Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 28 September 2011

Remove Advanced PC Shield 2012 (Uninstall Guide)

Posted on 13:14 by Unknown
Advanced PC Shield 2012 is a rogue anti-virus program meant to scare you into thinking that your computer is infected with Trojans, spyware and other malicious software, according to malekal.com. It may display pop-ups saying that malicious software has been detected on your computer. It then may redirect you to a website where you can purchase the rogue program in order to remove viruses and to protect your computer against emerging threats. Do not purchase this bogus software and do not share personal information like passwords, credit card numbers, etc., with cyber crooks. It won't protect your computer against malware anyway. Advanced PC Shield 2012 may block system utilities and legitimate anti-virus software as well. We can confirm that there is no legitimate security product with such a name on the market. If your computer is infected with Advanced PC Shield 2012, please follow the steps in the removal guide below.



Update (4:15 PM EDT): We received an email from our reader Colin saying that his laptop has just got infected with a virus called Advanced PC Shield 2012. The following files have been contributed by our reader:
  • C:\Documents and Settings\Colin\Start Menu\Programs\Advanced PC Shield 2012\Buy Advanced PC Shield 2012.lnk
  • C:\Documents and Settings\Colin\Start Menu\Programs\Advanced PC Shield 2012\Launch Advanced PC Shield 2012.lnk
  • C:\Documents and Settings\Colin\Desktop\Buy Advanced PC Shield 2012.lnk
  • C:\Documents and Settings\Colin\Local Settings\Application Data\gr5291f5w5071a02.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "gr5291f5w5071a02.exe"
The fake program attempted the following network connection: 178.162.174.147. It appears to be a control center.

Update (4:23 PM EDT):
Virustotal.com results: 2 /42
MD5: 4182cf81203e73ef44e642214b04d712
http://www.virustotal.com/file-scan/report.html?id=06b773f3a121851b9919e905b925721c2b2189372f407085aec611727f18e2a0-1317223457


Update (7:56 PM EDT):
Advanced PC Shield 2012 displays the following fake security alerts:
Severe system damage!
Spyware and viruses detected in the background. Sensitive system components under attack! Data loss, identity theft and system corruption are possible.
Act now, click here for a free security scan.

Tracking software found!
Your PC activity is being monitor. Possible spyware infection. Your data security may be compromised. Sensitive data can be stolen.
Prevent damage now by completing a security scan.






This scarware reports the same infections on different computers. It doesn't actually scan your computer. Advanced PC Shield 2012 reports the following infections:
  • Java.Trojan.Downloader.OpenConnection
  • Trojan.Spy.ZBot
  • Worm.P2P.Pron
  • Exploit.CplLnk.Gen
  • Win32.Worm.Prolaco
  • Trojan.Android.Geinimi
  • Backdoor.Destroy
  • AprNet-Worm.Win32.Kolab
  • Win32.Worm.Stuxnet
  • Trojan.MSIL.Agent
  • Trojan.Win32.Agent
  • Trojan.Spy.Ursnif
  • Win32.Ramnit
  • Java.Backdoor.ReverseBackdoor
  • Backdoor.Bifrose
  • Backdoor.Win32.Rbot
  • AprWorm.Win32.Agent
  • Trojan.Win32.Qhost
  • wscui_class
The rogue application displays fake Windows Security Center screen and fake BSOD.



Cyber crooks offer online support too. You can leave a ticket at advancedpc.coguar-systems-support.info. There's a great chance that they will actually help you, however, any any payment-related questions are usually ignored.



Although, Advanced PC Shield 2012 doesn't block malware removal tools, at least the current version, you can still activate it manually and make the removal procedure easier in case you got more aggressive version of this fake anti-virus product. Just click on Registration and select Manual Activation. Then use the following code: 8945315-6548431



However, the biggest problem is that Advanced PC Shield 2012 drops a rootkit (Trojan:WinNT/Necurs) that blogs legitimate anti-virus programs and makes it difficult to remove the infection from the computer. Hopefully, you can use TDSSKiller to remove rootkits from your computer. Otherwise, you'll have to use Combofix. For more information, please follow the removal instructions below.


Advanced PC Shield 2012 removal instructions:

1. Download ComboFix from one of the following URL: http://www.bleepingcomputer.com/download/anti-virus/combofix
2. Temporarily disable your anti-virus and anti-spyware programs as they may may interfere with Combofix.
3. Double-click on the ComboFix to run the utility. Please read the disclaimer and if you agree, click on the I Agree button.



4. ComboFix is now preparing to run. It may take a few moments. ComboFix will create a System Restore and prompt you to install Microsoft Windows Recovery Console. Please click on the Yes button to continue.



5. Please follow the directions given by ComboFix in order to finish the installation of the Microsoft Windows Recovery Console. Once finished, click on the Yes button to scan your computer for malware.



6. ComboFix will now start scanning your computer for malicious software. This may take up to ten minutes.



7. When ComboFix has finished, it may automatically reboot your computer. Don't worry, that's OK. Just don't reboot your computer manually. After a reboot it will show a log file. Advanced PC Shield 2012 should be gone from your computer.

8. Download free anti-malware software from the list below and run a full system scan to remove the remains.
  • MalwareBytes Anti-malware
  • SUPERAntispyware
  • Spybot S&D
  • Hitman Pro 3.5
NOTE: with all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.


Associated Advanced PC Shield 2012 files and registry values:

Files:

Windows XP:
  • %WINDIR%\SYSTEM32\drivers\[SET OF RANDOM CHARACTERS].sys
  • %UserProfile%\Start Menu\Programs\Advanced PC Shield 2012\Buy Advanced PC Shield 2012.lnk
  • %UserProfile%\Local Settings\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UserProfile%\Desktop\Buy Advanced PC Shield 2012.lnk
  • %UserProfile%\Start Menu\Programs\Advanced PC Shield 2012\Launch Advanced PC Shield 2012.lnk
%WINDIR% refers to: C:\WINDOWS
%UserProfile% refers to: C:\Documents and Settings\[User Name]

Windows Vista/7:
  • %WINDIR%\SYSTEM32\drivers\[SET OF RANDOM CHARACTERS].sys
  • %UserProfile%\Start Menu\Programs\Advanced PC Shield 2012\Buy Advanced PC Shield 2012.lnk
  • %UserProfile%\Local Settings\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UserProfile%\Desktop\Buy Advanced PC Shield 2012.lnk
  • %UserProfile%\Start Menu\Programs\Advanced PC Shield 2012\Launch Advanced PC Shield 2012.lnk
%WINDIR% refers to: C:\WINDOWS
%UserProfile% refers to: C:\Users\[User Name]

Registry values:
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[SET OF RANDOM CHARACTERS]
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1 "*" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1 ":Range" = '127.0.0.1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with your friends:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Rogue programs | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • How to remove 'TidyNetwork' adware virus from your computer
    As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ▼  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ▼  September (24)
      • How to Remove Security Sphere 2012 (Uninstall Guide)
      • Remove Advanced PC Shield 2012 (Uninstall Guide)
      • Notification of Limited Account Access - PayPal Ph...
      • Remove Ask Search and Ask Toolbar (Uninstall Guide)
      • Cyberbullying
      • Facebook Price Grid Hoax
      • ZeroAccess/Sirefef/MAX++ Rootkit Removal Tool
      • Remove Startsear.ch and search.searchcompletion.co...
      • Remove Babylon Toolbar and "Search the web (Babylo...
      • Seeearch.com Browser Hijacker (Uninstall Guide)
      • Remove Classysearchserver.com (Uninstall Guide)
      • Remove Coolsearchserver.com (Uninstall Guide)
      • Remove Excellentsearchserver.com (Uninstall Guide)
      • Windows заблокирован! Ransomware (Uninstall Guide)
      • Remove Bigseekpro.com and Somoto.com Toolbar (Unin...
      • Apple - Important information about your Apple ID
      • Remove Webplains.net (Uninstall Guide)
      • Remove *dayoftheweek.com (Uninstall Guide)
      • Remove Chit Chat (Uninstall Guide)
      • Remove La policía ESPAÑOLA Ransomware (Uninstall G...
      • How to Remove "System Recovery" (Uninstall Guide)
      • How to Remove OpenCloud Security (Uninstall Guide)
      • How to Remove Master Utilities (Uninstall Guide)
      • Remove Bandoo (Uninstall Guide)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile