<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/" 
	xmlns:wfw="http://wellformedweb.org/CommentAPI/" 
	xmlns:dc="http://purl.org/dc/elements/1.1/" 
	xmlns:atom="http://www.w3.org/2005/Atom" 
	>

<channel>
	<title>Virus, Spyware, and Malware Removal Guides</title>

	<link>http://www.bleepingcomputer.com/virus-removal/</link>
	<description>The latest information about current virus, spyware, and malware threats to your computer.  Use these guides and tutorials to remove or uninstall various malware and infections from your comptuer. All removal instructions are free to use and do not cost any money to remove any of the malware listed in these guides. The content in this RSS feed is to be used by news aggregators and informational purposes.  It is not to be used to add as content on a web site.</description>
	<pubDate>Thu, 02 Jul 2009 23:30:37 EDT</pubDate>
	<generator>http://www.bleepingcomputer.com/</generator>
	<language>en</language>

 <item>
	<title>Remove AntivirusBest (Removal Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antivirusbest</link>
	<pubDate>Sun, 28 Jun 2009 23:34:12 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[AntivirusBest]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antivirusbest</guid>
	<description><![CDATA[AntivirusBest is a rogue anti-spyware program from the same family as Anti-Virus-1 and Anti-Virus Number 1. This program uses deceptive scan results and fake security warnings in order to convince you that you are infected. When AntivirusBest is installed on your computer it will be configured to start automatically. Once running the program will scan your computer and then show numerous infections that it states will not be removed unless you purchase the program. These infections, though, are all fake and do not exist anywhere on your computer and are only being shown to scam you into purchasing the program. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove AntivirusBest (Removal Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Sun, 28 Jun 2009 23:34:12 EDT &middot; Views: 470</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirusbest', 'Remove AntivirusBest (Removal Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirusbest', 'Remove AntivirusBest (Removal Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>AntivirusBest </strong> is a rogue anti-spyware program from the same 
  family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-unvirex">Anti-Virus-1</a> 
  and <a href="http://www.bleepingcomputer.com/virus-removal/remove-anti-virus-number-1">Anti-Virus 
  Number 1</a>. This program uses deceptive scan results and fake security warnings 
  in order to convince you that you are infected. When AntivirusBest is installed 
  on your computer it will be configured to start automatically. Once running 
  the program will scan your computer and then show numerous infections that it 
  states will not be removed unless you purchase the program. These infections, 
  though, are all fake and do not exist anywhere on your computer and are only 
  being shown to scam you into purchasing the program.</p>
<p> 
  
</p>
<p>While AntivirusBest is running you will see numerous pop-ups and alerts stating 
  that your computer is under attack. Some of the alerts you may see are:</p>
<blockquote>
  <p><font color="#0000FF">AntivirusBEST protection has detected Spyware program 
    Win32.Monster.fx that is trying to attack your computer.<br>
    Do you want to block the attack?</font></p>
  <p><font color="#0000FF"><strong>System files modification alert!</strong><br>
    Some critical files of your computer were modified by malicious programs. 
    It may cause system instability and data loss. Click here to block unauthorised 
    </font>&lt;sic&gt; <font color="#0000FF">modifications by removing threats.</font></p>
  <p><font color="#0000FF"><strong>Spyware activity alert!</strong><br>
    Spyware.IEMonster activity detected. It is spyware that attempts to steal 
    passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs, 
    including logins and passwords from online banking sessions, eBay, Paypal.</font></p>
  </blockquote>
<p>If you then click on any of these alerts you will be prompted to purchase AntivirusBest 
  in order to protect yourself. </p>
<p>AntivirusBest also utilizes numerous other tactics to scare you into thinking 
  there are infections on your computer. These include:</p>
<ul>
  <li>At random intervals a fake screen saver will appear that pretends to be 
    a Blue Screen of Death, or Windows crash. This screen will state that your 
    computer crashed because an malware called Malware.Monster.DX has infected 
    your computer. It will then pretend to reboot your computer, and while rebooting, 
    show a fake Windows boot up screen that recommends you purchase AntivirusBest. 
    <br>
    <br>
  </li>
  <li>A window that impersonates the Windows Security Center. This screen will 
    state that Security Center recommends that you register the program.<br>
    <br>
  </li>
  <li> An Internet Explorer hijack that displays a warnings whenever you visit 
    a web site. This warning states that Internet Explorer has detected that AntivirusBest 
    is not registered and that you should do so.<br>
    <br>
  </li>
  <li>Last, but not least, AntivirusBest will modify your Windows HOSTS file and 
    then randomly open fake review pages that appear to be from legitimate sites. 
    These fake review sites are from well-known companies such as PC Magazine, 
    CNET, ZDNet, Reevo, and Download.com.</li>
</ul>
<p>As you can see AntivirusBest is a program to avoid as it was created for one 
  purpose; to steal your money. If you find that you are infected with this program, 
  please do not purchase it, and instead use the free guide below to remove AntivirusBest 
  and any related malware.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O1 - Hosts: 70.38.19.201 www.review.2009softwarereviews.com<br />
O1 - Hosts: 70.38.19.201 review.2009softwarereviews.com<br />
O1 - Hosts: 70.38.19.201 a1.review.zdnet.com<br />
O1 - Hosts: 70.38.19.201 www.d1.reviews.cnet.com<br />
O1 - Hosts: 70.38.19.201 www.reviews.toptenreviews.com<br />
O1 - Hosts: 70.38.19.201 reviews.toptenreviews.com<br />
O1 - Hosts: 70.38.19.201 www.reviews.download.com<br />
O1 - Hosts: 70.38.19.201 reviews.download.com<br />
O1 - Hosts: 70.38.19.201 www.reviews.pcadvisor.c.uk<br />
O1 - Hosts: 70.38.19.201 reviews.pcadvisor.co.uk<br />
O1 - Hosts: 70.38.19.201 www.reviews.pcmag.com<br />
O1 - Hosts: 70.38.19.201 reviews.pcmag.com<br />
O1 - Hosts: 70.38.19.201 www.reviews.pcpro.co.uk<br />
O1 - Hosts: 70.38.19.201 reviews.pcpro.co.uk<br />
O1 - Hosts: 70.38.19.201 www.reviews.reevoo.com<br />
O1 - Hosts: 70.38.19.201 reviews.reevoo.com<br />
O1 - Hosts: 70.38.19.201 www.reviews.riverstreams.co.uk<br />
O1 - Hosts: 70.38.19.201 reviews.riverstreams.co.uk<br />
O1 - Hosts: 70.38.19.201 www.reviews.techradar.com<br />
O1 - Hosts: 70.38.19.201 reviews.techradar.com<br />
O1 - Hosts: 70.38.19.201 d1.reviews.cnet.com<br />
O2 - BHO: QWProtectBHO - {44B2C9F5-608D-46de-82E1-26C5BCB85193} - C:\Documents and Settings\All Users\Application Data\AB\QWProtect.dll<br />
O4 - HKLM\..\Run: [AntivirusBEST] C:\Documents and Settings\All Users\Application Data\AB\Installer.exe<br />
O4 - HKLM\..\Run: [AntivirusBEST] C:\Documents and Settings\All Users\Application Data\AB\abest.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/28/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for AntivirusBest using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>AntivirusBest</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>AntivirusBest</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antivirusbest/mbam-antivirusbest.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>AntivirusBest</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antivirusbest" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated AntivirusBest Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Application Data\AB<br />
c:\Documents and Settings\All Users\Application Data\AB\ABEST.CAB<br />
c:\Documents and Settings\All Users\Application Data\AB\abest.exe<br />
c:\Documents and Settings\All Users\Application Data\AB\Installer.exe<br />
c:\Documents and Settings\All Users\Application Data\AB\QWProtect.dll<br />
c:\Documents and Settings\All Users\Application Data\AB\svchost.exe<br />
c:\Documents and Settings\All Users\Desktop\AntivirusBEST.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntivirusBEST<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntivirusBEST\AntivirusBEST.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\AntivirusBEST\Uninstall.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated AntivirusBest Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\ABEST\ABEST<br />
HKEY_CLASSES_ROOT\AppID\{296A8A7F-B5AC-4789-9B33-F32C2F9A6ABD}<br />
HKEY_CLASSES_ROOT\AppID\QWProtect.DLL<br />
HKEY_CLASSES_ROOT\CLSID\{44B2C9F5-608D-46de-82E1-26C5BCB85193}<br />
HKEY_CLASSES_ROOT\Interface\{296A8A7F-B5AC-4789-9B33-F32C2F9A6ABD}<br />
HKEY_CLASSES_ROOT\QWProtect.QWProtectBHO<br />
HKEY_CLASSES_ROOT\QWProtect.QWProtectBHO.1<br />
HKEY_CLASSES_ROOT\TypeLib\{684A7904-2593-4BBE-A90E-CDAF2AC606AE}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44B2C9F5-608D-46de-82E1-26C5BCB85193}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AntivirusBEST"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Contraviro (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-contraviro</link>
	<pubDate>Sat, 20 Jun 2009 10:47:37 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Contraviro]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-contraviro</guid>
	<description><![CDATA[Contraviro is a rogue anti-spyware program from the same family as Unvirex. Contraviro uses aggressive and false certifications in order to promote their product as well as exaggerated and false scan results to convince you that your computer has a security risk. When installed, Contraviro will be configured to start automatically when you log into Windows. Once running, it will scan your computer and list hundreds of supposed security risks on your computer. These risks, though, are legitimate Microsoft programs and should not be deleted as it would cause Windows to not operate properly. If you attempt to remove these supposed infections with Contraviro it will then prompt you to purchase the program. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Contraviro (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Sat, 20 Jun 2009 10:47:37 EDT &middot; Views: 1144</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-contraviro', 'Remove Contraviro (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-contraviro', 'Remove Contraviro (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Contraviro </strong> is a rogue anti-spyware program from the same 
  family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-unvirex">Unvirex</a><a href="http://www.bleepingcomputer.com/virus-removal/remove-virus-shield-2009"></a>. 
  Contraviro uses aggressive and false certifications in order to promote their 
  product as well as exaggerated and false scan results to convince you that your 
  computer has a security risk. When installed, Contraviro will be configured 
  to start automatically when you log into Windows. Once running, it will scan 
  your computer and list hundreds of supposed security risks on your computer. 
  These risks, though, are legitimate Microsoft programs and should not be deleted 
  as it would cause Windows to not operate properly. If you attempt to remove 
  these supposed infections with Contraviro it will then prompt you to purchase 
  the program.</p>
<p> 
  
</p>
<p></p>
<p>Contraviro will also install a special networking DLL called a a <a href="http://www.bleepingcomputer.com/tutorials/tutorial59.html">Layered 
  Service Provider</a>, or LSP, on to your computer. These types of programs are 
  used to monitor network traffic that flows through your computer in order to 
  detect certain information and then act upon it. For example, an anti-malware 
  program may use an LSP to listen for known sites that would infect your computer 
  and then block access to it when it detects you are trying to connect to it. 
  The problem with an LSP, though, is that if you delete the file improperly it 
  will cause your computer to no longer have any network connectivity. Therefore 
  when removing Contraviro it is important that you remove it properly, such as 
  using this guide, rather than just manually deleting the associated files. With 
  this said, if you are infected with the Contraviro rogue anti-spyware program 
  then please use the removal guide below to remove it for free.</p>
<p>&nbsp;</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/16444/Contraviro.html">Contraviro</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: StatusBarPane - {CCB5551D-8594-4999-85F9-1E3EABCB95AC} - C:\Program Files\Contraviro\IEAddon.dll<br />
O4 - HKLM\..\Run: [Contraviro] C:\Program Files\Contraviro\Contraviro.exe<br />
O10 - Unknown file in Winsock LSP: c:\program files\contraviro\siglsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files\contraviro\siglsp.dll
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/20/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Contraviro using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Contraviro</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Contraviro</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Contraviro</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=contraviro" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Contraviro Files:</span></p>
     <blockquote>
        c:\Program Files\Contraviro<br />
c:\Program Files\Contraviro\Contraviro.exe<br />
c:\Program Files\Contraviro\daily.cvd<br />
c:\Program Files\Contraviro\Drvfltip.sys<br />
c:\Program Files\Contraviro\hjengine.dll<br />
c:\Program Files\Contraviro\IEAddon.dll<br />
c:\Program Files\Contraviro\main.cvd<br />
c:\Program Files\Contraviro\MFC71.dll<br />
c:\Program Files\Contraviro\MFC71ENU.DLL<br />
c:\Program Files\Contraviro\msvcp71.dll<br />
c:\Program Files\Contraviro\msvcr71.dll<br />
c:\Program Files\Contraviro\pthreadVC2.dll<br />
c:\Program Files\Contraviro\shellext.dll<br />
c:\Program Files\Contraviro\siglsp.dll<br />
c:\Program Files\Contraviro\uninstall.exe<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro<br />
c:\Documents and Settings\All Users\Desktop\Contraviro.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro\Contraviro.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro\How to Register Contraviro.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro\Register Contraviro.lnk<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Contraviro.lnk
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Contraviro Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\antivirus_contextscan<br />
HKEY_CLASSES_ROOT\AppID\{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}<br />
HKEY_CLASSES_ROOT\AppID\IEAddon.DLL<br />
HKEY_CLASSES_ROOT\CLSID\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}<br />
HKEY_CLASSES_ROOT\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}<br />
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\antivirus_contextscan<br />
HKEY_CLASSES_ROOT\Drives\shellex\ContextMenuHandlers\antivirus_contextscan<br />
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\antivirus_contextscan<br />
HKEY_CLASSES_ROOT\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}<br />
HKEY_CLASSES_ROOT\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Contraviro<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Contraviro<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "Contraviro"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Contraviro"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Malware Destructor 2009 (Removal Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-malware-destructor-2009</link>
	<pubDate>Wed, 17 Jun 2009 20:53:15 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Malware Destructor 2009]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-malware-destructor-2009</guid>
	<description><![CDATA[Malware Destructor 2009 is a rogue anti-spyware program from the same family as Malware Catcher 2009 and Virus Shield 2009. This program uses Trojans and deceptive advertising as a way of promoting itself. This rogue will also hijack your Internet Explorer's default search to point to plexfind.com. When installed, Malware Destructor 2009 will create the following files that pretend to be malware ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Malware Destructor 2009 (Removal Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 17 Jun 2009 20:53:15 EDT &middot; Views: 1628</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-malware-destructor-2009', 'Remove Malware Destructor 2009 (Removal Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-malware-destructor-2009', 'Remove Malware Destructor 2009 (Removal Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Malware Destructor 2009 </strong> is a rogue anti-spyware program from 
  the same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-malware-catcher-2009">Malware 
  Catcher 2009</a> and <a href="http://www.bleepingcomputer.com/virus-removal/remove-virus-shield-2009">Virus 
  Shield 2009</a>. This program uses Trojans and deceptive advertising as a way 
  of promoting itself. This rogue will also hijack your Internet Explorer's default 
  search to point to plexfind.com. When installed, Malware Destructor 2009 will 
  create the following files that pretend to be malware:</p>
<blockquote> 
  <p>%UserProfile%\Recent\ANTIGEN.exe<br>
    %UserProfile%\Recent\ANTIGEN.sys<br>
    %UserProfile%\Recent\cb.drv<br>
    %UserProfile%\Recent\energy.exe<br>
    %UserProfile%\Recent\energy.tmp<br>
    %UserProfile%\Recent\FS.sys<br>
    %UserProfile%\Recent\FS.tmp<br>
    %UserProfile%\Recent\FW.dll<br>
    %UserProfile%\Recent\hymt.exe<br>
    %UserProfile%\Recent\kernel32.drv<br>
    %UserProfile%\Recent\PE.dll<br>
    %UserProfile%\Recent\PE.tmp<br>
    %UserProfile%\Recent\tempdoc.exe<br>
    %UserProfile%\Recent\tjd.tmp</p>
</blockquote>
<p>These files are created so that when Malware Destructor 2009 scans your computer 
  it will detect them as infections. The files, though, are actually completely 
  harmless and have no way of harming your computer. While Malware Destructor 
  is running you will also constantly be shown fake security alerts on your computer. 
  These alerts state that the following behavior is occurring on your computer:</p>
<ul>
  <li>A program is trying to connect to the Internet</li>
  <li>A Trojan was found.</li>
  <li>A keylogger was found.</li>
  <li>A computer was remotely connected to.</li>
  <li>Your computer is infected with SpamBot and is sending out spam.</li>
</ul>
<p>When you click on any of these alerts you will then be prompted to purchase 
  Malware Destructor 2009. These alerts are all fake and are only being shown 
  to convince you that you are infected.</p>
<p> 
  
</p>
<p></p>
<p>If you find that you are infected with this program, please do not purchase 
  it. Instead use the removal guide below to remove this program for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O1 - Hosts: 74.125.45.100 test1111.com<br />
O1 - Hosts: 74.125.45.100 test1112.com<br />
O1 - Hosts: 74.125.45.100 4-open-davinci.com<br />
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com<br />
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com<br />
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com<br />
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com<br />
O1 - Hosts: 74.125.45.100 secure-plus-payments.com<br />
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com<br />
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com<br />
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com<br />
O4 - HKCU\..\Run: [Malware Destructor 2009] "C:\Documents and Settings\All Users\Application Data\345d567\MD345d.exe" /s /d
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/17/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Malware Destructor 2009 using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Malware Destructor 2009</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Malware Destructor 2009</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/m/malware-destructor-2009/mbam-malware-destructor.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Malware Destructor 2009</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=malware-destructor" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Malware Destructor 2009 Files:</span></p>
     <blockquote>
        %UserProfile%\Application Data\Malware Destructor 2009<br />
%UserProfile%\Application Data\Malware Destructor 2009\cookies.sqlite<br />
%UserProfile%\Application Data\Malware Destructor 2009\Instructions.ini<br />
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Destructor 2009.lnk<br />
%UserProfile%\Desktop\Malware Destructor 2009.lnk<br />
%UserProfile%\Local Settings\Temp\del.bat<br />
%UserProfile%\Recent\ANTIGEN.exe<br />
%UserProfile%\Recent\ANTIGEN.sys<br />
%UserProfile%\Recent\cb.drv<br />
%UserProfile%\Recent\energy.exe<br />
%UserProfile%\Recent\energy.tmp<br />
%UserProfile%\Recent\FS.sys<br />
%UserProfile%\Recent\FS.tmp<br />
%UserProfile%\Recent\FW.dll<br />
%UserProfile%\Recent\hymt.exe<br />
%UserProfile%\Recent\kernel32.drv<br />
%UserProfile%\Recent\PE.dll<br />
%UserProfile%\Recent\PE.tmp<br />
%UserProfile%\Recent\tempdoc.exe<br />
%UserProfile%\Recent\tjd.tmp<br />
%UserProfile%\Start Menu\Malware Destructor 2009.lnk<br />
%UserProfile%\Start Menu\Programs\Malware Destructor 2009.lnk<br />
c:\Documents and Settings\All Users\Application Data\345d567<br />
c:\Documents and Settings\All Users\Application Data\345d567\384.mof<br />
c:\Documents and Settings\All Users\Application Data\345d567\MD345d.exe<br />
c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll<br />
c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll<br />
c:\Documents and Settings\All Users\Application Data\345d567\MDestrSys<br />
c:\Documents and Settings\All Users\Application Data\345d567\MDestrSys\vd952342.bd<br />
c:\Documents and Settings\All Users\Application Data\MDestrSys<br />
c:\Documents and Settings\All Users\Application Data\MDestrSys\mdestr.cfg<br />
c:\WINDOWS\Temp\IMT7.xml<br />
c:\WINDOWS\Temp\IMT8.xml<br />
c:\WINDOWS\Temp\IMT9.xml
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Malware Destructor 2009 Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
HKEY_CLASSES_ROOT\MD345d.DocHostUIHandler<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft<br />
Numerous entries underHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Virus Remover Professional  (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-virus-remover-professional</link>
	<pubDate>Wed, 17 Jun 2009 18:53:01 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Virus Remover Professional ]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-virus-remover-professional</guid>
	<description><![CDATA[Virus Remover Professional is a rogue anti-spyware program from the same family as AV AntiSpyware and P Antispyware 09. This program is advertised through the use of Trojans that display fake security alerts from your Windows taskbar. If you click on these alerts, you will be brought to a web site prompting you to download and install Virus Remover Professional in order to protect your computer. On this web site you will also see numerous fake awards and accolades attributed to this program. Research has shown that none of these awards are legitimate. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Virus Remover Professional  (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 17 Jun 2009 18:53:01 EDT &middot; Views: 1102</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-virus-remover-professional', 'Remove Virus Remover Professional  (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-virus-remover-professional', 'Remove Virus Remover Professional  (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Virus Remover Professional</strong> is a rogue anti-spyware program 
  from the same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-av-antispyware">AV 
  AntiSpyware</a> and <a href="http://www.bleepingcomputer.com/virus-removal/remove-p-antispyware-09">P 
  Antispyware 09</a>. This program is advertised through the use of Trojans that 
  display fake security alerts from your Windows taskbar. If you click on these 
  alerts, you will be brought to a web site prompting you to download and install 
  Virus Remover Professional in order to protect your computer. On this web site 
  you will also see numerous fake awards and accolades attributed to this program. 
  Research has shown that none of these awards are legitimate.</p>
<p>
  
</p>
<p></p>
<p>When Virus Remover Professional is installed on your computer it will be configured 
  to start automatically when Windows starts. Once started, it will scan your 
  computer and display a list of infections on your computer that it will not 
  remove until you purchase the program. These results, though, are all fake and 
  the files it states are infections are either legitimate files or files that 
  do not exist on your computer. It displays these results in order to scare you 
  into thinking you are infected in the hopes that you will buy the software. 
  While running the program will also display security alerts and nag screens 
  stating that your computer is infected or has a problem and that you should 
  purchase Virus Remover Professional in order to protect yourself. An example 
  of one of these alerts is:</p>
<blockquote> 
  <p><font color="#0000FF">Your computer is being attacked by an Internet Virus. 
    It could be a password-stealing attack, a trojan - dropper or similar.</font></p>
  </blockquote>
<p>If you find that you are infected with this program, please do not purchase 
  it. Instead use the removal guide below to remove this program for free.</p>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/16334/Virus-Remover-Professional.html">Virus Remover Professional</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [Virus Remover Profesional] C:\Program Files\Virus Remover Professional\virusremover.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/17/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Virus Remover Professional  using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Virus Remover Professional </strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Virus Remover Profesional </strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/v/virus-remover-professional/mbam-virus-remover-pro.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Virus Remover Profesional </strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=virus-remover-profes" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Virus Remover Professional  Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\Programs\Virus Remover Professional<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Virus Remover Professional\Order Full Version NOW!.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Virus Remover Professional\Virus Remover Professional.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Virus Remover Professional\Visit Virus Remover Professional Homepage.lnk<br />
c:\Documents and Settings\Bleeping\Application Data\LastSun Ltd<br />
c:\Documents and Settings\Bleeping\Application Data\LastSun Ltd\Virus Remover Profesional<br />
c:\Documents and Settings\Bleeping\Application Data\LastSun Ltd\Virus Remover Profesional\virusremover.exe<br />
c:\Documents and Settings\Bleeping\Application Data\Microsoft\Internet Explorer\Quick Launch\Virus Remover Professional.lnk<br />
c:\Documents and Settings\Bleeping\Desktop\Virus Remover Pro..lnk<br />
c:\Program Files\Virus Remover Professional<br />
c:\Program Files\Virus Remover Professional\hp.url<br />
c:\Program Files\Virus Remover Professional\license.rtf<br />
c:\Program Files\Virus Remover Professional\order.url<br />
c:\Program Files\Virus Remover Professional\unins000.dat<br />
c:\Program Files\Virus Remover Professional\unins000.exe<br />
c:\Program Files\Virus Remover Professional\virusremover.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Virus Remover Professional  Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\LastSun Ltd.<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virus Remover Professional_is1<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Remover Profesional"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove the VSCodec Pro Trojan (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-vscodec-pro</link>
	<pubDate>Tue, 16 Jun 2009 13:01:47 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[VSCodec Pro]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-vscodec-pro</guid>
	<description><![CDATA[VSCodec Pro is a video and audio codec package that is advertised through the use of Trojans. These Trojans, when installed, will constantly display alerts stating that there is something wrong with your video and audio settings on your computer. If you click on these alerts, it will then take you to the VSCodec Pro web site where you will be told that you need to purchase the program in order to fix your computer's video and audio configuration. This Trojan will also make it so that you are unable to open audio and video files on your computer. When you attempt to open one of these files, the file will be closed and you will be presented with an alert stating that there is something configured incorrectly so that you cannot run this type of media. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove the VSCodec Pro Trojan (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Tue, 16 Jun 2009 13:01:47 EDT &middot; Views: 882</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-vscodec-pro', 'Remove the VSCodec Pro Trojan (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-vscodec-pro', 'Remove the VSCodec Pro Trojan (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>VSCodec Pro</strong> is a video and audio codec package that is advertised 
  through the use of Trojans. These Trojans, when installed, will constantly display 
  alerts stating that there is something wrong with your video and audio settings 
  on your computer. If you click on these alerts, it will then take you to the 
  VSCodec Pro web site where you will be told that you need to purchase the program 
  in order to fix your computer's video and audio configuration. This Trojan will 
  also make it so that you are unable to open audio and video files on your computer. 
  When you attempt to open one of these files, the file will be closed and you 
  will be presented with an alert stating that there is something configured incorrectly 
  so that you cannot run this type of media. The current text of these alerts 
  are:</p>
<blockquote> 
  <p><font color="#0000FF"><strong>Fatal Error</strong><br>
    Fatal Error! The media system on your computer is corrupt. Update your sound 
    and video codec immediately to resolve this issue.</font></p>
  <p><font color="#0000FF"><strong>Fatal Erro </strong></font>(sic)<font color="#0000FF"><br>
    Windows can`t play the folowing </font>(sic)<font color="#0000FF"> media formats: 
    AVI;WMV;AVS;FLV;MKV;MOV;3GP;MP4;MPG;MPEG;MP3;AAC;WAV;WMA;CDA;FLAC;M4A;MID. 
    Update your video and sound codec to resolve this issue.</font> </p>
</blockquote>
<p>While this Trojan is running you will also find that the computer may begin 
  to act slower. This is because the program is constantly monitoring what files 
  you are opening in the event that it is a media file, which it will then close. 
  This monitoring will use CPU power and memory that other legitimate programs 
  would be better off using.</p>
<p> 
  
</p>
<p> </p>
<p>If you are finding these types of alerts or behavior on your computer, please 
  do not purchase the software it recommends as it is a scam. Instead, use the 
  guide below to remove this infection and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
   <li><a href="http://www.bleepingcomputer.com/virus-removal/trojan-horses">Trojan Horses</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/files/smitfraudfix.php">SmitFraudFix</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [mediacodec.exe] %UserProfile%\Temp\mediacodec.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>03-10-09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for VSCodec Pro using SmitFraudFix:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download SmitfraudFix.exe from here and save it to your desktop:<br>
    <br>
    <a href="http://www.bleepingcomputer.com/files/smitfraudfix.php" target="_new"><font color="#0000FF"><strong>SmitFraudFix.exe</strong></font></a><strong><br>
    <br>
    </strong>Confirm that the file<strong> SmitfraudFix.exe</strong> now resides 
    on your desktop, but do not double-click on the icon as of yet. We will use 
    it in later steps. The icon will look like the one below:<br>
    <br>
    <center>
      <img src="http://img.bleepingcomputer.com/swr-guides/smitfraudfix/sff-icon.gif"> 
      <br>
      <br>
    </center>
  </li>
  <br />
  <li>Next, please reboot your computer into <b><a href="http://www.bleepingcomputer.com/tutorials/tutorial61.html" target="_new"><font color="#FF0000">Safe 
    Mode</font></a></b> by doing the following:<br>
    <br>
    <ol>
      <li>Restart your computer<br>
        <br>
      </li>
      <li>After hearing your computer beep once during startup, but before the 
        Windows icon appears, press F8.<br>
        <br>
      </li>
      <li>Instead of Windows loading as normal, a menu should appear<br>
        <br>
      </li>
      <li>Select the first option, to run Windows in Safe Mode.<br>
        <br>
      </li>
      <li>When you are at the logon prompt, log in as the same user that you had 
        performed the previous steps as.<br>
        <br>
      </li>
    </ol>
  </li>
  <li>When your computer has started in safe mode, and you see the desktop, close 
    all open Windows.<br>
    <br>
  </li>
  <li> Now, double-click on the SmitFraudfix icon that should be residing on your 
    desktop.The icon will look like the one below:<br>
    <br>
    <center>
      <img src="http://img.bleepingcomputer.com/swr-guides/smitfraudfix/sff-icon.gif"> 
    </center>
    <br>
    <br>
  </li>
  <li> When the tool first starts you will see a credits screen. Simply press 
    any key on your keyboard to get to the next screen.<br>
    <br>
  </li>
  <li>You will now see a menu as shown in the image below. Press the number <strong>2</strong> 
    on your keyboard and the press the <strong>enter</strong> key to choose the 
    option <strong><em>Clean (safe mode recommended).</em></strong><br>
    <br>
    <br>
    <center>
      <img src="http://img.bleepingcomputer.com/swr-guides/smitfraudfix/menu.jpg"> 
    </center>
    <br>
  </li>
  <br />
  <li>The program will start cleaning your computer and go through a series of 
    cleanup processes. When it is done, it will automatically start the Disk Cleanup 
    program as shown by the image below.<br>
    <br>
    <br>
    <center>
      <img src="http://img.bleepingcomputer.com/swr-guides/smitrem/dc.jpg"> 
    </center>
    <br>
    <br>
    <br>
    This program will remove all Temp, Temporary Internet Files, and other files 
    that may be leftover files from this infection. This process can take up to 
    a few hours depending on your computer, so please be patient. When it is complete, 
    it will close automatically and you will should continue with step 11.<br>
    <br>
  </li>
  <li>When Disk Cleanup is finished, you will be presented with an option asking 
    <em><strong>Do you want to clean the registry ? (y/n)</strong></em>. At this 
    screen you should press the <strong>Y</strong> button on your keyboard and 
    then press the <strong>enter</strong> key.<br>
  </li>
  <br />
  <br />
  <li>When this last routine is finished, you will be presented with a red screen 
    stating <em><strong>Computer will reboot now. Close all applications.</strong> 
    </em>You should now press the spacebar on your computer. A counter will appear 
    stating that the computer will reboot in 15 seconds. Do not cancel this countdown 
    and allow your computer to reboot. <br>
  </li>
  <li>Once the computer has rebooted, you will be presented with a Notepad screen 
    containing a log of all the files removed from your computer. Examine this 
    log, and when you are done, close the Notepad screen.<br>
  </li>
</ol>
<p>Your computer should now be free of the <font color="#333333"><strong>VSCodec Pro</strong></font> 
  infection.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated VSCodec Pro Files:</span></p>
     <blockquote>
        %UserProfile%\Bleeping\Local Settings\Temp\mediacodec.exe<br />

     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated VSCodec Pro Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "mediacodec.exe"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Protection System (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-protection-system</link>
	<pubDate>Sun, 14 Jun 2009 11:23:28 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Protection System ]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-protection-system</guid>
	<description><![CDATA[Protection System is a rogue anti-spyware program from the same family as CoreGuard 2009. Protection System uses false scan results and fake security warnings as a method to make you think you are infected. To make matters worse, in order to protect itself from legitimate anti-malware programs it will attempt to automatically uninstall the following programs without your permission ... [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Protection System (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Sun, 14 Jun 2009 11:23:28 EDT &middot; Views: 1619</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-protection-system', 'Remove Protection System (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-protection-system', 'Remove Protection System (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Protection System</strong> is a rogue anti-spyware program from the 
  same family as <a href="http://www.bleepingcomputer.com/virus-removal/remove-coreguard-antivirus-2009">CoreGuard 
  2009</a>. Protection System uses false scan results and fake security warnings 
  as a method to make you think you are infected. To make matters worse, in order 
  to protect itself from legitimate anti-malware programs it will attempt to automatically 
  uninstall the following programs without your permission:</p>
<ul>
  <li>F-Secure</li>
  <li>Malwarebytes' Anti-Malware</li>
  <li> NOD32</li>
  <li> avast!</li>
  <li> AntiVir</li>
  <li> AVG</li>
  <li> Norton Internet Security</li>
</ul>
<p>When Protection System is installed it will be configured to start automatically 
  when Windows starts. Once started, the program will perform a scan and then 
  list a variety of infections that it will not remove until you purchase the 
  program. These infections, though, either do not exist on your computer or are 
  legitimate programs being identified as infections. In fact, some of these legitimate 
  files are necessary Windows files that if deleted will cause problems with the 
  normal operation of your computer. Therefore, do not delete any files that this 
  program states are infections, as what it displays cannot be trusted.</p>
<p> 
  
</p>
<p> While the program is running, Protection System will also display numerous 
  security warnings and nag screens. The security warnings that are shown as either 
  pop-ups on your desktop or balloon alerts from the Windows taskbar. These security 
  warnings range from an alert stating that your computer is being attacked from 
  a remote PC to a warning stating that Internet Explorer is infected with a rootkit. 
  All of these warnings are false as they are scripted to be shown regardless 
  of what is running on your computer. The program will also constantly show you 
  alerts asking you to register the program. These alerts will stay on top of 
  any running application and will only go away when you manually close them. 
  As they are shown so frequently this can become quite an annoyance.</p>
<p>With all of this said, if you are infected with Protection System, please do 
  not purchase this program. Instead, use the guide below to remove this infection 
  and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/16314/Protection-System.html">Protection System</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O2 - BHO: BhoApp - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\WINDOWS\system32\wingenocx.dll<br />
O4 - HKCU\..\Run: [Protection System] C:\Program Files\Protection System\psystem.exe<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/14/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Protection System  using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Protection System </strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>ProtectionSystem</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/p/protection-system/mbam-protection-system.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>ProtectionSystem</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=protection-system" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Protection System  Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\Programs\Protection System<br />
c:\Documents and Settings\All Users\Desktop\Protection System.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Protection System.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Uninstall Protection System.lnk<br />
c:\Program Files\Protection System<br />
c:\Program Files\Protection System\blacklist.cga<br />
c:\Program Files\Protection System\core.cga<br />
c:\Program Files\Protection System\coreext.dll<br />
c:\Program Files\Protection System\firewall.dll<br />
c:\Program Files\Protection System\psystem.exe<br />
c:\Program Files\Protection System\uninstall.exe<br />
c:\Program Files\Protection System\Help<br />
c:\Program Files\Protection System\Help\support.png<br />
c:\Program Files\Protection System\Help\unreg.html<br />
c:\Program Files\Protection System\Help\images<br />
c:\Program Files\Protection System\Help\images\delete.png<br />
c:\Program Files\Protection System\Help\images\info.png<br />
c:\Program Files\Protection System\Help\images\plus_circle.png<br />
c:\Program Files\Protection System\Help\images\tick.png<br />
c:\Program Files\Protection System\Help\images\warn.png<br />
c:\Program Files\Protection System\Help\images\buttons<br />
c:\Program Files\Protection System\Help\images\buttons\offline.gif<br />
c:\Program Files\Protection System\Help\images\buttons\online.gif<br />
c:\Program Files\Protection System\Help\images\buttons\voice.gif<br />
c:\WINDOWS\system32\wingenocx.dll
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Protection System  Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\Protection System<br />
HKEY_CLASSES_ROOT\BhoNew.BhoApp<br />
HKEY_CLASSES_ROOT\BhoNew.BhoApp.1<br />
HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}<br />
HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}<br />
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Protection System<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Protection System"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Wind Optimizer (Removal Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-wind-optimizer</link>
	<pubDate>Tue, 09 Jun 2009 23:43:12 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Wind Optimizer]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-wind-optimizer</guid>
	<description><![CDATA[Wind Optimizer is a rogue Windows optimization software from the same developers of General Antivirus and Personal Antivirus. When Wind Optimizer is installed it will be configured to start automatically. Once started it will prompt you to scan your computer, and when finished, will state that there are a variety of problems on your computer. In order to fix any of these problems, though, you will be required to first purchase the program. What Wind Optimizer is not telling you is that the problems it states you have are grossly exaggerated, or not a problem at all, and that fixing them will most likely not help with your computer's performance. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Wind Optimizer (Removal Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Tue, 09 Jun 2009 23:43:12 EDT &middot; Views: 780</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-wind-optimizer', 'Remove Wind Optimizer (Removal Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-wind-optimizer', 'Remove Wind Optimizer (Removal Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Wind Optimizer</strong> is a rogue Windows optimization software from 
  the same developers of <a href="http://www.bleepingcomputer.com/virus-removal/remove-general-antivirus">General 
  Antivirus</a> and <a href="http://www.bleepingcomputer.com/virus-removal/remove-personal-antivirus">Personal 
  Antivirus</a>. When Wind Optimizer is installed it will be configured to start 
  automatically. Once started it will prompt you to scan your computer, and when 
  finished, will state that there are a variety of problems on your computer. 
  In order to fix any of these problems, though, you will be required to first 
  purchase the program. What Wind Optimizer is not telling you is that the problems 
  it states you have are grossly exaggerated, or not a problem at all, and that 
  fixing them will most likely not help with your computer's performance.</p>
<p> 
  
</p>
<p> In fact, while this program is running you may actually find that your computer 
  begins to run slower. This is because the program is always running in the background 
  and displaying unintelligible alerts that are very difficult to dismiss. The 
  program also uses a a lot of your computer's CPU and memory, which will cause 
  other programs that need these resources to run slower.</p>
<p>With all of this said, please do not purchase Wind Optimizer regardless of 
  what it tells you. Instead use the removal guide below to remove this program 
  for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/16233/Wind-Optimizer-1.0.0.2.html">Wind Optimizer (1.0.0.2)</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [Wind Optimizer] "C:\Program Files\Wind Optimizer\WindOptimizer.exe" /s 
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/09/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Wind Optimizer using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Wind Optimizer</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Wind Optimizer</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/results-page.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Wind Optimizer</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=wind-optimizer" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Wind Optimizer Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Start Menu\Programs\Wind Optimizer<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Wind Optimizer\Purchase License.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Wind Optimizer\Uninstall  Wind Optimizer.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Wind Optimizer\Wind Optimizer Home Page.lnk<br />
c:\Documents and Settings\All Users\Start Menu\Programs\Wind Optimizer\Wind Optimizer.lnk<br />
%UserProfile%\Application Data\Wind Optimizer<br />
%UserProfile%\Application Data\Wind Optimizer\updateloadlist.ini<br />
%UserProfile%\Application Data\Wind Optimizer\db<br />
%UserProfile%\Application Data\Wind Optimizer\db\Settings.ini<br />
%UserProfile%\Application Data\Wind Optimizer\db\Urls.inf<br />
%UserProfile%\Desktop\WOSetup.exe.txt<br />
%UserProfile%\Desktop\WOSetup.tmp.txt<br />
c:\Program Files\Wind Optimizer<br />
c:\Program Files\Wind Optimizer\activate.ico<br />
c:\Program Files\Wind Optimizer\Contig.exe<br />
c:\Program Files\Wind Optimizer\Explorer.ico<br />
c:\Program Files\Wind Optimizer\log_09062009.wlg<br />
c:\Program Files\Wind Optimizer\unins000.dat<br />
c:\Program Files\Wind Optimizer\unins000.exe<br />
c:\Program Files\Wind Optimizer\uninstall.ico<br />
c:\Program Files\Wind Optimizer\vista.manifest<br />
c:\Program Files\Wind Optimizer\vista.res<br />
c:\Program Files\Wind Optimizer\WindOptimizer.exe<br />
c:\Program Files\Wind Optimizer\WO_install.iss<br />
c:\Program Files\Wind Optimizer\WO_install.new.iss<br />
c:\Program Files\Wind Optimizer\WODefragmenter.exe<br />
c:\Program Files\Wind Optimizer\WOIsnce.db<br />
c:\Program Files\Wind Optimizer\db
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Wind Optimizer Windows Registry Information:</span></p>
     <blockquote>
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wind Optimizer_is1<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Wind Optimizer"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AutoUpdateDisableNotify"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "InternetSettingsDisableNotify"<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "UacDisableNotify"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove Antivirus System Pro (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro</link>
	<pubDate>Fri, 05 Jun 2009 08:54:51 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[Antivirus System Pro]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro</guid>
	<description><![CDATA[Antivirus System Pro is a rogue anti-spyware that uses false scan results, fake security alerts, and Internet Explorer hijacking in order to have you purchase this program. It is because of these actions that we classify Antivirus System Pro as a rogue anti-spyware program. When installed, Antivirus System pro will be configured to start automatically when you log into Windows. Once running it will scan your computer and display numerous infections that do not actually exist. Furthermore, it will state it will not remove these infections unless you first purchase the program. This method of stating there are infections, but not removing it until you purchase it, is just another tactic to have you purchase the software. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove Antivirus System Pro (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Fri, 05 Jun 2009 08:54:51 EDT &middot; Views: 31571</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro', 'Remove Antivirus System Pro (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-pro', 'Remove Antivirus System Pro (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>Antivirus System Pro</strong> is a rogue anti-spyware that uses false 
  scan results, fake security alerts, and Internet Explorer hijacking in order 
  to have you purchase this program. It is because of these actions that we classify 
  Antivirus System Pro as a rogue anti-spyware program. When installed, Antivirus 
  System pro will be configured to start automatically when you log into Windows. 
  Once running it will scan your computer and display numerous infections that 
  do not actually exist. Furthermore, it will state it will not remove these infections 
  unless you first purchase the program. This method of stating there are infections, 
  but not removing it until you purchase it, is just another tactic to have you 
  purchase the software.</p>
<p> 
  
</p>
<p> While running, you will also be constantly barraged with fake security alerts 
  stating that your computer is under attack or that you have viruses on your 
  computer. For example, one alert is labeled Infiltration Alert and it states 
  that your computer is being attacked by an Internet Virus. Another alert prompts 
  you to scan your computer and when you click on it, will automatically launch 
  Antivirus System Pro and then prompt you to purchase it. The text of this alert 
  is:</p>
<blockquote> 
  <p><font color="#0000FF"><strong>Windows Security alert</strong><br>
    Windows reports that computer is infected. Antivirus software helps to protect 
    your computer against viruses and other security threats. Click here for the 
    scan you computer. Your system might be at risk now.</font></p>
</blockquote>
<p>Last, but not least, Antivirus System Pro will install a Internet Explorer 
  Browser Helper Object that will hijack Internet Explorer so that when you are 
  browsing web sites, instead of going to the page you want, you will be shown 
  a warning message. This warning message will state that the site you are going 
  to is harmful to your computer and that you should purchase Antivirus System 
  Pro to protect yourself.</p>
<p>As you can see, this program utilizes many tactics to make you think you are 
  infected and thus tricking you into purchase the program. Please do not purchase 
  this program as it will not protect your computer in any way. Instead, use the 
  guide below to remove this infection and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O1 - Hosts: ::1 localhost<br />
O1 - Hosts: 209.44.111.57 security.microsoft.com<br />
O1 - Hosts: 209.44.111.57 inetavirus.com<br />
O1 - Hosts: 209.44.111.57 www.inetavirus.com<br />
O2 - BHO: BHO - {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} - C:\WINDOWS\system32\iehelper.dll<br />
O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/05/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for Antivirus System Pro using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>Antivirus System Pro</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>Antivirus System Pro</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/a/antivirus-system-pro/mbam-antivirus-system-pro.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>Antivirus System Pro</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=antivirus-system-pro" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated Antivirus System Pro Files:</span></p>
     <blockquote>
        c:\WINDOWS\sysguard.exe<br />
c:\WINDOWS\system32\iehelper.dll
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated Antivirus System Pro Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\AvScan<br />
HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove XP Deluxe Protector (Uninstall Guide)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-xp-deluxe-protector</link>
	<pubDate>Wed, 03 Jun 2009 22:47:08 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[XP Deluxe Protector]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-xp-deluxe-protector</guid>
	<description><![CDATA[XP Deluxe Protector is a rogue anti-spyware from the same family as XP Police Antivirus. This rogue is advertised through the use of Trojans that display fake security alerts from your Windows taskbar. These alerts state that your computer is compromised or infected and then prompts you to download and install XP Deluxe Protector. Once downloaded and installed, XP Deluxe Protector will be configured to automatically start when you login to Windows. Once started, the program will scan your computer and then list a variety of infections that do not actually exist on your computer. If you try to remove these infections using the program, it will state that you need to purchase it before you can do so.  [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove XP Deluxe Protector (Uninstall Guide)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 03 Jun 2009 22:47:08 EDT &middot; Views: 18346</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-xp-deluxe-protector', 'Remove XP Deluxe Protector (Uninstall Guide)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-xp-deluxe-protector', 'Remove XP Deluxe Protector (Uninstall Guide)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>XP Deluxe Protector</strong> is a rogue anti-spyware from the same 
  family as <a href="http://www.bleepingcomputer.com/malware-removal/remove-xp-police-antivirus">XP 
  Police Antivirus</a>. This rogue is advertised through the use of Trojans that 
  display fake security alerts from your Windows taskbar. These alerts state that 
  your computer is compromised or infected and then prompts you to download and 
  install XP Deluxe Protector. Once downloaded and installed, XP Deluxe Protector 
  will be configured to automatically start when you login to Windows. Once started, 
  the program will scan your computer and then list a variety of infections that 
  do not actually exist on your computer. If you try to remove these infections 
  using the program, it will state that you need to purchase it before you can 
  do so. </p>
<p>
  
</p>
<p> While the program is running you will also constantly be shown fake security 
  alerts. These alerts state that your computer is infected or that your computer 
  is being attacked from a remote location. The text of one of the alerts is:</p>
<blockquote> 
  <p><strong><font color="#0000FF">Hidden file transfer to remote host was detected</font></strong><font color="#0000FF"><br>
    XP Deluxe Protector has detected that somebody is trying to transfer your 
    private data via Internet. We strongly recommend you to block the attack immediately.</font> 
  </p>
</blockquote>
<p>XP Deluxe Protector will also display a fake Windows Security Center window 
  that states that your computer is vulnerable and that you should purchase the 
  program to protect yourself. It goes without saying this program is a scam and 
  you should not purchase it for any reason. Instead, please use the removal guide 
  below to remove XP Deluxe Protector and any related malware for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKCU\..\Run: [xpprotect] %UserProfile%\XP Deluxe Protector\xpdeluxe.exe
     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/03/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for XP Deluxe Protector using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>XP Deluxe Protector</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>XP Deluxe Protector</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/x/xp-deluxe-protector/mbam-xp-deluxe-protector.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>XP Deluxe Protector</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=xp-deluxe-protector" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated XP Deluxe Protector Files:</span></p>
     <blockquote>
        %UserProfile%\Desktop\XP Deluxe Protector.LNK<br />
%UserProfile%\Start Menu\XP Deluxe Protector.LNK<br />
%UserProfile%\XP Deluxe Protector\xpdeluxe.exe
     </blockquote>
  <p>&nbsp;</p>
<a name="keys"></a><p><span class='swr-heading'>Associated XP Deluxe Protector Windows Registry Information:</span></p>
     <blockquote>
        HKEY_CURRENT_USER\Software\XP Deluxe Protector<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xpprotect
     </blockquote>
  <p>&nbsp;</p>

</span></div>
]]></content:encoded>
 </item>

 <item>
	<title>Remove WinBlueSoft (How to Uninstall)</title>
	<link>http://www.bleepingcomputer.com/virus-removal/remove-winbluesoft</link>
	<pubDate>Wed, 03 Jun 2009 00:31:12 EDT</pubDate>
	<dc:creator>Grinler</dc:creator>

	<category><![CDATA[Spyware Removal]]></category>

	<category><![CDATA[Rogue anti-spyware]]></category>

	<category><![CDATA[Malware Removal Guide]]></category>

	<category><![CDATA[WinBlueSoft]]></category>

	<guid>http://www.bleepingcomputer.com/virus-removal/remove-winbluesoft</guid>
	<description><![CDATA[WinBlueSoft is a rogue anti-spyware and ransomware program from the same family as WiniBlueSoft. This incarnation, though, uses some interesting tricks to keep itself from being removed and to force you to install WinBlueSoft in order to try and fix your computer. First, Trojans will constantly bombard you with security alerts stating your computer is horribly infected and that you should download and install WinBlueSoft in order to clean your computer. These types of alerts, though, are common for programs of this nature. It is another part part of the malware recipe that WinBlueSoft uses called blocker.dll that makes this infection more devastating. Blocker.dll is a malware file that is loaded through the Windows AppInit_DLLs Registry value. When loaded, blocker.dll will make it so that you cannot launch any programs unless the program's filename is among the 53 filenames that it allows such as iexplore.exe, explorer.exe, sidebar.exe, and of course WinBlueSoft.exe. Essentially, the blocker.dll is acting as Ransomware requiring you to install and purchase WinBlueSoft, so that WinBlueSoft can then remove blocker.dll and allow you to launch your normal programs. Furthermore, when blocker.dll is loaded for the first time it will change your desktop to a black background with dark red ominous text written over it. [...]]]></description>
	<content:encoded><![CDATA[<div id="swrguide">
<span id="intelliTxt">
 <h1>Remove WinBlueSoft (How to Uninstall)</h1>
 <h3>Posted by <a href="http://www.bleepingcomputer.com/forums/index.php?showuser=3">Grinler</a> on Wed, 03 Jun 2009 00:31:12 EDT &middot; Views: 10407</h3>
<div align='center'>
    <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-winbluesoft', 'Remove WinBlueSoft (How to Uninstall)');"><img src="http://img.bleepingcomputer.com/bc/guide/sm-favorites.png" align="absmiddle" alt="Add to Favorites" /></a>
       <a href="javascript:window.external.AddFavorite('http://www.bleepingcomputer.com/virus-removal/remove-winbluesoft', 'Remove WinBlueSoft (How to Uninstall)');"><b>Add to Favorites!</b></a>&nbsp;&nbsp;&nbsp;<a href="javascript:window.print();"><img src="http://img.bleepingcomputer.com/bc/guide/sm-print.png" align="absmiddle" alt="Print Guide" /></a> <a href="javascript:window.print();"><b>Print Guide!</b></a>
</div>
 <p>&nbsp;</p>
  <p><span class='swr-heading'>What this programs does:</span></p>
  <p><strong>WinBlueSoft</strong> is a rogue anti-spyware and ransomware program 
  from the same family as <a href="http://www.bleepingcomputer.com/virus-removal/how-to-remove-winibluesoft">WiniBlueSoft</a>. 
  This incarnation, though, uses some interesting tricks to keep itself from being 
  removed and to force you to install WinBlueSoft in order to try and fix your 
  computer. First, Trojans will constantly bombard you with security alerts stating 
  your computer is horribly infected and that you should download and install 
  WinBlueSoft in order to clean your computer. These types of alerts, though, 
  are common for programs of this nature. It is another part part of the malware 
  recipe that WinBlueSoft uses called <strong>blocker.dll</strong> that makes 
  this infection more devastating. Blocker.dll is a malware file that is loaded 
  through the Windows AppInit_DLLs Registry value. When loaded, blocker.dll will 
  make it so that you cannot launch any programs unless the program's filename 
  is among the 53 filenames that it allows such as iexplore.exe, explorer.exe, 
  sidebar.exe, and of course WinBlueSoft.exe. Essentially, the blocker.dll is 
  acting as Ransomware requiring you to install and purchase WinBlueSoft, so that 
  WinBlueSoft can then remove blocker.dll and allow you to launch your normal 
  programs. Furthermore, when blocker.dll is loaded for the first time it will 
  change your desktop to a black background with dark red ominous text written 
  over it. This text is:</p>
<blockquote>
  <p><font color="#0000FF">Warning!<br>
    Your're </font><em>&lt;sic&gt;</em><font color="#0000FF"> in danger!<br>
    Your computer is infected with Spyware!<br>
    All you do with computers is stored forever in your hard disk. When you visit 
    sites, send emails... All your actions are logged. And it is impossible to 
    remove them with standard tools. Your data is still available for forensics. 
    And in some cases </font></p>
  <p><font color="#0000FF">For your boss, your friends, your wife, your children.<br>
    <br>
    Every site you or somebody or even something, like spyware, opened in the 
    browsers, with all the images, and all the downloaded and maybe later removed 
    movies or mp3 songs - ARE STILL THERE and could break your life!</font></p>
  <p><font color="#0000FF">Secure yourself right now!<br>
    Remove all Spyware from your PC!</font></p>
</blockquote>
<p>If WinBlueSoft is installed it will configure itself to start automatically 
  when you login to Windows. Once started, it will scan your computer and state 
  that you have a variety of infections on your computer, but will not remove 
  them until you first purchase the program. As you now know, this program is 
  a scam that utilizes malware and deception in order to have you purchase their 
  product.</p>
<p> 
  
</p>
<p> If you have become infected with WinBlueSoft, blocker.dll, or the fake security 
  alert Trojans that advertise it, then please use the removal guide shown below 
  to remove it for free.</p>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Threat Classification:</span> </p>
     <ul>   <li><a href="http://www.bleepingcomputer.com/virus-removal/rogue-programs">Information on Rogue Programs & Scareware</a></li>
</ul>
  
  
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Entries for this program found in the Add or Remove Programs control panel:</span></p>
     <blockquote>
        	<a href="http://www.bleepingcomputer.com/uninstall/16176/WinBlueSoft.html">WinBlueSoft</a><br />

     </blockquote>

  <p>&nbsp;</p>
  <p><span class='swr-heading'>Tools Needed for this fix:</span></p>
     <ul>   <li><a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe">Malwarebytes' Anti-Malware</a></li>
</ul>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Symptoms that may be in a HijackThis Log:</span></p>
     <blockquote class="hjt">
	O4 - HKLM\..\Run: [WinBlueSoft] C:\Program Files\WinBlueSoft Software\WinBlueSoft\WinBlueSoft.exe -min<br />
O20 - AppInit_DLLs: blocker.dll<br />

     </blockquote>
  <p>&nbsp;</p>
  <p><span class='swr-heading'>Guide Updates:</span></p>
	<blockquote>
   	  <em>06/03/09 - Initial guide creation.</em>
	</blockquote>
  <p>&nbsp;</p>
  <hr>
  <p><span class='swr-heading'><a name="first"></a> Automated Removal Instructions for WinBlueSoft using Malwarebytes' Anti-Malware:</span></p>
  <p>&nbsp;</p>
	<ol>
  <li>Print out these instructions as we will need to close every window that 
    is open later in the fix.<br>
    <br>
  </li>
  <li>Download Malwarebytes' Anti-Malware, or MBAM, from the following location 
    and save it to your desktop:<br>
    <br>
    <a href="http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe" target="_new" rel="nofollow">Malwarebytes' Anti-Malware Download Link</a><br>
    <br>
  </li>
  <br />
  <li>Once downloaded, close all programs and Windows on your computer, including 
    this one.<br>
    <br>
  </li>
  <li>Double-click on the icon on your desktop named <strong>mbam-setup.exe</strong>. 
    This will start the installation of MBAM onto your computer.<br>
    <br>
  </li>
  <li>When the installation begins, keep following the prompts in order to continue 
    with the installation process. Do not make any changes to default settings 
    and when the program has finished installing, make sure you leave both the 
    <strong>Update Malwarebytes' Anti-Malware</strong> and <strong> </strong><strong>Launch 
    Malwarebytes' Anti-Malware</strong> checked. Then click on the <strong>Finish</strong> 
    button.<br>
    <br>
  </li>
  <li>MBAM will now automatically start and you will see a message stating that 
    you should update the program before performing a scan. As MBAM will automatically 
    update itself after the install, you can press the <strong>OK</strong> button 
    to close that box and you will now be at the main program as shown below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/mbam.jpg" alt="MalwareBytes Anti-Malware Screen"><br>
    </div>
    <br>
  </li>
  <li> On the <strong>Scanner</strong> tab, make sure the the <strong>Perform 
    quick scan</strong> option is selected and then click on the <strong>Scan</strong> 
    button to start scanning your computer for <strong>WinBlueSoft</strong> related 
    files.<br>
    <br>
  </li>
  <li>MBAM will now start scanning your computer for malware. This process can 
    take quite a while, so we suggest you go and do something else and periodically 
    check on the status of the scan. When MBAM is scanning it will look like the 
    image below.<br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scanning.jpg" alt="MalwareBytes Anti-Malware Scanning Screen"><br>
    </div>
    <br>
  </li>
  <li>When the scan is finished a message box will appear as shown in the image 
    below. <br>
    <br>
    <br>
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/mbam/scan-finished.jpg" alt="MalwareBytes Anti-Malware Scan Finished Screen"><br>
      <br>
    </div>
    You should click on the OK button to close the message box and continue with 
    the <strong>WinBlueSoft</strong> removal process.<br>
    <br>
  </li>
  <li>You will now be back at the main Scanner screen. At this point you should 
    click on the <strong>Show Results</strong> button.<br>
    <br>
  </li>
  <li>A screen displaying all the malware that the program found will be shown 
    as seen in the image below. Please note that the infections found may be different than what is shown in the image.<br>
    <br>
    <br>
      
    <div align='center'><img src="http://img.bleepingcomputer.com/swr-guides/w/winbluesoft/mbam-winbluesoft.jpg" alt="MalwareBytes Scan Results"><br>
      <br>
    </div>
    <br>
    You should now click on the <strong>Remove Selected</strong> button to remove 
    all the listed malware. MBAM will now delete all of the files and registry 
    keys and add them to the programs quarantine. When removing the files, MBAM 
    may require a reboot in order to remove some of them. If it displays a message 
    stating that it needs to reboot, please allow it to do so. Once your computer 
    has rebooted, and you are logged in, please continue with the rest of the 
    steps.<br>
    <br>
  </li>
  <li>When MBAM has finished removing the malware, it will open the scan log and 
    display it in Notepad. Review the log as desired, and then close the Notepad 
    window.<br>
    <br>
  </li>
  <li>You can now exit the MBAM program.<br>
  </li>
</ol>
<p>Your computer should now be free of the <strong>WinBlueSoft</strong> program. If your current anti-virus solution let this infection through, you may want to consider <a href="https://www.cleverbridge.com/342/?affiliate=1878&amp;cart=29945&amp;scope=checkout&amp;x-at=winbluesoft" rel="nofollow">purchasing the PRO version of Malwarebytes' Anti-Malware</a> to protect against these types of threats in the future.</p>
  <p>If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:</p>
  <p><a href="http://www.bleepingcomputer.com/forums/topic34773.html" target="_new">Preparation Guide For Use Before Posting A Hijackthis Log</a></p>
  <p>&nbsp;</p>
  <hr>
  <p>&nbsp;</p>
  <a name="files"></a><p><span class='swr-heading'>Associated WinBlueSoft Files:</span></p>
     <blockquote>
        c:\Documents and Settings\All Users\Desktop\WinBlueSoft.lnk<br />
c:\Documents and Settings\All Users\Start