<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/" 
	xmlns:wfw="http://wellformedweb.org/CommentAPI/" 
	xmlns:dc="http://purl.org/dc/elements/1.1/" 
	xmlns:atom="http://www.w3.org/2005/Atom" 
	>

<channel>
	<title>Virus, Spyware, and Malware Removal Guides</title>

	<link>http://www.bleepingcomputer.com/virus-removal/</link>
	<description>The latest information about current virus, spyware, and malware threats to your computer.  Use these guides and tutorials to remove or uninstall various malware and infections from your comptuer. All removal instructions are free to use and do not cost any money to remove any of the malware listed in these guides. The content in this RSS feed is to be used by news aggregators and informational purposes.  It is not to be used to add as content on a web site.</description>
	<pubDate>Tue, 09 Feb 2010 09:55:06 EST</pubDate>
	<generator>http://www.bleepingcomputer.com/</generator>
	<language>en</language>

 <item>
	<title>Remove SecurePcAv (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-securepcav</link>
	<pubDate>Mon, 08 Feb 2010 20:39:21 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[SecurePcAv]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-securepcav</guid>
	<description><![CDATA[SecurePcAv is a rogue anti-spyware program from the Wini family of malware. This rogue is promoted and installed through the use of Trojans that pretend to be programs necessary to view certain online videos. When you download and install this Trojan it will install the rogue and configure it to start automatically when your computer starts. This same Trojan will also create fake malware files on your computer with random filenames that are then detected as viruses when SecurePcAv scans your computer. The program, though, will state that it will not remove these files until you first purchase it. This is obviously a scam as the program is only detecting the files it created in the first place. In reality, these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove SecurePcAv (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 08 Feb 2010 20:39:21 EST &middot; Views: 237</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-securepcav', 'Remove SecurePcAv (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-securepcav', 'Remove SecurePcAv (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>SecurePcAv</strong> is a rogue anti-spyware program from the Wini 
  family of malware. This rogue is promoted and installed through the use of Trojans 
  that pretend to be programs necessary to view certain online videos. When you 
  download and install this Trojan it will install the rogue and configure it 
  to start automatically when your computer starts. This same Trojan will also 
  create fake malware files on your computer with random filenames that are then 
  detected as viruses when SecurePcAv scans your computer. The program, though, 
  will state that it will not remove these files until you first purchase it. 
  This is obviously a scam as the program is only detecting the files it created 
  in the first place. In reality, these files are harmless and do not pose any 
  risk to your computer. Thus this programs scan results should be ignored.</p>
<p>Please note, some variants of Wini rogues have been bundling a rootkit infection 
  called TDL3. Therefore, though MalwareByte's may remove the rogue infection, 
  you may still have problems with pop-ups or redirections when you click on search 
  engine results. If this type of behavior is occurring on your computer, then 
  you may have this infection and should follow the steps in the <a href="http://www.bleepingcomputer.com/forums/topic34773.html">Preparation 
  Guide For Use Before Using HijackThis and other Malware Removal Tools</a> topic.</p>
<p>

</p>
<p>The Trojan that installed SecurePcAv will also display fake security alerts 
  and messages on your desktop. These alerts will state that active malware has 
  been found, that your being attacked by a remote computer, or that you are sending 
  sensitive data to a remote location. The titles of these alerts will be Spyware 
  Alert!, Infiltration Alert!, or Security Center Alert!. The current text of 
  one of the alerts is:</p>
<blockquote>
  <p><strong><strong>German Alert:</strong><font
 color="#0000ff"><strong><br>
Spzprogramm Warnzeichen!</strong><br>
  </font></strong><font color="#0000ff">Ihr
Computer ist mit Spionprogramm infektioniert. Das kann Ihren Dateien
und die im Internet zugänglich machen. Klicken bitte hier, um Ihre
Kopie von SecurePcAv zu registrieren und Ihr PC von Spyprogramm frei
zu machen.</font></p>
  <p><strong>English Alert:</strong><br>
  <font color="#0000ff"><strong>Spyware Alert!</strong><br>
Your computer is infected with spyware. It could damage your critical
files or expose your private data on the Internet. Click here to
register your copy of SecurePcAv and remove spyware threats from
your PC.</font></p>
  <p><strong>French Alert:<br>
  <font color="#0000ff">Spyware Alerte!<br>
  </font></strong><font color="#0000ff">Votre
ordinateur est infecté de spyware. Il pourrait endommager vos fichiers
critiques ou exposer vos données prives sur 'Internet. Cliquez ici pour
enregistrer votre copie de SecurePcAv et enléver des menaces spyware
de votre OP. </font></p>
  <p><strong>Italian Alert:<br>
  <font color="#0000ff">Spyware miniaccia!<br>
  </font></strong><font color="#0000ff">Il suo
computer è infetto di spyware. Puo dannegiare i suoi files criticali
rivelare i suoi dati personali nell'Internet. Clicca qui per registrare
la sua coppia di SecurePcAv e rimouvere le minacce di spyware dal suo
computer. </font></p>
</blockquote>
<p>The Trojan will also display a fake Windows Security Center
screen that will suggest that you purchase SecurePcAv to protect
yourself. SecurePcAv will also hijack Internet Explorer so that it
randomly displays a security warning when you browse the web. This
security warning will state that the site you are visiting is infected
or malicious and that you should purchase SecurePcAv to protect
yourself. Just like the scan results, these fake warnings and messages
should be ignored as they are just another attempt to make you think
your computer has a security problem.</p>
<p>As you can see, you should not purchase this program
regardless of what it may state. If you have already purchased the
program, then please contact your credit card company and dispute the
charges. Finally, please use the guide below to remove this infection
and any related malware for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/18591/SecurePcAv.html">SecurePcAv</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [SecurePcAv] C:\Program Files\SecurePcAv Software\SecurePcAv\SecurePcAv.exe -min<br />
O4 - HKCU\..\Run: [&lt;random&gt;.exe] C:\WINDOWS\system32\&lt;random&gt;.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>02/08/10 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for SecurePcAv using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    SecurePcAv
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>SecurePcAv</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/securepcav/mbam-securepcav.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SecurePcAv</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=securepcav" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated SecurePcAv Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\SecurePcAv.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecurePcAv<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecurePcAv\1 SecurePcAv.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecurePcAv\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SecurePcAv\3 Uninstall.lnk<br />
c:\Program Files\SecurePcAv Software<br />
c:\Program Files\SecurePcAv Software\SecurePcAv<br />
c:\Program Files\SecurePcAv Software\SecurePcAv\SecurePcAv.exe<br />
c:\Program Files\SecurePcAv Software\SecurePcAv\uninstall.exe<br />
c:\WINDOWS\10133zo9m49d5.cpl<br />
c:\WINDOWS\10190wormz5e.dll<br />
c:\WINDOWS\system32\5725viruz9.dll<br />
c:\WINDOWS\system32\57634hzcktool3d59.bin<br />
c:\WINDOWS\system32\57939tzoj5fc.bin<br />
c:\WINDOWS\system32\&lt;random&gt;.exe<br />
%Temp%\&lt;random&gt;.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated SecurePcAv Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\SecurePcAv<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SecurePcAv<br />
HKEY_LOCAL_MACHINE\SOFTWARE\SecurePcAv<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SecurePcAv"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Your PC Protector (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-your-pc-protector</link>
	<pubDate>Mon, 08 Feb 2010 19:02:19 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Your PC Protector]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-your-pc-protector</guid>
	<description><![CDATA[Your PC Protector is a rogue anti-spyware program that uses aggressive techniques to stop your from removing it from your computer. This malware is installed via Trojans that install it on to your computer without permission. Once installed the rogue will attempt to stop you from running any executable programs and will display an alert when you run them stating that the program is infected. It will also automatically restart itself via a Windows service every time you shut down the process, so you will need to shutdown both the service and the rogue process to stop it from being restarted. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Your PC Protector (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 08 Feb 2010 19:02:19 EST &middot; Views: 21814</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-your-pc-protector', 'Remove Your PC Protector (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-your-pc-protector', 'Remove Your PC Protector (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Your PC Protector</strong> is a rogue anti-spyware program that uses 
  aggressive techniques to stop your from removing it from your computer. This 
  malware is installed via Trojans that install it on to your computer without 
  permission. Once installed the rogue will attempt to stop you from running any 
  executable programs and will display an alert when you run them stating that 
  the program is infected. It will also automatically restart itself via a Windows 
  service every time you shut down the process, so you will need to shutdown both 
  the service and the rogue process to stop it from being restarted.</p>
<p>Once running, Your PC Protector will scan your computer and state that there 
  are numerous infections on it. It will not, though, allow you to remove any 
  infections until you first purchase the program. As these scan results are all 
  fake, please do not purchase the program as you will not get any benefit from 
  it.</p>
<p>

</p>
<p>While the rogue is running you will also see fake security warnings appear 
  on your desktop. These warnings will state that your computer is infected, that 
  malicious programs have been found running on your computer, or that you are 
  under attack. The Trojan that installed Your PC Protector will also display 
  fake security alerts and messages on your desktop. These alerts will state that 
  active malware has been found, that your being attacked by a remote computer, 
  or that you are sending sensitive data to a remote location. The text of one 
  of these alerts is:</p>
<blockquote>
  <p><strong><font
 color="#0000ff"><strong>Security Warning</strong><br>
    </font></strong><font color="#0000ff">There are critical system files on your 
    computer that were modified by malicious program. It will cause unstable work 
    of your system and permanent data loss. Click here to undo performed modifications 
    and remove malicious software. (Highly Recommended)</font></p>
</blockquote>
<p>Just like the scan results, these fake security warnings are all fake and should 
  be ignored.</p>
<p>As you can see, you should not purchase this program
regardless of what it may state. If you have already purchased the
program, then please contact your credit card company and dispute the
charges. Finally, please use the guide below to remove this infection
and any related malware for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: ADC PlugIn - {77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02} - C:\Program Files\adc32.dll
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>02/03/10 - Initial guide creation.
02/08/10 - Updated due to Vundo reports.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Your PC Protector using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Your PC Protector
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Your PC Protector
    and other Rogue programs. Please be patient while the program looks for various 
    malware programs and ends them. When it has finished, the black window will 
    automatically close and you can continue with the next step. If you get a 
    message that rkill is an infection, do not be concerned. This message is just 
    a fake warning given by 
    Your PC Protector
    when it terminates programs that may potentially remove it. If you run into 
    these infections warnings that close Rkill, a trick is to leave the warning 
    on the screen and then run Rkill again. By not closing the warning, this typically 
    will allow you to bypass the malware trying to protect itself so that rkill 
    can terminate 
    Your PC Protector
    . So, please try running Rkill until malware is no longer running. You will 
    then be able to proceed with the rest of the guide.<strong><br>
    <br>
    Do not reboot your computer after running rkill as the malware programs will 
    start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing and is at the last screen, make 
    sure you uncheck both of the <strong>Update Malwarebytes' Anti-Malware</strong> 
    and <strong> </strong><strong>Launch Malwarebytes' Anti-Malware</strong> check 
    boxes. Then click on the <strong>Finish</strong> button. If Malwarebytes' 
    prompts you to reboot, <strong>please do not do so</strong>.<br>
    <br>
    If you receive a code 2 error while installing Malwarebytes's, please press 
    the <strong>OK</strong> button to close these errors as we will resolve them 
    in future steps. The code 2 error will look similar to the image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/code-2-error.jpg" alt="Malwarebytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li>As this infection deletes a core executable of Malwarebytes' we will need 
    to download a new copy of it and put it in the <strong>C:\program files\Malwarebytes' 
    Anti-Malware\ </strong>folder. To download the file please click on the following 
    link:<br>
    <br>
    <blockquote><a href="http://mbam.malwarebytes.org/program/random.php">Malwarebytes' 
      EXE Download</a></blockquote>
    When your browser prompts you where to save it to, please save it to the <strong>C:\program 
    files\Malwarebytes' Anti-Malware\ </strong> folder. When downloading the file, 
    it will have a random filename. Please leave the filename the way it is as 
    it is important that it is not changed. You may want to write down the name 
    of the file as you will need to know the name in the next step.<br>
    <br>
  </li>
  <li>Once the file has been downloaded, open the <strong>C:\program files\Malwarebytes' 
    Anti-Malware\ </strong> folder and double-click on the file you downloaded 
    in step 8. MBAM will now start and you will be at the main program screen 
    as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="Malwarebytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> Before you can perform a scan, you must first update the program. To do 
    this click on the<strong> Update</strong> tab, and that at the new screen 
    click on the <strong>Check for Updates</strong> button. Malwarebytes' will 
    now check for new updates and download and install them as necessary. When 
    the update is completed, you will be prompted with a message stating either 
    that you already have the latest updates or that they have been updated. Either 
    way, you should now click on the <strong>OK</strong> button to continue.<br>
    <br>
  </li>
  <li>Now click on the <strong>Scanner</strong> tab and make sure the the <strong>Perform 
    full scan</strong> option is selected. Then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Your PC Protector
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="Malwarebytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="Malwarebytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    Your PC Protector
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="Malwarebytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
    <br>
  </li>
  <li>Due to the fact that this infection deletes certain MalwareBytes' files, 
    and we had to work around this, if you wish to continue using MalwareBytes' 
    Anti-Malware, which we suggest you do, then you should uninstall and then 
    install it again so that the files are created properly.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Your PC Protector</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=your-pc-protector" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Your PC Protector Files:</span></p>
     <blockquote>
        c:\Program Files\adc32.dll<br />
c:\Program Files\alggui.exe<br />
c:\Program Files\nuar.old<br />
c:\Program Files\skynet.dat<br />
c:\Program Files\svchost.exe<br />
c:\Program Files\wp3.dat<br />
c:\Program Files\wp4.dat<br />
c:\Program Files\schtml<br />
c:\Program Files\schtml\dbsinit.exe<br />
c:\Program Files\schtml\wispex.html<br />
c:\Program Files\schtml\images<br />
c:\Program Files\schtml\images\i1.gif<br />
c:\Program Files\schtml\images\i2.gif<br />
c:\Program Files\schtml\images\i3.gif<br />
c:\Program Files\schtml\images\j1.gif<br />
c:\Program Files\schtml\images\j2.gif<br />
c:\Program Files\schtml\images\j3.gif<br />
c:\Program Files\schtml\images\jj1.gif<br />
c:\Program Files\schtml\images\jj2.gif<br />
c:\Program Files\schtml\images\jj3.gif<br />
c:\Program Files\schtml\images\l1.gif<br />
c:\Program Files\schtml\images\l2.gif<br />
c:\Program Files\schtml\images\l3.gif<br />
c:\Program Files\schtml\images\pix.gif<br />
c:\Program Files\schtml\images\t1.gif<br />
c:\Program Files\schtml\images\t2.gif<br />
c:\Program Files\schtml\images\Thumbs.db<br />
c:\Program Files\schtml\images\up1.gif<br />
c:\Program Files\schtml\images\up2.gif<br />
c:\Program Files\schtml\images\w1.gif<br />
c:\Program Files\schtml\images\w11.gif<br />
c:\Program Files\schtml\images\w2.gif<br />
c:\Program Files\schtml\images\w3.gif<br />
c:\Program Files\schtml\images\w3.jpg<br />
c:\Program Files\schtml\images\word.doc<br />
c:\Program Files\schtml\images\wt1.gif<br />
c:\Program Files\schtml\images\wt2.gif<br />
c:\Program Files\schtml\images\wt3.gif<br />
c:\Program Files\Your PC Protector<br />
c:\Program Files\Your PC Protector\Your PC Protector.exe<br />
%UserProfile%\Start Menu\Programs\Your PC Protector<br />
%UserProfile%\Desktop\Your PC Protector.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Your PC Protector Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager<br />
HKEY_CURRENT_USER\Software\Your PC Protector<br />
HKEY_CLASSES_ROOT\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ADBUPD<br />
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AdbUpd<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ADBUPD<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Advanced Defender (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-advanced-defender</link>
	<pubDate>Mon, 08 Feb 2010 18:22:49 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Advanced Defender]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-advanced-defender</guid>
	<description><![CDATA[Advanced Defender is a rogue anti-spyware program from the same family as Personal Protector. This rogue is distributed through malware that will install the program onto your computer without your permission or knowledge. While being installed this program will also create fake and harmless malware files on your computer that will be detected by Advanced Defender when it scans your computer. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Advanced Defender (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Mon, 08 Feb 2010 18:22:49 EST &middot; Views: 357</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-advanced-defender', 'Remove Advanced Defender (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-advanced-defender', 'Remove Advanced Defender (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Advanced Defender</strong> is a rogue anti-spyware program from the 
  same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-personal-protector">Personal 
  Protector</a>. This rogue is distributed through malware that will install the 
  program onto your computer without your permission or knowledge. While being 
  installed this program will also create fake and harmless malware files on your 
  computer that will be detected by Advanced Defender when it scans your computer. 
  The files it creates are:</p>
<blockquote>
  <p> <font color="#0000FF">c:\WINDOWS\certofsystem.exe<br>
    c:\WINDOWS\explorers.exe<br>
    c:\WINDOWS\microsoftdefend.dll<br>
    c:\WINDOWS\regp.exe<br>
    c:\WINDOWS\secureit.com<br>
    c:\WINDOWS\spoos.exe<br>
    c:\WINDOWS\system32\winscent.exe </font></p>
</blockquote>
<p>Once installed, Advanced Defender will hide your desktop icons and then start 
  scanning your computer for infections. When done it will list a variety of infections, 
  including the fake ones above, but will not allow you to remove them until you 
  first purchase the program. Many of the infections it states, though, are legitimate 
  programs that if deleted would affect the proper operation of your computer. 
  Therefore, please do not manually delete any of the files on your computer that 
  it states are infections.</p>
<p>As a method to protect itself, Advanced Defender will terminate almost any 
  executable that you run while stating that the file is an infection. It does 
  this to stop legitimate anti-malware programs from removing it. When an executable 
  is launched it will display a message that contains the following text:</p>
<blockquote>
  <p><font color="#0000FF"><strong>Cmd.exe is infected with worm Lsas.Blaster.Keyloger. 
    This worm is trying to send your credit card details using to connect to remote 
    host.</strong></font></p>
</blockquote>
<p>Do not worry, though, your executables are not infected. This is just another 
  fake alert of the program.</p>
<p>

</p>
<p>While the program is running you will also see fake security alerts stating 
  that your computer is under attack or that malware has been detected that can 
  steal your personal information. An example of one of these alerts is:</p>
<blockquote> 
  <p><strong><font color="#0000FF">Attention! System detected a potential hazard 
    on your computer that may infect executable files. Your private information 
    and PC safety is at risk.<br>
    </font></strong><font color="#0000FF">To get rid of unwanted spyware and keep 
    your computer safe you need to update your Current security software. <br>
    Click Yes to download official intrusion detection system (IDS software)</font></p>
  </blockquote>
<p>Just like the scan results and fake infection messages, these security warnings 
  are just another trick by Advanced Defender to make you think you are infected.</p>
<p>As you can see, Advanced Defender was created for one purpose; to scare you 
  into thinking your computer has a security problem so that you will then purchase 
  the program. It goes without saying that you should not purchase this program 
  regardless of what it may state. If you have already purchased the program, 
  then please contact your credit card company and dispute the charges. Finally, 
  please use the guide below to remove this infection and any related malware 
  for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/18590/Advanced-Defender.html">Advanced Defender</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [advanceddefender] C:\Program Files\Advanced Defender\advanceddefender.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>02/08/10 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Advanced Defender using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>It is possible that the infection you are trying to remove will not allow 
    you to download files on the infected computer. If this is the case, then 
    you will need to download the files requested in this guide on another computer 
    and then transfer them to the infected computer. You can transfer the files 
    via a CD/DVD, external drive, or USB flash drive.<br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Advanced Defender
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Advanced Defender
    and other Rogue programs. Please be patient while the program looks for various 
    malware programs and ends them. When it has finished, the black window will 
    automatically close and you can continue with the next step. If you get a 
    message that rkill is an infection, do not be concerned. This message is just 
    a fake warning given by 
    Advanced Defender
    when it terminates programs that may potentially remove it. If you run into 
    these infections warnings that close Rkill, a trick is to leave the warning 
    on the screen and then run Rkill again. By not closing the warning, this typically 
    will allow you to bypass the malware trying to protect itself so that rkill 
    can terminate 
    Advanced Defender
    . So, please try running Rkill until malware is no longer running. You will 
    then be able to proceed with the rest of the guide.<strong><br>
    <br>
    Do not reboot your computer after running rkill as the malware programs will 
    start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button. If MalwareBytes' prompts you to reboot, please do not do so.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Advanced Defender
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    AdvancedDefender
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/advanced-defender/mbam-advanced-defender.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>AdvancedDefender</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=advanced-defender" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Advanced Defender Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Microsoft PData<br />
c:\Documents and Settings\All Users\Microsoft PData\track.wid<br />
%UserProfile%\Desktop\Advanced Defender.lnk<br />
%UserProfile%\Start Menu\Programs\Advanced Defender<br />
%UserProfile%\Start Menu\Programs\Advanced Defender\Advanced Defender.lnk<br />
c:\Program Files\Advanced Defender<br />
c:\Program Files\Advanced Defender\advanceddefender.exe<br />
c:\Program Files\Advanced Defender\base.wdb<br />
c:\Program Files\Advanced Defender\baseadd.wdb<br />
c:\Program Files\Advanced Defender\conf.wcf<br />
c:\Program Files\Advanced Defender\quarant.wdb<br />
c:\Program Files\Advanced Defender\q<br />
c:\WINDOWS\certofsystem.exe<br />
c:\WINDOWS\explorers.exe<br />
c:\WINDOWS\microsoftdefend.dll<br />
c:\WINDOWS\regp.exe<br />
c:\WINDOWS\secureit.com<br />
c:\WINDOWS\spoos.exe<br />
c:\WINDOWS\system32\winscent.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Advanced Defender Windows Registry Information:</span></p>
     <blockquote>
        HKEY_LOCAL_MACHINE\SOFTWARE\Advanced Defender<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Defender<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "advanceddefender"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Paladin Antivirus (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-paladin-antivirus</link>
	<pubDate>Sun, 07 Feb 2010 11:56:32 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Paladin Antivirus]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-paladin-antivirus</guid>
	<description><![CDATA[Paladin Antivirus is a rogue anti-spyware program from the same family as Malware Defense. This rogue is installed and promoted through the use of Trojans that will install it on to your computer without your permission. Once installed, it will scan through the list of programs installed on your computer, and if it finds certain legitimate anti-malware programs, will prompt you to uninstall them. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Paladin Antivirus (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Sun, 07 Feb 2010 11:56:32 EST &middot; Views: 1441</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-paladin-antivirus', 'Remove Paladin Antivirus (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-paladin-antivirus', 'Remove Paladin Antivirus (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Paladin Antivirus</strong> is a rogue anti-spyware program from the 
  same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-malware-defense">Malware 
  Defense</a>. This rogue is installed and promoted through the use of Trojans 
  that will install it on to your computer without your permission. Once installed, 
  it will scan through the list of programs installed on your computer, and if 
  it finds certain legitimate anti-malware programs, will prompt you to uninstall 
  them. Some of the programs that it will attempt to remove are:</p>
<ul>
  <li>F-Secure</li>
  <li> Malwarebytes' Anti-Malware</li>
  <li> NOD32</li>
  <li> Agnitum Outpost Security Suite</li>
  <li> Avira AntiVir</li>
  <li>avast!</li>
  <li> AntiVir</li>
  <li> AVG8</li>
  <li> Norton Internet Security</li>
</ul>
<p>When installed, Paladin Antivirus will be configured to start automatically 
  when your computer loads. Once started, it will scan your computer and detect 
  numerous infections. These infections, though, are all fake or legitimate programs 
  that should not be deleted. Therefore, please do not act upon any of the scan 
  results that this program may show.</p>
<p> 
  
</p>
<p>While Paladin Antivirus is running it will also display numerous security alerts 
  on your desktop. These alerts will state that the program you are running is 
  infected or that your computer is being attacked. Some of the messages you may 
  see are:</p>
<blockquote> 
  <p><font color="#0000FF"><strong>Network Intrusion Detected!</strong><br>
    <strong>Your computer is being attacked from a remote PC.</strong><br>
    </font><font color="#0000FF">Process is trying to steal your passwords listed 
    below. It is highly recommended to block this threat now.<br>
    You are using a trial version.<br>
    It is recommended to purchase a commercial version.</font></p>
  <p><font color="#0000FF"> <strong>Adware module detected on your PC!</strong><br>
    Zlob.Porn.Ad adware has been detected. This adware module advertises websites 
    with explicit content. Be advised of such content being possibly illegal. 
    Please click the button below to locate and remove this threat now.</font> 
  </p>
</blockquote>
<p>Just like the scan results, these security alerts are all fake and should be 
  ignored.</p>
<p>Without a doubt, Paladin Antivirus was designed to scare you into thinking 
  that you are infected so that you will then purchase the program. If you have 
  already purchased the program, then please contact your credit card company 
  and dispute the charges. Finally, please use the guide below to remove Paladin 
  Antivirus and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/18566/Paladin-Antivirus.html">Paladin Antivirus</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [Paladin Antivirus] "C:\Program Files\Paladin Antivirus\pav.exe" -noscan
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>02/07/10 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Paladin Antivirus using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>It is possible that the infection you are trying to remove will not allow 
    you to download files on the infected computer. If this is the case, then 
    you will need to download the files requested in this guide on another computer 
    and then transfer them to the infected computer. You can transfer the files 
    via a CD/DVD, external drive, or USB flash drive.<br>
    <br>
  </li>
  <li>Before we can do anything we must first end the processes that belong to 
    Paladin Antivirus
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Paladin Antivirus
    and other Rogue programs. Please be patient while the program looks for various 
    malware programs and ends them. When it has finished, the black window will 
    automatically close and you can continue with the next step. If you get a 
    message that rkill is an infection, do not be concerned. This message is just 
    a fake warning given by 
    Paladin Antivirus
    when it terminates programs that may potentially remove it. If you run into 
    these infections warnings that close Rkill, a trick is to leave the warning 
    on the screen and then run Rkill again. By not closing the warning, this typically 
    will allow you to bypass the malware trying to protect itself so that rkill 
    can terminate 
    Paladin Antivirus
    . So, please try running Rkill until malware is no longer running. You will 
    then be able to proceed with the rest of the guide.<strong><br>
    <br>
    Do not reboot your computer after running rkill as the malware programs will 
    start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button. If MalwareBytes' prompts you to reboot, please do not do so.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Paladin Antivirus
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    Paladin Antivirus
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/p/paladin-antivirus/mbam-paladin-antivirus.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Paladin Antivirus</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=paladin-antivirus" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Paladin Antivirus Files:</span></p>
     <blockquote>
        %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Paladin Antivirus.lnk<br />
%UserProfile%\Desktop\Paladin Antivirus Support.lnk<br />
%UserProfile%\Desktop\Paladin Antivirus.lnk<br />
%UserProfile%\Start Menu\Programs\Paladin Antivirus<br />
%UserProfile%\Start Menu\Programs\Paladin Antivirus\Paladin Antivirus Support.lnk<br />
%UserProfile%\Start Menu\Programs\Paladin Antivirus\Paladin Antivirus.lnk<br />
%UserProfile%\Start Menu\Programs\Paladin Antivirus\Uninstall Paladin Antivirus.lnk<br />
c:\Program Files\Paladin Antivirus<br />
c:\Program Files\Paladin Antivirus\help.ico<br />
c:\Program Files\Paladin Antivirus\pav.db<br />
c:\Program Files\Paladin Antivirus\pav.exe<br />
c:\Program Files\Paladin Antivirus\pavext.dll<br />
c:\Program Files\Paladin Antivirus\phook.dll<br />
c:\Program Files\Paladin Antivirus\uninstall.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Paladin Antivirus Windows Registry Information:</span></p>
     <blockquote>
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove SafePcAv (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-safepcav</link>
	<pubDate>Fri, 05 Feb 2010 11:31:19 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[SafePcAv]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-safepcav</guid>
	<description><![CDATA[SafePcAv is a rogue anti-spyware program from the Wini family of malware. This rogue is promoted and installed through the use of Trojans that pretend to be programs necessary to view certain online videos. When you download and install this Trojan it will install the rogue and configure it to start automatically when your computer starts. This same Trojan will also create fake malware files on your computer with random filenames that are then detected as viruses when SafePcAv scans your computer. The program, though, will state that it will not remove these files until you first purchase it. This is obviously a scam as the program is only detecting the files it created in the first place. In reality, these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove SafePcAv (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 05 Feb 2010 11:31:19 EST &middot; Views: 870</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-safepcav', 'Remove SafePcAv (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-safepcav', 'Remove SafePcAv (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>SafePcAv</strong> is a rogue anti-spyware program from the Wini 
  family of malware. This rogue is promoted and installed through the use of Trojans 
  that pretend to be programs necessary to view certain online videos. When you 
  download and install this Trojan it will install the rogue and configure it 
  to start automatically when your computer starts. This same Trojan will also 
  create fake malware files on your computer with random filenames that are then 
  detected as viruses when SafePcAv scans your computer. The program, though, 
  will state that it will not remove these files until you first purchase it. 
  This is obviously a scam as the program is only detecting the files it created 
  in the first place. In reality, these files are harmless and do not pose any 
  risk to your computer. Thus this programs scan results should be ignored.</p>
<p>Please note, the WiniSoft family of rogues have been incorporating TDL3 into 
  their installers. This is a rootkit infection that is known to redirect Google 
  search links to page thats you did not request. If you have this rogue installed 
  on your computer and your search results are being redirected in Google then 
  you may have this infection and should follow the steps in the <a href="http://www.bleepingcomputer.com/forums/topic34773.html">Preparation 
  Guide For Use Before Using HijackThis and other Malware Removal Tools</a> topic 
  in order to receive help in removing the TDL3 infection.</p>
<p>

</p>
<p>The Trojan that installed SafePcAv will also display fake security alerts 
  and messages on your desktop. These alerts will state that active malware has 
  been found, that your being attacked by a remote computer, or that you are sending 
  sensitive data to a remote location. The titles of these alerts will be Spyware 
  Alert!, Infiltration Alert!, or Security Center Alert!. The current text of 
  one of the alerts is:</p>
<blockquote>
  <p><strong><strong>German Alert:</strong><font
 color="#0000ff"><strong><br>
Spzprogramm Warnzeichen!</strong><br>
  </font></strong><font color="#0000ff">Ihr
Computer ist mit Spionprogramm infektioniert. Das kann Ihren Dateien
und die im Internet zugänglich machen. Klicken bitte hier, um Ihre
Kopie von SafePcAv zu registrieren und Ihr PC von Spyprogramm frei
zu machen.</font></p>
  <p><strong>English Alert:</strong><br>
  <font color="#0000ff"><strong>Spyware Alert!</strong><br>
Your computer is infected with spyware. It could damage your critical
files or expose your private data on the Internet. Click here to
register your copy of SafePcAv and remove spyware threats from
your PC.</font></p>
  <p><strong>French Alert:<br>
  <font color="#0000ff">Spyware Alerte!<br>
  </font></strong><font color="#0000ff">Votre
ordinateur est infecté de spyware. Il pourrait endommager vos fichiers
critiques ou exposer vos données prives sur 'Internet. Cliquez ici pour
enregistrer votre copie de SafePcAv et enléver des menaces spyware
de votre OP. </font></p>
  <p><strong>Italian Alert:<br>
  <font color="#0000ff">Spyware miniaccia!<br>
  </font></strong><font color="#0000ff">Il suo
computer è infetto di spyware. Puo dannegiare i suoi files criticali
rivelare i suoi dati personali nell'Internet. Clicca qui per registrare
la sua coppia di SafePcAv e rimouvere le minacce di spyware dal suo
computer. </font></p>
</blockquote>
<p>The Trojan will also display a fake Windows Security Center
screen that will suggest that you purchase SafePcAv to protect
yourself. SafePcAv will also hijack Internet Explorer so that it
randomly displays a security warning when you browse the web. This
security warning will state that the site you are visiting is infected
or malicious and that you should purchase SafePcAv to protect
yourself. Just like the scan results, these fake warnings and messages
should be ignored as they are just another attempt to make you think
your computer has a security problem.</p>
<p>As you can see, you should not purchase this program
regardless of what it may state. If you have already purchased the
program, then please contact your credit card company and dispute the
charges. Finally, please use the guide below to remove this infection
and any related malware for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/18462/SafePcAv.html">SafePcAv</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [SafePcAv] C:\Program Files\SafePcAv Software\SafePcAv\SafePcAv.exe -min<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>02/05/10 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for SafePcAv using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    SafePcAv
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>SafePcAv</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/s/safepcav/mbam-safepcav.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>SafePcAv</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=safepcav" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated SafePcAv Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\SafePcAv.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SafePcAv<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SafePcAv\1 SafePcAv.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SafePcAv\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\SafePcAv\3 Uninstall.lnk<br />
c:\Program Files\SafePcAv Software<br />
c:\Program Files\SafePcAv Software\SafePcAv<br />
c:\Program Files\SafePcAv Software\SafePcAv\main_config.xml<br />
c:\Program Files\SafePcAv Software\SafePcAv\SafePcAv.exe<br />
c:\Program Files\SafePcAv Software\SafePcAv\uninstall.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated SafePcAv Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\SafePcAv<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafePcAv<br />
HKEY_LOCAL_MACHINE\SOFTWARE\SafePcAv<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = "0"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SafePcAv"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>How to remove XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010</link>
	<pubDate>Wed, 03 Feb 2010 21:23:05 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010</guid>
	<description><![CDATA[Antivirus Vista 2010, Win 7 Antispyware 2010, and XP Internet Security 2010 are new rogues that are exactly the same program, but are shown with different names and interfaces depending on the version of Windows that it is run on. After I wrote this guide, I was told that this rogue goes under quite a few different names, which I have listed below:

Antivirus Vista 2010

Vista Antispyware 2010

Vista Guardian

Vista Antivirus Pro

Vista Internet Security

Vista Internet Security 2010

XP Guardian

XP Antivirus Pro

XP AntiSpyware 2010

XP Internet Security

XP Internet Security 2010

Antivirus XP 2010

Antivirus Win 7 2010

Win7 Guardian

Win 7 Antivirus Pro

Win 7 Antispyware 2010

Win 7 Internet Security

Win 7 Internet Security 2010 [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>How to remove XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 03 Feb 2010 21:23:05 EST &middot; Views: 45190</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010', 'How to remove XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010', 'How to remove XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Antivirus Vista 2010</strong>, <strong>Win 7 Antispyware 2010</strong>, 
  and <strong>XP Internet Security 2010</strong> are new rogues that are exactly 
  the same program, but are shown with different names and interfaces depending 
  on the version of Windows that it is run on. After I wrote this guide, I was 
  told that this rogue goes under quite a few different names, which I have listed 
  below:</p>
<ul>
  <li>Antivirus Vista 2010</li>
  <li> Vista Antispyware 2010</li>
  <li> Vista Guardian</li>
  <li> Vista Antivirus Pro</li>
  <li>Vista Internet Security</li>
  <li>Vista Internet Security 2010</li>
  <li> XP Guardian</li>
  <li>XP Antivirus Pro</li>
  <li>XP AntiSpyware 2010</li>
  <li>XP Internet Security</li>
  <li> XP Internet Security 2010</li>
  <li> Antivirus XP 2010</li>
<li>Antivirus Win 7 2010</li>
  <li> Win7 Guardian</li>
  <li>Win 7 Antivirus Pro</li>
  <li> Win 7 Antispyware 2010</li>
  <li>Win 7 Internet Security</li>
  <li> Win 7 Internet Security 2010</li>
</ul>
<p>When installed, this rogue pretends to be an update for Windows installed via 
  Automatic Updates. It will then install itself as a single executable called 
  AV.exe that uses very aggressive techniques to make it so that you cannot remove 
  it. First, it makes it so that if you launch any executable it instead launches 
  Antivirus Vista 2010, Win 7 Antispyware 2010, or XP Internet Security 2010. 
  If the original program that you wanted to launch is deemed safe by the rogue, 
  it will then launch it as well. This allows the rogue to determine what executables 
  it wants to allow you to run in order to protect itself. It will also modify 
  certain keys so that when you launch FireFox or Internet Explorer it will launch 
  the rogue instead and display a fake firewall warning. Last, but not least, 
  when try to browse to a web site, it will hijack your browser and state that 
  the site is a security risk and not allow you to visit it.</p>
<p>
  
</p>
<p>Once started, the rogue itself, like all other rogues, will scan your computer 
  and state that there are numerous infections on it. If you attempt to use the 
  program to remove any of these infections, though, it will state that you need 
  to purchase the program first. In reality, though, the infections that the rogues 
  states are on your computer are all legitimate files that if deleted could cause 
  Windows to not operate correctly. Therefore, please do not trust anything it 
  states are infections.</p>
<p> While running, Antivirus Vista 2010, Win 7 Antispyware 2010, and XP Internet 
  Security 2010 will also display fake security alerts on the infected computer. 
  The text of some of these alerts are:</p>
<blockquote>
  <p><font color="#0000FF"><strong>Tracking software found!</strong><br>
    Your PC activity is being monitored. Possible spyware infection. Your data 
    security may be compromised. Sensitive data can be stolen. Prevent damage 
    now by completing security scan.</font></p>
  <p><font color="#0000FF"><strong>XP Internet Security 2010 Firewall Alert!<br>
    </strong>XP Internet Security 2010 has blocked a program from accessing the 
    Internet<br>
    Internet Explorer is infected with Trojan-BNK.Win32-Keylogger.gen<br>
    Private data can be stolen by third parties, including credit card details 
    and passwords.</font></p>
</blockquote>
<p>Just like the scan results, these fake security warnings and alerts are all 
  fake and should be ignored.</p>
<p>Without a doubt, this rogue is designed to scam you out of your money by hijacking 
  your computer and trying to trick you into thinking you are infected. Therefore, 
  please do not purchase this program , and if you have, please contact your credit 
  card company and dispute the charges. Finally, to remove Antivirus Vista 2010, 
  Win 7 Antispyware 2010, and XP Internet Security 2010 please use the guide below, 
  which only contains programs that are free to use.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>01/27/10 - Initial guide creation.
01/27/10 - Updated for new rogue names.
01/28/10 - Updated for new rogue names.
02/03/10 - Updated for new rogue names.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>For the first part of this removal guide you will need to use a different 
    computer than the infected one. This is also a tricky rogue to remove, so 
    please follow the instructions carefully. If you are concerned about whether 
    or not you can do this, do not be, as I have made these instructions easy 
    to follow for people of any computer expertise.<br>
    <br>
  </li>
  <li>From another computer, please download Malwarebytes' Anti-Malware, or MBAM, 
    and the reg files from the following locations and save it to an external 
    media such as an external hard drive or a USB flash drive. We will then use 
    the external drive or flash drive to to transfer these files to your infected 
    computer. If you do not own a USB flash drive, you can get one from any local 
    or online computer store for a small price. An example of a good and cheap 
    one can be found at <a href="http://www.newegg.com/Product/Product.aspx?Item=N82E16820148153&nm_mc=AFC-Bleeping&cm_mmc=AFC-Bleeping-_-NA-_-NA-_-NA">Newegg</a>. 
    The files that you should download onto this device are:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a> - Everyone should download this<br>
    <br>
    <a href="http://download.bleepingcomputer.com/reg/antivirus-vista-2010/FixExe.reg">FixExe.reg</a> 
    - Everyone should download this<br>
    <br>
  </li>
  <br />
  <li>Once you have downloaded all the necessary files to a removable device, 
    you need to plug it into your infected your computer so it can access them.<br>
    <br>
  </li>
  <li>On the infected computer make sure XP Internet Security 2010, Antivirus 
    Vista 2010, or Win 7 Antispyware 2010 is running. If it is not, you can launch 
    it by running any program on your computer as that will trigger the rogue 
    program to run. Once running, <strong>do not close it</strong> during the 
    entire length of this guide.<br>
    <br>
  </li>
  <li>Now open the drive that corresponds to the removable media that you copied 
    the programs from step 2 onto. Once open, double-click on the <strong>FixExe.reg</strong> 
    file. When Windows prompts whether or not you want to allow the data to be 
    added to your computer, click on the <strong>Yes</strong> button.<br>
    <br>
  </li>
  <li> Now you should be able to run the <strong>mbam-setup.exe</strong> file 
    that you saved on your removable media in step 2. Double-click on this file 
    to install MalwareBytes' on to your computer. When the installation begins, 
    keep following the prompts in order to continue with the installation process. 
    Do not make any changes to default settings and when the program has finished 
    installing, make sure you leave both the <strong>Update Malwarebytes' Anti-Malware</strong> 
    and <strong> </strong><strong>Launch Malwarebytes' Anti-Malware</strong> checked. 
    Then click on the <strong>Finish</strong> button. If you already have MalwareBytes' 
    installed, simply launch it now and continue to step 8.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antivirus-vista-2010/mbam-antivirus-vista-2010.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>
  XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010
  </strong> programs. If your current anti-virus solution let this infection through, 
  you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antivirus-vista-2010" rel="nofollow">purchasing the 
  PRO version of Malwarebytes' Anti-Malware</a> to protect against these types 
  of threats in the future.</p>

  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010 Files:</span></p>
     <blockquote>
        %UserProfile%\Local Settings\Application Data\av.exe<br />
%UserProfile%\Local Settings\Application Data\WRblt8464P<br />
%UserProfile%\AppData\Local\av.exe &lt;In Antivirus Vista 2010 &amp; Win 7 Antispyware 2010&gt;<br />
%UserProfile%\AppData\Local\WRblt8464P &lt;In Antivirus Vista 2010 &amp; Win 7 Antispyware 2010&gt;<br />

     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated XP Internet Security 2010, Antivirus Vista 2010, and Win 7 Antispyware 2010 Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*<br />
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*<br />
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*<br />
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"<br />

     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove GuardWWW (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-guardwww</link>
	<pubDate>Tue, 02 Feb 2010 15:38:12 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[GuardWWW]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-guardwww</guid>
	<description><![CDATA[GuardWWW is a rogue anti-spyware program from the Wini family of malware. This rogue is promoted and installed through the use of Trojans that pretend to be programs necessary to view certain online videos. When you download and install this Trojan it will install the rogue and configure it to start automatically when your computer starts. This same Trojan will also create fake malware files on your computer with random filenames that are then detected as viruses when GuardWWW scans your computer. The program, though, will state that it will not remove these files until you first purchase it. This is obviously a scam as the program is only detecting the files it created in the first place. In reality, these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove GuardWWW (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Tue, 02 Feb 2010 15:38:12 EST &middot; Views: 1080</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-guardwww', 'Remove GuardWWW (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-guardwww', 'Remove GuardWWW (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>GuardWWW</strong> is a rogue anti-spyware program from the Wini 
  family of malware. This rogue is promoted and installed through the use of Trojans 
  that pretend to be programs necessary to view certain online videos. When you 
  download and install this Trojan it will install the rogue and configure it 
  to start automatically when your computer starts. This same Trojan will also 
  create fake malware files on your computer with random filenames that are then 
  detected as viruses when GuardWWW scans your computer. The program, though, 
  will state that it will not remove these files until you first purchase it. 
  This is obviously a scam as the program is only detecting the files it created 
  in the first place. In reality, these files are harmless and do not pose any 
  risk to your computer. Thus this programs scan results should be ignored.</p>
<p>Please note, some variants of Wini rogues have been bundling a rootkit infection 
  called TDL3. Therefore, though MalwareByte's may remove the rogue infection, 
  you may still have problems with pop-ups or redirections when you click on search 
  engine results. If this type of behavior is occurring on your computer, then 
  you may have this infection and should follow the steps in the <a href="http://www.bleepingcomputer.com/forums/topic34773.html">Preparation 
  Guide For Use Before Using HijackThis and other Malware Removal Tools</a> topic.</p>
<p>

</p>
<p>The Trojan that installed GuardWWW will also display fake security alerts 
  and messages on your desktop. These alerts will state that active malware has 
  been found, that your being attacked by a remote computer, or that you are sending 
  sensitive data to a remote location. The titles of these alerts will be Spyware 
  Alert!, Infiltration Alert!, or Security Center Alert!. The current text of 
  one of the alerts is:</p>
<blockquote>
  <p><strong><strong>German Alert:</strong><font
 color="#0000ff"><strong><br>
Spzprogramm Warnzeichen!</strong><br>
  </font></strong><font color="#0000ff">Ihr
Computer ist mit Spionprogramm infektioniert. Das kann Ihren Dateien
und die im Internet zugänglich machen. Klicken bitte hier, um Ihre
Kopie von GuardWWW zu registrieren und Ihr PC von Spyprogramm frei
zu machen.</font></p>
  <p><strong>English Alert:</strong><br>
  <font color="#0000ff"><strong>Spyware Alert!</strong><br>
Your computer is infected with spyware. It could damage your critical
files or expose your private data on the Internet. Click here to
register your copy of GuardWWW and remove spyware threats from
your PC.</font></p>
  <p><strong>French Alert:<br>
  <font color="#0000ff">Spyware Alerte!<br>
  </font></strong><font color="#0000ff">Votre
ordinateur est infecté de spyware. Il pourrait endommager vos fichiers
critiques ou exposer vos données prives sur 'Internet. Cliquez ici pour
enregistrer votre copie de GuardWWW et enléver des menaces spyware
de votre OP. </font></p>
  <p><strong>Italian Alert:<br>
  <font color="#0000ff">Spyware miniaccia!<br>
  </font></strong><font color="#0000ff">Il suo
computer è infetto di spyware. Puo dannegiare i suoi files criticali
rivelare i suoi dati personali nell'Internet. Clicca qui per registrare
la sua coppia di GuardWWW e rimouvere le minacce di spyware dal suo
computer. </font></p>
</blockquote>
<p>The Trojan will also display a fake Windows Security Center
screen that will suggest that you purchase GuardWWW to protect
yourself. GuardWWW will also hijack Internet Explorer so that it
randomly displays a security warning when you browse the web. This
security warning will state that the site you are visiting is infected
or malicious and that you should purchase GuardWWW to protect
yourself. Just like the scan results, these fake warnings and messages
should be ignored as they are just another attempt to make you think
your computer has a security problem.</p>
<p>As you can see, you should not purchase this program
regardless of what it may state. If you have already purchased the
program, then please contact your credit card company and dispute the
charges. Finally, please use the guide below to remove this infection
and any related malware for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/18461/GuardWWW.html">GuardWWW</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [GuardWWW] C:\Program Files\GuardWWW Software\GuardWWW\GuardWWW.exe -min<br />
O4 - HKCU\..\Run: [&lt;random&gt;.exe] C:\WINDOWS\system32\&lt;random&gt;.exe<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>02/02/10 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for GuardWWW using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    GuardWWW
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>GuardWWW</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/g/guardwww/mbam-guardwww.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>GuardWWW</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=guardwww" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated GuardWWW Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\GuardWWW.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\GuardWWW<br />
c:\Documents and Settings\All Users\Start Menu\Programs\GuardWWW\1 GuardWWW.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\GuardWWW\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\GuardWWW\3 Uninstall.lnk<br />
c:\Program Files\GuardWWW Software<br />
c:\Program Files\GuardWWW Software\GuardWWW<br />
c:\Program Files\GuardWWW Software\GuardWWW\GuardWWW.exe<br />
c:\Program Files\GuardWWW Software\GuardWWW\main_config.xml<br />
c:\Program Files\GuardWWW Software\GuardWWW\uninstall.exe<br />
c:\WINDOWS\10247not-5-vi9us2zd.dll<br />
c:\WINDOWS\10399zroj555.cpl<br />
c:\WINDOWS\10z7worm559.ocx<br />
c:\WINDOWS\system32\2z55vir2951.ocx<br />
c:\WINDOWS\system32\2z593spy3505.dll<br />
c:\WINDOWS\system32\2z5dow9loader222.exe<br />
c:\WINDOWS\system32\&lt;random&gt;.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated GuardWWW Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\GuardWWW<br />
HKEY_LOCAL_MACHINE\SOFTWARE\GuardWWW<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GuardWWW<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GuardWWW"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Antivirus Soft (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft</link>
	<pubDate>Tue, 02 Feb 2010 10:49:05 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Antivirus Soft]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft</guid>
	<description><![CDATA[Antivirus Soft is a rogue anti-spyware and ransomware program from the same family as Antivirus Live. These infections are installed on to your computer through the use of malware that installs the program onto your computer without your permission or knowledge. It is also common for this rogue to be installed on your computer through the use of malicious PDF files that exploit known vulnerabilities in older versions of Adobe Reader. Once installed, Antivirus Soft will be configured to start automatically when Windows starts. Once running it will scan your computer and display numerous infections, but will state it will not remove them until you purchase the program. In reality, the infected files it detects are all fake and do not actually exist on your computer. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Antivirus Soft (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Tue, 02 Feb 2010 10:49:05 EST &middot; Views: 67778</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft', 'Remove Antivirus Soft (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft', 'Remove Antivirus Soft (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Antivirus Soft</strong> is a rogue anti-spyware and ransomware program 
  from the same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-antivirus-live">Antivirus 
  Live</a>. These infections are installed on to your computer through the use 
  of malware that installs the program onto your computer without your permission 
  or knowledge. It is also common for this rogue to be installed on your computer 
  through the use of malicious PDF files that exploit known vulnerabilities in 
  older versions of Adobe Reader. Once installed, Antivirus Soft will be configured 
  to start automatically when Windows starts. Once running it will scan your computer 
  and display numerous infections, but will state it will not remove them until 
  you purchase the program. In reality, the infected files it detects are all 
  fake and do not actually exist on your computer.</p>
<p>This program also uses aggressive techniques to protect itself from being removed 
  by anti-malware programs. When the Antivirus Soft process is running it will 
  close almost any running program while falsely stating that they are infected. 
  Antivirus Soft will also change the Proxy settings in Internet Explorer so that 
  you cannot browse to any web site other than the site for Antivirus Soft so 
  that you can purchase the program. It does this so that you cannot browse the 
  web to find removal guides or download software that will help you remove the 
  infection. Using these two methods, the program essentially ransoms the normal 
  use of your computer until you purchase the program or use the guide below to 
  remove the infection.</p>
<p>
  
</p>
<p>While Antivirus Soft is running you will also see numerous security warnings 
  and alerts that try to trick you into thinking that you have a security problem 
  on your computer. An example of one of the alerts you will see is a fake Windows 
  Security Center that looks exactly like the legitimate one, but instead suggests 
  that you purchase Antivirus Soft to protect your computer. The infection will 
  also show numerous alerts that state that your computer is infected, that you 
  are sending personal data to a remote location, or a that your computer is being 
  attacked. One of the alerts will have this text:</p>
<blockquote>
  <p><font color="#0000FF"><strong>Antivirus Software Alert</strong><br>
    <strong>Infiltration Alert</strong><br>
    Your computer is being attacked by an internet virus. It could be a password-stealing 
    attack, a trojan-dropper or similar.<br>
    Threat: Win32/Nuqel.E</font></p>
</blockquote>
<p>Just like the fake scan results, these security alerts are all fake and are 
  just being shown to trick you into purchasing the program.</p>
<p>Without a doubt, Antivirus Soft was created solely to try and scam you into 
  thinking that your computer is infected in the hopes that you will then purchase 
  it. It goes without saying that you should not purchase this program, and if 
  you already have, please contact your credit card company and dispute the charges 
  stating the program is a scam. Finally, to remove this infection please use 
  the removal guide below to remove it for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/ransomware">Information on Ransomware Programs</a></li>
   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	<b>Windows XP:</b><br />
<br />
O4 - HKLM\..\Run: [&lt;random&gt;] %UserProfile%\Local Settings\Application Data\&lt;random&gt;\&lt;random&gt;sysguard.exe<br />
O4 - HKLM\..\Run: [&lt;random&gt;] %UserProfile%\Local Settings\Application Data\&lt;random&gt;\&lt;random&gt;sftav.exe<br />
<br />
<b>Windows Vista and Windows 7:</b><br />
<br />
O4 - HKCU\..\Run: [ucmnrejs] %UserProfile%\AppData\Local\&lt;random&gt;\&lt;random&gt;sysguard.exe<br />
O4 - HKCU\..\Run: [ucmnrejs] %UserProfile%\AppData\Local\&lt;random&gt;\&lt;random&gt;sftav.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>01/30/10 - Initial guide creation.
02/01/10 - Updated for new files and registry entries.
02/02/10 - Updated for new filename.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Antivirus Soft using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we may need to close every window that is 
    open later in the fix. <br>
    <br>
  </li>
  <li>It is possible that the infection you are trying to remove will not allow 
    you to download files on the infected computer. If you run into this problem 
    when following the steps in this guide you will need to download the files 
    requested in this guide on another computer and then transfer them to the 
    infected computer. You can transfer the files via a CD/DVD, external drive, 
    or USB flash drive.<br>
    <br>
  </li>
  <li>Reboot your computer into <strong>Safe Mode with Networking</strong> using 
    the instructions for your version of Windows found in the following tutorial:<br>
    <br>
    <blockquote><a href="http://www.bleepingcomputer.com/tutorials/tutorial61.html">How 
      to start Windows in Safe Mode</a></blockquote>
    <br>
    When following the steps in the above tutorial, select <strong>Safe Mode with 
    Networking</strong> rather than just Safe Mode. When the computer reboots 
    into Safe Mode with Networking make sure you login with the username you normally 
    use. When you are at your Windows desktop, please continue with the rest of 
    the steps.<br>
    <br>
  </li>
  <li>This infection changes your Internet Explorer settings to use a proxy server 
    that will not allow you to browse any pages on the Internet. Therefore, if 
    you only have Internet Explorer installed, we will first need need to fix 
    this problem so that we can download the utilities we need to remove this 
    infection. If you already have another browser installed, then you can skip 
    to <a href="#step8">step 8</a> to proceed with the removal instructions. I 
    still advise that you do all of these steps so that Internet Explorer works 
    as well.<br>
    <br>
    Please start Internet Explorer, and when the program is open, click on the 
    <strong>Tools</strong> menu and then select<strong> Internet Options</strong> 
    as shown in the image below.<br>
    <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/tools/proxy/tools-internet-options.jpg" alt="Internet Explorer Tools Menu"><br>
      <br>
      <br>
    </div>
  </li>
  <li>You should now be in the Internet Options screen as shown in the image below.<br>
    <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/tools/proxy/internet-options.jpg" alt="Internet Options screen"></div>
    <br>
    <br>
    <br>
    Now click on the <strong>Connections</strong> tab as designated by the blue 
    arrow above.<br>
    <br>
  </li>
  <li>You will now be at the Connections tab as shown by the image below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/tools/proxy/connections.jpg" alt="Internet Options connections tab"></div>
    <br>
    <br>
    <br>
    Now click on the <strong>Lan Settings</strong> button as designated by the 
    blue arrow above.<br>
    <br>
  </li>
  <li>You will now be at the Local Area Network (LAN) settings screen as shown 
    by the image below. <br>
    <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/tools/proxy/uncheck-proxy.jpg" alt="Proxy Settings screen"></div>
    <br>
    <br>
    <br>
    Under the Proxy Server section, please uncheck the checkbox labeled <strong>Use 
    a proxy server for your LAN</strong>. Then press the <strong>OK</strong> button 
    to close this screen. Then press the <strong>OK</strong> button to close the 
    Internet Options screen. Now that you have disabled the proxy server you will 
    be able to browse the web again with Internet Explorer.<br>
    <br>
  </li>
  <li><a name="step8"></a>Now we must end the processes that belong to 
    Antivirus Soft
    so that it does not interfere with the cleaning procedure. To do this, download 
    the following file to your desktop.<br>
    <br>
    <a href="http://download.bleepingcomputer.com/grinler/rkill.com">rkill.com 
    Download Link</a><br>
    <br>
    If you are unable to connect to the site to download rkill, please go back 
    and do steps 3-6 again and make sure the infection has not reenabled the proxy 
    settings. You may have to do this quite a few times before you can get the 
    rkill.com file downloaded. If you still cannot download the rkill.com program 
    on the infected computer, you should download it to a clean computer and copy 
    it to the infected one via a USB flash drive or CDROM.<br>
    <br>
  </li>
  <li>Once it is downloaded, double-click on the <strong>rkill.com</strong> in 
    order to automatically attempt to stop any processes associated with 
    Antivirus Soft
    and other Rogue programs. Please be patient while the program looks for various 
    malware programs and ends them. When it has finished, the black window will 
    automatically close and you can continue with the next step. If you get a 
    message that rkill is an infection, do not be concerned. This message is just 
    a fake warning given by 
    Antivirus Soft
    when it terminates programs that may potentially remove it. If you run into 
    these infections warnings that close Rkill, a trick is to leave the warning 
    on the screen and then run Rkill again. By not closing the warning, this typically 
    will allow you to bypass the malware trying to protect itself so that rkill 
    can terminate 
    Antivirus Soft
    . So, please try running Rkill until malware is no longer running. You will 
    then be able to proceed with the rest of the guide.<strong><br>
    <br>
    Do not reboot your computer after running rkill as the malware programs will 
    start again. </strong> <br>
    <br>
  </li>
  <li>Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following 
    location and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware 
    Download Link</a><br>
    <br>
    If you are unable to connect to the site to download Malwarebytes', please 
    go back and do steps 3-6 again and make sure the infection has not reenabled 
    the proxy settings. <br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button. If MalwareBytes' prompts you to reboot, please do not do so.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Antivirus Soft
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong> 
    Antivirus Soft
    </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different 
    than what is shown in the image.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antivirus-soft/mbam-antivirus-soft.png" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong> 
  Antivirus Soft
  </strong> program. You may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antivirus-soft" rel="nofollow">purchasing 
  the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types 
  of threats in the future, as if you had the real-time protection component, 
  that comes with the paid for version, activated it would not have allowed this 
  infection to install.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Antivirus Soft Files:</span></p>
     <blockquote>
        <b>Windows XP:</b><br />
<br />
%UserProfile%\Local Settings\Application Data\&lt;random&gt;\<br />
%UserProfile%\Local Settings\Application Data\&lt;random&gt;\&lt;random&gt;sysguard.exe<br />
%UserProfile%\Local Settings\Application Data\&lt;random&gt;\&lt;random&gt;sftav.exe<br />
<br />
<b>Windows Vista and Windows 7:</b><br />
<br />
%UserProfile%\AppData\Local\&lt;random&gt;\<br />
%UserProfile%\AppData\Local\&lt;random&gt;\&lt;random&gt;sysguard.exe<br />
%UserProfile%\AppData\Local\&lt;random&gt;\&lt;random&gt;sftav.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Antivirus Soft Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;" <br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"<br />
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""<br />
HKEY_CURRENT_USER\Software\avsoft
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Antimalware Defender (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antimalware-defender</link>
	<pubDate>Sun, 31 Jan 2010 20:57:29 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Antimalware Defender]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antimalware-defender</guid>
	<description><![CDATA[Antimalware Defender is a rogue anti-spyware program that is installed through the use of Trojans that pretend to be security updates for Windows. When this Trojan is executed it will show a window that looks like legitimate Windows update, but is instead the installer for the Antimalware Defender rogue. The text of this installer states the following:

Antimalware security update for Windows XP (KB961118)
Size: 433KB
This critical update will install System Security Update 2010.01.023 (Antimalware Defender Upgrade; KB648759)



It will then prompt you to install the so-called update. Once installed, it will launch Antimalware Defender, which will perform a scan of your computer. When it has finished it will state that your computer is infected with a variety of malware. If you attempt to remove these infections, though, it will state that you must first purchase it before it will allow you to do so. This is a scam because the infections it displays are either legitimate programs or do not exist at all on your computer. Therefore, please do not manually delete any of the files it shows or purchase this program thinking that it will help you. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Antimalware Defender (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Sun, 31 Jan 2010 20:57:29 EST &middot; Views: 2083</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antimalware-defender', 'Remove Antimalware Defender (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antimalware-defender', 'Remove Antimalware Defender (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Antimalware Defender </strong> is a rogue anti-spyware program that 
  is installed through the use of Trojans that pretend to be security updates 
  for Windows. When this Trojan is executed it will show a window that looks like 
  legitimate Windows update, but is instead the installer for the Antimalware 
  Defender rogue. The text of this installer states the following:</p>
<blockquote> 
  <p><strong><font color="#0000FF">Antimalware security update for Windows XP 
    (KB961118)</font></strong><font color="#0000FF"><br>
    Size: 433KB<br>
    This critical update will install System Security Update 2010.01.023 (Antimalware 
    Defender Upgrade; KB648759)</font></p>
</blockquote>
<p>It will then prompt you to install the so-called update. Once installed, it 
  will launch Antimalware Defender, which will perform a scan of your computer. 
  When it has finished it will state that your computer is infected with a variety 
  of malware. If you attempt to remove these infections, though, it will state 
  that you must first purchase it before it will allow you to do so. This is a 
  scam because the infections it displays are either legitimate programs or do 
  not exist at all on your computer. Therefore, please do not manually delete 
  any of the files it shows or purchase this program thinking that it will help 
  you.</p>
<p> 
  
</p>
<p>If you have been infected with Antimalware Defender, then please do not purchase 
  it. If you have already purchased it then we suggest you contact your credit 
  card company and dispute the charges stating that it is a scam. Finally, to 
  remove Antimalware Defender please use the removal guide below to remove it 
  for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: {ca84c702-c758-4421-974e-b02662e76d7c} - {ca84c702-c758-4421-974e-b02662e76d7c} - C:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.avi<br />
O4 - HKLM\..\Run: [ca84c702-c758-4421-974e-b02662e76d7c_6] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.avi", start minimized<br />
O4 - HKCU\..\Run: [ca84c702-c758-4421-974e-b02662e76d7c_6] "C:\WINDOWS\system32\rundll32.exe" "%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi", start minimized<br />
O4 - Startup: ca84c702-c758-4421-974e-b02662e76d7c_6.lnk = C:\WINDOWS\system32\rundll32.exe<br />
O4 - Global Startup: ca84c702-c758-4421-974e-b02662e76d7c_6.lnk = C:\WINDOWS\system32\rundll32.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>01/31/10 - Initial guide creation.
</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Antimalware Defender using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    Antimalware Defender
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Antimalware Defender</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antimalware-defender/mbam-antimalware-defender.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Antimalware Defender</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antimalware-defender" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Antimalware Defender Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi<br />
c:\Documents and Settings\All Users\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico<br />
c:\Documents and Settings\All Users\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antimalware Defender<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Antimalware Defender\Antimalware Defender.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Startup\ca84c702-c758-4421-974e-b02662e76d7c_6.lnk<br />
c:\Program Files\Antimalware Defender<br />
c:\Program Files\Antimalware Defender\Antimalware Defender.dll<br />
c:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.avi<br />
c:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.ico<br />
%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi<br />
%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico<br />
%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Defender.lnk<br />
%UserProfile%\Desktop\Antimalware Defender.lnk<br />
%UserProfile%\Local Settings\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi<br />
%UserProfile%\Local Settings\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico<br />
%UserProfile%\Local Settings\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv<br />
%UserProfile%\Start Menu\Programs\Antimalware Defender<br />
%UserProfile%\Start Menu\Programs\Antimalware Defender\Antimalware Defender.lnk<br />
%UserProfile%\Start Menu\Programs\Startup\ca84c702-c758-4421-974e-b02662e76d7c_6.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Antimalware Defender Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\CLSID\{ca84c702-c758-4421-974e-b02662e76d7c}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ca84c702-c758-4421-974e-b02662e76d7c}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ca84c702-c758-4421-974e-b02662e76d7c_6"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove MyPcSecure (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-mypcsecure</link>
	<pubDate>Fri, 29 Jan 2010 16:53:09 EST</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[MyPcSecure]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-mypcsecure</guid>
	<description><![CDATA[MyPcSecure is a rogue anti-spyware program from the Wini family of malware. This rogue is promoted and installed through the use of Trojans that pretend to be programs necessary to view certain online videos. When you download and install this Trojan it will install the rogue and configure it to start automatically when your computer starts. This same Trojan will also create fake malware files on your computer with random filenames that are then detected as viruses when MyPcSecure scans your computer. The program, though, will state that it will not remove these files until you first purchase it. This is obviously a scam as the program is only detecting the files it created in the first place. In reality, these files are harmless and do not pose any risk to your computer. Thus this programs scan results should be ignored. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove MyPcSecure (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 29 Jan 2010 16:53:09 EST &middot; Views: 1280</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-mypcsecure', 'Remove MyPcSecure (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-mypcsecure', 'Remove MyPcSecure (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>MyPcSecure</strong> is a rogue anti-spyware program from the Wini 
  family of malware. This rogue is promoted and installed through the use of Trojans 
  that pretend to be programs necessary to view certain online videos. When you 
  download and install this Trojan it will install the rogue and configure it 
  to start automatically when your computer starts. This same Trojan will also 
  create fake malware files on your computer with random filenames that are then 
  detected as viruses when MyPcSecure scans your computer. The program, though, 
  will state that it will not remove these files until you first purchase it. 
  This is obviously a scam as the program is only detecting the files it created 
  in the first place. In reality, these files are harmless and do not pose any 
  risk to your computer. Thus this programs scan results should be ignored.</p>
<p>Please note, some variants of Wini rogues have been bundling a rootkit infection 
  called TDL3. Therefore, though MalwareByte's may remove the rogue infection, 
  you may still have problems with pop-ups or redirections when you click on search 
  engine results. If this type of behavior is occurring on your computer, then 
  you may have this infection and should follow the steps in the <a href="http://www.bleepingcomputer.com/forums/topic34773.html">Preparation 
  Guide For Use Before Using HijackThis and other Malware Removal Tools</a> topic.</p>
<p>

</p>
<p>The Trojan that installed MyPcSecure will also display fake security alerts 
  and messages on your desktop. These alerts will state that active malware has 
  been found, that your being attacked by a remote computer, or that you are sending 
  sensitive data to a remote location. The titles of these alerts will be Spyware 
  Alert!, Infiltration Alert!, or Security Center Alert!. The current text of 
  one of the alerts is:</p>
<blockquote>
  <p><strong><strong>German Alert:</strong><font
 color="#0000ff"><strong><br>
Spzprogramm Warnzeichen!</strong><br>
  </font></strong><font color="#0000ff">Ihr
Computer ist mit Spionprogramm infektioniert. Das kann Ihren Dateien
und die im Internet zugänglich machen. Klicken bitte hier, um Ihre
Kopie von MyPcSecure zu registrieren und Ihr PC von Spyprogramm frei
zu machen.</font></p>
  <p><strong>English Alert:</strong><br>
  <font color="#0000ff"><strong>Spyware Alert!</strong><br>
Your computer is infected with spyware. It could damage your critical
files or expose your private data on the Internet. Click here to
register your copy of MyPcSecure and remove spyware threats from
your PC.</font></p>
  <p><strong>French Alert:<br>
  <font color="#0000ff">Spyware Alerte!<br>
  </font></strong><font color="#0000ff">Votre
ordinateur est infecté de spyware. Il pourrait endommager vos fichiers
critiques ou exposer vos données prives sur 'Internet. Cliquez ici pour
enregistrer votre copie de MyPcSecure et enléver des menaces spyware
de votre OP. </font></p>
  <p><strong>Italian Alert:<br>
  <font color="#0000ff">Spyware miniaccia!<br>
  </font></strong><font color="#0000ff">Il suo
computer è infetto di spyware. Puo dannegiare i suoi files criticali
rivelare i suoi dati personali nell'Internet. Clicca qui per registrare
la sua coppia di MyPcSecure e rimouvere le minacce di spyware dal suo
computer. </font></p>
</blockquote>
<p>The Trojan will also display a fake Windows Security Center
screen that will suggest that you purchase MyPcSecure to protect
yourself. MyPcSecure will also hijack Internet Explorer so that it
randomly displays a security warning when you browse the web. This
security warning will state that the site you are visiting is infected
or malicious and that you should purchase MyPcSecure to protect
yourself. Just like the scan results, these fake warnings and messages
should be ignored as they are just another attempt to make you think
your computer has a security problem.</p>
<p>As you can see, you should not purchase this program
regardless of what it may state. If you have already purchased the
program, then please contact your credit card company and dispute the
charges. Finally, please use the guide below to remove this infection
and any related malware for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/18453/MyPcSecure.html">MyPcSecure</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [MyPcSecure] C:\Program Files\MyPcSecure Software\MyPcSecure\MyPcSecure.exe -min
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>01/29/10 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for MyPcSecure using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    full scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong> 
    MyPcSecure
    </strong> related files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>MyPcSecure</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/m/mypcsecure/mbam-mypcsecure.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>MyPcSecure</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=mypcsecure" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated MyPcSecure Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\MyPcSecure.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\MyPcSecure<br />
c:\Documents and Settings\All Users\Start Menu\Programs\MyPcSecure\1 MyPcSecure.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\MyPcSecure\2 Homepage.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\MyPcSecure\3 Uninstall.lnk<br />
c:\Program Files\MyPcSecure Software<br />
c:\Program Files\MyPcSecure Software\MyPcSecure<br />
c:\Program Files\MyPcSecure Software\MyPcSecure\main_config.xml<br />
c:\Program Files\MyPcSecure Software\MyPcSecure\MyPcSecure.exe<br />
c:\Program Files\MyPcSecure Software\MyPcSecure\uninstall.exe<br />
c:\WINDOWS\100239ormz1e5.cpl<br />
c:\WINDOWS\102295roj72z.ocx<br />
c:\WINDOWS\1054stzal5419.bin<br />
c:\WINDOWS\system32\159ztroj5b.dll<br />
c:\WINDOWS\system32\15z2not-a-vir59659.exe<br />
c:\WINDOWS\system32\15zasp5rse2999.ocx
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated MyPcSecure Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\MyPcSecure<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPcSecure<br />
HKEY_LOCAL_MACHINE\SOFTWARE\MyPcSecure<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "MyPcSecure"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

</channel>
</rss>