Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 9 December 2013

Squirrel Web Removal Guide

Posted on 11:34 by Unknown
Squirrel Web is an adware program that is bundled along with free software that you download from the Internet. Usually, such adware programs are distributed through popular software download websites and fake web pages claiming that you need to update your Flash Player or Java. Be aware of these download traps. As you may already know, some free downloads do not adequately disclose that adware or even spyware will also be installed and you may find that you have installed SquirrelWeb without your knowledge. Squirrel Web displays advertisements, banners and coupons for sites you are visiting that would not otherwise appear at sites like Amazon, Ebay or BestBuy. Though this may sound like a useful service, the program can be intrusive and will display ads whether you want them to or not. It can also convert words on pages you view into hyperlinks that are linked to advertisements. Furthermore, it constantly communicates with third-party servers to check for new offers using updateSquirrelWeb.exe (PUP.Optional.Squirrelweb.A) program which runs automatically when Windows starts. This guide will walk you through removing Squirrel Web from your computer and web browsers.

Here's an example of the Squirrel Web ads that were injected at the top of Google search results when I searched for iPhone.


And here's another block of ads 'Powered by SquirrelWeb' at the bottom of the page.


It also injects ads on other webpages you visit, the ads are usually labeled 'Ads by SquirrelWeb'. You will notice them right away because they are kind of annoying and sometimes even intrusive. You may also get a huge ad popup labeled 'Topic Torch by SquirrelWeb', you may opt-out but it would be better to remove this adware program instead of simply disabling it for a while. Please note that Squirrel Web can also monitor and record certain information when you are browsing the Internet. So, it's not just adware it's also spyware. Of course, it's not a computer infection that is installed through exploits or infections, but it's advised that you remove it from your computer.

Written by Michael Kaur, http://deletemalware.blogspot.com


Squirrel Web removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this infection. Hopefully you won't have to do that.





2. Remove Squirrel Web program from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove the following SquirrelWeb.



If you are using Windows Vista, Windows 7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove Squirrel Web from Google Chrome:

1. Click on Chrome menu button. Go to Tools → Extensions.



2. Click on the trashcan icon to remove the SquirrelWeb 1.0.0 extension:




Remove Squirrel Web from Mozilla Firefox:

1. Open Mozilla Firefox. Go to Tools → Add-ons.



2. Select Extensions. Click Remove button to the SquirrelWeb 1.0.0 extension.




Remove Squirrel Web from Internet Explorer:

1. Open Internet Explorer. Go to Tools → Manage Add-ons. If you have the latest version, simply click on the Settings button.



2. Select Toolbars and Extensions. Click Remove/Disable button to remove the SquirrelWeb browser add-on.


Associated Scorpion Saver Files:
  • C:\Program Files\SquirrelWeb\updateSquirrelWeb.exe
  • C:\Program Files\SquirrelWeb\SquirrelWebBHO.dll
  • C:\Program Files\SquirrelWeb\SquirrelWeb.ico
  • C:\Program Files\SquirrelWeb\sqlite3.exe
  • C:\Program Files\SquirrelWeb\SquirrelWebUninstall.exe
Associated Scorpion Saver Windows Registry Information:
  • HKLM\Software\SquirrelWeb
  • HKCU\Software\SquirrelWeb
  • HKLM\SYSTEM\CurrentControlSet\Services\Update SquirrelWeb
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SquirrelWeb
Read More
Posted in Adware | No comments

Tuesday, 3 December 2013

What is levelqualitywatcher64.exe and how to remove it?

Posted on 10:03 by Unknown

levelqualitywatcher64.exe - Adpeak Service by Adpeak, Inc.


What is levelqualitywatcher64.exe?


levelqualitywatcher64.exe is a part of Level Quality Watcher adware. The program runs automatically on Windows start up. It creates a Windows service with the same name and attempts to access the internet, usually the advertising servers located at amazonaws.com. Firewall programs usually flag this file as potentially dangerous because it tries to download ads from third party servers. What is more, this program has been detected as malicious by multiple anti-virus scanners, Dr.Web, Sophos, ESET, Malwarebytes, just to name a few. It is usually detected as adware, PUP (PUP.Optional.Adpeak) and in some cases even as a Trojan horse (Trojan.DownLoader10.41037). One way or another, this application isn't essential for Windows and should be uninstalled. Keep in mind that it displays ads and may download and install additional malware on your computer. Even though, the file has a valid digital signature it's still a part of ad-supported application which not only displays advertisements but also gathers information about your browsing habits. Most of the time, this adware is bundled with spyware and other malware. It is promoted through the use of fake software updates webpages. If you found this program running in the background then your computer is infected with adware and spyware. I recommend you to remove levelqualitywatcher64.exe from your computer and run a full system scan with recommended anti-malware software.







File name: levelqualitywatcher64.exe
Publisher: Adpeak, Inc.
File Location Windows XP: %PROGRAM_FILES%\Level Quality Watcher\levelqualitywatcher64.exe
File Location Windows 7: %PROGRAM_FILES%\Level Quality Watcher\levelqualitywatcher64.exe
Startup file: HKLM\SYSTEM\ControlSet001\Services\Level Quality Watcher
Read More
Posted in Process Information | No comments

What is levelqualitywatcher32.exe and how to remove it?

Posted on 08:53 by Unknown

levelqualitywatcher32.exe - Adpeak Service by Adpeak, Inc.


What is levelqualitywatcher32.exe?


levelqualitywatcher32.exe is the main executable file of Level Quality Watcher adware. It's a part Adpeak adware family. The file runs automatically on Windows start up. It creates a Windows service with the same name and attempts to access the internet, usually the ad servers located at amazonaws.com. Firewall programs usually flag this file as potentially dangerous because it tries to download ads from third party servers. What is more, levelqualitywatcher32.exe has been detected as malicious by multiple anti-virus scanners, Dr.Web, Sophos, ESET, Malwarebytes, just to name a few. It is usually detected as adware, PUP (PUP.Optional.Adpeak) and in some cases even as a Trojan horse (Trojan.DownLoader10.41037). One way or another, this application isn't essential for Windows and should be uninstalled. Keep in mind that it displays ads and may download and install additional malware on your computer. Even though, the file has a valid digital signature it's still a part of ad-supported application which not only displays advertisements but also gathers information about your browsing habits. I recommend you to remove this adware from your computer and run a full system scan with recommended anti-malware software.







File name: levelqualitywatcher32.exe
Publisher: Adpeak, Inc.
File Location Windows XP: %PROGRAM_FILES%\Level Quality Watcher\LevelQualityWatcher32.exe
File Location Windows 7: %PROGRAM_FILES%\Level Quality Watcher\LevelQualityWatcher32.exe
Startup file: HKLM\SYSTEM\ControlSet001\Services\Level Quality Watcher
Read More
Posted in Process Information | No comments

What is adpeakproxy.exe and how to remove it?

Posted on 08:09 by Unknown

AdpeakProxy.exe - Adpeak Service by Adpeak, Inc.


What is adpeakproxy.exe?


AdpeakProxy.exe runs as a service named "AdpeakProxy". This service runs automatically when Windows starts. As a result your computer may become noticeably slower. This program is a part of Adpeak adware that installs malicious web browser extensions and applications: ScorpionSaver, GetSavin, DealCabby, and CouponAmazing. These programs deliver search-based ads. It can also redirect you to misleading websites and inject contextual ads. Adpeakproxy.exe has the ability to monitor and track your web browsing activity and to update itself without your permission or knowledge. The file is not digitally signed. It's usually located in C:\Program Files\ folder. I recommend you to remove adpeakproxy.exe and related adware from your computer. The program isn't essential for Windows and may cause problems. Since it comes bundled with spyware, please scan your computer with anti-malware software.







File name: adpeakproxy.exe
Publisher: Adpeak, Inc.
File Location Windows XP: C:\Program Files\[adware application]\adpeakproxy.exe
File Location Windows 7: C:\Program Files\[adware application]\adpeakproxy.exe
Startup file: SYSTEM\CurrentControlSet\Services 'AdpeakProxy'

Read More
Posted in Process Information | No comments

How to remove ScorpionSaver adware (Uninstall Guide)

Posted on 07:21 by Unknown
ScorpionSaver is adware installed by Adpeak. It can be installed on your computer without your knowledge when it is included with other software, for example Level Quality Watcher. Normally, this adware is promoted via software download websites. It could be a very reliable site like CNET or a fake Flash player update webpage, like this one. Once installed, this adware will slow down your computer and pass on your web browsing information to a third party. In addition, many websites and advertising banners set cookies on your system that track your web usage. Of course, it will display ads on your computer as well. You will see ads mostly on web stores. For example, if you are looking for a new laptop, you will get popup ads from ScorpionSaver with "deals" from other web stores and obviously from advertising partners. While some of those ads might be useful the majority of them will try to trick you into buying products or services from questionable companies. I wouldn't buy or download anything that is recommended by ScorpionSaver adware.


You may also see ads when using Google search. The image below illustrates how well this adware works. As you can see, a simple search for an iPhone triggered this adware and it displayed ads on Google search front page. It goes without saying that it's not just adware but also spyware.


ScorpionSaver removal might be a tricky task because you can't just rely on its uninstaller. Otherwise it will keep re-installing itself. It won't completely remove this adware from your computer. It will leave add-ons in web browsers and it won't uninstall additionally installed malware. ScorpionSaver web browser add-ons can access your data on all websites, read your browsing history and even access your browsing activity that's why you should remove them from your computer.


To avoid similar adware and spyware infections in the future, please do not download suspicious programs, and check programs before you install them. Often, choosing the advanced or custom install for software will allow you to de-select components and you can remove adware and spyware from the installation process. If a website asks you to download software you should leave it immediately unless you requested it.

Written by Michael Kaur, http://deletemalware.blogspot.com


ScorpionSaver removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this infection. Hopefully you won't have to do that.





2. Remove ScorpionSaver application from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove the following ScorpionSaver.



If you are using Windows Vista, Windows 7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove ScorpionSaver from Google Chrome:

1. Click on Chrome menu button. Go to Tools → Extensions.



2. Click on the trashcan icon to remove the ScorpionSaver 5.0 extension:




Remove ScorpionSaver from Mozilla Firefox:

1. Open Mozilla Firefox. Go to Tools → Add-ons.



2. Select Extensions. Click Remove button to the ScorpionSaver 5.0 extension.




Remove ScorpionSaver from Internet Explorer:

1. Open Internet Explorer. Go to Tools → Manage Add-ons. If you have the latest version, simply click on the Settings button.



2. Select Toolbars and Extensions. Click Remove/Disable button to remove the ScorpionSaver browser add-on.

Read More
Posted in Adware | No comments

Monday, 2 December 2013

Remove Level Quality Watcher, removal guide

Posted on 11:39 by Unknown
Simply put, Level Quality Watcher is adware. It's a part of Adpeak adware that is heavily promoted via software download sites and fake updates web pages. Once installed, it modifies Windows registry, adds a web browser add-on on all web browsers and starts a Windows service with administrator rights. This service runs every time Windows starts. Not only it makes your computer run slow but also establishes network connections with ad servers using either levelqualitywatcher32.exe or levelqualitywatcher64.exe programs depending on the Windows version you are using. It is currently being distributed via CNET and other popular download sites, so many users are facing the same nuisance to say the least. The biggest problem is that users cannot remove it by simply going into Control Panel because it's not listed there. To remove Level Quality Watcher adware from your computer, please use the removal guide below.


Keep in mind that once running, Level Quality Watcher displays advertisements, mostly popups. It may, however, display in-line ads and pop unders. At the time I was testing this adware on my computer it promoted a tech support service called "NP Call for great tech support". The ad appeared on pretty much every tech related website. At least it was relevant even though I didn't as for it. You may, however, get completely different ads based on browsing history and your location.


Multiple anti-virus scanners have detected it as adware, potentially unwanted application or even malware, including Sophos, Eset, Avast, Malwarebytes and some others. Needless to say, it's not useful and may be potentially dangerous, especially if you click on ads. Some of those ads are clearly misleading and may lead you to malicious websites and services. What is more, Level Quality Watcher is usually installed along with other adware and even spyware, for example BuzzSearch or Scorpion Saver. Scan your computer with anti-malware software to get this malware off your computer. If you have any questions, please leave a comment below. Good luck and be safe online!


Level Quality Watcher removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this infection. Hopefully you won't have to do that.





2. Open Windows services list. Open the Start Menu, type services.msc in the search box, press Enter.

3. Right click on the Level Quality Watcher and click Stop. Wait a sec for the service to stop, then close the Windows services window.



4. Open Registry Editor and navigate to: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Level Quality Watcher.



Right-click the Level Quality Watcher key and click Delete.

5. Delete the folder Level Quality Watcher located in Program Files.



That's it!
Read More
Posted in Adware | No comments

Friday, 15 November 2013

How to Remove Aartemis Portal Site (aartemis.com)

Posted on 12:00 by Unknown
Aartemis Portal Site is a brower hijacker that hijackers your homepage, changes default search engine provider and tracks your web searches. It's operated by Koyoter Technology, the same company that created Qvo6, Qone8 and Do-Search browser hijackers. This browser hijacker appends the command line argument http://aartemis.com/?type=sc&ts=[time stamp]&from=tugs&uid=[hardware ID] to web browser shortcuts which cause aartemis.com web page to open when you launch your web browser. It usually gets onto your computer through software downloads, even from reputable and well known websites or potentially unwanted installers like Firseria or DomaIQ. If there's an option not to install it, please select it, but unfortunately there are plenty of reports of Aartemis being loaded without permission.

Aartemis Portal Site

To remove Aartemis Portal Site from your computer you will have to uninstall associated applications through Control Panel. Then remove web browser extensions called Extended Protection, New Tab and Lightning NewTab. And finally, you will have to reset web browsers' preferences and settings and of course remove additional arguments from shortcuts. All the removal steps are well explained and illustrated below. Hopefully, this removal guide will help you remove the annoying and pesky browser hijackers. If you need help or maybe you you have something to add about it, please leave a comment below. Last but not least, scan your computer with anti-malware software. Aartemis Portal Site comes bundled with spyware, adware and malicious web browser extensions. Who knows what other potentialy dangerous or even malicious applications were installed with this browser hijacker. Better safe than sorry!

Written by Michael Kaur, http://deletemalware.blogspot.com


Aartemis Portal Site removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Uninstall Aartemis Portal Site related programs from your computer using the Add/Remove Programs control panel (Windows XP) or Uninstall a program control panel (Windows 7 and Windows 8).

Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



If you are using Windows 8, simply drag your mouse pointer to the right edge of the screen, select Search from the list and search for "control panel".



Or you can right-click on a bottom left hot corner (formerly known as the Start button) and select Control panel from there.



3. When the Add/Remove Programs or the Uninstall a Program screen is displayed, scroll through the list of currently installed programs and remove:
  • Wsys Control
  • Extended Protection
  • eSave Security Control
  • Desk 365
As I said earlier, this application is never listed as Aartemis Portal Site in the currently installed programs list. So, either look for applications mentioned here or try to remember what software you installed recently. It's probably the culprit.



Simply select the application and click Remove. If you are using Windows Vista, Windows 7 or Windows 8, click Uninstall up near the top of that window. When you're done, please close the Control Panel screen.


Remove Aartemis Portal Site from Google Chrome:

1. Click on Customize and control Google Chrome icon. Select Settings.




2. Click Set pages under the On startup.


Remove aartemis.com by clicking the "X" mark as shown in the image below.



3. Click Show Home button under Appearance. Then click Change.



Select Use the New Tab page and click OK to save changes.



4. Click Manage search engines button under Search.



Select Google or any other search engine you like from the list and make it your default search engine provider.



Select Aartemis from the list and remove it by clicking the "X" mark as shown in the image below.



5. Right-click the Google Chrome shortcut you are using to open your web browser and select Properties.

6. Select Shortcut tab and remove "http://aartemis.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Chrome executable file.




Remove Aartemis Portal Site from Mozilla Firefox:

1. Open Mozilla Firefox. In the URL address bar, type about:config and hit Enter.



Click I'll be careful, I promise! to continue.



In the search filter at the top, type: aartemis



Now, you should see all the preferences that were changed by Aartemis. Right-click on the preference and select Reset to restore default value. Reset all found preferences!



4. Right-click the Mozilla Firefox shortcut you are using to open your web browser and select Properties.

5. Select Shortcut tab and remove "http://aartemis.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Firefox executable file.




Remove Aartemis Portal in Internet Explorer:

1. Open Internet Explorer. Go to Tools → Manage Add-ons.



2. Select Search Providers. First of all, choose Live Search search engine and make it your default web search provider (Set as default).

3. Select Aartemis and click Remove to remove it. Close the window.



4. Right-click the Internet Explorer shortcut you are using to open your web browser and select Properties.

5. Select Shortcut tab and remove "http://aartemis.com...." from the Target field and click OK to save changes. Basically, there should be only the path to Internet Explorer executable file.



6. Finally, go to Tools → Internet Options and restore your home page to default. That's it!
Read More
Posted in Browser Hijackers | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • How to remove 'TidyNetwork' adware virus from your computer
    As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ▼  December (6)
      • Squirrel Web Removal Guide
      • What is levelqualitywatcher64.exe and how to remov...
      • What is levelqualitywatcher32.exe and how to remov...
      • What is adpeakproxy.exe and how to remove it?
      • How to remove ScorpionSaver adware (Uninstall Guide)
      • Remove Level Quality Watcher, removal guide
    • ►  November (13)
      • How to Remove Aartemis Portal Site (aartemis.com)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile