|
-
Atfxqogp Toolbar
معلومات عنه:
Atfxqogp Toolbar, or simply known as Atfxqogp or Atfxqogp.dll, is spyware-driven toolbar that promotes fake products or websites. As many of you might have already known, Atfxqogp Toolbar is new variant or clone of the notorious zlob clone toolbar. Normally, it gives itself a new name periodically so normal users would be fooled. Likely error message include, “Warning: possible spyware or adware infection! Click here to scan your computer for spyware and adware.” Atfxqogp Toolbar usually gets installed onto your PC without your notice, through Trojan, malware and virus (or you could get it by installing a fake video codec), then Atfxqogp Toolbar directly or indirectly promotes rogue antispyware products. Atfxqogp Toolbar will cause your computer to perform sluggishly, which makes you believe that your computer is affected by spyware so you would purchase the products Atfxqogp Toolbar promoted.
طريقة التخلص منه:
قم بعملية unregister لمفات الدل
Atfxqogp.dll
turbosearchsite.dll
oggview32.dll
toprates.dll
قم بحذف الملفات التالية:
Atfxqogp.dll
oggview32.dll
turbosearchsite.dll
toprates.dll
قم بحذف الريجستري:
A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D
47EFD4AD-CB46-4549-B24B-CEE415394C56
17D2F953-B2D1-4D1B-BCD3-20432E09ECF1
4090F502-6B2D-41B4-8409-B08905A3A0E6
F10587E9-0E47-4CBE-84AE-7DD20B8684BB
80DFDD57-D8B8-4991-82B9-9E9D426668B0
F4D76F09-7896-458a-890F-E1F05C46069F
-
Backdoor.Win32.TheThing.a
معلومات عنه:
Backdoor.Win32.TheThing.a is a fake popup error messages from rogue antispyware named Antivirus 2008 Pro. Backdoor.Win32.TheThing.a is a popup that tries to trick user to buy the paid version of Antivirus 2008 Pro. The possible error messages are either “Your browser was hijacked by Backdoor.Win32.TheThing.a”, or “Your browser was hijacked by Backdoor.Win32.TheThing.a” or “Likely error message includes, ““Dangerous files found! Your privacy is at Risk! To prevent yourself from personal data loss, you need to install a special application to help protect your personal data from possible theft or unauthorized use.” As discussed previously, these messages are completely misleading. You can safely remove Backdoor.Win32.TheThing.a by following our manual removal instructions if you are familiar with regedit and dll files. Good luck!
قم بعملية unregister لملفات الدل:
stream32a.dll
msvideo.dll
windivx.dll
websrc32.dll
mscfg32.dll
pdswin.dll
ecxwp.dll
pmspl.dll
vipextqtr.dll
قم بحذف الملفات التالية:
mscfg32.dll
cjvy.dll
vtssp.dll
ttvbonvgl.dll
ssqppol.dll
gqagksr.dll
esent9.dll
pmspl.dll
windivx.dll
msvideo.dll
ecxwp.dll
stream32a.dll
websrc32.dll
mlljh.dll
urqnomm.dll
قم بحذف الريجستري:
c4545fc9-26d0-4ccf-b4fb-728aed895dbd
BBB05D9E-0297-404D-A6BF-D8F2876B84A6
F9EAAA11-DF98-4615-A2C7-7D03C86A6BE9
202EBB90-ABD4-46CC-BB5A-4F0ECC67B331
62EA9201-8CC7-4199-AC30-7744F836322E
b166be07-30a4-4d38-b781-44528a630706
D17CFF74-A19C-4C36-821A-E074E4F889CA
15EB9F40-D775-4463-B75B-8687B3C66BB7
E856E05E-1B91-4339-9EFC-9A3308CB5491
B3E45A9B-7756-46A2-AB14-90175CD374F9
69B98C68-D2B8-4A4E-9CB7-E85B6F3A7014
A8565FBC-8D53-4D4F-9BB0-CBC68A22B126
43BA0532-0D69-458A-8C71-AD0F6AE70D19
6D64B03B-3B93-4AF2-BFC6-01264A4C7F2A
6A719349-BDF5-4268-9019-4ACA0C2562D2
-
RegistryDoctor2008 (Registry Doctor 2008)
معلومات عنه:
RegistryDoctor2008, also known Registry Doctor 2008, is the latest counterfeit anti-spyware software that creates hassles for computer users around the world. Just like most fake antispywares, it issues misleading and exaggerated issues. RegistryDoctor2008 usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. RegistryDoctor2008 will display fake system alerts or fake security alerts to trick user to buy the paid version of RegistryDoctor2008, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملف التالي:
registrydoctor.exe
قم بحذف الملفات التالية:
%program_files%\registrydoctor2008\registrydoctor. exe
%program_files%\registrydoctor2008\registrydoctor. ini
rgd_freeinstaller.exe
%common_programs%\registrydoctor2008\registrydocto r2008.lnk
%desktopdirectory%\registrydoctor2008.lnk
%profile%\application data\microsoft\internet explorer\quick launch\registrydoctor2008.lnk
%program_files%\registrydoctor2008\registrydoctor. exe
rgd_freeinstaller.exe
قم بحذف الريجستري:
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run RegistryDoctor2008
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run registrydoctor2008
-
WinSpyProtect (Win Spy Protect)
معلومات عنه:
WinSpyProtect, also known as Win Spy Protect, is another misleading and malicious application created to detriment the world of computers. WinSpyProtect. It is the latest counterfeit anti-spyware software that causes headaches and hassles for for Internet users. WinSpyProtect usually installed itself onto your PC without your permission, through Vundo Trojan, Zlob Trojan, Virus or fake software. WinSpyProtect will display fake system alerts or fake security alerts to trick user to buy the paid version of WinSpyProtect, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
WinSpyProtect.EXE
WinSpyProtectSetup.exe
قم بخذف الملفات التالية:
WinSpyProtect.exe
WinSpyProtect.url
WinSpyProtectSetup.exe
%UserProfile%\Application Data\Adsl Software Limited\WinSpyProtect\BASE\vbase.dat
%UserProfile%\Application Data\Adsl Software Limited\WinSpyProtect\LOG\[TIMESTAMP].log
%UserProfile%\Application Data\Adsl Software Limited\WinSpyProtect\program.ini
%UserProfile%\Application Data\Adsl Software Limited\WinSpyProtect\WinSpyProtect.exe
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpyProtect\BASE\vbase.dat
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpyProtect\program.id
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpyProtect\program.ini
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpyProtect\WinSpyProtect.exe
C:\Documents and Settings\All Users\Start Menu\Programs\WinSpyProtect\WinSpyProtect.lnk
%ProgramFiles%\WinSpyProtect\unins000.dat
%ProgramFiles%\WinSpyProtect\unins000.exe
%ProgramFiles%\WinSpyProtect\WSPLauncher.exe
قم بحذف الريجستري التالي:
HKEY_LOCAL_MACHINE\SOFTWARE\WinSpyProtect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\WinSpyProtect
HKEY_ALL_USERS\Software\Adsl Software Limited
HKEY_CLASSES_ROOT\TacOnlyOne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\WinSpyProtect
-
شكرا لك يا منازار على هذا الجهد الكبير
والسؤال كيف اعرف ان نوع هذه الفايروسات موجودة او لا ؟!!!!!
-
اخي الفاضل هذه البرامج والتولز بار مرئية ستراها وستسبب لك مشاكل في الحاسبة
ما عليك الا الحذر بتحميل اي برنامج حماية الا اذا كان موثوق والمذكورين فكلهم مزيفيين
-
SecureExpertCleaner (Secure Expert Cleaner)
معلومات عنه:
SecureExpertCleaner, also known Secure Expert Cleaner, is the latest counterfeit anti-spyware software that creates hassles for computer users around the world. Just like most fake antispywares, it issues misleading and exaggerated issues. SecureExpertCleaner usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. SecureExpertCleaner will display fake system alerts or fake security alerts to trick user to buy the paid version of SecureExpertCleaner, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملف التالي:
sec.exe
قم بحذف الملفات التالية:
%ProgramFiles%\SecureExpertCleaner\base.dat
%ProgramFiles%\SecureExpertCleaner\mfc80.dll
%ProgramFiles%\SecureExpertCleaner\Microsoft.VC80. CRT\Microsoft.VC80.CRT.manifest
%ProgramFiles%\SecureExpertCleaner\Microsoft.VC80. CRT\msvcp80.dll
%ProgramFiles%\SecureExpertCleaner\Microsoft.VC80. CRT\msvcr80.dll
%ProgramFiles%\SecureExpertCleaner\Microsoft.VC80. MFC.manifest
%ProgramFiles%\SecureExpertCleaner\Reminder.exe
%ProgramFiles%\SecureExpertCleaner\SEC.exe
%ProgramFiles%\SecureExpertCleaner\SEC.ico
%ProgramFiles%\SecureExpertCleaner\SEC.xml
%ProgramFiles%\SecureExpertCleaner\unins.ico
%ProgramFiles%\SecureExpertCleaner\unins000.dat
%ProgramFiles%\SecureExpertCleaner\unins000.exe
قم بحذف الريجستري:
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run SecureExpertCleaner
-
WinProtector
معلومات عنه:
WinProtector, also known Win Protector, is the latest counterfeit anti-spyware software that creates hassles for computer users around the world. Just like most fake antispywares, it issues misleading and exaggerated issues. WinProtector usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. WinProtector will display fake system alerts or fake security alerts to trick user to buy the paid version of WinProtector, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملف التالي:
WinProtector.exe
قم بحذف الملفات التالية:
WinProtector.exe
winprotector.lnk
uninstall winprotector.lnk
قم بحذف الريجستري:
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run WinProtector
-
XPertAntivirusEnterprise (XPert Antivirus Enterprise)
معلومات عنه:
XPertAntivirusEnterprise, also known as XPert Antivirus Enterprise, is a direct clone of Vista Antivirus 2008 or Vitae Antivirus 2008. XPert Antivirus Enterprise is a counterfeit antispyware that devastates the computer world. XPert Antivirus Enterprise usually come up after you installed a video codec that come with Trojan, malware and virus. XPert Antivirus Enterprise normally generates fake and misleading system popup error messages so end-users will be tricked into purchase XPert Antivirus Enterprise.
طريقة التخلص منه:
قم بحذف الملفات التالية:
XAE.exe
XPertAntivirusEnterprise.exe
XPertAntivirusEnterprise.lnk
UninstallXPertAntivirusEnterprise.lnk
c:\Program Files\XAE
c:\Program Files\XAE\XAE.cpl
c:\Program Files\XAE\XAE.exe
c:\Program Files\XAE\XAE0.dat
c:\Program Files\XAE\XAE1.dat
c:\WINDOWS\system32\XAE.cpl
c:\Documents and Settings\Administrator\Desktop\XPertAntivirusEnter prise.lnk
قم بايقاف الملفات التالية:
XAE.exe
XPertAntivirusEnterprise.exe
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\AntiVirus
HKEY_CURRENT_USER\Software\XAE
HKEY_CLASSES_ROOT\.key
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run “Antivirus”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run “Antivirus”
-
MSNBC Breaking News” Email
معلومات عنه:
“MSNBC Breaking News” email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from MSNBC.com. “MSNBC Breaking News” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
MSA.exe (MSA)
معلومات عنه:
MSA.exe, also known as MSA, is relating to a counterfeit antispyware called MS Antivirus. MSA is an infected file that devastates the computer world. MSA usually come up after you installed a video codec that come with Trojan, malware and virus. MSA normally generates fake and misleading system popup error messages so end-users will be tricked into purchase MSA.
طريقة التخلص منه:
قم بايقاف الملف التالي:
msa.exe
قم بحذف الملفات التالية:
MSA.exe
MSA.lnk
UninstallMSA.lnk
c:\Program Files\MSA
c:\Program Files\MSA\MSA.cpl
c:\Program Files\MSA\MSA.exe
c:\Program Files\MSA\msa0.dat
c:\Program Files\MSA\msa1.dat
c:\WINDOWS\system32\MSA.cpl
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\AntiVirus
HKEY_CURRENT_USER\Software\MSA
HKEY_CLASSES_ROOT\.key
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run “Antivirus”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run “Antivirus
-
RE: Official Update 2008 Email
معلومات عنه:
RE: Official Update 2008″ email Virus is another fraudulent email that circulates the web after a few variants of fake CNN alerts. This fraudulent email can cause serious issues. It just pretends that it’s from MSNBC.com. “RE: Official Update 2008″ Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
Fedex Tracking Number” Email
معلومات عنه:
Fedex Tracking Number” Email Virus or “Fedex Tracking Number” is another fraudulent email that circulates the web lately. The creator of this virus is getting more creative each time. “Fedex tracking number” email just pretends that it’s from fedex.com. No! It’s not! “Fedex Tracking Number” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
“CNN Alerts: Breaking news” Email
معلومات عنه:
CNN Alerts: Breaking news” Email Virus or “CNN Alerts Breaking news” is a fraudulent email that circulates the web lately. Somehow the creator of this virus did not leave CNN alone. NO! It’s NOT from CNN.com. It just pretends that it’s from CNN.com. “CNN Alerts: Breaking news” Email is malicious and dangerous. Do NOT open the attachments. This e-mail attachment contains a virus.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
CbEvtSvc.exe
lphcjkrj0etfg.exe
phcjkrj0etfg.bmp
pphcjkrj0etfg.exe
قم بحذف الملفات التالية:
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\blphcjkrj0etfg.scr
c:\WINDOWS\system32\CbEvtSvc.exe
c:\WINDOWS\system32\lphcjkrj0etfg.exe
c:\WINDOWS\system32\phcjkrj0etfg.bmp
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\WINDOWS\system32\drivers\54c70b2e.sys
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg
c:\Documents and Settings\LocalService\Application Data\rhcnkrj0etfg\Quarantine
قم بحذف الريجستري:
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
-
MaxAntiSpy (Max AntiSpy)
معلومات عنه:
MaxAntiSpy, also known as Max AntiSpy by a lot of people, is the latest counterfeit anti-spyware software that endangers the world of computers. MaxAntiSpy usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. MaxAntiSpy will display fake system alerts or fake security alerts to trick user to buy the paid version of MaxAntiSpy, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.
طريقة التخلص منه:
قم بايقاف الملفات التالية:
MaxAntiSpy.exe
قم بحذف الملفات التالية:
%ProgramFiles%\MaxAntiSpy\MaxAntiSpy.exe
%ProgramFiles%\MaxAntiSpy\MaxAntiSpy.url
%ProgramFiles%\MaxAntiSpy\MaxAntiSpyUpdate.exe
%ProgramFiles%\MaxAntiSpy\pn.cfg
%ProgramFiles%\MaxAntiSpy\spyware.dat
%ProgramFiles%\MaxAntiSpy\SysBackup\explorer.exe
%ProgramFiles%\MaxAntiSpy\SysBackup\explorer.exe.m d5
%ProgramFiles%\MaxAntiSpy\SysBackup\ntoskrnl.exe
%ProgramFiles%\MaxAntiSpy\SysBackup\ntoskrnl.exe.m d5
%ProgramFiles%\MaxAntiSpy\SysBackup\shlwapi.dll
%ProgramFiles%\MaxAntiSpy\SysBackup\shlwapi.dll.md 5
%ProgramFiles%\MaxAntiSpy\SysBackup\wininet.dll
%ProgramFiles%\MaxAntiSpy\SysBackup\wininet.dll.md 5
%ProgramFiles%\MaxAntiSpy\unins000.dat
%ProgramFiles%\MaxAntiSpy\unins000.exe
%ProgramFiles%\MaxAntiSpy\ver.dat
%ProgramFiles%\MaxAntiSpy\whitelist.cfg
قم بحذف الريجستري:
60B244BE-559D-4269-B96E-CD264D828EC9
ضوابط المشاركة
- لا تستطيع إضافة مواضيع جديدة
- لا تستطيع الرد على المواضيع
- لا تستطيع إرفاق ملفات
- لا تستطيع تعديل مشاركاتك
-
قوانين المنتدى
|
|