Showing posts with label RFA. Show all posts
Showing posts with label RFA. Show all posts
Wednesday, January 22, 2014

Remove Windows Prime AcceleratorRemove Windows Prime Accelerator

Windows Prime Accelerator Removal Guide
Windows Prime Accelerator is a fake antivirus program that cannot detect and remove any kind of virus, malware or trojan. However, Windows Prime Accelerator. pretends to be a legitimate antivirus which can protect computers from the attack malwares. Once Windows Prime Accelerator is installed on the computer, it will start automatically when Windows boot. Then Windows Prime Accelerator will do a fake scan on the computer and will definitely scare the user with pop ups which shows that the computer has been infected by a lot of malwares. Windows Prime Accelerator will repeatedly shows the pop ups to urge the user to purchase the full version of Windows Prime Accelerator so that to remove all the threats. However, Windows Prime Accelerator cannot detect and remove any kind of virus, malware and trojan.


Windows Prime Accelerator can be removed by stopping the processes and removing the files ([random].exe) by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Windows Prime Accelerator shown in the removal guide below. Windows Prime Accelerator DLL Files should be unregistered too (see removal guide). All files related to Windows Prime Accelerator must be deleted. 

Windows Prime Accelerator provide fake feature such as Home, Firewall, Automatic updates, Antivirus Protection, Anti-Phishing, Advanced Process Control, Autorun Manager, Service Manager, All-in-One Suite, Quick Scan, Deep Scan, Custom Scan, History, Settings, etc. All of them cannot protect the computer from any kind of malware.

Windows Prime Accelerator should be removed immediately!

Windows Prime Accelerator Removal Guide
Kill Process
(How to kill a process effectively?)
svc-lefx.exe

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd "ImagePath" = "123123.sys"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "GuardSoftware" = %AppData%\svc-lefx.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%AppData%\safe-[random].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableVirtualization" = 0

Remove Folders and Files
%AppData%\svc-lefx.exe
%AppData%\data.sec

File Location Notes:

%AppData% refers to the current users Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Roaming.


Wednesday, January 15, 2014

Remove Windows Prime ShieldRemove Windows Prime Shield

Windows Prime Shield Removal Guide
Windows Prime Shield is a fake antivirus program that cannot detect and remove any kind of virus, malware or trojan. However, Windows Prime Shield. pretends to be a legitimate antivirus which can protect computers from the attack malwares. Once Windows Prime Shield is installed on the computer, it will start automatically when Windows boot. Then Windows Prime Shield will do a fake scan on the computer and will definitely scare the user with pop ups which shows that the computer has been infected by a lot of malwares. Windows Prime Shield will repeatedly shows the pop ups to urge the user to purchase the full version of Windows Prime Shield so that to remove all the threats. However, Windows Prime Shield cannot detect and remove any kind of virus, malware and trojan.


Windows Prime Shield can be removed by stopping the processes and removing the files ([random].exe) by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Windows Prime Shield shown in the removal guide below. Windows Prime Shield DLL Files should be unregistered too (see removal guide). All files related to Windows Prime Shield must be deleted. 

Windows Prime Shield provide fake feature such as Home, Firewall, Automatic updates, Antivirus Protection, Anti-Phishing, Advanced Process Control, Autorun Manager, Service Manager, All-in-One Suite, Quick Scan, Deep Scan, Custom Scan, History, Settings, etc. All of them cannot protect the computer from any kind of malware.

Windows Prime Shield should be removed immediately!

Windows Prime Shield Removal Guide
Kill Process
(How to kill a process effectively?)
svc-lefx.exe

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd "ImagePath" = "123123.sys"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "GuardSoftware" = %AppData%\svc-lefx.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%AppData%\safe-[random].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableVirtualization" = 0

Remove Folders and Files
%AppData%\svc-lefx.exe
%AppData%\data.sec

File Location Notes:

%AppData% refers to the current users Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Roaming.


Tuesday, December 10, 2013

Remove Smart Guard ProtectionRemove Smart Guard Protection

Remove Smart Guard Protection
Smart Guard Protection is a fake antivirus that disguises itself to cheat the user that it can detect and remove trojans, viruses, malwares and so on. In fact, Smart Guard Protection WILL SURELY state that there are many malwares, trojans and viruses are detected in the system. All of them are lies! Smart Guard Protection will display this types of fake alert to urge the user to purchase the full version of Smart Guard Protection which cannot detect and remove any kind malware, trojan or virus.

Smart Guard Protection can be removed by stopping all of the processes in random file name, delete all the related files and remove the registry keys stated below.

Smart Guard Protection provide fake features such as General, Scan PC, Quarantine, Updates, Log, Configuration, Help, etc. None of them can help to protect the computer from any kind of malware.

Smart Guard Protection should be removed immediately!

Smart Guard Protection Removal Guide
Kill Process
(How to kill a process effectively?)
WaDprnV7.exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AS2014"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableVirtualization" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "RPSessionInterval" = 0

Remove Folders and Files
%CommonAppData%\WaDprnV7


%CommonAppData% refers to the Application Data folder for the All Users Profile. By default, this is C:\Documents and Settings\All Users\Application Data for Windows 2000/XP and C:\ProgramData\ in Windows Vista, Windows 7, and Windows 8.

%CommonAppData% refers to the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Application Data\, and for Windows Vista, Windows 7, and Windows 8 it is C:\ProgramData.

Saturday, December 7, 2013

Remove AntiVirus Plus 2014Remove AntiVirus Plus 2014

Remove AntiVirus Plus 2014
AntiVirus Plus 2014 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which AntiVirus Plus 2014 is installed. AntiVirus Plus 2014 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. AntiVirus Plus 2014 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of AntiVirus Plus 2014 is to urge the user to register AntiVirus Plus 2014 by purchasing the full version of AntiVirus Plus 2014 so that to earn some money from the user. AntiVirus Plus 2014 cannot detect and remove any malware / virus / trojan.


AntiVirus Plus 2014 provide fake features such as Full PC Scan, Privacy Keeper, Firewall, Update Settings, Global Settings. It give warnings: "Your PC might be at risk. Activate the software to protect it." It scare the user: "Attention! We strongly recommend that you activate Antivirus Plus 2014 for that safety and faster running of your PC." 

AntiVirus Plus 2014 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by AntiVirus Plus 2014 shown in the removal guide below. All files related to AntiVirus Plus 2014 must be deleted. 

AntiVirus Plus 2014 should be removed immediately!

AntiVirus Plus 2014 Removal Guide
Kill Process
(How to kill a process effectively?)
avplus.exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AntiVirus Plus 2014"
HKEY_CURRENT_USER\Software\[random]

Remove Folders and Files
%AppData%\avplus.exe

Saturday, October 5, 2013

Remove Security Cleaner ProRemove Security Cleaner Pro

Remove Security Cleaner Pro
Security Cleaner Pro is a fake antivirus program created to urge the user to buy the full version of Security Cleaner Pro in order to earn some profit. Don't ever buy it as it is a cheat! Security Cleaner Pro install itself into the computer without confirmation of the users and it start automatically when the windows boot. Security Cleaner Pro produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Security Cleaner Pro is nothing more than a scam and plagiarized antispyware program

Security Cleaner Pro provide fake features such as Perform Scan, Internet Security, Personal Security, Proactive Defense, Firewall, Settings, Complete PC Protection, Automating Updating, Protection against bank account fraud, Self-protection from malware etc. All of them cannot protect the computer from any kind of malware.

Security Cleaner Pro can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Security Cleaner Pro. Finally, all the file related to Security Cleaner Pro must be deleted from the hard drive. All of them has been shown in the removal guide below.

Security Cleaner Pro should be removed immediately!
Security Cleaner Pro Removal Guide
Kill Process
shl.exe

Delete Registry
HKCU\Software\Protection
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "ProtSoftware Inc" = "%AppData%\shl.exe"

Remove Folders and Files
%StartMenu%\Programs\Startup\shl.exe
%AppData%\shl.exe
File Location Notes:

%AppData% refers to the current users Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Roaming.

%StartMenu% refers to the Windows Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\[Current User]\Start Menu\, and for Windows Vista/7/8 it is C:\Users\[Current User]\AppData\Roaming\Microsoft\Windows\Start Menu.



Wednesday, September 18, 2013

Remove Sinergia CleanerRemove Sinergia Cleaner

Remove Sinergia Cleaner
Sinergia Cleaner is a fake antivirus program that look like a legitimate antivirus such as Kaspersky Antivirus which can protect the computer from the attack of viruses, malwares or trojans. However, Sinergia Cleaner cannot detect and remove any kind of virus, malware or trojan on the computer. When Sinergia Cleaner is installed in the computer, it will start automatically when Windows boot and then will do a fake scan on the computer and will surely scare the user with pop ups which show that the computer has been infected by a lot of malwares, viruses and trojans. Do not believe any pop ups shown by Sinergia Cleaner. Sinergia Cleaner will recommend the user to purchase the full version of Sinergia Cleaner in order to remove all the detected threats. Do not buy Sinergia Cleaner as it can do nothing.

Sinergia Cleaner provide fake features such as Perform Scan, Internet security, Personal security, Proactive defense, firewall and Configuration.

Sinergia Cleaner can be removed by stop processes and kill all files with random name in the hard drives. The user also must remove the autorun setting added by Sinergia Cleaner. These can be done by using Emsisoft HiJackFree.

Sinergia Cleaner should be removed immediately!

Sinergia Cleaner Removal Guide
Kill Process
(How to kill a process effectively?)
sinergia_cleaner.exe

Delete Registry
HKEY_CURRENT_USER\Software\Protection

Remove Folders and Files
%LocalAppData%\.exe
%System%\drivers\.sys
%StartMenu%\Programs\Sinergia Cleaner
%UserProfile%\Desktop\Buy Sinergia Cleaner.lnk
Friday, August 30, 2013

Remove Titan Antivirus 2013Remove Titan Antivirus 2013

Remove Titan Antivirus 2013
Titan Antivirus 2013 is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Titan Antivirus 2013 is installed. Titan Antivirus 2013 installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Titan Antivirus 2013 will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Titan Antivirus 2013 is to urge the user to register Titan Antivirus 2013 by purchasing the full version of Titan Antivirus 2013 so that to earn some money from the user. Titan Antivirus 2013 cannot detect and remove any malware / virus / trojan.


Titan Antivirus 2013 provide fake features such as Scan your PC, Internet Security, Personal Security, Proactive Defence, Firewall, Update, Configuration, Ultimate Protection System, Network Defense Layer Protection etc.  Titan Antivirus 2013 claims that: "Our patented layers of protection detect and eliminate threats more quickly and accurately than other technologies" and "Stop online threats before they can reach your computer".  Titan Antivirus 2013 displays "Product Not Activated. Please Register. Previous scan: Not scanned yet."

Titan Antivirus 2013 can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Titan Antivirus 2013 shown in the removal guide below. All files related to Titan Antivirus 2013 must be deleted. 

Titan Antivirus 2013 should be removed immediately!

Titan Antivirus 2013 Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ifdstore
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "4g"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = ""%CommonAppData%\ifdstore\[random].exe" /ex "%1" %*"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "idefsvc" = "%CommonAppData%\ifdstore\[random].exe /min"

Remove Folders and Files
%CommonAppData%\ifdstore
%CommonStartMenu%\Programs\Titan Antivirus 2013
%Desktop%\Titan Antivirus 2013.lnk

%Desktop% means that the file is located directly on your desktop. This is C:\DOCUMENTS AND SETTINGS\[Current User]\Desktop\ for Windows 2000/XP, and C:\Users\[Current User]\Desktop\ for Windows Vista, Windows 7, and Windows 8.

%CommonAppData% refers to the Application Data folder for the All Users Profile. By default, this is C:\Documents and Settings\All Users\Application Data for Windows 2000/XP and C:\ProgramData\ in Windows Vista, Windows 7, and Windows 8.

%CommonStartMenu% refers to the Windows Start Menu for All Users. Any programs or files located in the All Users Start menu will appear in the Start Menu for all user accounts on the computer. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Start Menu\, and for Windows Vista, Windows 7, and Windows 8 it is C:\ProgramData\Microsoft\Windows\Start Menu\.

%CommonAppData% refers to the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Application Data\, and for Windows Vista, Windows 7, and Windows 8 it is C:\ProgramData.


Friday, August 23, 2013

Remove Antivirus Security ProRemove Antivirus Security Pro

Remove Antivirus Security Pro
Antivirus Security Pro is a fake antivirus program created to urge the user to buy the full version of Antivirus Security Pro in order to earn some profit. Don't ever buy it as it is a cheat! Antivirus Security Pro install itself into the computer without confirmation of the users and it start automatically when the windows boot. Antivirus Security Pro produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. Antivirus Security Pro is nothing more than a scam and plagiarized antispyware program

Antivirus Security Pro provide fake features such as General, Scan PC, Quarantine, Updates, Log, Configuration, Help, Full scan, Signature database, Memory Protection, File System, Anti-Spyware, Firewall etc. All of them cannot protect the computer from any kind of malware.

Antivirus Security Pro can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Antivirus Security Pro. Finally, all the file related to Antivirus Security Pro must be deleted from the hard drive. All of them has been shown in the removal guide below.

Antivirus Security Pro should be removed immediately!
Antivirus Security Pro Removal Guide
Kill Process
WaDprnV7.exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AA2014" = "%CommonAppData%\WaDprnV7\WaDprnV7.exe"

Remove Folders and Files
%CommonAppData%\WaDprnV7

File Location Notes:
%CommonAppData% refers to the Application Data folder for the All Users Profile. By default, this is C:\Documents and Settings\All Users\Application Data for Windows 2000/XP and C:\ProgramData\ in Windows Vista, Windows 7, and Windows 8.

%CommonAppData% refers to the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Application Data\, and for Windows Vista, Windows 7, and Windows 8 it is C:\ProgramData.




Monday, August 19, 2013

Remove My Safe PC 2014Remove My Safe PC 2014

Remove My Safe PC 2014
My Safe PC 2014 is a fake antivirus program created to force the user to purchase the full version of My Safe PC 2014 so that to earn some profit. Don't ever buy it as it is a cheat! My Safe PC 2014 install itself into the computer without confirmation of the users and it start automatically when the windows boot. My Safe PC 2014 produce fake virus warning alert consistently to force the user to purchase the full version so that to remove the malwares. My Safe PC 2014 is nothing more than a scam!

My Safe PC 2014 provide fake features such as provide fake features such as System Scanner, Internet Security, Personal Security, Proactive Defence, Firewall, Configuration, SCAN MY COMPUTER, UPDATE DATABASE, Complete PC protection, Automatic updates, Protection from bank account fraud, Self-protection from malware and etc. All of them cannot protect the computer from any kind of malware.

My Safe PC 2014 can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by My Safe PC 2014. Finally, all the file related to My Safe PC 2014 must be deleted from the hard drive. All of them has been shown in the removal guide below.

My Safe PC 2014 should be removed immediately!
My Safe PC 2014 Removal Guide
Kill Process
security_defender.exe

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pavsdata
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "4g"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = ""%CommonAppData%\pavsdata\security_defender.exe" /ex "%1" %*"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "avsdsvc" = "%CommonAppData%\pavsdata\security_defender.exe /min"

Remove Folders and Files
%CommonAppData%\pavsdata
%CommonStartMenu%\Programs\My Safe PC 2014
%Desktop%\My Safe PC 2014.lnk

%Desktop% means that the file is located directly on your desktop. This is C:\DOCUMENTS AND SETTINGS\[Current User]\Desktop\ for Windows 2000/XP, and C:\Users\[Current User]\Desktop\ for Windows Vista, Windows 7, and Windows 8.

%CommonAppData% refers to the Application Data folder for the All Users Profile. By default, this is C:\Documents and Settings\All Users\Application Data for Windows 2000/XP and C:\ProgramData\ in Windows Vista, Windows 7, and Windows 8.

%CommonStartMenu% refers to the Windows Start Menu for All Users. Any programs or files located in the All Users Start menu will appear in the Start Menu for all user accounts on the computer. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Start Menu\, and for Windows Vista, Windows 7, and Windows 8 it is C:\ProgramData\Microsoft\Windows\Start Menu\.

%CommonAppData% refers to the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Application Data\, and for Windows Vista, Windows 7, and Windows 8 it is C:\ProgramData.

Monday, August 12, 2013

Remove PC Defender 360Remove PC Defender 360

Remove PC Defender 360
PC Defender 360 is a fake antivirus which will infect the computer after a Trojan opens a backdoor on the computer. Normally this program is installed to the computer without the permission of the users when they visit some websites. PC Defender 360 start automatically when the computer boot. It will scan the infected computer and shows that the computer has been infected by many malwares. In fact, the computer is infected by itself! Then, PC Defender 360 will persuade the user to purchase the license in order to activate it. This fake antivirus should be removed immediately.

PC Defender 360 provide fake features such as Scan your PC, Internet Security, Personal Security, Proactive Defence, Firewall, Update, Configuration etc. All of them cannot protect computer from any kind of malware.

PC Defender 360 can be removed by stopping its processes [random].exe and the user should remember to kill the file. The registry settings should be restored by following the removal guide below.

PC Defender 360 must be removed from your computer immediately!

Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe

Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ifdstore
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "4g"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = ""%CommonAppData%\ifdstore\pcdefender.exe" /ex "%1" %*"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "idefsvc" = "%CommonAppData%\ifdstore\pcdefender.exe /min"

Remove Folders and Files
%CommonAppData%\ifdstore
%CommonStartMenu%\Programs\PC Defender 360
%Desktop%\PC Defender 360.lnk


Sunday, July 28, 2013

Attentive AntivirusAttentive Antivirus

Remove Attentive Antivirus
Attentive Antivirus is a fake antivirus program that produce fake alert that there are several vulnerabilities are detected in the computer which Attentive Antivirus is installed. Attentive Antivirus installs into the computer and will configure itself to start automatically (in registry) when Windows boot. Attentive Antivirus will scan the computer and WILL SURELY detect many malwares in the computer. In fact, it is just a fake alert. The intention of Attentive Antivirus is to urge the user to register Attentive Antivirus by purchasing the full version of Attentive Antivirus so that to earn some money from the user. Attentive Antivirus cannot detect and remove any malware / virus / trojan.


Attentive Antivirus can be removed by stopping the processes and removing the files by using Emsisoft HiJackFree. Then the user should remove the registry entries added or modified by Attentive Antivirus shown in the removal guide below. All files related to Attentive Antivirus must be deleted. Attentive Antivirus provide fake features such as Scan PC, Quarantine, Updates, Memory Protection, File System, Anti-Spyware and even Firewall, but none of them can really protect the computer from any kind of malwares.

Attentive Antivirus should be removed immediately!

Attentive Antivirus Removal Guide
Kill Process
(How to kill a process effectively?)
WaDprnV7.exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AA2014" = "%CommonAppData%\WaDprnV7\WaDprnV7.exe"

Remove Folders and Files
%CommonAppData%\WaDprnV7