|
-
Notification from Chase Bank Email Virus
معلومات عنه:
Notification from Chase Bank” email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from Chase.com. “Notification from Chase Bank” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
cashU Team: Restore Your account Email Virus
معلومات عنه:
cashU Team: Restore Your account” email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from legit party. “cashU Team: Restore Your account” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
Bankofamerica Alert: Restore Your account Email Virus
معلومات عنه:
“Bankofamerica Alert: Restore Your account” email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from BankofAmerica.com. “Bankofamerica Alert: Restore Your account” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
Hilton Sex Tape Shot at Hyatt Email Virus
معلومات عنه:
Hilton Sex Tape Shot at Hyatt” email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from MSNBC.com. “Hilton Sex Tape Shot at Hyatt” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
If you open the attachment, your computer will be infected. Simply delete it if you happen to see this email in your mailbox. What if you opened it already? Don’t panic. We have put together a simple removal instruction to take care of this. Be sure to stay away from this or remove it immediately if your computer is infected. Good luck!
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري التالي:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
Warning Spyware detected on your computer Wallpaper Error Message
معلومات عنه:
“Warning! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer” is a common error message that generated by spywares. Most recently this error message is relating to a rogue antispyware called Antivirus XP 2008. It’s annoying and devastating to the computer users, but none are more catastrophic than putting the privacy and data in risk. Now what? We’ve created a removal instructions to take care of your headache.
قم بحذف الملفات التالية:
%ProgramFiles%\[RANDOM NAME]\MFC71ENU.DLL
%ProgramFiles%\[RANDOM NAME]\msvcp71.dll
%ProgramFiles%\[RANDOM NAME]\msvcr71.dll
%ProgramFiles%\[RANDOM NAME]\shlwapi.dll
%ProgramFiles%\[RANDOM NAME]\wininet.dll
%program_files%\rhc7nsj0e57c\mfc71.dll
%program_files%\rhc7nsj0e57c\mfc71enu.dll
%program_files%\rhc7nsj0e57c\msvcp71.dll
antivirusxp2008installer.exe
rhc7nsj0e57c.exe
%common_desktopdirectory%\antivirus xp 2008.lnk
%common_programs%\antivirus xp 2008.lnk
%common_programs%\antivirus xp 2008\antivirus xp 2008.lnk
%common_programs%\antivirus xp 2008\how to register antivirus xp 2008.lnk
%common_programs%\antivirus xp 2008\license agreement.lnk
%common_programs%\antivirus xp 2008\register antivirus xp 2008.lnk
%common_programs%\antivirus xp 2008\uninstall.lnk
%profile%\application data\microsoft\internet explorer\quick launch\antivirus xp 2008.lnk
%program_files%\rhc7nsj0e57c\database.dat
%program_files%\rhc7nsj0e57c\license.txt
%program_files%\rhc7nsj0e57c\uninstall.exe
%program_files%\rhc7nsj0e57c\msvcr71.dll
%program_files%\rhc7nsj0e57c\rhc7nsj0e57c.exe
%program_files%\rhc7nsj0e57c\rhc7nsj0e57c.exe.loca l
antivirusxp2008installer.exe
%program_files%\rhc7nsj0e57c\uninstall.exe
%program_files%\rhc7nsj0e57c\rhc7nsj0e57c.exe
%program_files%\rhc7nsj0e57c\mfc71.dll
%program_files%\rhc7nsj0e57c\msvcr71.dll
%program_files%\rhc7nsj0e57c\msvcp71.dll
%program_files%\rhc7nsj0e57c\mfc71enu.dll
قم بحذف الريجستري التالي:
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c registrationdiscurl
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run smrhc7nsj0e57c
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c registrationurl
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c scandepth
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c scanpriority
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c scansystemonstartup
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c softid
HKEY_USERS\Software\XP antivirus
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run smrhc7nsj0e57c
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\rhc7nsj0e57c
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\rhc7nsj0e57c displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\rhc7nsj0e57c uninstallstring
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c advid
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c automaticallyupdates
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c backgroundscan
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c backgroundscantimeout
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c databaseversion
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c daysinterval
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c domain
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c engineversion
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c guiversion
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c installdir
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c minimizeonstart
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c programversion
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c proxyname
HKEY_LOCAL_MACHINE\software\rhc7nsj0e57c proxyport
-
TheRegistrySentinel (The Registry Sentinel)
معلومات عنه:
TheRegistrySentinel, also known The Registry Sentinel by a lot of people, is the latest counterfeit Windows Utility software that endangers the world of computers. TheRegistrySentinel usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. TheRegistrySentinel will display fake system alerts or fake security alerts to trick user to buy the paid version of TheRegistrySentinel, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
TheRegistrySentinel.exe
قم بحذف الملفات التالية:
TheRegistrySentinel.lnk
TheRegistrySentinel.exe
%UserProfile%\Desktop\The Registry Sentinel.lnk
%UserProfile%\Start Menu\Programs\The Registry Sentinel\The Registry Sentinel.lnk
%UserProfile%\Start Menu\Programs\The Registry Sentinel\UninstallCleanReg.lnk
%ProgramFiles%\The Registry Sentinel\rnf456 (this file name may vary)
%ProgramFiles%\The Registry Sentinel\The Registry Sentinel.exe
%ProgramFiles%\The Registry Sentinel\UninstallCleanReg.exe
%Windir%\delete.jpg
%Windir%\delete1.jpg
%Windir%\IEBHO.dll
%Windir%\paths.jpg
%Windir%\prgrsbar.gif
%Windir%\pskill.exe
%Windir%\refs.jpg
%Windir%\setts.jpg
%Windir%\stores.jpg
%Windir%\vals.jpg
قم بحذف الريجستري:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\TheRegistrySentinel
HKEY_CLASSES_ROOT\CLSID\{82297D11-31C1-40B1-960A-BDF40B3B365F}
-
You’ve received A Hallmark E-Card (Hallmark Email Virus)
معلومات عنه:
You’ve received A Hallmark E-Card” email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from hallmark.com. “You’ve received A Hallmark E-Card” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري التالي:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
Rafbsvnx Toolbar (Rafbsvnx) Removal Instructions
معلومات عنه:
Rafbsvnx Toolbar, or simply known as Rafbsvnx, is a malicious toolbar that promotes fake antispyware applications or related websites. As many of you might have already known, Rafbsvnx Toolbar is new variant or clone of the notorious zlob clone toolbar. Generally, it gives itself a new name periodically so normal users would be fooled. Likely error message include, “Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware.”
طريقة التخلص منه:
قم بحذف الملفات التالية:
Rafbsvnx.dll
oggview32.dll
turbosearchsite.dll
toprates.dll
قم بايقاف الملفات التالية:
Rafbsvnx.dll
turbosearchsite.dll
oggview32.dll
toprates.dll
قم بحذف الريجستري:
Rafbsvnx.dll
turbosearchsite.dll
oggview32.dll
toprates.dll
-
AdvancedPrivacyGuard (Advanced Privacy Guard)
معلومات عنه:
AdvancedPrivacyGuard , also known as Advanced Privacy Guard , is the latest counterfeit anti-spyware software that created to confuse the Internet community. Just like most fake antispywares, Advanced Privacy Guard issues misleading and exaggerated results. Advanced Privacy Guard usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. AdvancedPrivacyGuard will display fake system alerts or fake security alerts to trick user to buy the paid version of AdvancedPrivacyGuard , in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
AdvancedPrivacyGuard .exe
قم بحذف الملفات التالية:
AdvancedPrivacyGuard %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\AdvancedPrivacyGuard .lnk
AdvancedPrivacyGuard %UserProfile%\Desktop\AdvancedPrivacyGuard .lnk
AdvancedPrivacyGuard %UserProfile%\Start Menu\Programs\AdvancedPrivacyGuard \AdvancedPrivacyGuard on the Web.lnk
AdvancedPrivacyGuard %UserProfile%\Start Menu\Programs\AdvancedPrivacyGuard \AdvancedPrivacyGuard .lnk
AdvancedPrivacyGuard %UserProfile%\Start Menu\Programs\AdvancedPrivacyGuard \Uninstall AdvancedPrivacyGuard .lnk
AdvancedPrivacyGuard %ProgramFiles%\AdvancedPrivacyGuard \AdvancedPrivacyGuard .exe
AdvancedPrivacyGuard %ProgramFiles%\AdvancedPrivacyGuard \AdvancedPrivacyGuard .url
AdvancedPrivacyGuard %ProgramFiles%\AdvancedPrivacyGuard \unins000.dat
AdvancedPrivacyGuard %ProgramFiles%\AdvancedPrivacyGuard \unins000.exe
قم بحذف الريجستري التالي:
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run AdvancedPrivacyGuard
-
SpywarePreventer (Spyware Preventer)
معلومات عنه:
SpywarePreventer , also known as Spyware Preventer, is the latest counterfeit antispyware that created to mislead and annoy the innocent web surfers. SpywarePreventer is a variant of MS Antivirus 2008 and other nasty fake antispyware software. SpywarePreventer usually come up after you installed a video codec that come with Trojan, malware and virus. SpywarePreventer normally generates fake and misleading system popup error messages so end-users will be tricked into purchase SpywarePreventer.
طريقة التخلص منه:
قم بايقاف الملف التالي:
spp.exe
قم بحذف الملفات التالية:
SpywarePreventer.exe
c:\Program Files\SPP
c:\Program Files\SPP\SPP.cpl
c:\Program Files\SPP\SPP.exe
c:\Program Files\SPP\SPP1.dat
c:\WINDOWS\system32\SPP.cpl
c:\Documents and Settings\Adminstrator\Desktop\Spyware Preventer.lnk
قم بحذف الريجستري:
HKEY_CLASSES_ROOT\.key
HKEY_CURRENT_USER\Software\SPP
HKEY_CURRENT_USER\Software\Antivirus
-
InstantSafePage.com
معلومات عنه:
InstantSafePage.com, or simply InstantSafePage, is a nasty Internet Hijacker that directly or indirectly promotes rogue antispyware products. InstantSafePage.com will cause your computer to perform sluggishly or even lead to a complete crash, which makes you believe that the computer is affected by spyware so you would purchase their products.
If your Internet homepage has been hijacked to “InstantSafePage.com”, it’s very likely your computer being infected with Zlob.Trojan. InstantSafePage.com website pops up a warning message stating that you have Virus or Trojan in your computer. If you click OK, it will redirect you to buy products such as Win Spykiller or Antispyware Sheild or Virus Heat.
طريقة التخلص منه:
(Tools>Internet Options>Advanced>Reset)
-
SafeShortcuts.com
معلومات عنه:
directly or indirectly promotes rogue antispyware products. SafeShortcuts.com will cause your computer to perform sluggishly or even lead to a complete crash, which makes you believe that the computer is affected by spyware so you would purchase their products.
If your Internet homepage has been hijacked to “SafeShortcuts.com”, it’s very likely your computer being infected with Zlob.Trojan. SafeShortcuts.com website pops up a warning message stating that you have Virus or Trojan in your computer. If you click OK, it will redirect you to buy products such as Win Spykiller or Antispyware Sheild or Virus Heat.
طريقة التخلص منه:
(Tools>Internet Options>Advanced>Reset)
-
Warninglinks.com
معلومات عنه:
Warninglinks.com, or simply Warninglinks, is a nasty Internet Hijacker that directly or indirectly promotes rogue antispyware products. warninglinks.com will cause your computer to perform sluggishly or even lead to a complete crash, which makes you believe that the computer is affected by spyware so you would purchase their products.
If your Internet homepage has been hijacked to “warninglinks.com”, it’s very likely your computer being infected with Zlob.Trojan. warninglinks.com website pops up a warning message stating that you have Virus or Trojan in your computer. If you click OK, it will redirect you to buy products such as Win Spykiller or Antispyware Sheild or Virus Heat.
طريقة التخلص منه:
Tools>Internet Options>Advanced>Reset)
-
LifeLongPC (Life Long PC)
معلومات عنه:
LifeLongPC, also known Life Long PC, is the latest counterfeit anti-spyware software that creates hassles for computer users around the world. Just like most fake antispywares, it issues misleading and exaggerated issues. LifeLongPC usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. LifeLongPC will display fake system alerts or fake security alerts to trick user to buy the paid version of LifeLongPC, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملف التالي:
LifeLongPC.exe
قم بحذف الملفات التالية:
~uavsetup.exe
%common_desktopdirectory%\lifelongpc.lnk
%common_programs%\lifelongpc\contact customer support.lnk
%common_programs%\lifelongpc\lifelongpc.lnk
%common_programs%\lifelongpc\uninstall lifelongpc.lnk
%profile%\application data\lifelongpc\logs\threats.log
%profile%\application data\lifelongpc\pge.dat
%program_files%\lifelongpc\activate.exe
%program_files%\lifelongpc\al.dat
%program_files%\lifelongpc\config\pgs.xml
%program_files%\lifelongpc\dat\activate.dat
%program_files%\lifelongpc\dat\bksites.dat
%program_files%\lifelongpc\dat\bnlink.dat
%program_files%\lifelongpc\dat\cd.dat
%program_files%\lifelongpc\dat\incmp.dat
%program_files%\lifelongpc\dat\index.dat
%program_files%\lifelongpc\dat\pguplst.dat
%program_files%\lifelongpc\dat\pv.dat
%program_files%\common files\lifelongpc\bm.exe
%program_files%\common files\lifelongpc\ugac.exe
%program_files%\lifelongpc\dhlp.dll
%program_files%\lifelongpc\engines\awbase\database \enemies.dat
%program_files%\lifelongpc\engines\awbase\vbpv.dat
%program_files%\lifelongpc\engines\pgbase\vbpv.dat
%program_files%\lifelongpc\engines\plugins\borlndm m.dll
%program_files%\lifelongpc\engines\plugins\scanadw r.dll
%program_files%\lifelongpc\engines\plugins\scanbcd r.dll
%program_files%\lifelongpc\engines\plugins\scandld r.dll
%program_files%\lifelongpc\engines\plugins\scandos 1.dll
%program_files%\lifelongpc\engines\plugins\scanemu l.dll
%program_files%\lifelongpc\engines\plugins\scanfun c.dll
%program_files%\lifelongpc\engines\plugins\scankrn l.dll
%program_files%\lifelongpc\engines\plugins\scanmcr 1.dll
%program_files%\lifelongpc\engines\plugins\scanoth r.dll
%program_files%\lifelongpc\engines\plugins\scanscr .dll
%program_files%\lifelongpc\engines\plugins\scantoo l.dll
%program_files%\lifelongpc\engines\plugins\scantro j.dll
%program_files%\lifelongpc\engines\plugins\scanwin 1.dll
%program_files%\lifelongpc\engines\plugins\unacpu. dll
%program_files%\lifelongpc\engines\plugins\unadbx. dll
%program_files%\lifelongpc\engines\plugins\unamsca n.dll
%program_files%\lifelongpc\engines\plugins\unmime. dll
%program_files%\lifelongpc\engines\plugins\unpack. dll
%program_files%\lifelongpc\engines\plugins\unpacks .dll
%program_files%\lifelongpc\engines\plugins\unpacks 2.dll
%program_files%\lifelongpc\engines\plugins\unpepac k.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27601.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27602.dll
%program_files%\lifelongpc\engines\plugins\update\ uadaily.dll
%program_files%\lifelongpc\engines\plugins\vbpv.da t
%program_files%\lifelongpc\fwsettings.bin
%program_files%\lifelongpc\graphics\cross.gif
%program_files%\lifelongpc\graphics\ga6p.gif
%program_files%\lifelongpc\graphics\kb.url
%program_files%\lifelongpc\graphics\main.ico
%program_files%\lifelongpc\graphics\mini.ico
%program_files%\lifelongpc\graphics\online.url
%program_files%\lifelongpc\graphics\rm.url
%program_files%\lifelongpc\graphics\support.ico
%program_files%\lifelongpc\graphics\support.url
%program_files%\lifelongpc\graphics\uninstall.ico
%program_files%\lifelongpc\history.db
%program_files%\lifelongpc\la\lapv.dat
%program_files%\lifelongpc\la\license.rtf
%program_files%\lifelongpc\main.log
%program_files%\lifelongpc\tools\sbiebho.dll
%program_files%\lifelongpc\unins000.dat
%program_files%\lifelongpc\unins000.exe
%program_files%\lifelongpc\up\asupdater.dat
%program_files%\lifelongpc\up\gup.exe
%program_files%\lifelongpc\up\pgupdater.dat
%program_files%\lifelongpc\up\ubupdater.dat
%program_files%\lifelongpc\up\up.dat
%program_files%\lifelongpc\up\updater.dat
%program_files%\lifelongpc\engines\plugins\update\ ua27603.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27604.dll
%program_files%\lifelongpc\pgs.exe
%program_files%\lifelongpc\ptask.exe
%program_files%\lifelongpc\reload.exe
%program_files%\lifelongpc\reserrors.log
%program_files%\lifelongpc\scnkrnl.dll
%program_files%\lifelongpc\settings.ini
%program_files%\lifelongpc\sqlite3.dll
%program_files%\lifelongpc\sr.log
%program_files%\lifelongpc\tools\pblock.dll
%program_files%\lifelongpc\tools\sbiebho.dll
%program_files%\lifelongpc\tools\pblock.dll
%program_files%\lifelongpc\sqlite3.dll
%program_files%\lifelongpc\scnkrnl.dll
%program_files%\lifelongpc\engines\plugins\update\ uadaily.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27604.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27603.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27602.dll
%program_files%\lifelongpc\engines\plugins\update\ ua27601.dll
%program_files%\lifelongpc\engines\plugins\unpepac k.dll
%program_files%\lifelongpc\engines\plugins\unpacks 2.dll
%program_files%\lifelongpc\engines\plugins\unpacks .dll
%program_files%\lifelongpc\engines\plugins\unpack. dll
%program_files%\lifelongpc\engines\plugins\unmime. dll
%program_files%\lifelongpc\engines\plugins\unamsca n.dll
%program_files%\lifelongpc\engines\plugins\unadbx. dll
%program_files%\lifelongpc\engines\plugins\unacpu. dll
%program_files%\lifelongpc\engines\plugins\scanwin 1.dll
%program_files%\lifelongpc\engines\plugins\scantro j.dll
%program_files%\lifelongpc\engines\plugins\scantoo l.dll
%program_files%\lifelongpc\engines\plugins\scanscr .dll
%program_files%\lifelongpc\engines\plugins\scanoth r.dll
%program_files%\lifelongpc\engines\plugins\scanmcr 1.dll
%program_files%\lifelongpc\engines\plugins\scankrn l.dll
%program_files%\lifelongpc\engines\plugins\scanfun c.dll
%program_files%\lifelongpc\engines\plugins\scanemu l.dll
%program_files%\lifelongpc\engines\plugins\scandos 1.dll
%program_files%\lifelongpc\engines\plugins\scandld r.dll
%program_files%\lifelongpc\engines\plugins\scanbcd r.dll
%program_files%\lifelongpc\engines\plugins\scanadw r.dll
%program_files%\lifelongpc\engines\plugins\borlndm m.dll
%program_files%\lifelongpc\dhlp.dll
%program_files%\lifelongpc\activate.exe
%program_files%\common files\lifelongpc\ugac.exe
%program_files%\common files\lifelongpc\bm.exe
~uavsetup.exe
%program_files%\lifelongpc\pgs.exe
%program_files%\lifelongpc\reload.exe
%program_files%\lifelongpc\ptask.exe
%program_files%\lifelongpc\up\gup.exe
%program_files%\lifelongpc\unins000.exe
قم بحذف الريجستري
HKEY_CURRENT_USER\software\lifelongpc
HKEY_CURRENT_USER\software\lifelongpc lastlogontime
HKEY_CURRENT_USER\software\lifelongpc\settings active
HKEY_CURRENT_USER\software\lifelongpc\settings allowpopupclicktype
HKEY_CURRENT_USER\software\lifelongpc\settings blockdomainonpopups
HKEY_CURRENT_USER\software\lifelongpc\settings blockdomainpopuplimit
HKEY_CURRENT_USER\software\lifelongpc\settings defaultaction
HKEY_CURRENT_USER\software\lifelongpc\settings enableieblocksite
HKEY_CURRENT_USER\software\lifelongpc\settings enableis
HKEY_CURRENT_USER\software\lifelongpc\settings firstrun
HKEY_CURRENT_USER\software\lifelongpc\settings iepage
HKEY_CURRENT_USER\software\lifelongpc\settings lastupdatetimedbok
HKEY_CURRENT_USER\software\lifelongpc\settings mailarchivescan
HKEY_CURRENT_USER\software\lifelongpc\settings mailprotect
HKEY_CURRENT_USER\software\lifelongpc\settings mozillapage
HKEY_CURRENT_USER\software\lifelongpc\settings normalizeaddborders
HKEY_CURRENT_USER\software\lifelongpc\settings normalizeaddmenuandtoolbar
HKEY_CURRENT_USER\software\lifelongpc\settings normalizefittodesktop
HKEY_CURRENT_USER\software\lifelongpc\settings normalizeopenedpopups
HKEY_CURRENT_USER\software\lifelongpc\settings startblockontimedpopups
HKEY_CURRENT_USER\software\lifelongpc\settings storehistory
HKEY_CURRENT_USER\software\lifelongpc\settings timedpopuplimit
HKEY_CURRENT_USER\software\lifelongpc\settings updatedata
HKEY_CURRENT_USER\software\lifelongpc\settings updatedatabin
HKEY_CURRENT_USER\software\lifelongpc\settings virusshield
HKEY_CURRENT_USER\software\lifelongpc\settings vsscan
HKEY_CURRENT_USER\software\lifelongpcdownloader
HKEY_CURRENT_USER\software\lifelongpcdownloader seekpos
HKEY_CURRENT_USER\software\lifelongpcdownloader totalsize
HKEY_LOCAL_MACHINE\software\lifelongpc abbr
HKEY_LOCAL_MACHINE\software\lifelongpc activationcode
HKEY_LOCAL_MACHINE\software\lifelongpc installdate
HKEY_LOCAL_MACHINE\software\lifelongpc installpath
HKEY_LOCAL_MACHINE\software\lifelongpc productcode
HKEY_LOCAL_MACHINE\software\lifelongpc\settings activethreats
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run lifelongpc
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run lifelongpc
-
BugDoctor (Bug Doctor)
معلومات عنه:
BugDoctor, also known Bug Doctor, is the latest counterfeit anti-spyware software that creates hassles for computer users around the world. Just like most fake antispywares, it issues misleading and exaggerated issues. BugDoctor usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. BugDoctor will display fake system alerts or fake security alerts to trick user to buy the paid version of BugDoctor, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
قم بايقاف الملفات التالية:
BugDoctor.exe
قم بحذف الملفات التالية:
BugDoctor.lnk
BugDoctor.exe
redir.dll
UserProfile%\Application Data\BugDoctor\base.dat
%UserProfile%\Application Data\BugDoctor\base2.dat
%UserProfile%\Application Data\BugDoctor\Desc.dat
%UserProfile%\Application Data\BugDoctor\spline.dat
%UserProfile%\Application Data\BugDoctor\BugDoctor.ini
%UserProfile%\redir.dll
%UserProfile%\BugDoctor.exe
قم بحذف الريجستري:
HKEY_CLASSES_ROOT\clsid\{f3642b57-3ea8-4eea-a643-9de138381a57}
HKEY_CLASSES_ROOT\clsid\{f3642b57-3ea8-4eea-a643-9de138381a57}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{f3642b57-3ea8-4eea-a643-9de138381a57}\inprocserver32 threadingmodel
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run BugDoctor
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{f3642b57-3ea8-4eea-a643-9de138381a57}
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run BugDoctor
ضوابط المشاركة
- لا تستطيع إضافة مواضيع جديدة
- لا تستطيع الرد على المواضيع
- لا تستطيع إرفاق ملفات
- لا تستطيع تعديل مشاركاتك
-
قوانين المنتدى
|
|