Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 28 July 2012

Remove Windows Ultra Antivirus (Uninstall Guide)

Posted on 10:30 by Unknown
It's been a while since we've last seen a rogue security program from scareware families other that Fakevimes and Winwebsec. Ransomware applications have been roaming around the net for a while replacing (only partly) fake antivirus programs. Our guess is that ransomware scams became more profitable than rogue AVs. However, yesterday we stumbled upon a new rogue anti-virus program called Windows Ultra Antivirus which only proves that affiliate scareware networks are still active and not leaving anytime soon.



Windows Ultra-Antivirus is not a particularly nasty piece of malware. It's a typical fake antivirus program which claims that your computer is infected with viruses. Once installed, the rogue program pretends to scan your machine for malicious software. It randomly displays genuine Windows files and assigns assumed malware infections for each of those files. The rogue program rarely detects less then ten malware infections even on a perfectly clean computer with freshly installed Windows on it.

Unlike most fake antivirus programs, Windows Ultra Antivirus provides short threat descriptions for all the infections found during the scan. Not sure why malware authors did that but again we can guess they are trying to drive more sales by adding some extra reliability to their useless software.

Win32/Exploit.CVE-2010-3333.0 threat description:



Win32/Agent.TMP threat description:



Windows Ultra Antivirus is promoted through the use of fake online virus scanners and Trojan horses that masquerade as a legitimate Microsoft updates. The rogue application is configured to run automatically when Windows starts. The most worrying part is a rookit infection which comes bundled with this fake antivirus program. The malicious randomly named .sys file is dropped in C:\WINDOWS\system32\drivers folder. The file is locked so you can’t remove it manually.



In our case, the rootkit was detected as Gen:Variant.Zusy.8505 by GData ((Engine A).

Startup properties:
HKLM\SYSTEM\ControlSet001\Services\52fb2397ad5bf9eb\

The Windows Ultra Antivirus itself was detected as Trojan.FakeAlert.CYD, BackDoor.Bulknet.713, and Trojan-Dropper!IK by three different antivirus engines.

Normally, in order to remove found malware, victims are asked to purchase rogue AV programs. Windows Ultra-Antivirus scam works the same way but the problem is that at least at the time we tested this scareware, the payment page was unavailable.

hxxp://www.zokaisoft.com/payments/buynow.php?vendorId=1



So, it’s either a sign of a poorly organized scareware attack or they have some serious problems with payment processing.

Zokaisoft.com was registered by Aleksandr Bakcheev from Russia just a few weeks ago. But the whois information is probably false. We don't think such person even exists, unless cyber criminals used stolen credit card and personal details to register this domain.

So, what to do if you got infected by this annoying malware? First and foremost, do not attempt to remove Windows Ultra Antivirus manually. If you don't remove all malware components, malware authors can do anything while on your computer including reading your key strokes and getting personal identification information. To remove this malware from your computer properly, please follow the removal instructions below. Comments and questions are welcome. Good luck!


Windows Ultra Antivirus removal instructions:

1. First of all, we need to remove the rootkit. Download TDSSKiller and save it on your desktop.

2. Double-click on it to start TDSSKiller. NOTE: sometimes, rootkits block this utility to avoid removal. If you can't run this utility, simply rename tdsskiller.exe to iexplore.exe and run it again.

3. Once started, TDSSKiller may display an error message stating that it Can't Load Driver. Don't worry about that, simply click OK to continue.



4. Click on the Start Scan button to begin scanning your computer for rootkits.



5. When the scan is over, the utility outputs a list of detected objects with description. You should see a locked service which is the actual rootkit we need to remove.

Choose to Delete this rootkit and click on the Continue to remove delete the rootkit.



6. A reboot might require after disinfection. Click on the Reboot computer button.



7. TDSSKiller will now reboot your computer, but instead going into normal Windows mode reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

8. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus and associated malware from your computer.

NOTE: don't forget to update anti-malware software before scanning your computer.


Associated Windows Ultra Antivirus files and registry values:

Files:

Windows XP:
  • C:\Windows\System32\[SET OF RANDOM CHARACTERS].exe
  • C:\Windows\System32\drivers\[SET OF RANDOM CHARACTERS].sys
Registry values:
  • HHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
Tell your friends:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Rogue programs | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • WebCake Adware Removal Guide
    If you’re reading this it is very likely that your computer is infected with WebCake adware which displays extremely obnoxious and intrusiv...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ▼  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ▼  July (11)
      • Remove Windows Ultra Antivirus (Uninstall Guide)
      • SearchYa! Toolbar and Searchya.com (Uninstall Guide)
      • Boxore Adware (Uninstall Guide)
      • Remove Welcome to Nginx! (Uninstall Guide)
      • Remove Police Central e-crime Unit Virus (Uninstal...
      • Remove International Police Association (I.P.A.) V...
      • Remove MyStart by IncrediBar Search and Toolbar (U...
      • Apple Computers ARE Susceptible After All
      • Remove "File Recovery" Malware (Uninstall Guide)
      • Effective Network Internet Control for Effective S...
      • Remove FBI MoneyPak Ransomware (Uninstall Guide)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile