Monday, May 16, 2011

Windows Tweaking Utility Removal GuideWindows Tweaking Utility Removal Guide

Windows Tweaking Utility Removal Guide
Windows Tweaking Utility is a fake antivirus program which try to make money from the users of infected computers. Windows Tweaking Utility display fake warnings and scans the computers that return false results only to urge the users to buy the full version of Windows Tweaking Utility. Windows Tweaking Utility claims that it can remove computer viruses, spyware or other types of malware if the users buy the full version of Windows Tweaking Utility. Don't be cheated by what it has claimed as all of them is a lie! Windows Tweaking Utility blocks the running of other programs to intimidate targeted computer users into thinking that their systems are corrupted with malware.

Windows Tweaking Utility can be removed first by stopping its processes and then kill its files by using Emsisoft HiJackFree. Then the user has to remove all the related files and folder. Finally, restore the registry entries added and modified by Windows Tweaking Utility (Read the removal guide below to remove Windows Tweaking Utility successfully).

Windows Tweaking Utility should be removed immediately!


Windows Tweaking Utility Removal Guide
Read How to remove virus effectively before following the guide below.
Kill Process
[random].exe
all process which has the name ofWindows Tweaking Utility.

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "DisableSR " = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"

Remove Folders and Files
%UserProfile%\Application Data\Microsoft\[random].*
all files stated in the autorun settings.

No comments:

Post a Comment