<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/" 
	xmlns:wfw="http://wellformedweb.org/CommentAPI/" 
	xmlns:dc="http://purl.org/dc/elements/1.1/" 
	xmlns:atom="http://www.w3.org/2005/Atom" 
	>

<channel>
	<title>Virus, Spyware, and Malware Removal Guides</title>

	<link>http://www.bleepingcomputer.com/virus-removal/</link>
	<description>The latest information about current virus, spyware, and malware threats to your computer.  Use these guides and tutorials to remove or uninstall various malware and infections from your comptuer. All removal instructions are free to use and do not cost any money to remove any of the malware listed in these guides. The content in this RSS feed is to be used by news aggregators and informational purposes.  It is not to be used to add as content on a web site.</description>
	<pubDate>Sat, 07 Nov 2009 12:40:38 EST</pubDate>
	<generator>http://www.bleepingcomputer.com/</generator>
	<language>en</language>

 <item>
	<title>Remove SystemVeteran (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-systemveteran</link>
	<pubDate>Sat, 07 Nov 2009 10:13:39 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[SystemVeteran]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-systemveteran</guid>
	<description><![CDATA[SystemVeteran is a rogue security program that is installed through the use of Trojans that impersonate Flash updates or video codecs that are required to view a video online. When these Trojans are installed they will download and install SystemVeteran onto your computer and then create a large amount of files with random names on your computer. These files will then be detected as malware when SystemVeteran scans your computer. The program, though, will state it cannot remove them unless you first purchase it. The reality is that the files that were created by Trojan are harmless and are only being created to substantiate the claims of SystemVeteran that there is malware on your computer. Therefore, you should ignore anything this program states. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove SystemVeteran (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Sat, 07 Nov 2009 10:13:39 EST &middot; Views: 36</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-systemveteran', 'Remove SystemVeteran (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-systemveteran', 'Remove SystemVeteran (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>SystemVeteran</strong> is a rogue security program that is installed 
  through the use of Trojans that impersonate Flash updates or video codecs that 
  are required to view a video online. When these Trojans are installed they will 
  download and install SystemVeteran onto your computer and then create a large 
  amount of files with random names on your computer. These files will then be 
  detected as malware when SystemVeteran scans your computer. The program, though, 
  will state it cannot remove them unless you first purchase it. The reality is 
  that the files that were created by Trojan are harmless and are only being created 
  to substantiate the claims of SystemVeteran that there is malware on your computer. 
  Therefore, you should ignore anything this program states.</p>
<p>
  
</p>
<p>While the Trojan is running you will also see a fake Windows Security Center 
  window appear on your desktop. This window impersonates the legitimate Windows 
  Security Center except that it suggest that you purchase SystemVeteran to protect 
  your computer. The Trojan will also display fake security alerts and warnings 
  on your computer that state that a remote computer is attempting to hack yours, 
  that you are sending sensitive data to a remote location, or that an active 
  malware infections has been found. Just like the scan results, these warnings 
  are just another tactic being used by the program to try and trick you into 
  thinking you are infected so that you then purchase it.</p>
<p>As you can see, SystemVeteran was created for one purpose; to trick you into 
  thinking your computer has a security problem so that you then purchase the 
  program. It goes without saying that should definitely not purchase this program, 
  and if you already have, I suggest you contact your credit card company and 
  dispute the charges. Last, but not least, to remove this infection and any related 
  malware please use the guide below to remove it for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17743/SystemVeteran.html">SystemVeteran</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [SystemVeteran.exe] C:\Program Files\SystemVeteran Software\SystemVeteran\SystemVeteran.exe<br />
O4 - HKCU\..\Run: [wjq4.tmp.exe] C:\WINDOWS\system32\wjq4.tmp.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/07/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for SystemVeteran using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>SystemVeteran</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>SystemVeteran</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/systemveteran/mbam-systemveteran.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SystemVeteran</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=systemveteran" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated SystemVeteran Files:</span></p>
     <blockquote>
        c:\Documents and Settings\Bleeping\Desktop\SystemVeteran.lnk<br />
c:\Documents and Settings\Bleeping\Start Menu\Programs\SystemVeteran.lnk<br />
c:\Program Files\SystemVeteran Software<br />
c:\Program Files\SystemVeteran Software\SystemVeteran<br />
c:\Program Files\SystemVeteran Software\SystemVeteran\SystemVeteran.exe<br />
c:\Program Files\SystemVeteran Software\SystemVeteran\Uninstall.exe<br />
c:\WINDOWS\11542no5-a-9izus6e3.exe<br />
c:\WINDOWS\11935w9zm138.cpl<br />
c:\WINDOWS\12944viruz4759.ocx<br />
c:\WINDOWS\system32\379athiez2365.cpl<br />
c:\WINDOWS\system32\38019zrus115.ocx<br />
c:\WINDOWS\system32\390sp91d5z.ocx
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated SystemVeteran Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\SystemVeteran<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemVeteran<br />
HKEY_LOCAL_MACHINE\SOFTWARE\SystemVeteran<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wjq4.tmp.exe"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SystemVeteran.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove MaCatte Antivirus 2009 (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-macatte-antivirus-2009</link>
	<pubDate>Wed, 04 Nov 2009 17:10:05 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[MaCatte Antivirus 2009]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-macatte-antivirus-2009</guid>
	<description><![CDATA[MaCatte Antivirus 2009 is a rogue anti-spyware program that display fake security alerts and scan results as a method to trick you into thinking you are infected. This program also attempts to emulate the legitimate McAfee anti-virus program by using a similar name and web site template. When installed, MaCatte Antivirus will be configured to start automatically when you boot up Windows. Once started, it will scan your computer and then display numerous infections, but will not remove them until you first purchase the program. The reality is that the scan results it shows are all fake and are only being shown to trick you into thinking you are infected so that you will then purchase the program. It goes without saying that you should not do this. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove MaCatte Antivirus 2009 (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 04 Nov 2009 17:10:05 EST &middot; Views: 989</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-macatte-antivirus-2009', 'Remove MaCatte Antivirus 2009 (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-macatte-antivirus-2009', 'Remove MaCatte Antivirus 2009 (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>MaCatte Antivirus 2009</strong> is a rogue anti-spyware program that 
  display fake security alerts and scan results as a method to trick you into 
  thinking you are infected. This program also attempts to emulate the legitimate 
  McAfee anti-virus program by using a similar name and web site template. When 
  installed, MaCatte Antivirus will be configured to start automatically when 
  you boot up Windows. Once started, it will scan your computer and then display 
  numerous infections, but will not remove them until you first purchase the program. 
  The reality is that the scan results it shows are all fake and are only being 
  shown to trick you into thinking you are infected so that you will then purchase 
  the program. It goes without saying that you should not do this.</p>
<p>
  
</p>
<p>When MaCatte Antivirus 2009 is running it will also display various security 
  alerts from your Windows taskbar. These alerts will state that your computer 
  is infected, that malware is sending private data to a remote location, or that 
  a password stealing Spyware has been detected. An example of an alert you will 
  see is:</p>
<blockquote> 
  <p><strong><font color="#0000FF">MaCatte</font></strong><font color="#0000FF"><br>
    Spyware activity alert!<br>
    Spyware.IEMonster activity detected. It is spyware that attempts to steal 
    passwords from Internet Explorer, Mozilla Firefox, Outlook and other other 
    programs, including logins and passwords from online baking sessions, eBay, 
    PayPal.</font></p>
</blockquote>
<p>Just like the fake scan results, these security alerts are false and are only 
  being shown to scare you into thinking that your computer has a security problem.</p>
<p>If you find that MaCatte Antivirus 2009 is installed on your computer, then 
  please do not purchase it as it is a scam. If you have already purchased the 
  program, then we advise you to contact your credit card company and dispute 
  the charges. Last, but not least, to remove this infection and any related malware, 
  please use the removal guide below.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/index.php?act=add_entry">msca</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [wsc] C:\Program Files\msca\mstdl.exe<br />
O4 - HKCU\..\Run: [msc] C:\Program Files\msca\msc.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/04/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for MaCatte Antivirus 2009 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>MaCatte Antivirus 2009</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>MaCatte Antivirus 2009</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/m/macatte-antivirus-2009/mbam-macatte-antivirus-2009.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>MaCatte Antivirus 2009</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=macatte-antivirus-20" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated MaCatte Antivirus 2009 Files:</span></p>
     <blockquote>
        C:\Program Files\msca\<br />
C:\Program Files\msca\msc.exe<br />
C:\Program Files\msca\msca.ico<br />
C:\Program Files\msca\mstdl.exe<br />
C:\Program Files\msca\Viruses.dat<br />
C:\Documents and Settings\All Users\Application Data\msca<br />
C:\Documents and Settings\All Users\Application Data\msca\msca.ico<br />
C:\Documents and Settings\All Users\Application Data\msca\mcull.exe<br />
C:\Documents and Settings\All Users\Application Data\msca\msc.exe<br />
C:\Documents and Settings\All Users\Application Data\msca\Viruses.dat<br />
C:\Documents and Settings\All Users\Application Data\Microsoft\Media\WPtect.dll<br />
C:\Documents and Settings\All Users\Desktop\msca.lnk<br />
C:\Documents and Settings\All Users\Start Menu\Programs\msca<br />
C:\Documents and Settings\All Users\Start Menu\Programs\msca\msca.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated MaCatte Antivirus 2009 Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\msca<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{459b6bf8-5320-4c41-8833-85baedf31086}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A73890FC-177F-4198-AE3D-C64F7D9E69D8}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\NetworkNeighborhood\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "msca"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wsc"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "msc"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\msca<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPost "0"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect "0"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnonBadCertRecving "0"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove BlockProtector (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-blockprotector</link>
	<pubDate>Wed, 04 Nov 2009 16:29:52 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[BlockProtector]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-blockprotector</guid>
	<description><![CDATA[BlockProtector is a security program from the Wini family of rogues. This program is installed through Trojans that masquerade as video codecs or flash updates required to watch an online video. When the Trojan is installed, it will install BlockProtector on to your computer and configure it to start automatically when Windows starts. The Trojan will also create numerous files on your hard drive that will then be detected as malware when BlockProtector scans your computer. BlockProtector will not, though, attempt to remove these programs until you first purchase it. This tactic of a rogue creating the files that it will then detect is just a scam where they are trying to convince you that you are infected. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove BlockProtector (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 04 Nov 2009 16:29:52 EST &middot; Views: 1175</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-blockprotector', 'Remove BlockProtector (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-blockprotector', 'Remove BlockProtector (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>BlockProtector</strong> is a security program from the Wini family 
  of rogues. This program is installed through Trojans that masquerade as video 
  codecs or flash updates required to watch an online video. When the Trojan is 
  installed, it will install BlockProtector on to your computer and configure 
  it to start automatically when Windows starts. The Trojan will also create numerous 
  files on your hard drive that will then be detected as malware when BlockProtector 
  scans your computer. BlockProtector will not, though, attempt to remove these 
  programs until you first purchase it. This tactic of a rogue creating the files 
  that it will then detect is just a scam where they are trying to convince you 
  that you are infected.</p>
<p>
  
</p>
<p>While the Trojan is running you will also see warning messages appear on your 
  desktop or from your Windows taskbar stating that your computer has some sort 
  of security problem. An example of one of the alerts you will see is:</p>
<blockquote>
  <p><font color="#0000FF">Spyware Alert!</font></p>
  <p><font color="#0000FF">Your computer is infected with spyware. It could damage 
    your critical files or expose your private data on the Internet. Click here 
    to register your copy of BlockProtector and remove spyware threats from your 
    PC. </font></p>
</blockquote>
<p>The Trojan will also display a fake Windows Security Center window that suggests 
  you register the BlockProtector program. Just like the fake scan results, these 
  messages should be ignored as it is just another tactic that they are using 
  to scare you into thinking that your computer is infected.</p>
<p>If BlockProtector is on your computer, then I suggest you use the removal guide 
  below. By no means should you purchase the program as it is only a scam. If 
  you have already purchased the program, then I suggest you contact your credit 
  card company and dispute the charges.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17737/BlockProtector.html">BlockProtector</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [BlockProtector.exe] C:\Program Files\BlockProtector Software\BlockProtector\BlockProtector.exe<br />
O4 - HKCU\..\Run: [rwb4.tmp.exe] C:\WINDOWS\system32\rwb4.tmp.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/04/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for BlockProtector using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>BlockProtector</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>BlockProtector</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/b/blockprotector/mbam-blockprotector.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>BlockProtector</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=blockprotector" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated BlockProtector Files:</span></p>
     <blockquote>
        c:\Documents and Settings\Bleeping\Desktop\BlockProtector.lnk<br />
c:\Documents and Settings\Bleeping\Start Menu\Programs\BlockProtector.lnk<br />
c:\Program Files\BlockProtector Software<br />
c:\Program Files\BlockProtector Software\BlockProtector<br />
c:\Program Files\BlockProtector Software\BlockProtector\BlockProtector.exe<br />
c:\Program Files\BlockProtector Software\BlockProtector\Uninstall.exe<br />
c:\WINDOWS\1069szyware7695.exe<br />
c:\WINDOWS\1095th5zf21449.cpl<br />
c:\WINDOWS\11763zpy1f95.exe<br />
c:\WINDOWS\system32\335steal97z2.ocx<br />
c:\WINDOWS\system32\348eb9ckdoor1z785.cpl<br />
c:\WINDOWS\system32\35z0sp9rse478.bin<br />
%Temp%\rwb4.tmp.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated BlockProtector Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\BlockProtector<br />
HKEY_LOCAL_MACHINE\SOFTWARE\BlockProtector<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlockProtector<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "rwb4.tmp.exe"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "BlockProtector.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-vundo-virtumonde</link>
	<pubDate>Tue, 03 Nov 2009 09:35:13 EST</pubDate>
	<dc:creator>D-Trojanator</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Trojan.vundo and Virtumonde]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-vundo-virtumonde</guid>
	<description><![CDATA[The Vundo family of Trojans is one of the most common infections 
    we find on user's computers. This infection can cause popups that include 
    advertisements for rogue anti-spyware programs. Some common rogue antispyware 
    programs that are advertised include WinFixer, SysProtect and WinAntiSpyware. 
    Users are normally targeted by false positives, fake alerts, and warning of 
    infections on their computer. An example of this type of misleading advertisement 
    would be popups alerting users that they are infected with a blackworm virus. 
    The most common method of infection is through outdated versions of the Sun 
    Java platform; older versions are being exploited so it is important to firstly 
    make sure that your Java software is fully up to date. This infection is normally 
    detectable by users receiving popups when they use the Internet. Your antivirus 
    program might also notify you via an alert that you have a Vundo Trojan on 
    your computer.
 [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=38920">D-Trojanator</a> on Tue, 03 Nov 2009 09:35:13 EST &middot; Views: 1606469</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-vundo-virtumonde', 'How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-vundo-virtumonde', 'How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p>The Vundo family of Trojans is one of the most common infections 
    we find on user's computers. This infection can cause popups that include 
    advertisements for rogue anti-spyware programs. Some common rogue antispyware 
    programs that are advertised include WinFixer, SysProtect and WinAntiSpyware. 
    Users are normally targeted by false positives, fake alerts, and warning of 
    infections on their computer. An example of this type of misleading advertisement 
    would be popups alerting users that they are infected with a blackworm virus. 
    The most common method of infection is through outdated versions of the Sun 
    Java platform; older versions are being exploited so it is important to firstly 
    make sure that your Java software is fully up to date. This infection is normally 
    detectable by users receiving popups when they use the Internet. Your antivirus 
    program might also notify you via an alert that you have a Vundo Trojan on 
    your computer.
</p>
<p>The Vundo infection has evolved over time to include harder 
    and harder protection methods so that it cannot be easily removed. These methods 
    are random names, random autorun locations, random CLSIDs, and rootkits to 
    hide these locations from removal tools. Due to this, specialized tools have 
    been created in order to target this specific infection and remove it. The 
    following guide will explain how to use the tool, and hopefully rid your system 
    of this malware.
</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/trojan-horses">Trojan Horses</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
   <li><a href="http://www.atribune.org/ccount/click.php?id=4">VundoFix</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	<b>The file names in these entries are random:</b><br />
<br />
O2 - BHO: (no name) - {904e23fc-67aa-4ac1-89e6-dd4eed16b596} - C:\WINDOWS\system32\zibuzuhu.dll<br />
O4 - HKLM\..\Run: [nohawevufi] Rundll32.exe "C:\WINDOWS\system32\vosevodi.dll",s<br />
O4 - HKLM\..\Run: [7cc01263] rundll32.exe "C:\WINDOWS\system32\ropoligi.dll",b<br />
O4 - HKLM\..\Run: [CPM7ff321ff] Rundll32.exe "c:\windows\system32\kamideva.dll",a<br />
O4 - HKUS\S-1-5-19\..\Run: [nohawevufi] Rundll32.exe "C:\WINDOWS\system32\vosevodi.dll",s (User 'LOCAL SERVICE')<br />
O4 - HKUS\S-1-5-20\..\Run: [nohawevufi] Rundll32.exe "C:\WINDOWS\system32\vosevodi.dll",s (User 'NETWORK SERVICE')<br />
O20 - AppInit_DLLs: C:\WINDOWS\system32\mufezuwi.dll c:\windows\system32\kamideva.dll<br />
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kamideva.dll<br />
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kamideva.dll<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>01/09/07 - Updated guide to reflect updates to the tools
11/03/09 - Updated for new removal technique.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul>   <li><a href="#first">Automated Removal using Malwarebytes' Anti-Malware</a></li>   <li><a href="#second">Automated Removal Instructions for the Vundo or Virtumonde infection using VundoFix</a></li></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Trojan.vundo and Virtumonde using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Trojan.vundo and Virtumonde
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Trojan.vundo and Virtumonde
    and other Rogue programs. Please be patient while the programs looks for various 
    programs and closes them. When it has finished, the black window will automatically 
    close. If your desktop was hidden, you should also now be able to view it 
    again. <strong>Do not reboot your computer at this point, or the programs 
    will start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing and is at the last screen, make 
    sure you uncheck both of the <strong>Update Malwarebytes' Anti-Malware</strong> 
    and <strong> </strong><strong>Launch Malwarebytes' Anti-Malware</strong> check 
    boxes. Then click on the <strong>Finish</strong> button. If Malwarebytes' 
    prompts you to reboot, <strong>please do not do so</strong>.<br>
    <br>
    If you receive a code 2 error while installing Malwarebytes's, please press 
    the <strong>OK</strong> button to close these errors as we will resolve them 
    in future steps. The code 2 error will look similar to the image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/code-2-error.jpg" alt="Malwarebytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li>As this infection deletes a core executable of Malwarebytes' we will need 
    to download a new copy of it and put it in the <strong>C:\program files\Malwarebytes' 
    Anti-Malware\ </strong>folder. To download the file please click on the following 
    link:<br>
    <br>
    <blockquote><a href="http://mbam.malwarebytes.org/program/random.php">Malwarebytes' 
      EXE Download</a></blockquote>
    When your browser prompts you where to save it to, please save it to the <strong>C:\program 
    files\Malwarebytes' Anti-Malware\ </strong> folder. When downloading the file, 
    it will have a random filename. Please leave the filename the way it is as 
    it is important that it is not changed. You may want to write down the name 
    of the file as you will need to know the name in the next step.<br>
    <br>
  </li>
  <li>Once the file has been downloaded, open the <strong>C:\program files\Malwarebytes' 
    Anti-Malware\ </strong> folder and double-click on the file you downloaded 
    in step 8. MBAM will now start and you will be at the main program screen 
    as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="Malwarebytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> Before you can perform a scan, you must first update the program. To do 
    this click on the<strong> Update</strong> tab, and that at the new screen 
    click on the <strong>Check for Updates</strong> button. Malwarebytes' will 
    now check for new updates and download and install them as necessary. When 
    the update is completed, you will be prompted with a message stating either 
    that you already have the latest updates or that they have been updated. Either 
    way, you should now click on the <strong>OK</strong> button to continue.<br>
    <br>
  </li>
  <li>Now click on the <strong>Scanner</strong> tab and make sure the the <strong>Perform 
    full scan</strong> option is selected. Then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Trojan.vundo and Virtumonde
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="Malwarebytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="Malwarebytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    Trojan.vundo and Virtumonde
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/v/vundo/mbam-vundo.jpg" alt="Malwarebytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Trojan.vundo and Virtumonde</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=vundo" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> Automated Removal Instructions for the Vundo or Virtumonde infection using VundoFix:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li> Please print these instructions as they will be needed later when Internet 
    access is not available.<br>
    <br>
  </li>
  <li> Save these instructions in word or notepad to the desktop where they can 
    be easily found.<br>
    <br>
  </li>
  <li>Download <a href="http://www.atribune.org/ccount/click.php?id=4" target="_blank" rel="nofollow"><b>Vundo 
    Fix</b></a> and save it to your desktop.<br>
    <br>
  </li>
  <li>When it has completed downloading, double-click<i> </i><strong>VundoFix.exe</strong><i> 
    </i> to run it.<br>
    <br>
  </li>
  <li> Click the<strong> Scan for Vundo</strong> button.<br>
    <br>
  </li>
  <li> Once it's done scanning, click the <b>Remove Vundo </b> button.<br>
    <br>
  </li>
  <li>You will now receive a prompt asking if you want to remove the files, click 
    the <b>YES</b> button. Once you click yes, your desktop will go blank as it 
    starts removing Vundo.<br>
    <br>
  </li>
  <li>When completed, it will prompt that it will shutdown your computer, click 
    the <b>OK</b> button.<br>
    <br>
  </li>
  <li> When the computer has shutdown, turn your computer back on.</li>
</ol>
<p>The WinFixer and Vundo infection should now be removed from your computer. 
</p>
<p>&nbsp; </p>
<p><strong>If you are still having a problem then please perform the following 
  steps:</strong></p>
<p><i>Note: This step should only be used if the instructions in the previous 
  steps did not remove the infection</i>: </p>
<ol>
  <li> Download <a href="http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe" target="_blank" rel="nofollow"><b>VirtumundoBegone</b></a> 
    and save it to your desktop. <br>
    <br>
  </li>
  <li>Now reboot into <a href="http://www.bleepingcomputer.com/tutorials/tutorial61.html" target="_blank">Safe 
    Mode</a>. <br>
    <br>
    <ol>
      <li>This can be done tapping the F8 key as soon as you start your computer 
        <br>
        <br>
      </li>
      <li>You will be brought to a menu where you can choose to boot into safe 
        mode. <br>
        <br>
      </li>
      <li>Select safe mode with networking using your arrow keys on the keyboard 
        and then press enter.<br>
        <br>
      </li>
      <li>When you computer reaches the desktop make sure you log in as the same 
        user which you had performed the previous steps,<br>
        <br>
      </li>
    </ol>
  </li>
  <li>Once you are logged into safe mode, double-click <strong>VirtumundoBeGone.exe</strong> 
    file you just downloaded and follow the instructions.<br>
    <br>
  </li>
  <li>Exit when it has finished, and reboot back to normal mode.</li>
</ol>
<p>The WinFixer and Vundo infection should now be removed from your computer. 
  <b><font color="#FFFFFF">Conclusion </font></b><br>
</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Security Tool and SecurityTool (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-security-tool</link>
	<pubDate>Tue, 03 Nov 2009 09:34:29 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Security Tool]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-security-tool</guid>
	<description><![CDATA[Security Tool, otherwise known as SecurityTool, is a rogue anti-spyware program from the same family as System Security. This program is promoted through the use of Trojans and web pop-ups. When this rogue is promoted via a Trojan it will be installed onto your computer without your permission or knowledge. When promoted via web pop-ups, you will be shown a pop-up when browsing the web that states your computer is infected. If you click on the pop-up you will be brought to a page that shows an advertisement that pretends to be a fake online anti-malware scanner. At the end of the advertisement, it will state that there are infections and then prompt you to download and install Security Tool onto your computer. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Security Tool and SecurityTool (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Tue, 03 Nov 2009 09:34:29 EST &middot; Views: 117609</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-security-tool', 'Remove Security Tool and SecurityTool (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-security-tool', 'Remove Security Tool and SecurityTool (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Security Tool</strong>, otherwise known as SecurityTool, is a rogue 
  anti-spyware program from the same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-system-security">System 
  Security</a>. This program is promoted through the use of Trojans and web pop-ups. 
  When this rogue is promoted via a Trojan it will be installed onto your computer 
  without your permission or knowledge. When promoted via web pop-ups, you will 
  be shown a pop-up when browsing the web that states your computer is infected. 
  If you click on the pop-up you will be brought to a page that shows an advertisement 
  that pretends to be a fake online anti-malware scanner. At the end of the advertisement, 
  it will state that there are infections and then prompt you to download and 
  install Security Tool onto your computer.</p>
<p> 
  
</p>
<p> When the program is installed it will be configured to start automatically 
  when you login to your computer. Once started, it will perform a scan, and when 
  finished, state that there are numerous infections on your computer. If you 
  attempt to remove these infections, though, it will not allow it until you first 
  purchase the program. The reality is that the scan results are a scam and the 
  infected files it states are on your computer are actually legitimate Windows 
  files. With this said, please do not manually delete any of the files it states 
  are infections as it may affect the proper operation of your computer.</p>
<p>When the program is running you will be shown numerous alerts on your desktop 
  and from your Windows taskbar. These alerts will state that your computer is 
  under attack, that the Security Tool firewall has blocked a malware program, 
  or that active malware infections have been detected. The text of some of the 
  alerts you may see are:</p>
<blockquote> 
  <p><font color="#0000FF"><strong>Security Tool Warning<br>
    </strong></font><font color="#0000FF">Spyware.IEMonster activity detected. 
    This is spyware that attempts to steal passwords from Internet Explorer, Mozilla 
    Firefox, Outlook and other programs.<br>
    Click here to remove it immediately with SecurityTool.</font></p>
  <p>and</p>
  <p><font color="#0000FF"><strong>Security Tool Warning<br>
    </strong></font><font color="#0000FF">Some critical system files of your computer 
    were modified by malicious program. It may cause system instability and data 
    loss.<br>
    Click here to block unauthorised modification by removing threats (Recommended)</font></p>
</blockquote>
<p>Just like the scan results, these security notices are not real either and 
  are only being shown to scare you into thinking you are infected. The biggest 
  problem this program poses is that it will not allow you to run any program 
  other than ones required by your operating system. When you attempt to start 
  a program when Security Tool is running it will shut down the program and state 
  that it is infected. In reality there is nothing wrong with these programs and 
  instead Security Tool is holding your ability to run programs ransom until you 
  purchase it. Thankfully, we have a way of bypassing these restrictions so that 
  you can fix your computer without paying the ransom.</p>
<p>If you are infected with Security Tool then please use the guide below to remove 
  it from your computer for free. If you have already purchased the program, then 
  we recommend that you contact your credit card company and dispute the charges 
  as this program is a scam.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	<b>Please note that the files and folders for Security Tool and SecurityTool have random names.</b><br />
<br />
O4 - HKLM\..\Run: [4946550101] %UserProfile%\Application Data\4946550101\4946550101.exe<br />
O4 - HKCU\..\Run: [Install] %UserProfile%\Application Data\4946550101\4946550101.bat
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>09/25/09 - Initial guide creation.
10/14/09 - Updated guide to allow you to remove the program even though it does not allow you to run applications.
11/03/09 - Updated for new technique asit is bundled with vundo.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul>   <li><a href="#first">Automated Removal using Malwarebytes' Anti-Malware</a></li></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Security Tool using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Security Tool
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Security Tool
    and other Rogue programs. Please be patient while the programs looks for various 
    programs and closes them. When it has finished, the black window will automatically 
    close. If your desktop was hidden, you should also now be able to view it 
    again. <strong>Do not reboot your computer at this point, or the programs 
    will start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing and is at the last screen, make 
    sure you uncheck both of the <strong>Update Malwarebytes' Anti-Malware</strong> 
    and <strong> </strong><strong>Launch Malwarebytes' Anti-Malware</strong> check 
    boxes. Then click on the <strong>Finish</strong> button. If Malwarebytes' 
    prompts you to reboot, <strong>please do not do so</strong>.<br>
    <br>
    If you receive a code 2 error while installing Malwarebytes's, please press 
    the <strong>OK</strong> button to close these errors as we will resolve them 
    in future steps. The code 2 error will look similar to the image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/code-2-error.jpg" alt="Malwarebytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li>As this infection deletes a core executable of Malwarebytes' we will need 
    to download a new copy of it and put it in the <strong>C:\program files\Malwarebytes' 
    Anti-Malware\ </strong>folder. To download the file please click on the following 
    link:<br>
    <br>
    <blockquote><a href="http://mbam.malwarebytes.org/program/random.php">Malwarebytes' 
      EXE Download</a></blockquote>
    When your browser prompts you where to save it to, please save it to the <strong>C:\program 
    files\Malwarebytes' Anti-Malware\ </strong> folder. When downloading the file, 
    it will have a random filename. Please leave the filename the way it is as 
    it is important that it is not changed. You may want to write down the name 
    of the file as you will need to know the name in the next step.<br>
    <br>
  </li>
  <li>Once the file has been downloaded, open the <strong>C:\program files\Malwarebytes' 
    Anti-Malware\ </strong> folder and double-click on the file you downloaded 
    in step 8. MBAM will now start and you will be at the main program screen 
    as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="Malwarebytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> Before you can perform a scan, you must first update the program. To do 
    this click on the<strong> Update</strong> tab, and that at the new screen 
    click on the <strong>Check for Updates</strong> button. Malwarebytes' will 
    now check for new updates and download and install them as necessary. When 
    the update is completed, you will be prompted with a message stating either 
    that you already have the latest updates or that they have been updated. Either 
    way, you should now click on the <strong>OK</strong> button to continue.<br>
    <br>
  </li>
  <li>Now click on the <strong>Scanner</strong> tab and make sure the the <strong>Perform 
    full scan</strong> option is selected. Then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Security Tool
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="Malwarebytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="Malwarebytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    SecurityTool
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/securitytool/mbam-security-tool.jpg" alt="Malwarebytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SecurityTool</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=securitytool" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Security Tool Files:</span></p>
     <blockquote>
        <b>Please note that the files and folders for Security Tool and SecurityTool have random names.</b><br />
<br />
%UserProfile%\Application Data\4946550101<br />
%UserProfile%\Application Data\4946550101\4946550101.bat<br />
%UserProfile%\Application Data\4946550101\4946550101.cfg<br />
%UserProfile%\Application Data\4946550101\4946550101.exe<br />
%UserProfile%\Desktop\Security Tool.lnk<br />
%UserProfile%\Start Menu\Programs\Security Tool.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Security Tool Windows Registry Information:</span></p>
     <blockquote>
        <b>Please note that the files and folders for Security Tool and SecurityTool have random names.</b><br />
<br />
HKEY_CURRENT_USER\Software\Security Tool<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4946550101"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove BlockKeeper (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-blockkeeper</link>
	<pubDate>Mon, 02 Nov 2009 17:29:41 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[BlockKeeper]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-blockkeeper</guid>
	<description><![CDATA[BlockKeeper is a rogue anti-spyware program that is installed through the use of Trojans that impersonate video codecs or Flash updates required to see an online movie. When the Trojan is installed it will download and install BlockKeeper on to your computer. The Trojan will also create numerous files on your hard drive that pretend to be malware files. These harmless files will then be detected as infections when BlockKeeper scans your computer, but the program will state it will not remove them until you first purchase it. The reality is that these files are harmless and cannot hurt your computer. They are only being detected to substantiate the scan results and to convince you that are infected in the hopes that you will then purchase the program. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove BlockKeeper (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 02 Nov 2009 17:29:41 EST &middot; Views: 1372</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-blockkeeper', 'Remove BlockKeeper (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-blockkeeper', 'Remove BlockKeeper (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>BlockKeeper</strong> is a rogue anti-spyware program that is installed 
  through the use of Trojans that impersonate video codecs or Flash updates required 
  to see an online movie. When the Trojan is installed it will download and install 
  BlockKeeper on to your computer. The Trojan will also create numerous files 
  on your hard drive that pretend to be malware files. These harmless files will 
  then be detected as infections when BlockKeeper scans your computer, but the 
  program will state it will not remove them until you first purchase it. The 
  reality is that these files are harmless and cannot hurt your computer. They 
  are only being detected to substantiate the scan results and to convince you 
  that are infected in the hopes that you will then purchase the program.</p>
<p>
  
</p>
<p>The Trojan also display fake warnings and messages on your computer. These 
  warnings, or infiltration alerts, will state that your computer is infested 
  with malware, has spyware, or is transmitting private data to the Internet. 
  An example of one of the alerts you would see is:</p>
<blockquote>
  <p><font color="#0000FF">Spyware Alert!</font></p>
  <p><font color="#0000FF">Your computer is infected with spyware. It could damage 
    your critical files or expose your private data on the Internet. Click here 
    to register your copy of BlockKeeper and remove spyware threats from your 
    PC. </font></p>
</blockquote>
<p>The Trojan will also display a fake Windows Security Center window that suggests 
  you register the BlockKeeper program. Just like the fake scan results, these 
  messages should be ignored as it is just another tactic that they are using 
  to scare you into thinking there is a security problem with your computer.</p>
<p>If BlockKeeper is on your computer, then I suggest you use the removal guide 
  below. By no means should you purchase the program as it is only a scam. If 
  you have already purchased the program, then I suggest you contact your credit 
  card company and dispute the charges.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17698/BlockKeeper.html">BlockKeeper</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	HKEY_CURRENT_USER\Software\BlockKeeper<br />
HKEY_LOCAL_MACHINE\SOFTWARE\BlockKeeper<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlockKeeper<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "BlockKeeper"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "fjs6.tmp.exe"
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11/02/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul>   <li><a href="#first">Automated Removal using Malwarebytes' Anti-Malware</a></li></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for BlockKeeper using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>BlockKeeper</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>BlockKeeper</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/b/blockkeeper/mbam-blockkeeper.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>BlockKeeper</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=blockkeeper" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated BlockKeeper Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\BlockKeeper.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockKeeper<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockKeeper\1 BlockKeeper.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockKeeper\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockKeeper\3 Uninstall.lnk<br />
%Temp%\fjs6.tmp.exe<br />
c:\Program Files\BlockKeeper Software<br />
c:\Program Files\BlockKeeper Software\BlockKeeper<br />
c:\Program Files\BlockKeeper Software\BlockKeeper\BlockKeeper.exe<br />
c:\Program Files\BlockKeeper Software\BlockKeeper\uninstall.exe<br />
c:\WINDOWS\10091szyc5.bin<br />
c:\WINDOWS\10218h9cktzo565f.cpl<br />
c:\WINDOWS\105z9hacktool50f.dll<br />
c:\WINDOWS\system32\333059oz563.ocx<br />
c:\WINDOWS\system32\3395d9wnlozder1905.exe<br />
c:\WINDOWS\system32\34335own9oader199z.ocx
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated BlockKeeper Windows Registry Information:</span></p>
     <blockquote>
        O4 - HKCU\..\Run: [fjs6.tmp.exe] C:\WINDOWS\system32\fjs6.tmp.exe<br />
O4 - HKCU\..\Run: [BlockKeeper] C:\Program Files\BlockKeeper Software\BlockKeeper\BlockKeeper.exe -min<br />

     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>How to use SUPERAntiSpyware to scan and remove malware from your computer</title>
	<link>http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial</link>
	<pubDate>Mon, 02 Nov 2009 16:54:08 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[SUPERAntiSpyware]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial</guid>
	<description><![CDATA[With viruses, worms, Trojans, and malware becoming more and more pervasive in every computer users life, it is important to have an arsenal of tools that can be used to scan your computer and remove any malware that has been found. An excellent tool to accomplish this is SUPERAntiSpyware. SUPERAntiSpyware is a malware removal tool that focuses on all types of infections. It is free and easy to use, and for those who want more advanced features such as real-time protection, there is a commercial professional version. Even more important, though, is the fact that it does an excellent job in removing malware. The guide below will walk you through installing, configuring, and scanning your computer with SUPERAntiSpyware. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>How to use SUPERAntiSpyware to scan and remove malware from your computer</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 02 Nov 2009 16:54:08 EST &middot; Views: 296</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial', 'How to use SUPERAntiSpyware to scan and remove malware from your computer');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial', 'How to use SUPERAntiSpyware to scan and remove malware from your computer');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong><u>Table of Contents</u></strong></p>
<ol>
  <li><a href="#intro">Introduction</a></li>
  <li><a href="#tutorial">How to use SUPERAntiSpyware</a></li>
  <li><a href="#troubleshoot">Alternate methods of starting SUPERAntiSpyware and 
    Troubleshooting </a></li>
</ol>
<p>&nbsp;</p>
<p><span class='swr-heading'><a name="intro"></a>Introduction:</span></p>
<p>With viruses, worms, Trojans, and malware becoming more and more pervasive 
  in every computer users life, it is important to have an arsenal of tools that 
  can be used to scan your computer and remove any malware that has been found. 
  An excellent tool to accomplish this is SUPERAntiSpyware. SUPERAntiSpyware is 
  a malware removal tool that focuses on all types of infections. It is free and 
  easy to use, and for those who want more advanced features such as real-time 
  protection, there is a commercial professional version. Even more important, 
  though, is the fact that it does an excellent job in removing malware. The guide 
  below will walk you through installing, configuring, and scanning your computer 
  with SUPERAntiSpyware.</p>
<p>&nbsp;</p>
<hr>
<p><span class='swr-heading'><a name="tutorial"></a>How to use SUPERAntiSpyware:</span></p>
<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download SUPERAntiSpyware Free, or SAS, from the following location and 
    save it to your desktop:<br>
    <br>
    <a href="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE&rid=3324" target="_new" rel="nofollow">SUPERAntiSpyware 
    Free Download Link</a><br>
    <br>
    When you visit the above link you will be at a page asking if you would like 
    to download SUPERAntiSpyware Free or the Professional version. Please click 
    on the <strong>Download Free Version Home Users</strong> button at the top 
    of the page. You will then be brought to a page where the download will automatically 
    start. <br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click the icon on your desktop named <strong>SUPERAntiSpyware.exe</strong>. 
    This will start the installation of SUPERAntiSpyware onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings, 
    and when the program has finished installing, click on the <strong>Finish</strong> 
    button to get back to your Windows desktop.<br>
    <br>
  </li>
  <li>SUPERAntiSpyware will now automatically start and you will see a message 
    asking you to select the language you would like the program to use. Please 
    select your language and then press the <strong>OK</strong> button to continue.<br>
    <br>
  </li>
  <li>You will now be prompted to update the SUPERAntiSpyware definitions. Please 
    press the <strong> Yes</strong> button to allow the program to download and 
    install the latest updates so that it can properly detect and remove the latest 
    malware.<br>
    <br>
    If there is an error when trying to update the definitions, you can download 
    them directly from the <a href="http://www.superantispyware.com/definitions.html?rid=3324">SUPERAntiSpyware 
    Database Definitions page</a>. Once at that page, click on the <strong>Download 
    Installer</strong> link and save the SASDEFINITIONS.EXE file to your desktop. 
    Once download, double-click on the <strong>SASDEFINITIONS.EXE</strong>. Follow 
    the prompts to install the latest SAS definitions onto your computer.<br>
    <br>
  </li>
  <li>After the definitions are updated, the welcome screen for SUPERAntiSpyware 
    will appear. If for some reason SUPERAntiSpyware is not starting, please see 
    our <a href="#troubleshoot">troubleshooting section</a>. Otherwise, at the 
    welcome screen you should keep following the prompts, while leaving all the 
    default settings as they are. When you get to the screen asking if you would 
    like to send the diagnostics, you can choose to allow it to or not. Either 
    choice will have no affect on the effectiveness of its malware scan. When 
    you get to the last screen, click on the <strong>Finish</strong> button.<br>
    <br>
  </li>
  <li>You will now be prompted if you would like SAS to protect your home page. 
    If you select the <strong>Protect Home page</strong> option, SUPERAntiSpyware 
    will alert you if another program is trying to change your browser's home 
    page. I suggest you allow SAS to protect your home page by clicking on the 
    <strong>Protect Home page</strong> button.<br>
    <br>
  </li>
  <li>You will now be at the main screen for SUPERAntiSpyware as shown in the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/sas/superantispyware.jpg" alt="SuperAntiSpyware Screen"><br>
      <strong>SUPERAntiSpyware screen shot</strong><br>
    </div>
    <br>
    Please click on the <strong>Preferences</strong> button to customize how SUPERAntiSpyware 
    will scan your computer.<br>
    <br>
  </li>
  <li> When the program's preferences screen opens, click on the <strong>Scanning 
    Control</strong> tab and put a checkmark in the following options <br>
    <ol>
      <li><strong>Close browsers before scanning.<br>
        </strong></li>
      <li><strong>Scan for tracking cookies.</strong></li>
    </ol>
  </li>
  <p>When done, the settings on the Scanning Control preferences screen be similar 
    to the image below.<br>
    <br>
  </p>
  <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/sas/scanning-control.jpg" alt="SUPERAntiSpyware Scanning Controls Preferences Screen"><br>
    <strong>SUPERAntiSpyware Scanning Controls Preferences Screen</strong><br>
  </div>
  <p>Now press the <strong>Close</strong> button to go back to the main screen.<br>
  </p>
  <li>You will now be at the main screen and should click on the <strong>Scan 
    your Computer...</strong> button to begin the scanning process.<br>
    <br>
  </li>
  <li>You will now be at the Scan page where you can choose the type of scan you 
    would like to perform as shown by the image below.<br>
    <br>
    <p> </p>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/sas/scan-screen.jpg" alt="SUPERAntiSpyware Scan Screen"><br>
      <strong>SUPERAntiSpyware Scan Screen </strong></div>
    <br>
    <br>
    At this screen you should select the <strong>Perform Complete Scan</strong> 
    option and then press the <strong>Next</strong> button to start scanning your 
    computer.<br>
    <br>
  </li>
  <li>SUPERAntiSpyware will now prompt you to close all of your browser windows 
    in order to continue. Please click on the <strong>Yes</strong> button.<br>
    <br>
  </li>
  <li>SUPERAntiSpyware will now start to scan your computer for malware as shown 
    in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/sas/scanning-screen.jpg" alt="SUPERAntiSpyware scanning screen"><br>
      <strong>Scanning screen</strong><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a screen will appear showing the summary of what 
    was detected as shown in the image below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/sas/scan-summary.jpg" alt="SUPERAntiSpyware Scan Summary"><br>
      <strong>SUPERAntiSpyware Scan Summary</strong><br>
      <br>
    </div>
    You should click on the <strong>OK</strong> button to close the summary screen 
    box and continue with the <strong> </strong>removal process.<br>
    <br>
  </li>
  <li>You will now be at a screen displaying all the malware that the program 
    has found. Please note that the infections found may be different than what 
    is shown in the image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/sas/scan-results.jpg" alt="SUPERAntiSpyware Scan Results"><br>
      <strong>SUPERAntiSpyware Scan Results</strong><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Next</strong> button to remove all the 
    listed malware. SUPERAntiSpyware will now delete all of the files and registry 
    keys that were detected and add them to the program's quarantine. When removing 
    the files, SAS may require you to reboot your computer in order to remove 
    certain files. If it displays a message stating that it needs to reboot, please 
    press the <strong>Yes</strong> button to allow it to do so. Your computer 
    should now reboot.<br>
    <br>
  </li>
  <li>Once your computer has rebooted, the malware should be removed and you can 
    use your computer like normal. If you wish to view a log of what was removed, 
    you can start the SUPERAntiSpyware program and then click on the <strong>Preferences</strong> 
    button. Now click on the <strong>Statistics/Logs</strong> tab and then double-click 
    on the log you would like to view.<br>
  </li>
</ol>
<p>Your computer should now be free of any malware that was detected on your computer. 
  If your current anti-virus solution let this infection through, you may want 
  to consider <a href="<%PUR_LNK%>" rel="nofollow">purchasing the Professional 
  version of SUPERAntiSpyware</a> to protect against these types of threats in 
  the future.</p>
<p>&nbsp;</p>
<p><strong><u><a name="troubleshoot"></a>Alternate methods of starting SUPERAntiSpyware 
  and Troubleshooting</u></strong></p>
<p>At times, you may run into a situation where you cannot install or start SUPERAntiSpyware. 
  Many times this is caused by infections that are purposely blocking SUPERAntiSpyware 
  from running in order to protect itself. Below is a list of steps that you should 
  take if you are having trouble installing or running the program.</p>
<p>If you are unable to install SUPERAntiSpyware through the normal installer, 
  you can try and download the following alternate installers and use them instead:</p>
<blockquote>
  <p><a href="http://downloads.superantispyware.com/downloads/SAS_FREE.EXE">SUPERAntiSpyware 
    FREE Edition Installer</a></p>
  <p><a href="http://downloads.superantispyware.com/downloads/SAS_PRO.EXE">SUPERAntiSpyware 
    Professional Installer</a></p>
</blockquote>
<p><br>
  If SUPERAntiSpyware is installed, but you are unable to launch the program, 
  then please try each of these methods in the following order until the program 
  launches:</p>
<ul>
  <li>Launch the program through the <strong>SUPERAntiSpyware Alternate Start</strong> 
    shortcut in the SUPERAntiSpyware program folder in your Start Menu.<br>
    <br>
  </li>
  <li>Rename C:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe to C:\program 
    files\SUPERAntiSpyware\explorer.exe and try launching the <strong>explorer.com</strong> 
    program.<br>
    <br>
  </li>
  <li>Download the <a href="http://www.superantispyware.com/downloads/RUNSAS.EXE">RUNSAS.exe</a> 
    program and launch it.<br>
    <br>
  </li>
  <li>If none of the previous steps allowed you to launch SUPERAntiSpyware, then 
    please download and launch <a href="http://www.superantispyware.com/downloads/SASSAFERUN.COM">SASSAFERUN.COM</a>. 
    This program can be copied to USB Flash drives or other external media and 
    run directly from there.</li>
</ul>
<p>If, after trying all of these methods, you are still unable to install or run 
  SUPERAntiSpyware then please ask for help in our <a href="http://www.bleepingcomputer.com/forums/forum25.html">AntiVirus, 
  Firewall and Privacy Products and Protection Methods.</a></p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul></ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>11-02-09 - Tutorial created.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove Security Central</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-security-central</link>
	<pubDate>Fri, 30 Oct 2009 17:35:06 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Security Central]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-security-central</guid>
	<description><![CDATA[Security Central is a rogue anti-spyware program that uses deceptive advertising and aggressive techniques to protect itself from removal. This program is installed without your consent through the use of malware that when executed, silently downloads and installs Security Central in the background and then launches the program. Once the program is launched it will scan your computer and then display a variety of false infections that were supposedly detected. It will not, though, allow you to remove any of these infections without first purchasing the program. These infections are all not really there, so you do not need to be concerned as Security Central is just trying to scare you into purchasing the program. To protect itself, Security Central will not allow you to run executable programs any anti-malware programs until the process is terminated. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>How to remove Security Central</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 30 Oct 2009 17:35:06 EDT &middot; Views: 2618</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-security-central', 'How to remove Security Central');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-security-central', 'How to remove Security Central');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Security Central </strong> is a rogue anti-spyware program that uses 
  deceptive advertising and aggressive techniques to protect itself from removal<a href="http://www.bleepingcomputer.com/virus-removal/uninstall-barracuda-antivirus"></a>. 
  This program is installed without your consent through the use of malware that 
  when executed, silently downloads and installs Security Central in the background 
  and then launches the program. Once the program is launched it will scan your 
  computer and then display a variety of false infections that were supposedly 
  detected. It will not, though, allow you to remove any of these infections without 
  first purchasing the program. These infections are all not really there, so 
  you do not need to be concerned as Security Central is just trying to scare 
  you into purchasing the program. To protect itself, Security Central will not 
  allow you to run executable programs any anti-malware programs until the process 
  is terminated.</p>
<p> 
  
</p>
<p>While Security Central is running you will also see pop-ups and nag screens 
  on your computer. These nag screens will state that malicious activity was detected 
  and then suggest that you purchase Security Central in order to protect yourself. 
  The text of one of these messages is:</p>
<blockquote>
  <p><strong><font color="#0000FF">Windows Security alert</font></strong><font color="#0000FF"><br>
    Windows reports that computer is infected. Antivirus software helps to protect 
    your computer against viruses and other security threats. Click here for the 
    scan you computer. Your system might be at risk now.</font></p>
</blockquote>
<p>If you find Security Central is installed on your computer, then please do 
  not purchase it. Instead you should use the free removal guide listed below 
  in order to remove this infection from your computer.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [system ] C:\WINDOWS\systemdb.exe<br />
O4 - HKLM\..\Run: [Security Central] C:\Program Files\Security Central\Security Central.exe<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>07/08/09 - Initial guide creation.
10/30/09 - Updated for the new version of this program.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul>   <li><a href="#first">Automated Removal using Malwarebytes' Anti-Malware</a></li></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Security Central using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Security Central
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Security Central
    and other Rogue programs. Please be patient while the programs looks for various 
    programs and closes them. When it has finished, the black window will automatically close. 
    <strong>Do not reboot your computer at this point, or the programs will start 
    again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button. If MalwareBytes' prompts you to reboot, please do not do so.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Security Central
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    SecurityCentral
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/security-central/mbam-security-central.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SecurityCentral</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=security-central" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Security Central Files:</span></p>
     <blockquote>
        c:\WINDOWS\systemdb.exe<br />
c:\Documents and Settings\Bleeping\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Central.lnk<br />
c:\Documents and Settings\Bleeping\Desktop\Security Central.lnk<br />
c:\Documents and Settings\Bleeping\Start Menu\Security Central<br />
c:\Documents and Settings\Bleeping\Start Menu\Security Central\Security Central.lnk<br />
c:\Program Files\Security Central<br />
c:\Program Files\Security Central\Security Central.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Security Central Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\AvScan<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system "<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Security Central"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove BlockWatcher (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-blockwatcher</link>
	<pubDate>Fri, 30 Oct 2009 16:06:41 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[BlockWatcher]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-blockwatcher</guid>
	<description><![CDATA[BlockWatcher is a rogue anti-spyware program that is promoted through the use of Trojans. These Trojans masquerade as Flash updates or video codecs that are required to watch an online video. Once the Trojan is installed it will download and install BlockWatcher on to your computer. The installer will also create numerous files that will then be detected as malware when BlockWatcher scans your computer. When you try and remove the files it finds in the scan results, BlockWatcher will state that you need to first purchase it before it will remove anything. This is a scam, because the files that are found are harmless and cannot harm your computer. They are only stating they are infection to scare you into purchasing the program. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove BlockWatcher (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 30 Oct 2009 16:06:41 EDT &middot; Views: 1753</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-blockwatcher', 'Remove BlockWatcher (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-blockwatcher', 'Remove BlockWatcher (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>BlockWatcher</strong> is a rogue anti-spyware program that is promoted 
  through the use of Trojans. These Trojans masquerade as Flash updates or video 
  codecs that are required to watch an online video. Once the Trojan is installed 
  it will download and install BlockWatcher on to your computer. The installer 
  will also create numerous files that will then be detected as malware when BlockWatcher 
  scans your computer. When you try and remove the files it finds in the scan 
  results, BlockWatcher will state that you need to first purchase it before it 
  will remove anything. This is a scam, because the files that are found are harmless 
  and cannot harm your computer. They are only stating they are infection to scare 
  you into purchasing the program.</p>
<p>
  
</p>
<p>The Trojan will also display fake security warnings on your computer. These 
  warnings will state that malware has been detected or that your computer is 
  under attack. The Trojan will also display a fake Windows Security Center that 
  states that you should purchase BlockWatcher to protect your computer. Last, 
  but not least, this infection will also hijack Internet Explorer so that it 
  randomly shows a security warning when browsing the web. The text of the warning 
  is:</p>
<blockquote>
  <p><font color="#0000FF">Insecure Internet activity. Threat of virus attack!</font></p>
  <p><font color="#0000FF">Due to insecure Internet browsing your PC can easily 
    get infected with viruses, worms and trojans without your knowledge, which 
    can lead to system slowdowns, freezes and crashes. Also insecure Internet 
    activity can result in revealing your personal information.<br>
    To get full advanced real-time protection for PC and Internet activity, register 
    BlockWatcher. We recommend you to protect your PC now and continue safe Internet 
    browsing.</font></p>
</blockquote>
<p>Just like the scan results, these warnings are all fake and should be ignored.</p>
<p>If you find that you are infected with BlockWatcher, please do not purchase 
  the program. If you have already purchase it, then please dispute the charges 
  as it is a scam. To remove the BlockWatcher infection, and any related malware, 
  please use the removal guide below.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/17656/BlockWatcher.html">BlockWatcher</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [yxh5.tmp.exe] C:\WINDOWS\system32\yxh5.tmp.exe<br />
O4 - HKCU\..\Run: [BlockWatcher] C:\Program Files\BlockWatcher Software\BlockWatcher\BlockWatcher.exe -min
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>10/30/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul>   <li><a href="#first">Automated Removal using Malwarebytes' Anti-Malware</a></li></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for BlockWatcher using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>BlockWatcher</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>BlockWatcher</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/b/blockwatcher/mbam-blockwatcher.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>BlockWatcher</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=blockwatcher" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated BlockWatcher Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\BlockWatcher.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockWatcher<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockWatcher\1 BlockWatcher.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockWatcher\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\BlockWatcher\3 Uninstall.lnk<br />
%Temp%\yxh5.tmp.exe<br />
c:\Program Files\BlockWatcher Software<br />
c:\Program Files\BlockWatcher Software\BlockWatcher<br />
c:\Program Files\BlockWatcher Software\BlockWatcher\BlockWatcher.exe<br />
c:\WINDOWS\10068tro9zd85.exe<br />
c:\WINDOWS\10258z9amb5t73a.bin<br />
c:\WINDOWS\10518virzs5f9.ocx<br />
c:\WINDOWS\system32\19z89s5y663.dll<br />
c:\WINDOWS\system32\1a605tzal32359.dll<br />
c:\WINDOWS\system32\1aa8tzi952064.cpl
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated BlockWatcher Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\BlockWatcher<br />
HKEY_LOCAL_MACHINE\SOFTWARE\BlockWatcher<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BlockWatcher<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "BlockWatcher"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "yxh5.tmp.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Windows Enterprise Suite (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-windows-enterprise-suite</link>
	<pubDate>Thu, 29 Oct 2009 16:59:11 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Windows Enterprise Suite]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-windows-enterprise-suite</guid>
	<description><![CDATA[Windows Enterprise Suite is a rogue that is advertised through the use of fake online anti-malware scanners. When visiting various sites you will be presented with a pop-up that states your computer is infected. If you click on the pop-up, you will be brought to a page that shows an advertisement pretending to be an online anti-malware scanner. When the advertisement is finished, it will state your computer is infected and that you should download and install Windows Enterprise Suite. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Windows Enterprise Suite (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Thu, 29 Oct 2009 16:59:11 EDT &middot; Views: 7187</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-windows-enterprise-suite', 'Remove Windows Enterprise Suite (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-windows-enterprise-suite', 'Remove Windows Enterprise Suite (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Windows Enterprise Suite</strong> is a rogue that is advertised through 
  the use of fake online anti-malware scanners. When visiting various sites you 
  will be presented with a pop-up that states your computer is infected. If you 
  click on the pop-up, you will be brought to a page that shows an advertisement 
  pretending to be an online anti-malware scanner. When the advertisement is finished, 
  it will state your computer is infected and that you should download and install 
  Windows Enterprise Suite.</p>
<p>When Windows Enterprise Suite is installed it will be configured to start automatically 
  when you login to Windows. The installer will also create numerous files on 
  your computer that will then be detected as malware when Windows Enterprise 
  Suite scans your computer. The name of the harmless and fake malware files are:</p>
<blockquote>
  <p><font color="#0000FF">%UserProfile%\Recent\ANTIGEN.sys<br>
    %UserProfile%\Recent\cb.exe<br>
    %UserProfile%\Recent\cid.dll<br>
    %UserProfile%\Recent\CLSV.dll<br>
    %UserProfile%\Recent\DBOLE.sys<br>
    %UserProfile%\Recent\ddv.dll<br>
    %UserProfile%\Recent\eb.exe<br>
    %UserProfile%\Recent\eb.sys<br>
    %UserProfile%\Recent\energy.exe<br>
    %UserProfile%\Recent\exec.tmp<br>
    %UserProfile%\Recent\kernel32.drv<br>
    %UserProfile%\Recent\PE.drv<br>
    %UserProfile%\Recent\PE.tmp<br>
    %UserProfile%\Recent\ppal.exe<br>
    %UserProfile%\Recent\SICKBOY.tmp<br>
    %UserProfile%\Recent\sld.drv<br>
    %UserProfile%\Recent\tjd.dll<br>
    %UserProfile%\Recent\tjd.sys</font></p>
</blockquote>
<p>The program will then prompt you to remove these infections, and if select 
  that it should do so, it will tell you that you need to first purchase the program 
  before it will allow you to do. This is obviously a scam where the program is 
  creating the same files it is detecting in order to convince you that you have 
  malware infections on your computer.</p>
<p>
  
</p>
<p>While Windows Enterprise Suite is running, it will display fake security warnings 
  and messages on your computer. These warnings will state that your computer 
  is infected, active malware has been detected, or that a remote computer is 
  trying to hack into yours. Just like the fake scan results, these warnings should 
  be ignored. If you are infected with this malware, then please do not purchase 
  it and instead use the removal guide below to remove it for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [Windows Enterprise Suite] "C:\Documents and Settings\All Users\Application Data\61a60\WE83b.exe" /s /d<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>10/29/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p><hr>
<p>Choose the removal method you would like to use:</p>
 <ul>   <li><a href="#first">Automated Removal using Malwarebytes' Anti-Malware</a></li></ul>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Windows Enterprise Suite using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Windows Enterprise Suite</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Windows Enterprise Suite</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/w/windows-enterprise-suite/mbam-windows-enterprise.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Windows Enterprise Suite</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=windows-enterprise-s" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>

  <hr>
  <p><span class='swr-heading'><a name="second"></a> :</span></p>
  <p>&nbsp;</p>
	
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Windows Enterprise Suite Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\61a60<br />
c:\Documents and Settings\All Users\Application Data\61a60\WE83b.exe<br />
c:\Documents and Settings\All Users\Application Data\61a60\WES.ico<br />
c:\Documents and Settings\All Users\Application Data\WESSys<br />
c:\Documents and Settings\All Users\Application Data\WESSys\wes.cfg<br />
c:\Documents and Settings\All Users\Application Data\WESSys\vd952342.bd<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Enterprise Suite.lnk<br />
%UserProfile%\Application Data\Windows Enterprise Suite<br />
%UserProfile%\Application Data\Windows Enterprise Suite\cookies.sqlite<br />
%UserProfile%\Application Data\Windows Enterprise Suite\47.mof<br />
%UserProfile%\Application Data\Windows Enterprise Suite\mozcrt19.dll<br />
%UserProfile%\Application Data\Windows Enterprise Suite\sqlite3.dll<br />
%UserProfile%\Application Data\Windows Enterprise Suite\Instructions.ini<br />
%UserProfile%\Desktop\Windows Enterprise Suite.lnk<br />
%UserProfile%\Recent\ANTIGEN.sys<br />
%UserProfile%\Recent\cb.exe<br />
%UserProfile%\Recent\cid.dll<br />
%UserProfile%\Recent\CLSV.dll<br />
%UserProfile%\Recent\DBOLE.sys<br />
%UserProfile%\Recent\ddv.dll<br />
%UserProfile%\Recent\eb.exe<br />
%UserProfile%\Recent\eb.sys<br />
%UserProfile%\Recent\energy.exe<br />
%UserProfile%\Recent\exec.tmp<br />
%UserProfile%\Recent\kernel32.drv<br />
%UserProfile%\Recent\PE.drv<br />
%UserProfile%\Recent\PE.tmp<br />
%UserProfile%\Recent\ppal.exe<br />
%UserProfile%\Recent\SICKBOY.tmp<br />
%UserProfile%\Recent\sld.drv<br />
%UserProfile%\Recent\tjd.dll<br />
%UserProfile%\Recent\tjd.sys<br />
%UserProfile%\Start Menu\Windows Enterprise Suite.lnk<br />
%UserProfile%\Start Menu\Programs\Windows Enterprise Suite.lnk<br />
c:\Program Files\Mozilla Firefox\searchplugins\search.xml
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Windows Enterprise Suite Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
HKEY_CLASSES_ROOT\xp_ca0d5.DocHostUIHandler<br />
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" => "http://search-gala.com/?&uid=7&q={searchTerms}"<br />
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = 1<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Enterprise Suite"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

</channel>
</rss>