Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 4 April 2012

Removing Advanced Antispyware Solution (Uninstall Guide)

Posted on 10:44 by Unknown
If you are a regular visitor to our blog you probably noticed that the last few weeks had been a bit slow compared to the previous months. This is mostly due that we have been working on other projects. Besides, the volume of actively spread rogue security products has decreased significantly over the past few weeks, at least in some regions, which is a good thing after all. However, malware authors will probably exploit Easter just like any other special event to send out rogue security programs and other malicious software. Malware may show up in Easter greeting cards and images, so please be very cautious when downloading and opening Easter greeting cards, especially this weekend. Cyber crooks are already distributing new rogue security programs and will probably double the number of new malware samples this weekend.



Ok, so today we are looking at a new rogue security program called Advanced Antispyware Solution. As far as we can tell, this rogue security program is being delivered through Twitter spam messages that lead to fake Windows Antivirus 2012 online scanners. All the domains that were found distributing this malware had .info TLDs. Some of the popular registrars offered .info domains for under $5 or less, so cyber crooks apparently bought lots of .info domains as well.

Advanced Antispyware Solution reports non-existent malware infections and displays lost of fake and very annoying security alerts to make you think that your computer is infected. All the rogue applications from the FakeVimes family, we've seen more than ten this year so far, share common characteristics. Once installed, Advanced Antispyware Solution drops several absolutely harmless files on the compromised computer. The rogue program later pretends to scan the compromised computer for malware and once the 'scan' is finished, it flags those files as dangerous. A funny things is that this rogue anti-spyware drops and detects exactly the same files on each and every compromised machine.

Fake security alerts are rather well designed and may look like a real thing for unsuspecting computer users despite the fact people are being exposed to technology like never before. Here are some of the fake security alerts you may see when your computer is infected with Advanced Antispyware Solution scareware:





What is more, this malware may block Windows system utilities and genuine malware removal tools. Some variants of this malware may modify Windows host file and redirect users to misleading websites. We will show you how to restore the Windows Host file in the removal guide below. You should scan your computer for rootkits as well, because removing Advanced Antispyware Solution won't help you much if you won't get rid of rootkits. You can remove this rogue anti-spyware program using legit anti-malware software recommended in the removal guide below. Follow the steps in the removal guide very carefully. If you need help removing this malware from your computer, please leave a comment. Good luck and be safe online!


Advanced Antispyware Solution removal guide:

1. Click on Help and select Activate Now.



2. Enter one the following debugged registration keys and click Activate to register the rogue antivirus program. Don't worry, this is completely legal since it's not genuine software.

U2FD-S2LA-H4KA-UEPB
K7LY-H4KA-SI9D-U2FD
K7LY-R5GU-SI9D-EVFB



2. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this malware from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.

Source: http://deletemalware.blogspot.com


Associated Advanced Antispyware Solution files and registry values:

Files:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]\
  • %AppData%\Advanced Antispyware Solution\
  • %AppData%\Microsoft\Internet Explorer\Quick Launch\Advanced Antispyware Solution.lnk
  • %UserProfile%\Desktop\Advanced Antispyware Solution\
  • %UserProfile%\Start Menu\Advanced Antispyware Solution\
  • %UserProfile%\Start Menu\Programs\Advanced Antispyware Solution.lnk
Registry values:
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\Advanced Antispyware Solution = "%AllUsersProfile%\Application Data\34g561\AV62c_8538.exe" /s /d
  • HKEY_CURRENT_USER\software\3
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\[RANDOM].exe\Debugger = svchost.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun = 01000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\[1...15]
Tell your friends:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Rogue programs | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • How to remove 'TidyNetwork' adware virus from your computer
    As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ▼  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ▼  April (7)
      • Backdoor.Multi.Zaccess.gen Removal Instructions
      • How to Remove Data Recovery (Uninstall Guide)
      • Remove Malware Belonging to The Family FakeVimes (...
      • Remove Searchnu (Uninstall Guide)
      • Fake Windows Antivirus 2012 (Uninstall Guide)
      • Remove Happili Redirect Virus (Uninstall Guide)
      • Removing Advanced Antispyware Solution (Uninstall ...
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile