Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 1 September 2012

Remove Win 8 Security System (Uninstall Guide)

Posted on 10:54 by Unknown
We came across a new rogue security program called Win 8 Security System a few days ago. It's been quite some time since we discussed rogue anti-virus software. The truth is there wasn't much to say about scareware apart from some slightly modified or extremely buggy pieces of malicious code that couldn't even load properly. Anyway, rogue security products are not completely gone yet but rather replaced with ransomware. On the other hand, second opinion malware scanners confirm that rogue security programs are still the most widely spread threats, holding the top positions. What that means? Well, it means that most antivirus programs fail to detect rogue AVs, especially those that are obfuscated and re-packed very often, sometimes a couple of times a day.



So, Win 8 Security System is a rogue antivirus program that reports non-existent computer infections and tries to scare less computer savvy users into paying for completely useless antivirus solution. In most aspects, it's a very typical rogue. Win 8 Security System is a very generic term too. As the name suggests, cyber crooks would infect machines running Windows 8 rather than Windows XP or Seven. However, this rogue antivirus program works just fine on different versions of Windows.



Once installed, the rogue program pretends to scan the computer for malicious software. It manages to find a bunch of extremely dangerous and sophisticated malware on perfectly clean computers. The way it presents supposedly infected files would definitely put a smile on your faces if you were security expert. In order to remove supposedly detected malware infections victim has to pay almost 100 bucks. That’s probably the most expensive antivirus software you’ve ever seen.

The rogue antivirus program is configured so that it runs automatically when Windows starts. But that's not the biggest problem. Win 8 Security System has a rather complex self-protection mechanism. It drops a rootkit on infected machine which monitors PC activity and blocks pretty much all attempts to terminate the rogue program or run legitimate antivirus software. This scareware doesn't block Task Manager or Registry editor but that changes nothing. You can't just simply end the offending process and delete associated files. Any attempt to end its process will trigger the following error message.


The operation could not be completed. Access denied.


The file is locked and protected by the rootkit known as Rootkit.Win32.Necurs.gen. As a matter of fact, detection rates are amazingly low for this rootkit. Cyber crooks did a great job and apparently spent many hours fine-tuning this malware. What is more, crooks made a different rootkit which works on 64-bit systems. It even has a valid certificate. Such combination can be very successful which means it's along term investment. We will probably see new variants of this malware soon and that's not very exciting.

When running, Win 8 Security System displays fake security alerts and pop-ups, mostly claiming that your computer is infected with spyware and Trojans that can steal your sensitive information. Simply ignore those fake alerts.





Furthermore, the rogue program displays a fake Security Center window claiming that your computer is not protected and encouraging you to purchase the full version of Win 8 Security System to protect your computer from malware attacks that exploit software vulnerabilities. For Windows Seven and Windows 8 the rogue program displays a fake Action Center window.



Last, but not least, the rogue program displays fake Win 8 Security System ALERT in Internet Explorer, Mozilla Firefox, and Google Chrome. The fake web browser security alerts claims that the website you're about to visit is infected with malware. If you choose to continue surfing the web unprotected you will be able to access requested website but only for a short period of time, then the fake warning message will appear again. Anyhow, it's still better than having no access to your web browser whatsoever.



Here's an example of Win 8 Security System payment page. As you can see in the image below, cyber crooks added to Comodo safe site graphics to make the payment page look more reliable and professional. Of course, the payment page is hardly safe. DO NOT pay for the bogus security program.



The official website of this malware is win8sec.com. Do not download anything from this site, don't even visit it. Even better, add it to the list of potentially harmful sites.

To remove Win 8 Security System, please follow the removal instructions very carefully. Use at your own risk. If you have any questions, feel free to comment. Good luck and be safe online!

Source: http://deletemalware.blogspot.com


Quick Win 8 Security System malware removal using cracked key:

1. Use the activation key given below to register your copy of Win 8 Security System. This will allow you to download and run recommended malware removal software. Don't worry, you're not doing anything illegal.

Select "Registration".



Then select "Manual Activation".



Use the following activation key:

8F42D6E3-FD18



Click "Register".

2. Download TDSSKiller and run a system scan to remove Rootkit.Win32.Necurs.gen. Reboot your computer if required.



NOTE: You may get the following TDSSKiller error. Ignore it, click OK to continue.



3. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove Win 8 Security System and associated malware from your computer.


Win 8 Security System in Safe Mode with Networking:

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Open Internet Explorer. Download exefix.reg and save it to your Desktop. Double-click on exefix.reg to run it. Click "Yes" for Registry Editor prompt window. Click OK.

3. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove Win 8 Security System from your computer.

NOTE: don't forget to update anti-malware software before scanning your computer.
    Tell your friends:
    Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
    Posted in Rogue programs | No comments
    Newer Post Older Post Home

    0 comments:

    Post a Comment

    Subscribe to: Post Comments (Atom)

    Popular Posts

    • What is wrtc.exe and how to remove it?
      wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
    • Remove ShopperReports (Uninstall Guide)
      ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
    • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
      Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
    • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
      This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
    • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
      RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
    • Remove Rattlingsearchsystem.com (Uninstall Guide)
      Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
    • Remove TR/ATRAPS.Gen2, removal instructions
      Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
    • Remove Ask Search and Ask Toolbar (Uninstall Guide)
      Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
    • How to remove 'TidyNetwork' adware virus from your computer
      As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
    • Remove Windows Attention Utility (Uninstall Guide)
      Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

    Categories

    • Adware
    • Answers
    • Antivirus software
    • Browser Hijackers
    • Cloud Computing
    • Fake Alerts
    • Giveaways
    • Hoax
    • How-To
    • IaaS
    • Internet
    • Malicious websites
    • Malware
    • PaaS
    • Parental Controls
    • Passwords
    • Phishing
    • Process Information
    • Ransomware
    • Rogue programs
    • Rootkits
    • SaaS
    • Security Advisories
    • Spam
    • Spyware
    • Trojans
    • Viruses
    • Web Browsers
    • Worms

    Blog Archive

    • ►  2013 (173)
      • ►  December (6)
      • ►  November (13)
      • ►  October (11)
      • ►  September (20)
      • ►  August (4)
      • ►  July (17)
      • ►  June (31)
      • ►  May (25)
      • ►  April (15)
      • ►  March (17)
      • ►  February (7)
      • ►  January (7)
    • ▼  2012 (86)
      • ►  November (2)
      • ►  October (4)
      • ▼  September (6)
        • Remove click.get-amazing-results.com redirect viru...
        • Remove click.gethotresults.com redirect virus (Uni...
        • Remove System Progressive Protection (Uninstall Gu...
        • Remove Yontoo Adware (Uninstall Guide)
        • Den Svenska Polisen IT-Sakerhet Ukash - how to remove
        • Remove Win 8 Security System (Uninstall Guide)
      • ►  August (6)
      • ►  July (11)
      • ►  June (1)
      • ►  May (5)
      • ►  April (7)
      • ►  March (7)
      • ►  February (17)
      • ►  January (20)
    • ►  2011 (239)
      • ►  December (8)
      • ►  November (18)
      • ►  October (21)
      • ►  September (24)
      • ►  August (28)
      • ►  July (32)
      • ►  June (16)
      • ►  May (23)
      • ►  April (15)
      • ►  March (16)
      • ►  February (9)
      • ►  January (29)
    • ►  2010 (2)
      • ►  December (2)
    Powered by Blogger.

    About Me

    Unknown
    View my complete profile