Tag Archives: computer

How to remove Antivirus Soft

Antivirus Soft is malicious software from the family of Antivirus Live. This malware makes entry in your PC without letting you think about it. These infections are installed in PC with help of malicious PDF file which are responsible to corrupt older versions of adobe reader. Antivirus soft malware also spread through scamming sites and social networking sites.

Once this software is installed, it continues to update itself automatically whenever you logs in your window and go online. This malware shows numerous infections which are fake and do not actually exist.

When you will be running, Antivirus Soft they display fake security alerts on the infected computer. The text of some of these alerts are:
. Antivirus Software Alert
. Infiltration Alert
. Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan-dropper or similar.
. Threat: Win32/Nuqel.E

This program uses aggressive techniques to protect itself from being removed by anti-malware programs. Such as –

. When the Antivirus Soft process is running it will close all the running programs by falsely stating that these programs are infected.
. This malware also changes the proxy settings in IE which prevents you from browsing any other site than Antivirus Soft. This is done to force user to purchase this malicious software.

How to Remove it

This malware can hamper your entire computer activity. If you are finding yourself stuck in similar situation, you can use following steps to remove this malware from your PC –

1. Restart your computer. This is important to work on PC in a safer atmosphere. The moment computer restarts, press “F8& 8243; key constantly. Now, use the arrow keys to highlight the “Safe Mode with Networking” option, and then press ENTER.
2. Now Open Internet Explorer, click on the ‘Tools menu’ and then select Internet Options.
3. In the Internet Options window click on the ‘Connections’ tab, which would be followed by a click on the LAN settings button.
4. Now you will see Local Area Network (LAN) settings window. Uncheck the checkbox labeled Use a proxy server for your LAN under the Proxy Server section and press OK.
5. To be more protected, download an automatic virus removal tool which you can find online. There are numbers of automatic removal tool available. After downloading a good tool, run the full system scan and remove detected files.

Antivirus Soft manual removal:
Kill processes:
[RANDOM CHARACTERS]sysguard.exe, for example ghrtsysguard.exe [RANDOM CHARACTERS]sftav.exe
HELP:

Delete registry values:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun “”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments “SaveZoneInformation” = “1& 8243;
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyServer” = “http=127.0.0.1:5555& 8243;
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAssociations “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload “RunInvalidSignatures” = “1& 8243;
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyOverride” = “”
HKEY_CURRENT_USERSoftwareAvScan
HELP:

Delete files:
Windows XP: %UserProfile%\Local Settings\Application Data\\[RANDOM CHARACTERS]sysguard.exe Windows Vista and Windows 7: %UserProfile%\AppData\Local\\[RANDOM CHARACTERS]sysguard.exe %UserProfile%\AppData\Local\\[RANDOM CHARACTERS]sftav.exe
HELP:

Delete directories:
%UserProfile%Local SettingsApplication Data[RANDOM CHARACTERS] (Win XP)
%UserProfile%AppDataLocal\ (Win Vista & 7)

How to remove Antivirus Soft

Antivirus Soft is malicious software from the family of Antivirus Live. This malware makes entry in your PC without letting you think about it. These infections are installed in PC with help of malicious PDF file which are responsible to corrupt older versions of adobe reader. Antivirus soft malware also spread through scamming sites and social networking sites.

Once this software is installed, it continues to update itself automatically whenever you logs in your window and go online. This malware shows numerous infections which are fake and do not actually exist.

When you will be running, Antivirus Soft they display fake security alerts on the infected computer. The text of some of these alerts are:
. Antivirus Software Alert
. Infiltration Alert
. Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan-dropper or similar.
. Threat: Win32/Nuqel.E

This program uses aggressive techniques to protect itself from being removed by anti-malware programs. Such as –

. When the Antivirus Soft process is running it will close all the running programs by falsely stating that these programs are infected.
. This malware also changes the proxy settings in IE which prevents you from browsing any other site than Antivirus Soft. This is done to force user to purchase this malicious software.

How to Remove it

This malware can hamper your entire computer activity. If you are finding yourself stuck in similar situation, you can use following steps to remove this malware from your PC –

1. Restart your computer. This is important to work on PC in a safer atmosphere. The moment computer restarts, press “F8& 8243; key constantly. Now, use the arrow keys to highlight the “Safe Mode with Networking” option, and then press ENTER.
2. Now Open Internet Explorer, click on the ‘Tools menu’ and then select Internet Options.
3. In the Internet Options window click on the ‘Connections’ tab, which would be followed by a click on the LAN settings button.
4. Now you will see Local Area Network (LAN) settings window. Uncheck the checkbox labeled Use a proxy server for your LAN under the Proxy Server section and press OK.
5. To be more protected, download an automatic virus removal tool which you can find online. There are numbers of automatic removal tool available. After downloading a good tool, run the full system scan and remove detected files.

Antivirus Soft manual removal:
Kill processes:
[RANDOM CHARACTERS]sysguard.exe, for example ghrtsysguard.exe [RANDOM CHARACTERS]sftav.exe
HELP:

Delete registry values:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun “”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments “SaveZoneInformation” = “1& 8243;
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyServer” = “http=127.0.0.1:5555& 8243;
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAssociations “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload “RunInvalidSignatures” = “1& 8243;
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings “ProxyOverride” = “”
HKEY_CURRENT_USERSoftwareAvScan
HELP:

Delete files:
Windows XP: %UserProfile%\Local Settings\Application Data\\[RANDOM CHARACTERS]sysguard.exe Windows Vista and Windows 7: %UserProfile%\AppData\Local\\[RANDOM CHARACTERS]sysguard.exe %UserProfile%\AppData\Local\\[RANDOM CHARACTERS]sftav.exe
HELP:

Delete directories:
%UserProfile%Local SettingsApplication Data[RANDOM CHARACTERS] (Win XP)
%UserProfile%AppDataLocal\ (Win Vista & 7)

How to Remove Security Essentials 2010

Security Essential 2010 is a rogue anti-spyware program from the family of Internet Security 2010. This malware is installed in PC by Trojans which pretend to be Flash update claiming to be an essential software to view video online. When a user clicks on this so-called ‘Flash Update’ program, instead of helping in watching videos online, it installs other malware and spyware in the PC.

As an example – C:WINDOWSsystem32smss32.exe is a similar Trojan that hijacks desktop with security warning, displays pop-ups with messages ‘you are infected’ which are actually fake messages. And at last it installs Security Essentials 2010.

While Security Essentials 2010 is running, you will be shown nag screens and fake security warnings from Windows task bar. Some of the warnings:

System Warning:
. Continue working in unprotected mode is very dangerous.
. Viruses can damage your confidential data and work on your computer.
. Click here to protect your computer.
. Intercepting programs that may compromise your privacy and harm your system have been detected on your PC.
. It’s highly recommended you scan your PC right now.

Danger quotient – Once Security Essentials 2010 gets installed on your PC, it automatically starts updating itself the moment you logs in. This also shows off pop-ups stating about numerous infections on your PC. When you try to uninstall of remove this program, it flaunts a message that says “you need to purchase the program first in order to remove it.” But all such messages are fraudulent acts which at the end of the day result in your loss.

Security Essentials 2010 files and registry values:

Files:
. C:WINDOWSsystem32warnings.html
. C:WINDOWSsystem32helpers32.dll
. C:WINDOWSsystem32winlogon32.exe
. C:WINDOWSsystem32smss32.exe
. C:WINDOWSsystem3241.exe
. %Temp%250904.exe
. %StartMenu%Security essentials 2010.lnk
. %Desktop%Security essentials 2010.lnk
. C:ProgramFilesSecurityessentials2010SE2010.exe

Registry keys and values:

. HKEY_CURRENT_USERSoftwareSE2010
. HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
. “Security essentials 2010”
. HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “smss32.exe”

How to remove it – There are many steps that can be conducted to remove security Essentials 2010 from your PC.

1. Reboot your computer is “Safe Mode with Networking”. As the computer is booting tap the “F8 key” continuously which should bring up the “Windows Advanced Options Menu” as shown below. Use your arrow keys to move to “Safe Mode with Networking” and press Enter key.

2. Download one of the good and legitimate anti-malware applications and run a quick system scan. Don’t forget to update it first. All programs a free.