</link>
	<pubDate>Wed, 18 Nov 2009 11:40:14 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[SecureKeeper]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-securekeeper</guid>
	<description><![CDATA[SafeKeeper is a rogue anti-spyware program from the Wini family. This rogue is promoted through the use of Trojans that pretend to be video codecs or flash updates that are required to watch an online video. When a user runs the Trojan it will download and install SafeKeeper onto your computer and configure it to start automatically. The same Trojan will also create numerous files in the C:\Windows and C:\Windows\System32 folder that are then detected as malware when SafeKeeper scans your computer. The program, though, will then state it will not remove them until you first purchase it. This is obviously a scam as the programs creates the same files it will detect to try and trick you into thinking there is actual malware on your computer. The reality is that these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove SecureKeeper (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 18 Nov 2009 11:40:14 EST &middot; Views: 563</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-securekeeper', 'Remove SecureKeeper (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-securekeeper', 'Remove SecureKeeper (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>SafeKeeper</strong> is a rogue anti-spyware program from the Wini 
  family. This rogue is promoted through the use of Trojans that pretend to be 
  video codecs or flash updates that are required to watch an online video. When 
  a user runs the Trojan it will download and install SafeKeeper onto your computer 
  and configure it to start automatically. The same Trojan will also create numerous 
  files in the C:\Windows and C:\Windows\System32 folder that are then detected 
  as malware when SafeKeeper scans your computer. The program, though, will 
  then state it will not remove them until you first purchase it. This is obviously 
  a scam as the programs creates the same files it will detect to try and trick 
  you into thinking there is actual malware on your computer. The reality is that 
  these files are harmless and do not pose any risk to your computer. Thus this 
  programs scan results should be ignored.</p>
<p>
  
</p>
<p>The Trojan that installed SafeKeeper will also display fake security alerts 
  and messages on your desktop. These alerts will state that active malware has 
  been found, that your being attacked by a remote computer, or that you are sending 
  sensitive data to a remote location. The Trojan will also display a fake Windows 
  Security Center screen that will suggest that you purchase SafeKeeper to protect 
  yourself. Just like the scan results, these fake warnings and messages should 
  be ignored as they are just another attempt to make you think your computer 
  has a security problem.</p>
<p>As you can see, you should not purchase this program regardless of what it 
  may state. If you have already purchased the program, then please contact your 
  credit card company and dispute the charges. Last, but not least, please use 
  the guide below to remove this infection and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17853/SecureKeeper.html">SecureKeeper</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [&lt;random&gt;.exe] C:\WINDOWS\system32\&lt;random&gt;.exe<br />
O4 - HKCU\..\Run: [SecureKeeper] C:\Program Files\SecureKeeper Software\SecureKeeper\SecureKeeper.exe -min
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/18/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for SecureKeeper using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>SecureKeeper</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>SecureKeeper</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/securekeeper/mbam-securitykeeper.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SecureKeeper</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=securekeeper" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated SecureKeeper Files:</span></p>
     <blockquote>
        c:\Program Files\SecureKeeper Software<br />
c:\Program Files\SecureKeeper Software\SecureKeeper<br />
c:\Program Files\SecureKeeper Software\SecureKeeper\SecureKeeper.exe<br />
c:\Program Files\SecureKeeper Software\SecureKeeper\uninstall.exe<br />
c:\WINDOWS\10073z9t-a-virus2ad5.cpl<br />
c:\WINDOWS\10939spam5oz722.exe<br />
c:\WINDOWS\109z5spam5ot39f.dll<br />
c:\WINDOWS\system32\46z9v5r2938.exe<br />
c:\WINDOWS\system32\473zvir1995.bin<br />
c:\WINDOWS\system32\4767dowzlo59er1019.bin<br />
c:\Documents and Settings\All Users\Desktop\SecureKeeper.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureKeeper<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureKeeper\1 SecureKeeper.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureKeeper\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecureKeeper\3 Uninstall.lnk<br />
%Temp%\&lt;random&gt;.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated SecureKeeper Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\SecureKeeper<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SecureKeeper<br />
HKEY_LOCAL_MACHINE\SOFTWARE\SecureKeeper<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SecureKeeper"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Personal Protector (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-personal-protector</link>
	<pubDate>Mon, 16 Nov 2009 22:09:37 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Personal Protector]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-personal-protector</guid>
	<description><![CDATA[Personal Protector is a rogue anti-spyware program that is promoted through fake online scanners and aggressive advertising. When installed, Personal Protector will be configured to start automatically. Once started it will scan your computer and state that there are a variety of infections on your computer, but will not remove them until you first purchase the program. In reality, these scan results are all fake or are legitimate programs being classified as infections. Therefore, please do not act upon any of the scan results that this program shows you as you may delete legitimate Windows files. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Personal Protector (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 16 Nov 2009 22:09:37 EST &middot; Views: 569</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-personal-protector', 'Remove Personal Protector (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-personal-protector', 'Remove Personal Protector (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Personal Protector</strong> is a rogue anti-spyware program that is 
  promoted through fake online scanners and aggressive advertising. When installed, 
  Personal Protector will be configured to start automatically. Once started it 
  will scan your computer and state that there are a variety of infections on 
  your computer, but will not remove them until you first purchase the program. 
  In reality, these scan results are all fake or are legitimate programs being 
  classified as infections. Therefore, please do not act upon any of the scan 
  results that this program shows you as you may delete legitimate Windows files.</p>
<p> 
  
</p>
<p>If you are infected with Personal Protector, please do not purchase this program 
  based on what it says. If you have already purchased it, then we suggest you 
  contact your credit card company and dispute the charges. Last, but not least, 
  to remove Personal Protector and any related malware, please follow the steps 
  in the removal guide below.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17826/Personal-Protector.html">Personal Protector</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [personalprotector] C:\Program Files\Personal Protector\personalprotector.exe<br />
O4 - HKLM\..\RunOnce: [suicide] C:\WINDOWS\tempfile2.bat<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/16/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Personal Protector using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Personal Protector</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>PersonalProtector</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/p/personal-protector/mbam-personal-protector.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>PersonalProtector</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=personal-protector" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Personal Protector Files:</span></p>
     <blockquote>
        c:\Program Files\Personal Protector<br />
c:\Program Files\Personal Protector\base.wdb<br />
c:\Program Files\Personal Protector\baseadd.wdb<br />
c:\Program Files\Personal Protector\conf.wcf<br />
c:\Program Files\Personal Protector\personalprotector.exe<br />
c:\Program Files\Personal Protector\quarant.wdb<br />
c:\Program Files\Personal Protector\queue.wdb<br />
c:\Program Files\Personal Protector\un.exe<br />
c:\Program Files\Personal Protector\q<br />
c:\WINDOWS\tempfile2.bat<br />
c:\Documents and Settings\All Users\Microsoft PData<br />
c:\Documents and Settings\All Users\Microsoft PData\inetprovider.dll<br />
%UserProfile%\Desktop\Personal Protector.lnk<br />
%UserProfile%\Start Menu\Programs\Personal Protector<br />
%UserProfile%\Start Menu\Programs\Personal Protector\Personal Protector.lnk<br />
%UserProfile%\Start Menu\Programs\Personal Protector\Uninstall.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Personal Protector Windows Registry Information:</span></p>
     <blockquote>
        HKEY_USERS\.DEFAULT\Printers\DevModePerUser<br />
HKEY_USERS\S-1-5-18\Printers\DevModePerUser<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Protector<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Personal Protector<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "personalprotector"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "suicide"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Control Center (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-control-center</link>
	<pubDate>Mon, 16 Nov 2009 16:11:51 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Control Center]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-control-center</guid>
	<description><![CDATA[Control Center is a rogue computer optimization suite from the same family as Privacy Center. This program is promoted through the use of misleading web sites and fake online anti-malware scanners that state your computer has a problem. These sites will then prompt you to download and install Control Center to fix the problem on your computer. When the program is installed it will be configured to start automatically when Windows starts. Once running it will scan your computer and state that there are numerous problems with various components of Windows. If you try and see what these problems are, though, it will state that you need to purchase the program to see the results. In reality, the program is not finding any problems at all, but is just saying that they exist in order to trick you into purchasing the program. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Control Center (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 16 Nov 2009 16:11:51 EST &middot; Views: 1549</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-control-center', 'Remove Control Center (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-control-center', 'Remove Control Center (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Control Center</strong> is a rogue computer optimization suite from 
  the same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-privacy-center">Privacy 
  Center</a>. This program is promoted through the use of misleading web sites 
  and fake online anti-malware scanners that state your computer has a problem. 
  These sites will then prompt you to download and install Control Center to fix 
  the problem on your computer. When the program is installed it will be configured 
  to start automatically when Windows starts. Once running it will scan your computer 
  and state that there are numerous problems with various components of Windows. 
  If you try and see what these problems are, though, it will state that you need 
  to purchase the program to see the results. In reality, the program is not finding 
  any problems at all, but is just saying that they exist in order to trick you 
  into purchasing the program.</p>
<p>
  
</p>
<p>Control Center was created for one purpose and that is to make you think your 
  computer has problems so that you then purchase the program to fix them. It 
  goes without saying that you should not purchase this program, and if you already 
  have, please contact your credit card company to dispute the charges. Finally, 
  to remove this infection and any related malware, please use the removal guide 
  found below.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17825/Control-center.html">Control center</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [agent.exe] %UserProfile%\Application Data\CC\agent.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/16/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Control Center using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Control Center
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Control Center
    and other Rogue programs. Please be patient while the programs looks for various 
    programs and closes them. When it has finished, the black window will automatically 
    close. While rkill is running, if you get a message stating that rkill or 
    other executable is an infection, ignore it, and let rkill.com finish. This 
    is just the infection trying to stop rkill from terminating it. Please note, 
    you may have to run rkill a few times before the malware process is terminated.<strong><br>
    <br>
    Do not reboot your computer after running rkill as the malware programs will 
    start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button. If MalwareBytes' prompts you to reboot, please do not do so.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Control Center
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    Control Center
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Control Center</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=control-center" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Control Center Files:</span></p>
     <blockquote>
        %UserProfile%\Application Data\CC<br />
%UserProfile%\Application Data\CC\agent.exe<br />
%UserProfile%\Application Data\CC\cc.exe<br />
%UserProfile%\Application Data\CC\settings.ini<br />
%UserProfile%\Application Data\CC\uninstall.exe<br />
%UserProfile%\Application Data\CC\faq<br />
%UserProfile%\Application Data\CC\faq\guide.html<br />
%UserProfile%\Application Data\CC\faq\images<br />
%UserProfile%\Application Data\CC\faq\images\05.png<br />
%UserProfile%\Application Data\CC\faq\images\06.png<br />
%UserProfile%\Application Data\CC\faq\images\07.png<br />
%UserProfile%\Application Data\CC\faq\images\08.png<br />
%UserProfile%\Application Data\CC\faq\images\09.png<br />
%UserProfile%\Application Data\CC\faq\images\10.png<br />
%UserProfile%\Desktop\Control center.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Control Center Windows Registry Information:</span></p>
     <blockquote>
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Control center<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "agent.exe"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%UserProfile%\Application Data\CC\cc.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Alpha Antivirus (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-alpha-antivirus</link>
	<pubDate>Mon, 16 Nov 2009 12:49:09 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Alpha Antivirus]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-alpha-antivirus</guid>
	<description><![CDATA[Alpha Antivirus is a rogue anti-spyware program from the same family as Personal Antivirus. This program is promoted through the use of malware and web pop-ups that will be displayed as you browse the web. If you are infected via a malware infection, then Alpha Antivirus will be installed onto your computer without your knowledge or permission. If you encounter it via a pop-up, you will see a prompt stating that your computer is infected. When you click on this prompt you will be brought to a page showing an advertisement that pretends to be an online anti-malware scanner. This advertisement will pretend to scan your computer and then state that there are infections and that you should download and install Alpha Antivirus to protect yourself.  [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Alpha Antivirus (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 16 Nov 2009 12:49:09 EST &middot; Views: 54520</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-alpha-antivirus', 'Remove Alpha Antivirus (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-alpha-antivirus', 'Remove Alpha Antivirus (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Alpha Antivirus</strong> is a rogue anti-spyware program from the same 
  family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-personal-antivirus">Personal 
  Antivirus</a>. This program is promoted through the use of malware and web pop-ups 
  that will be displayed as you browse the web. If you are infected via a malware 
  infection, then Alpha Antivirus will be installed onto your computer without 
  your knowledge or permission. If you encounter it via a pop-up, you will see 
  a prompt stating that your computer is infected. When you click on this prompt 
  you will be brought to a page showing an advertisement that pretends to be an 
  online anti-malware scanner. This advertisement will pretend to scan your computer 
  and then state that there are infections and that you should download and install 
  Alpha Antivirus to protect yourself. </p>
<p>When Alpha Antivirus is installed it will be configured to start automatically 
  when you boot into Windows. Once running it will perform a scan of your computer 
  and when finished state that there are numerous infections on your computer. 
  It will not allow you to remove these infections, though, until you first purchase 
  the program. These infections are all fake and do not exist on your computer. 
  They are only being shown to scare you into purchasing Alpha Antivirus.</p>
<p> 
  
</p>
<p> While the program is running you will see a constant barrage of fake security 
  alerts and windows. These alerts, like the fake scan results, are designed to 
  make you think there is a security risk on your computer and then suggest that 
  you purchase Alpha Antivirus in order to protect your computer. Just like the 
  scan results, these fake alerts are all fake and the only infection is Alpha 
  Antivirus and the malware that was installed alongside it.</p>
<p>If you are infected with Alpha Antivirus, then please do not purchase this 
  program. If you have already purchased it, then we advise you to contact your 
  credit card company and dispute the charges as this program is a scam. Last, 
  but not least, please use the guide below to remove Alpha Antivirus and related 
  malware from your computer.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17824/Alpha-Antivirus.html">Alpha Antivirus</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: &Helper - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\WINDOWS\system32\msnaoladdon.dll<br />
O2 - BHO: &Advanced Explorer Editor - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\ExplorerImages.dll<br />
O4 - HKLM\..\Run: [AlphaAV] C:\Program Files\AlphaAV\AlphaAV.exe<br />
O4 - HKCU\..\Run: [AlphaAnt] C:\Program Files\AlphaAnt\alpha.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>09/28/09 - Initial guide creation.
10/05/09 - Updated for new version
11/16/09 - Updated for new version.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Alpha Antivirus using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Alpha Antivirus</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>AlphaAntivirus</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/alpha-antivirus/mbam-alpha-antivirus.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>AlphaAntivirus</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=alpha-antivirus" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Alpha Antivirus Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\AlphaAV<br />
c:\Program Files\Common Files\Uninstall<br />
c:\Program Files\Common Files\Uninstall\AlphaAV<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAV\Alpha Antivirus.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAV\Uninstall.lnk<br />
c:\Documents and Settings\Bleeping\Desktop\Alpha Antivirus.lnk<br />
c:\Program Files\Common Files\Uninstall\AlphaAV\Uninstall.lnk<br />
c:\WINDOWS\system32\msnaoladdon.dll<br />
c:\Program Files\AlphaAnt<br />
c:\Program Files\AlphaAnt\alpha.exe<br />
c:\Program Files\Common Files\AlphaAntUninstall<br />
c:\Program Files\Common Files\AlphaAntUninstall\Uninstall.lnk<br />
c:\WINDOWS\system32\ExplorerImages.dll<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AlphaAnt.lnk<br />
%UserProfile%\Desktop\Alpha Antivirus.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Alpha Antivirus.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Computer Scan.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Help.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Registration.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Security Center.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Settings.lnk<br />
c:\Documents and Settings\All Users\Start Menu\AlphaAnt\Update.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Alpha Antivirus Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\CLSID\{A77D3539-581D-450C-9E44-A84C415A6172}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A77D3539-581D-450C-9E44-A84C415A6172}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "WinNT-PAI 05.10.2009"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AlphaAV"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\uninstall\AlphaAnt<br />
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\5FFB10D58FFCF482208906E6A889FD56<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AlphaAnt"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinTSI 15.11.2009"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove LinkSafeness (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-linksafeness</link>
	<pubDate>Mon, 16 Nov 2009 08:16:12 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[LinkSafeness]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-linksafeness</guid>
	<description><![CDATA[LinkSafeness is a rogue anti-spyware program from the Wini family. This rogue is promoted through the use of Trojans that pretend to be video codecs or flash updates that are required to watch an online video. When a user runs the Trojan it will download and install LinkSafeness onto your computer and configure it to start automatically. The same Trojan will also create numerous files in the C:\Windows and C:\Windows\System32 folder that are then detected as malware when LinkSafeness scans your computer. The program, though, will then state it will not remove them until you first purchase it. This is obviously a scam as the programs creates the same files it will detect to try and trick you into thinking there is actual malware on your computer. The reality is that these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove LinkSafeness (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 16 Nov 2009 08:16:12 EST &middot; Views: 1220</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-linksafeness', 'Remove LinkSafeness (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-linksafeness', 'Remove LinkSafeness (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>LinkSafeness</strong> is a rogue anti-spyware program from the Wini 
  family. This rogue is promoted through the use of Trojans that pretend to be 
  video codecs or flash updates that are required to watch an online video. When 
  a user runs the Trojan it will download and install LinkSafeness onto your computer 
  and configure it to start automatically. The same Trojan will also create numerous 
  files in the C:\Windows and C:\Windows\System32 folder that are then detected 
  as malware when LinkSafeness scans your computer. The program, though, will 
  then state it will not remove them until you first purchase it. This is obviously 
  a scam as the programs creates the same files it will detect to try and trick 
  you into thinking there is actual malware on your computer. The reality is that 
  these files are harmless and do not pose any risk to your computer. Thus this 
  programs scan results should be ignored.</p>
<p>
  
</p>
<p>The Trojan that installed LinkSafeness will also display fake security alerts 
  and messages on your desktop. These alerts will state that active malware has 
  been found, that your being attacked by a remote computer, or that you are sending 
  sensitive data to a remote location. The Trojan will also display a fake Windows 
  Security Center screen that will suggest that you purchase LinkSafeness to protect 
  yourself. Just like the scan results, these fake warnings and messages should 
  be ignored as they are just another attempt to make you think your computer 
  has a security problem.</p>
<p>As you can see, you should not purchase this program regardless of what it 
  may state. If you have already purchased the program, then please contact your 
  credit card company and dispute the charges. Last, but not least, please use 
  the guide below to remove this infection and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17823/LinkSafeness.html">LinkSafeness</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [t5bgc2co.exe] C:\WINDOWS\system32\t5bgc2co.exe<br />
O4 - HKCU\..\Run: [LinkSafeness] C:\Program Files\LinkSafeness Software\LinkSafeness\LinkSafeness.exe -min<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/16/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for LinkSafeness using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>LinkSafeness</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>LinkSafeness</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/l/linksafeness/mbam-linksafeness.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>LinkSafeness</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=linksafeness" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated LinkSafeness Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\LinkSafeness.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\LinkSafeness<br />
c:\Documents and Settings\All Users\Start Menu\Programs\LinkSafeness\1 LinkSafeness.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\LinkSafeness\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\LinkSafeness\3 Uninstall.lnk<br />
c:\Program Files\LinkSafeness Software<br />
c:\Program Files\LinkSafeness Software\LinkSafeness<br />
c:\Program Files\LinkSafeness Software\LinkSafeness\LinkSafeness.exe<br />
c:\Program Files\LinkSafeness Software\LinkSafeness\uninstall.exe<br />
c:\WINDOWS\10595zor55f3.exe<br />
c:\WINDOWS\10715virus9z5.exe<br />
c:\WINDOWS\10858noz9a-virus5f5.ocx<br />
c:\WINDOWS\system32\3fc2th9ezt7504.ocx<br />
c:\WINDOWS\system32\3z19do9nlo5der78.exe<br />
c:\WINDOWS\system32\3z721worm4915.ocx<br />
%Temp%\t5bgc2co.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated LinkSafeness Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\LinkSafeness<br />
HKEY_LOCAL_MACHINE\SOFTWARE\LinkSafeness<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LinkSafeness<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "LinkSafeness"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "t5bgc2co.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove System Defender (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-system-defender</link>
	<pubDate>Fri, 13 Nov 2009 16:19:26 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[System Defender]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-system-defender</guid>
	<description><![CDATA[System Defender is a rogue anti-spyware program that is promoted through the use of fake online scanner sites and misleading advertisements. When this program is installed it will be configured to start automatically. The installer will also create numerous files on your computer that will then be detected as malware by System Defender when it scans your computer.  [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove System Defender (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 13 Nov 2009 16:19:26 EST &middot; Views: 2143</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-system-defender', 'Remove System Defender (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-system-defender', 'Remove System Defender (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>System Defender</strong> is a rogue anti-spyware program that is promoted 
  through the use of fake online scanner sites and misleading advertisements. 
  When this program is installed it will be configured to start automatically. 
  The installer will also create numerous files on your computer that will then 
  be detected as malware by System Defender when it scans your computer. The files 
  that this rogue creates are:</p>
<blockquote>
  <p><font color="#0000FF">%UserProfile%\Recent\ANTIGEN.dll<br>
    %UserProfile%\Recent\ANTIGEN.sys<br>
    %UserProfile%\Recent\ANTIGEN.tmp<br>
    %UserProfile%\Recent\cid.dll<br>
    %UserProfile%\Recent\CLSV.dll<br>
    %UserProfile%\Recent\ddv.tmp<br>
    %UserProfile%\Recent\PE.dll<br>
    %UserProfile%\Recent\PE.drv<br>
    %UserProfile%\Recent\PE.sys<br>
    %UserProfile%\Recent\ppal.exe<br>
    %UserProfile%\Recent\runddlkey.drv<br>
    %UserProfile%\Recent\std.sys<br>
    %UserProfile%\Recent\tempdoc.dll<br>
    %UserProfile%\Recent\tjd.exe<br>
    %UserProfile%\Recent\tjd.sys</font></p>
</blockquote>
<p>This method of creating the files that will be detected by the same program 
  is becoming more and more common with rogues. They do this to substantiate the 
  existence of supposed malware files even on machines that are completely clean. 
  Therefore, please do not believe any of the scan results presented by this program.</p>
<p>
  
</p>
<p>While System Defender is running you will also see a constant barrage of fake 
  security alerts and warnings appear on your desktop. These warnings will state 
  that a virus has been detected or that active malware is sending data on the 
  Internet. Just like the scan results, these fake security alerts are just another 
  method where the program is trying to trick you into thinking that you have 
  a security problem.</p>
<p>Without a doubt, System Defender is a scam designed to trick you into purchasing 
  the program to remove fake infections. It goes without saying that you should 
  not purchase this program and if you already have, we suggest you contact your 
  credit card company to dispute the charges. Finally, to remove this infection 
  and any related malware, please use the removal guide below.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [System Defender] "C:\Documents and Settings\All Users\Application Data\117fc\WS339.exe" /s /d
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/13/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for System Defender using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>System Defender</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>System Defender</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/system-defender/mbam-system-defender.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>System Defender</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=system-defender" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated System Defender Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\117fc<br />
c:\Documents and Settings\All Users\Application Data\117fc\WS339.exe<br />
c:\Documents and Settings\All Users\Application Data\117fc\WSD.ico<br />
c:\Documents and Settings\All Users\Application Data\WSDDSys<br />
c:\Documents and Settings\All Users\Application Data\WSDDSys\wsd.cfg<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\System Defender.lnk<br />
%UserProfile%\Application Data\System Defender<br />
%UserProfile%\Application Data\System Defender\cookies.sqlite<br />
%UserProfile%\Application Data\System Defender\Instructions.ini<br />
%UserProfile%\Desktop\System Defender.lnk<br />
%UserProfile%\Desktop\xp_7a9be\<br />
%UserProfile%\Desktop\xp_7a9be\68.mof<br />
%UserProfile%\Desktop\xp_7a9be\mozcrt19.dll<br />
%UserProfile%\Desktop\xp_7a9be\sqlite3.dll<br />
%UserProfile%\Desktop\xp_7a9be\WSDDSys<br />
%UserProfile%\Desktop\xp_7a9be\WSDDSys\vd952342.bd<br />
%UserProfile%\Recent\ANTIGEN.dll<br />
%UserProfile%\Recent\ANTIGEN.sys<br />
%UserProfile%\Recent\ANTIGEN.tmp<br />
%UserProfile%\Recent\cid.dll<br />
%UserProfile%\Recent\CLSV.dll<br />
%UserProfile%\Recent\ddv.tmp<br />
%UserProfile%\Recent\PE.dll<br />
%UserProfile%\Recent\PE.drv<br />
%UserProfile%\Recent\PE.sys<br />
%UserProfile%\Recent\ppal.exe<br />
%UserProfile%\Recent\runddlkey.drv<br />
%UserProfile%\Recent\std.sys<br />
%UserProfile%\Recent\tempdoc.dll<br />
%UserProfile%\Recent\tjd.exe<br />
%UserProfile%\Recent\tjd.sys<br />
%UserProfile%\Start Menu\System Defender.lnk<br />
%UserProfile%\Start Menu\Programs\System Defender.lnk<br />
c:\Program Files\Mozilla Firefox\searchplugins\search.xml
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated System Defender Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
HKEY_CLASSES_ROOT\xp_7a9be.DocHostUIHandler<br />
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=220&q={searchTerms}"<br />
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"<br />
HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=220&q={searchTerms}"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Defender"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Cyber Security (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-cyber-security</link>
	<pubDate>Fri, 13 Nov 2009 16:08:12 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Cyber Security]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-cyber-security</guid>
	<description><![CDATA[Cyber Security is a scareware program from the same family as Total Security . This rogue is promoted through the use of malware as well as fake online anti-malware scanners. When installed via Trojans, it will be installed on to your computer without your permission. When promoted via the web, you will see a pop-up that states that your computer is infected and that you should download and install Cyber Security to protect your computer. When the program is installed it will be configured to start automatically when you start Windows and perform a scan of your computer. When the scan has finished, Cyber Security will state that there are numerous infections on your computer, but will state it cannot remove anything unless you first purchase the program. This method of showing fake scan results is just a method where the developers of Cyber Security are trying to trick you into thinking that your computer has a security problem in the hopes that you will then purchase the program. As the only security problem on the computer is Cyber Security, you should not purchase this program. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Cyber Security (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 13 Nov 2009 16:08:12 EST &middot; Views: 125421</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-cyber-security', 'Remove Cyber Security (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-cyber-security', 'Remove Cyber Security (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong></strong>Cyber Security is a scareware program from the same family 
  as <a href="http://www.bleepingcomputer.com/virus-removal/remove-total-security">Total 
  Security </a>. This rogue is promoted through the use of malware as well as 
  fake online anti-malware scanners. When installed via Trojans, it will be installed 
  on to your computer without your permission. When promoted via the web, you 
  will see a pop-up that states that your computer is infected and that you should 
  download and install Cyber Security to protect your computer. When the program 
  is installed it will be configured to start automatically when you start Windows 
  and perform a scan of your computer. When the scan has finished, Cyber Security 
  will state that there are numerous infections on your computer, but will state 
  it cannot remove anything unless you first purchase the program. This method 
  of showing fake scan results is just a method where the developers of Cyber 
  Security are trying to trick you into thinking that your computer has a security 
  problem in the hopes that you will then purchase the program. As the only security 
  problem on the computer is Cyber Security, you should not purchase this program.</p>
<p> 
  
</p>
<p> Cyber Security also installs an Internet Explorer Browser Helper Object that 
  is used to hijack your browser when you are surfing the web. When browsing the 
  web you will be randomly be redirected to an about:blank page where you will 
  be shown a red screen with a message stating that <em>This website has been 
  reported to be unsafe </em> and will then suggest that you update your web protection 
  software. When you click on that link you will be brought to a site that is 
  attempting to sell Cyber Security to you. This browser hijack is attempting 
  to impersonate Firefox's and Google's Secure Browsing feature that alerts you 
  when you visit unsafe sites. In Cyber Security's method it does not matter if 
  the site you are visiting is legitimate or not, it will still randomly show 
  the message so that you think you are at risk.</p>
<p>While Cyber Security is running it will also show numerous alerts and screens 
  that are devised to make you think that there is a major security problem on 
  your computer. One tactic is to randomly display alerts from your Windows taskbar 
  that contain fake messages in various languages:</p>
<blockquote>
  <p><strong>In English:</strong></p>
  <p><font color="#0000FF"><strong>Privacy violation alert!</strong><br>
    Cyber Security has detected numerous privacy violations. Some programs may 
    send your private data to an untrusted internet host. Click here to permanently 
    block this activity and remove the possible threat (Recommended)</font></p>
  <p><font color="#0000FF"><strong>System files modification alert!</strong><br>
    Important system files of your computer may be modified by malicious program. 
    It may cause system instability and data loss. Click here to block unauthorized 
    modification and remove potential threats (Recommended).</font></p>
  <p><font color="#0000FF"><strong>Spyware activity alert!</strong><br>
    Spyware.IEMonster activity detected. It is spyware that attempts to steal 
    passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs, 
    including logins and passwords from online banking sessions, eBay, PayPal. 
    It may also create special tracking files to log your activity and compromise 
    your Internet privacy. It's strongly recommended to remove this threat as 
    soon as possible. Click here to remove Spyware.IEMonster.</font></p>
  <p><strong>In German:</strong></p>
  <p><font color="#0000FF"><strong>Gefahr!</strong><br>
    Systemdateien wurden geandert! Irgendeinen wichtigen Systemdateien wurden 
    von gefahrvolles Programm geandert. Das kann Systemsinstabilitat und Datenverzicht 
    zur Folge haben. Klicken Sie hier an um unberechtigten Modifikationen durch 
    die Loschung der Gefahrdungen zu blockieren (empfehlt).</font></p>
  <p><strong>In French:</strong></p>
  <p><font color="#0000FF"><strong>activite du Logiciel espion!</strong><br>
    Logiciel espion. Lactivite de IEMonster est decouverte. Cest un Logiciel espion, 
    qui tente de s'emparer des mots de passe d Internet Explorer, Mozilla Firefox, 
    Outlook et d autres programmes, y compris des logins et des mots de passe 
    des operations bancaires en ligne, eBay, PayPal. Il peut egalement creer des 
    poursuites speciales des fichiers pour enregistrer votre activite et compromettre 
    votre intimite a l'Internet. Il est fort recommande d eradiquer la menace 
    le plus vite possible. Cliquez ici pour supprimer le Logiciel espion. IEMonster.</font><br>
  </p>
</blockquote>
<p>Cyber Security will also display a window that will impersonate the legitimate 
  Microsoft Windows Security Center. The difference is that the imposter will 
  suggest that you purchase Cyber Security to secure your computer. Last, but 
  not the least in a long line of deceptive tactics, Cyber Security will randomly 
  display a screen saver that impersonates Windows crashing with a Blue Screen 
  of Death that contains a message that Spyware caused it. Then the screen saver 
  will show your computer rebooting with a message that you should purchase Cyber 
  Security to protect yourself. The text you will see in the screen saver crash 
  is:</p>
<blockquote> 
  <p><font color="#0000FF"> ***STOP: 0x000000D1 (0x00000000, 0xF73120AE, 0xC0000008, 
    0xC0000000)<br>
    A spyware application has been detected and Windows has been shut down to 
    <br>
    prevent damage to your computer<br>
    SPYWARE.MONSTER.FX_WILD_0x00000000<br>
    If this is the first time you've seen this Stop error screen, restart your<br>
    computer. If this screen appears again, follow these steps:<br>
    Check to make sure your antivirus software is properly installed. If this 
    is a<br>
    new installation, ask your software manufacturer for any antivirus updates<br>
    you might need.<br>
    Windows detected unregistered version of %product% protection on your computer. 
    <br>
    If problems continue, please activate your antivirus software to prevent computer 
    <br>
    damage and data loss.<br>
    *** SRV.SYS - Address F73120AE base at C00000000, DateStamp 36b072a3<br>
    Beginning dump of physical memory...</font><br>
  </p>
</blockquote>
<p> It is important to understand that this is just a screen saver and your computer 
  is not actually crashing and rebooting.</p>
<p>As you can see, Cyber Security uses numerous tactics to try and have you think 
  that there is a serious security problem on your computer. The reality, though, 
  is that the only serious problem is Cyber Security itself. Therefore, please 
  do not purchase the program due to the alerts this program shows you. If you 
  have already purchased the program, then please contact your credit card company 
  and dispute the charges. Last, but not least, please use the guide below to 
  remove Cyber Security and any related malware from your computer for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17471/Cyber-Security.html">Cyber Security</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\iehelpmod.dll<br />
O4 - HKCU\..\Run: [CS] C:\Program Files\CS\tsc.exe<br />
O4 - HKCU\..\Run: [CSec] C:\Program Files\CSec\cs.exe<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>10/09/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Cyber Security using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix. Due to this malware infecting Internet Explorer, 
    it is suggested that you use Firefox or another browser when following these 
    instructions. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the Cyber Security process so 
    that it does not interfere with the cleaning process. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Cyber Security
    and other Rogue programs. Please be patient while the programs looks for various 
    programs and closes them. When it has finished, the black window will automatically 
    close. <strong>Do not reboot your computer at this point, or the programs 
    will start again. </strong> <br>
    <br>
  </li>
  <li>Just to be sure, we will use another program to verify that the processes 
    are indeed terminated. To do this we must first download and install a Microsoft 
    program called Process Explorer. Normally, we would have you use the Windows 
    Task Manager, but this rogue will disable the ability to run it. Please download 
    Process Explorer from the following link and save it to your desktop:<br>
    <br>
    <a href="http://live.sysinternals.com/procexp.exe">Process Explorer Download 
    Link</a><br>
    <br>
  </li>
  <li>You should now have the Procexp.exe file on your desktop. You now need to 
    rename that file to <strong>iexplore.exe</strong>. To do this, right-click 
    on the Procexp.exe and select <strong>Rename</strong>. You can now edit the 
    name of the file and should name it to <strong>iexplore.exe</strong>. Once 
    it is renamed you should double-click on the file to launch it.<br>
    <br>
  </li>
  <li>Once the program is running, you should be presented with a screen similar 
    to the one below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/c/cyber-security/procexp.jpg" alt="Process Explorer"><br>
    </div>
    <br>
  </li>
  <li>Scroll through the list of running programs until you see a process named 
    <strong>tsc.exe</strong>. When you see this process, select the tsc.exe process 
    by left-clicking on it once so it becomes highlighted. Then click on the red 
    X button as shown in the image below. Newer versions of this executable may 
    be using names consisting of random numbers or characters. If you see a process 
    that is composed of random numbers or characters and has a shield icon <img src="http://img.bleepingcomputer.com/swr-guides/t/total-security/shield-icon.jpg" align="absmiddle"> 
    or a padlock icon <img src="http://img.bleepingcomputer.com/swr-guides/t/total-security/padlock-icon.jpg" align="absmiddle"> 
    next to it, then you have found the process you need to terminate. If you 
    do not see any processes using random characters or with the name tsc.exe, 
    please continue to <a href="#dlmbam">step 9</a>.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/c/cyber-security/procexp-cyber-security.jpg" alt="Cyber Security's TSC Process"><br>
    </div>
    <br>
  </li>
  <li>When you click on the red X to kill the process, Process Explorer will ask 
    you to confirm if you are sure you want to terminate it as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/tools/procexp-confirm.jpg" alt="Confirm the closing of the TSC process"><br>
    </div>
    <br>
    At this point you should press the <strong>Yes</strong> button in order to 
    kill the process.<br>
    <br>
  </li>
  <li><a name="dlmbam"></a>Download Malwarebytes' Anti-Malware, or MBAM, from 
    the following location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Cyber Security
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    CyberSecurity
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/c/cyber-security/mbam-cyber-security.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>CyberSecurity</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=cyber-security" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Cyber Security Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\CS<br />
c:\Documents and Settings\All Users\Start Menu\CS\Computer Scan.lnk<br />
c:\Documents and Settings\All Users\Start Menu\CS\Cyber Security.lnk<br />
c:\Documents and Settings\All Users\Start Menu\CS\Help.lnk<br />
c:\Documents and Settings\All Users\Start Menu\CS\Registration.lnk<br />
c:\Documents and Settings\All Users\Start Menu\CS\Security Center.lnk<br />
c:\Documents and Settings\All Users\Start Menu\CS\Settings.lnk<br />
c:\Documents and Settings\All Users\Start Menu\CS\Update.lnk<br />
%AppData%\Microsoft\Internet Explorer\Quick Launch\CS.lnk<br />
%UserProfile%\Desktop\Cyber Security.lnk<br />
c:\Program Files\Common Files\CSUninstall<br />
c:\Program Files\Common Files\CSUninstall\Uninstall.lnk<br />
c:\Program Files\CS<br />
c:\Program Files\CS\tsc.exe<br />
C:\Program Files\CSec\<br />
C:\Program Files\CSec\cs.exe<br />
c:\WINDOWS\system32\iehelpmod.dll
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Cyber Security Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\uninstall\CS<br />
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\5FFB10D58FFCF482208906E6A889FD56<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CS"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CSec"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Antivirus System Pro (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro</link>
	<pubDate>Thu, 12 Nov 2009 14:37:10 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Antivirus System Pro]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro</guid>
	<description><![CDATA[Antivirus System Pro is a rogue anti-spyware that uses false scan results, fake security alerts, and Internet Explorer hijacking in order to have you purchase this program. It is because of these actions that we classify Antivirus System Pro as a rogue anti-spyware program. When installed, Antivirus System pro will be configured to start automatically when you log into Windows. Once running it will scan your computer and display numerous infections that do not actually exist. Furthermore, it will state it will not remove these infections unless you first purchase the program. This method of stating there are infections, but not removing it until you purchase it, is just another tactic to have you purchase the software. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Antivirus System Pro (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Thu, 12 Nov 2009 14:37:10 EST &middot; Views: 290140</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro', 'Remove Antivirus System Pro (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro', 'Remove Antivirus System Pro (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Antivirus System Pro</strong> is a rogue anti-spyware that uses false 
  scan results, fake security alerts, and Internet Explorer hijacking in order 
  to have you purchase this program. It is because of these actions that we classify 
  Antivirus System Pro as a rogue anti-spyware program. When installed, Antivirus 
  System pro will be configured to start automatically when you log into Windows. 
  Once running it will scan your computer and display numerous infections that 
  do not actually exist. Furthermore, it will state it will not remove these infections 
  unless you first purchase the program. This method of stating there are infections, 
  but not removing it until you purchase it, is just another tactic to have you 
  purchase the software.</p>
<p> 
  
</p>
<p> While running, you will also be constantly barraged with fake security alerts 
  stating that your computer is under attack or that you have viruses on your 
  computer. For example, one alert is labeled Infiltration Alert and it states 
  that your computer is being attacked by an Internet Virus. Another alert prompts 
  you to scan your computer and when you click on it, will automatically launch 
  Antivirus System Pro and then prompt you to purchase it. The text of this alert 
  is:</p>
<blockquote> 
  <p><font color="#0000FF"><strong>Windows Security alert</strong><br>
    Windows reports that computer is infected. Antivirus software helps to protect 
    your computer against viruses and other security threats. Click here for the 
    scan you computer. Your system might be at risk now.</font></p>
</blockquote>
<p>Last, but not least, Antivirus System Pro will install a Internet Explorer 
  Browser Helper Object that will hijack Internet Explorer so that when you are 
  browsing web sites, instead of going to the page you want, you will be shown 
  a warning message. This warning message will state that the site you are going 
  to is harmful to your computer and that you should purchase Antivirus System 
  Pro to protect yourself.</p>
<p>As you can see, this program utilizes many tactics to make you think you are 
  infected and thus tricking you into purchase the program. Please do not purchase 
  this program as it will not protect your computer in any way. Instead, use the 
  guide below to remove this infection and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	<b>The filenames may be random.</b><br />
<br />
O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 209.44.111.57 security.microsoft.com<br />
O1 - Hosts: 209.44.111.57 inetavirus.com<br />
O1 - Hosts: 209.44.111.57 www.inetavirus.com<br />
O1 - Hosts: 91.212.127.227 osawarepro2009.microsoft.com<br />
O1 - Hosts: 91.212.127.227 osawarepro2009.com<br />
O1 - Hosts: 91.212.127.227 www.osawarepro2009.com<br />
O2 - BHO: BHO - {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} - C:\WINDOWS\system32\iehelper.dll<br />
O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe<br />
O4 - HKLM\..\Run: [vghuvmdh] C:\Documents and Settings\Bleeping\Local Settings\Application Data\qhpwjr\excksysguard.exe<br />
O4 - HKCU\..\Run: [vghuvmdh] C:\Documents and Settings\Bleeping\Local Settings\Application Data\qhpwjr\excksysguard.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/05/09 - Initial guide creation.
11/12/09 - Updated to use new removal technique due to new variant.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Antivirus System Pro using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Antivirus System Pro
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Antivirus System Pro
    and other Rogue programs. Please be patient while the programs looks for various 
    programs and closes them. When it has finished, the black window will automatically 
    close. While rkill is running, if you get a message stating that rkill or 
    other executable is an infection, ignore it, and let rkill.com finish. This 
    is just the infection trying to stop rkill from terminating it. Please note, 
    you may have to run rkill a few times before the malware process is terminated.<strong><br>
    <br>
    Do not reboot your computer after running rkill as the malware programs will 
    start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button. If MalwareBytes' prompts you to reboot, please do not do so.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Antivirus System Pro
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    Antivirus System Pro
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antivirus-system-pro/mbam-antivirus-system-pro.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Antivirus System Pro</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antivirus-system-pro" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Antivirus System Pro Files:</span></p>
     <blockquote>
        c:\WINDOWS\sysguard.exe<br />
c:\WINDOWS\system32\iehelper.dll
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Antivirus System Pro Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\AvScan<br />
HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove AntiAID (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antiaid</link>
	<pubDate>Wed, 11 Nov 2009 13:53:17 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[AntiAID]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antiaid</guid>
	<description><![CDATA[AntiAID is a rogue anti-spyware program from the Wini family. This variant is slightly different than previous versions as the it has changed its graphical user interface, or GUI. This rogue is advertised through Trojans that pretend to be video codecs or flash updates that are required to watch an online movie. When a user runs the Trojan it will download and install AntiAID onto your computer and configure it to start automatically. The same Trojan will also create numerous files in the C:\Windows and C:\Windows\System32 folder that are then detected as malware when AntiAID scans your computer. The program, though, will then state it will not remove them until you first purchase it. This is obviously a scam as the programs creates the same files it will detect to try and trick you into thinking there is actual malware on your computer. The reality is that these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove AntiAID (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 11 Nov 2009 13:53:17 EST &middot; Views: 3438</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antiaid', 'Remove AntiAID (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antiaid', 'Remove AntiAID (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>AntiAID</strong> is a rogue anti-spyware program from the Wini family. 
  This variant is slightly different than previous versions as the it has changed 
  its graphical user interface, or GUI. This rogue is advertised through Trojans 
  that pretend to be video codecs or flash updates that are required to watch 
  an online movie. When a user runs the Trojan it will download and install AntiAID 
  onto your computer and configure it to start automatically. The same Trojan 
  will also create numerous files in the C:\Windows and C:\Windows\System32 folder 
  that are then detected as malware when AntiAID scans your computer. The program, 
  though, will then state it will not remove them until you first purchase it. 
  This is obviously a scam as the programs creates the same files it will detect 
  to try and trick you into thinking there is actual malware on your computer. 
  The reality is that these files are harmless and do not pose any risk to your 
  computer. Thus this programs scan results should be ignored.</p>
<p>
  
</p>
<p>The same Trojan will also display fake security alerts and messages on your 
  desktop. These alerts will state that active malware has been found, that your 
  being attacked by a remote computer, or that you are sending sensitive data 
  to a remote location. The Trojan will also display a fake Windows Security Center 
  screen that will suggest that you purchase AntiAID to protect yourself. 
  Just like the scan results, these fake warnings and messages should be ignored 
  as they are just another attempt to make you think your computer has a security 
  problem.</p>
<p>As you can see, you should not purchase this program regardless of what it 
  may state. If you have already purchased the program, then please contact your 
  credit card company and dispute the charges. Last, but not least, please use 
  the guide below to remove this infection and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17792/AntiAID.html">AntiAID</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [8enyqcv1.exe] C:\WINDOWS\system32\8enyqcv1.exe<br />
O4 - HKCU\..\Run: [AntiAID] C:\Program Files\AntiAID Software\AntiAID\AntiAID.exe -min
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/11/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for AntiAID using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>AntiAID</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>AntiAID</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antiaid/mbam-antiaid.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>AntiAID</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antiaid" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated AntiAID Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\AntiAID.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntiAID<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntiAID\1 AntiAID.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntiAID\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntiAID\3 Uninstall.lnk<br />
c:\Program Files\AntiAID Software<br />
c:\Program Files\AntiAID Software\AntiAID<br />
c:\Program Files\AntiAID Software\AntiAID\AntiAID.exe<br />
c:\Program Files\AntiAID Software\AntiAID\uninstall.exe<br />
c:\WINDOWS\100849pambotz85.bin<br />
c:\WINDOWS\1019wo5m65bz.dll<br />
c:\WINDOWS\10568hack9o5l5z5.dll<br />
c:\WINDOWS\system32\2901sp55za.bin<br />
c:\WINDOWS\system32\29290wozm6795.cpl<br />
c:\WINDOWS\system32\29418tro5ez.ocx<br />
%Temp%\8enyqcv1.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated AntiAID Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\AntiAID<br />
HKEY_LOCAL_MACHINE\SOFTWARE\AntiAID<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiAID<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "8enyqcv1.exe"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AntiAID"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

</channel>
</rss>