Fake Eclipse Antivirus can be removed by stop processes and kill all files with random name in the hard drives. The user also must remove the autorun setting added. These can be done by using Emsisoft HiJackFree.
Fake Eclipse Antivirus should be removeld immediately.
Fake Eclipse Antivirus Removal Guide
Kill Process
(How to kill a process effectively?)
drivers.exe
[random].exe
system32.exe
Unregister DLL
c:\WINDOWS\system32.dll
c:\WINDOWS\system32\drivers.dll
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Eclipse Antivirus rogue"
HKEY_LOCAL_MACHINE\Software\Fake Eclipse Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = ".dll"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"
Remove Folders and Files
%PROGRAM_FILES%\Fake Eclipse Antivirus
c:\Documents and Settings\All Users\Start Menu\Fake Eclipse Antivirus\
c:\Documents and Settings\All Users\Fake Eclipse Antivirus
c:\WINDOWS\system32.dll
c:\WINDOWS\system32\drivers.dll
c:\WINDOWS\system32\drivers.exe
c:\WINDOWS\system32.exe
No comments:
Post a Comment