Hiển thị các bài đăng có nhãn Trojans. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn Trojans. Hiển thị tất cả bài đăng

Thứ Tư, 19 tháng 11, 2014

Remove Steam Messages Virus (Malicious links in Steam chat to .SCR, .EXE files)

There is a new virus going around through Steam. If you get a message that says "You will exchange this thing?" or "Is this you in the photo?" or "WTF Dude?" with a link DON'T OPEN IT! Even though it may appear as a link to a screenshot it actually redirects to a password stealing Trojan horse (VirusTotal scan results /safe to open). It loads a malicious .src or .exe file and infects your computer. Here are a few scan results: Spyware.OnlineGames, Trojan.Crypt, Win32:Malware-gen, BehavesLike.Win32.Backdoor.fm. Detection ratio is still very low, just about 20% which means that only one anti-virus program out of five will detect this virus and block it. Here are a few examples of fake Steam messages you may get in Steam chat:

You will exchange this thing? screenshot-url.com/Screen_19521.png


WTF Dude? http://screen-pictures.com/img_012/



Here's a list of malicious links that were used previously or still in use:

Click to Enlarge Image
Have you stumbled across the term password stealing 'Trojan Horse' when reading about IT, malware or computers? If so and you're wondering what on earth this ancient Greek mythological beast has to do with modern technology then you've come to the right place! Strange as it may sound, the name does make sense – or at least it should in a few moments.

Feeling slightly confused. Apologies – keep reading and everything will become clear.

What is a modern Trojan Horse?

To understand more about today's Trojans and how they got their name we need to go back in time. You may recall being told the story about Helena of Troy and the Trojan Horse back in your youth. Remember the tale of how the Greeks and Trojans were at war and to con the Trojans into letting the Greek army into their walled city, the Greeks hid inside a huge wooden horse which they offered as a peace offering to the people of Troy. The Trojans accepted this rather bizarre (but kind of cool!) gift and wheeled the horse through their city gates. Of course, as soon as night fell, the Greeks climbed out, opened the gates to the rest of their army, and overcame Troy.

History lesson over and you're still asking what on earth does that have to do with my computer?! Well, just like the wooden horse of yore which was lethal, despite looking like it was a perfectly innocent gift, so too are modern Trojan Horses. For a Trojan Horse in the IT world is actually a piece of malware which has been designed to fool you into thinking it's something you need or want. In 2014, the Greek army is a (malicious) software developer - and we are the unsuspecting, or some may say naive, people of Troy. This Steam chat virus works exactly the same. You get a message with an offer to exchange something which is't very unusual on Steam and you think that it indeed might be a good thing but what you get is a virus. Notice how Screen_19521.png in the fake Steam message becomes a knife.exe when you open a malicious link. And you don't even have to run that file. It loads malicious code automatically.

What will Steam messages virus do to my computer?

We've established that today's password stealing Trojan Horses are an enemy in disguise but how do they pose a threat to your PC? Well, once you've installed this Trojan, thinking it was an innocent plugin, a game, or even exchange item, they can wreak havoc on your computer and systems. Their usual MO is to corrupt your data and files by over-writing parts of your hard drive. In this case, however, it will use your Steam account to spam other users with malicious links hoping that more and more computers will becomes a part of a huge botnet of infected machines controlled by cyber crooks.

Clearly, the hard part is knowing what you can and can't trust when you're downloading software, thanks to the Trojan's innocent guise. The developers of Steam chat viruses are incredibly resourceful when it comes to convincing you to download, click a button, or fill in a form containing personal data or bank details – meaning we need to be on our guard.

How do I defend myself against this Steam virus?

First line of defense, give your city walls an added layer of protection by installing a reputable anti-malware program on your computer. And once it's on there, run it regularly and keep it bang up to date.

You also need to be careful when opening links, attachments in emails or downloading software. If in doubt, don’t! Simple as that. To remove Steam messages virus from your computer, please follow the steps in the removal guide below. If you have questions, leave a down comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Steam messages virus removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





NOTE: If you are using Internet Explorer and can't download anti-malware software because "Your current security settings do not allow this file to be downloaded" then please reset IE security settings and try again.

2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Sáu, 7 tháng 11, 2014

Remove TrojanClicker:JS/Chroject.A Virus (Uninstall Guide)

TrojanClicker:JS/Chroject.A is a malicious piece of software that can click on online advertisements without your permission or knowledge while you're browsing the Internet. This virus is usually installed by other malware, mostly Trojan droppers. Most of us, as computer users, are well aware of the large number of threats that computer viruses and malware can pose to our online security. However due to the many different strains of malicious software, not all of these dangers and annoyances act the same, or are prevented or removed in the same way. If I had to explain this virus in simple words I would say it's a malicious JavaScript code that automatically clicks on ads that are not necessarily visible on a web page. More advertisement clicks equals more money, simple as that. However, that's just part of the story. As I said, TrojanClicker:JS/Chroject.A comes bundled with other malware. It could be Trojan horses, spyware and even malicious programs that will use your computer for DDoS attacks.


It's a viscous circle: as quickly as anti-malware programs step up their game in order to catch the latest round of viruses, so too do the scammers. There are now a frightening number of sophisticated techniques being employed to steal your data and cause you harm and one of the very worst are Trojan Horses.

Trojan Horses are particularly worrying because they look perfectly innocent. However the reality is the opposite. You may think that it just clicks on ads but at the same time it can be installing more sophisticated malware on your computer.

Just because a program looks innocent and says it is counts for nothing when your security is at stake. There are even Trojan Horses that purport to be anti-virus software - and they will secretly infect you with viruses whilst pretending to be the very thing they claim to protect you from.

So where did Trojan Horses get their name? It comes from Greek mythology – surely you remember the story from your schooldays where the Greek army presented their enemies in the besieged city of Troy a huge wooden horse as a ‘peace offering’. The Trojans wheel the horse into the city and, once they’re asleep, Greek soldiers hiding inside the horse climb out and open the city gates to the rest of their army.

Now you probably understand a little more about the nature of the TrojanClicker:JS/Chroject.A virus. Quite simply, it tricks you into unwittingly installing it on your PC. However, to muddy matters further, not all Trojans are the same:
  • Remote Access Trojans. RATs allow a hacker total control over your operating system.
  • Denial-of-Service (DoS) Trojans. These can take down an entire network by flooding it with unwanted traffic.
  • Destructive Trojans. Similar to a virus, this will corrupt and/or delete your files.
  • Proxy Trojans. These turn your computer into a proxy server to allow a hacker to do what he likes by using your PC as he would his own.
  • Data Sending Trojans. These install keyloggers to record personal data from address books to credit card details and beyond.
  • Security Software Disabler Trojans. This disables your anti-virus software.
  • FTP Trojans. These allow a hacker to connect to your PC using FTP.
  • Trojan Clickers. These allow scammers to click on ads or imitate similar activities in order to increase traffic and ad clicks.
So how do you protect yourself? Don't be like the people of Troy; don't get fooled into thinking something is innocent without thoroughly checking it out first. It's a hackers 'job' to make you think something is safe to run on your PC – when really it's not.

First of all, install a reputable anti-malware on your PC, and run it frequently. You should also make sure it is up to date. Secondly don't click email attachments from senders you don't know and don't download games or other programs from unknown or third party sources.

To remove TrojanClicker:JS/Chroject.A virus and other threats that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a down comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



TrojanClicker:JS/Chroject.A virus removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Tư, 5 tháng 11, 2014

Remove dllhost.exe *32 COM Surrogate virus (Uninstall Guide)

Multiple dllhost.exe *32 (COM surrogate) instances may indicate that your computer is infected with malware, mostly likely a Trojan horse. It could be the Trojan.Poweliks or similar malware. Once your computer is infected, this virus may create 30 or even more instances of dllhost.exe *32 - COM Surrogate, consume 100% of the processor, and all of RAM. In same cases it consumes memory until crash. What is Trojan Horse software, you may ask? Well, just like the ancient Greek mythological horse that it takes its name from, today's Trojan Horse is something which, despite looking innocent, has actually been designed to do a lot of damage. The wooden horse that the Greeks built was created to infiltrate the City of Troy and destroy it from within, and in a similar vein, Trojan Horse malware is a program that makes you think it is safe - and then once installed on your computer, will attack you from the inside. If you have a good anti-malware program it will stop this infection right away or if it missed the Trojan dropper then at least block all the outbound traffic by dllhost.exe *32 virus.


So that the Trojan Horse can infect your PC or laptop you need to install its server function. And it is this that gives this particularly nasty type of malware its name. Because in the Greek tale the Greek army designed the wooden horse to look like a peace offering and presented it as a gift to the people of Troy (but were actually hiding their army inside the horse), modern Trojans also convince you that they're a legitimate application that will do you no harm. Unfortunately, as the people of Troy found out when they were attacked as soon as darkness fell, this is simply not the case.

What do Trojan Horses do to computers?

There are a number of ways a Trojan Horse can affect you. Some types might harass you with endless pop-up or pop-under adverts for goods or services that you probably have little to no interest in. Annoying yes, but this type of Trojan is the least of your worries for an increasingly large proportion of Trojan Horses have been designed to infiltrate your PC to corrupt your data and files. They will prevent you accessing them in some cases, or they might just decide to delete them altogether. And the sickest part? The person who developed the Trojan Horse malware doesn't even gain anything from this – they just do it purely because they can. Now, in this case, dllhost.exe *32 (COM surrogate) instances are usually used to display ads but it may also install spyware on your computer. Everything is done in the background without your knowledge, so there's not other way to spot this malware other than finding multiple instances dllhost.exe processes.


How does a Trojan Horse program get on to my computer?

There are actually a few ways that Trojan Horses can infect your laptop or PC. There are Trojans which come as attachments in spam emails – these will be in the form of .exe files. And there are yet others which will purport to be something useful that you'll stumble across when you’re online. They might be disguised as a fun looking game or even (ironically) as the latest and greatest, must-have new anti-virus program. The Trojan Horse's MO, or Modus Operandi, is to convince you to drop your guard and let it in through your defenses – so it can cause chaos. Just as it did to the good people of Troy.

How do I protect myself from Trojan Horses?

As always you want to ensure you're running a good anti-malware program on your computer. You should also make sure your PC is up to date with the most current Windows security patches too. Crucially you should be careful when you're downloading programs or applications. And don't forget the golden rule when dealing with spam emails. Don't open them - delete them!

To remove dllhost.exe *32 COM Surrogate virus and other threats that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a down comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Dllhost.exe *32 COM Surrogate virus removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.






NOTE: If you are using Internet Explorer and can't download anti-malware software because "Your current security settings do not allow this file to be downloaded" then please reset IE security settings and try again.

2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Bảy, 18 tháng 10, 2014

Remove Trojan.Gen.2 Virus (Uninstall Guide)

If you're reading this, chances are you've heard of Trojan.Gen.2 but you're not quite sure what it is. A few years ago, the only Trojan Horse most of us had heard of was the huge wooden one built by the Greeks and used to conceal their soldiers who connived their way through the city of Troy's gates after pretending that the horse was a peace offering. Well strange as it sounds, the Trojan Horse of Greek mythology actually has quite a lot in common with its 21st century counterpart.

Just as the Greeks used a very underhand method to enter Troy and attack it from within, Trojan.Gen.2 virus will employ the same means to attack your computer. That's because a modern Trojan Horse is a computer program that pretends to have useful qualities but actually will do far more harm than good. A Trojan Horse's MO is to con you into thinking it's useful or harmless when in fact it's the total opposite. This Trojan horse generic detection is usually used for detecting malware that cannot be identified and assigned to any particular malware family. Trojan.Gen.2 notification can be also shown when visiting infected websites. So, it's used not only to detect infected files and also websites.


What does Trojan.Gen.2 virus do?

Luckily it is pretty easy to spot if you have this Trojan horse on your PC - once you've installed it that is! There are a number of symptoms that will enable you to detect the presence of a Trojan horse, some of these are:
  • Your operating system has become sluggish and your computer keeps crashing
  • Your PC has suddenly become slow to start up when you turn it on
  • Opening websites takes a lot longer than you're used to
  • You start seeing a proliferation of pop up adverts
  • You have a new tool bar in your browser that you don't recall downloading
  • There are unrecognized icons in your list of programs or on your desktop
  • Your computer's default settings have changed - and keep changing even after you've switched them back
These symptoms are easy to notice however certain variants of Trojan.Gen.2 run in the background without any visible windows and pop-ups. The main goal of this virus is to download and install additional malware on your computer. It could be anything really, a browser hijacker or spyware. Since Trojan.Gen.2 is not the same for everyone and it keeps changing it's difficult to say what variant you have on your computer and what exactly it does. It may steal your personal information or maybe it will add your computer to a botnet. One thing is for sure - you need to remove it from your computer as soon as possible.

How to protect yourself from a malicious Trojan.Gen.2?

This is a list of a number of things you can do to make yourself as safe as possible when you're online:
  • Install a firewall to help stop unwanted and potentially dangerous connections from being made, thus preventing a Trojan horse from automatically connecting with your system. (Trojans scan networks and the Internet looking for vulnerable systems).
  • Always, always protect your computer from malware by installing a reputable anti-malware program. Manually run it with periodic frequency.
  • You need to make sure that your anti-malware is always the latest version and fully up to date too. Install the latest patches and upgrades that the developer issues.
  • Be careful opening attachments and links in emails if you don't recognize the sender.
  • Don't download software, programs, shareware or freeware if you don't know or trust the publisher or website. Trojans often piggyback on other, more legitimate, programs.
  • Be careful about the type of websites you visit. And that goes for anyone else who uses your PC too. Trojans target certain websites and install Active X controls on them, so do look out for these – and avoid wherever possible.
How to remove Trojan.Gen.2?

It's a very difficult infection to remove manually. Besides, it can download and install more malware on your computer which means you don't really know what else you have on your computer and where to find all the malicious files. A lot better idea would be to run a full system scan with anti-malware software and a few other on demand malware scanners. That's actually the only way to be 100% sure there are not other malicious file left behind that could possibly re-download deleted malware files. To remove this Trojan virus from your computer, please follow the steps in the removal guide below. If you have any questions, please leave a comment down below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Trojan.Gen.2 Removal Guide:


1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Tư, 17 tháng 9, 2014

Remove MalSign.Generic.DE7 (Uninstall Guide)

MalSign.Generic.DE7 is a generic detection for malicious programs that features or behaviors indicative of trojans, spyware, worms or even viruses. MalSig means malicious signature. Generic stands for specific characteristic that is unique for this malware family. And DE7 is a particular piece of malware that belongs to the MalSign.Generic malware family. There are thousands of malware threats that fall under this category, to find out more, please read MalSign.Generic post. This particular variant is distributed mostly via pay-per-install networks. It also comes bundled with freeware and other software installers. If the installer contains this malware, your anti-virus will notify you. Here's an example of a notification you may get:


In this case, it was bundled with BackupSetup.exe file. This was an installer file for rather popular free backup software. It can be distributed in other ways as well, for example via social networks and spam.

As mentioned, such malware infections are commonly spread via email attachments. The author will attach the file containing the malware to a mail and then spam hundreds or even thousands of people. And if you're unlucky enough that your name is on the list – one of them could be you.

Likewise if you've been sucked in to downloading something less than reputable – i.e. through social engineering – you may also find yourself on the receiving end installing of this malware.

If you do find you've been infected by MalSign.Generic.DE7, please follow the steps in the removal guide below or read how to Remove MalSign.Generic (Uninstall Guide). Scan your computer with anti-malware software and delete the questionable files. If you are unlucky enough, you may have to reinstall your operating system too, which is not fun. Therefore, it makes all the sense in the world to have a decent anti-malware installed and to exercise a little caution when opening emails.

If you have questions, leave a comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


MalSign.Generic.DE7 Removal Guide:


1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



That's it!

Chủ Nhật, 29 tháng 6, 2014

MalSign.OpenCandy.7AF Removal Guide

MalSign.OpenCandy.7AF is a generic AVG detection for malicious programs that may display ads and pop-ups on your computer. This threat is also detected as PUP.Optional.OpenCandy. MalSig means malicious signature. OpenCandy is the adware family. And 7AF the specific variant of this adware. The funny thing is that AVG detects Avast's file aswRec.dll as malware as well. This will probably be fixed soon. It's a false positive. If you keep getting notifications about this threat in Avast's folder, simply reboot your computer in SAFE MODE, go to Program files folder and remove the malicious file. Full path: Program Files/Avast Software/Avast/aswRec.dll. Or you could just delete the entire Avast software folder. However, other threats that you may get are likely to be real and not false positives. Please note that they start with the same indicator but have different identifier at the end which means that it's either a new variant of the same malware family or slightly modified version that may use additional features for example. Please use this guide to remove MalSign.OpenCandy.7AF and any associated malware.

What is MalSign.OpenCandy.7AF and how does one infect your computer?

Well, firstly it might come as quite a surprise to learn that you actually play a part in the process. This is because for this malware to attack your machine you need to install the server part of the application. Cyber crooks use social engineering to trick users into installing malicious software and adware. The good news is that it won't steel your passwords and credit card details but it's still a threat. Besides, it usually comes bundled with adware malicious programs, including malicious browser extensions, PUPs and sometimes even spyware that may gather information about your browsing habits.

In another scenario, the author might send you the malicious code as a file in an email, hoping that you open the attachment and then execute the malware by running the .exe file to install it. This is because, unlike a virus, it doesn't multiply of its own accord; it needs you to execute and install it instead. Once this has been done the malware server will automatically run every time you log in to your PC. What is more, you may get infected by visiting an infected website.

Why have I been targeted by this malware?

As mentioned, such malware infections are commonly spread via email attachments and infected websites. The author will attach the file containing the malware to a mail and then spam hundreds or even thousands of people. And if you're unlucky enough that your name is on the list – one of them could be you.

Likewise if you've been sucked in to downloading something less than reputable – i.e. through social engineering – you may also find yourself on the receiving end of MalSign.OpenCandy.7AF. As I said, it is being actively promoted using various pay-per-install networks.

Is it a threat?

MalSign.OpenCandy.7AF can be particularly nasty. Although not technically a virus, they are still a very unpleasant strain of malware and they can download and install additional malware on your computer. They can corrupt data on your system and make it inaccessible – and you probably don't need me to tell you how much of a nuisance that will be. Not to mention that such infections usually make computers run slower.

What can I do to protect myself from such threats?

Luckily there are a few steps you can take to protect yourself from MalSign.OpenCandy.7AF. Probably the most obvious one being to never open emails from an unknown sender. And if you do open one in error – definitely do NOT open any attachments. All you need to do in this situation is to delete the message. You should, it goes without saying, also install a reputable anti-malware on your system as this will scan any files you download – even those that are sent by someone in your contact list.

If you do find you've been infected by MalSign.OpenCandy.7AF, scan your computer with anti-malware software and delete the questionable files. If you are unlucky enough, you may have to reinstall your operating system too, which is not fun. Therefore, it makes all the sense in the world to have a decent anti-malware installed and to exercise a little caution when opening emails.

If you have questions, leave a down comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


MalSign.OpenCandy.7AF Removal Guide:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. As this infection is known to be installed by vulnerabilities in out-dated and insecure programs, it is strongly suggested that you use an automatic software update tool to scan for vulnerable programs on your computer.

3. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



4. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Tư, 18 tháng 6, 2014

Remove URL:Mal Virus Infection (Uninstall Guide)

URL:Mal is an Avast detection of malicious websites that may infect your computer with malware. If you got this warning once and your anti-virus blocked it then everything should be fine. However, if you are constantly getting Infection URL:Mal pop-ups then your computer might be already infected with malware, most likely a Trojan horse (Trojan.Agent or Trojan.Tracur) that either attempts to download additional malware files on your computer or tries to connect a command and control server in order to report some kind of information about your computer. It could be even sensitive information, your passwords for instance, in case the Trojan horse also has spyware modules. One way or another, you need to remove it from your computer as soon as possible. Otherwise, you will keep getting URL:Mal infection pop-ups and most importantly, your computer will be wide open for cyber crooks. Besides, if your anti-virus can't handle this infection then you obviously will have to use additional tools to remove the infection. For more details, please follow the steps in the removal guide below.


OK, so you may have heard of Trojan horses but if you're not quite sure what they are and how they affect you and your computer, read on as we take a closer look. The first thing you need to know is that if your PC has been infected, you may well be at fault. URL:Mal infection blocked pop-up is usually a good indicator that a Trojan horse is active. At least, you have had a part to play in the process. I hear you – surely no one would knowingly infect their own computer with malware, but that's where Trojan horses get sneaky. In order for a Trojan to infect your computer you have to install the application's server function. And this is how the software gets its name; from Greek mythology where the ancient Greeks infiltrated the city of Troy by hiding their army in the belly of a giant wooden horse. This is how modern day Trojan horses work too as they convince you that they're legitimate programs that have nothing wrong with them. This is known as social engineering.

A Trojan horse may be sent to you by a spammer in an email. Open the email click the enclosed attachment and boom – you've just installed the Trojan on your machine by running the .exe file. This common method is employed by the creators of Trojans as, unlike viruses, Trojans don't replicate themselves – they rely on you to do their dirty work by executing them yourself. After execution and installation are complete the server linked to the Trojan will launch automatically each time you log on. And as a result, you may get URL:Mal pop-up on every startup.

You may also install a Trojan horse or some other kind of malware if you've downloaded a program that has been designed to look like the latest must-have software – but it will be disguised as something that has a Trojan attached - another instance of social engineering.

Trojan horses are definitely something you want to avoid at all costs and you shouldn't be fooled into thinking they won't cause you any problems just because they're not technically a virus. Trojans are still malicious software, and they are an unpleasant one at that. Trojan horses can unleash a whole world of pain on your computer, your hard drive and your files by corrupting your data and make it impossible to access. Just imagine the nightmare of not being open any of your files or documents. As I said, Trojan are very often installed with spyware modules that can steal your passwords and credit card information.

Thankfully there are a number of precautions you can take. From making sure you have reputable – and bang up to date – anti-virus and anti-malware programs installed on your machine, to never opening emails if you don't recognize the sender. Should you open such an email by mistake please, please don't open any attachments! Simply delete the mail. Then, don't visit shady websites and don't download files from dodgy, unreliable sites.

To remove URL:Mal and other threats that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a down comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


URL:Mal removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. As this infection is known to be installed by vulnerabilities in out-dated and insecure programs, it is strongly suggested that you use an automatic software update tool to scan for vulnerable programs on your computer.

3. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



4. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Năm, 12 tháng 6, 2014

Remove USPS Virus (Uninstall Guide)

First of all, I want to make it very clear that there's no such thing as the USPS virus. Just like any other company USPS is almost continually targeted by scammers and cyber crooks who try steal your personal information or infect your computer with different types of malware. So, when I say USPS virus I have different malicious programs in mind that use the same spreading vector - fake USPS emails. Most of the time, fake email notices from "USPS.com" claim that a package you were actually expecting could not be delivered. It's an old scam actually but unfortunately still works pretty well despite multiple warnings from the company itself and well known security companies. I know that some people are ashamed they fell for it but the truth is there's really no need to be ashamed. Report the scam, learn your lesson and don't repeat the same mistake again.

Fake USPS email notification. Anyone else notice the misspelling?
Infected with the USPS virus? Don't freak out! You aren't the first person to ever get infected. This guide will walk you through removing malware from your computer. Now, you need to understand that this infection is not the same for everyone. Infected email attachments install different malware. You will have to run multiple anti-malware tools to detect and remove it. Very often, it's a combination of a Trojan horse, spyware and malware that can send out email from your email account. So what's the deal with USPS viruses then and why should you try and protect yourself from them? The problem for most people lies in the fact that they are more often than not surreptitiously downloaded onto your computer without your knowledge after you run an infected email attachment. Let's take a closer look at the different types of malware your PC can get infected after opening an infected attachment:
  • Adware: we all know adware – those annoying pop-up adverts that distract us when we're in the middle of working (or playing) online. Irritating yes, but did you know that adware also monitors the sites that you visit and then targets these ads to you? It might sound useful, but if you have adware on your PC it can have a detrimental effect on your operating and Internet speeds.
  • Password crackers: ok, these can be a lifesaver if you've lost or forgotten your passwords, but should someone unscrupulous gain access to your log-ins – well, it's definitely not such good news. Jokes: joke programs? Hmmm. Not viral and not usually harmful – but not particularly funny either!
  • Dialers: this one is definitely no laughing matter. Dialers redirect your Internet connection to someone else's computer. And that means you end up footing the bill for their Internet charges!
  • Remote admin tools: great if someone you trust needs to fix an issue on your PC. No so fantastic when they're being deployed by a mysterious third party, for example creepware authors.
  • Spyware: whilst fairly closely related to its cousin adware, spyware can be a lot more intrusive. At its 'best' it will simply monitor your Internet usage habits and send targeted spam mails to your inbox or bombard you with pop-up adverts. At its most dangerous it will collect personal data such as passwords, your contact address book, your hardware and software configurations plus personal identity information such as your name, address, date and place of birth and gender. Its even more malicious form may use key loggers to capture which keys you're hitting. In other words it will be capturing your passwords, credit card information and online banking details
Pop-up adverts can be the least of your worries if you're unlucky enough to get hit by a really nasty USPS malware. I strongly suggest taking steps to protect yourself today. Explore the original notice in greater detail. If you are not sure if it's a genuine email notice, contact USPS and ask for verification. Scan email attachments with anti-malware software before opening them.

To remove this virus and other malware, including rootkits, that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


USPS virus removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Bảy, 7 tháng 6, 2014

Remove SearchProtection.exe Virus (Uninstall Guide)

Infected with SearchProtection.exe virus? Read on as we take a closer look at what it is, why it's dangerous, how it's distributed, and – crucially – how to remove it.


First of all, you should know that there are more than one malicious program that uses this process name and file to trick users into thinking that it's a genuine and safe program. However, some malicious programs are more dangerous than others. The least dangerous variant of SearchProtection.exe belongs to a PUP called Spigot. This PUP changes default home page and search engine. It may also display ads, sometimes very intrusive and even misleading. Surprisingly, it changes default search engine to https://search.yahoo.com/?type=599486&fr=spigot-yhp-ch which means they are somehow affiliated with the Yahoo company. If the suspicious SearchProtection.exe *32 file found on your computer causes the same problems then it's not that bad after all because it's just a PUP or adware at worst if you want. Unwanted changes and system modifications are usually restored rather easily. But as I said, there are more dangerous programs, mostly Trojans, that use the same file name. The best way to find out what type of malware is installed on your computer is by scanning your computer with anti-malware sofware.

Trojans are used for purely malicious purposes and will either damage your files, data and PC, or compromises its security. For the most part, SearchProtection.exe Trojan horses are spread via email but they also use instant messages or file-sharing tools to worm their way onto your hard drive. This is where the cunning part comes in, because the author of the Trojan needs to convince you to accept his so-called gift, and use it to wreak havoc upon your system. Just as the ancient Greeks did all those years ago.

There are a number of different SearchProtection.exe viruses; some are browser plug-ins that make you believe you're downloading a viewer that will let you view e-cards. This may then install software which will then bombard you with annoying pop-up adverts.

Pop-up ads are irritating but some Trojans can really be nasty. Take the ones that enable a third party to access your PC via the Internet. These open a portal on your system which they will then use to connect to your computer. This unscrupulous person can then view, modify and even delete your files. They may also log your keystrokes which enables them to monitor the websites you visit, and potentially steal your passwords.

To remove SearchProtection.exe virus and other malware, including rootkits, that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


SearchProtection.exe virus removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Thứ Năm, 5 tháng 6, 2014

Remove MalSign.Generic (Uninstall Guide)

MalSign.Generic is a generic detection for malicious programs that features or behaviors indicative of trojans, spyware, worms or even viruses. MalSig means malicious signature. There are thousands of malware threats that fall under this category, for instance, MalSign.Generic.98F, MalSign.Generic.6A6, MalSign.Generic.6A4, MalSign.Generic.853, MalSign.Generic.A8A, MalSign.Generic.89B, Malsign.Generic.c28 and so on. I could easily continue the list but I think you already got the idea. They are start with the same indicator but have different identifier at the end which means that it's either a new variant of the same malware family or slightly modified version that may use additional features for example. One way or another, if your computer is already infected with this malware, please follow the steps in the removal guide below.


What exactly is MalSign.Generic and how does one infect your computer?

Well, firstly it might come as quite a surprise to learn that you actually play a part in the process. This is because for this malware to attack your machine you need to install the server part of the application. But why would you do this unwittingly? This is the cunning part – and much like the mythological Greek story where the Greek army conned their way in the city of Troy by hiding inside a giant wooden horse, so too will the creator of the malware version of a Trojan convince you that there is nothing wrong with it; a practice known as social engineering.

In another scenario, the author might send you the malicious code as a file in an email, hoping that you open the attachment and then execute the malware by running the .exe file to install it. This is because, unlike a virus, it doesn't multiply of its own accord; it needs you to execute and install it instead. Once this has been done the malware server will automatically run every time you log in to your PC.

Why have I been targeted by this malware?

As mentioned, such malware infections are commonly spread via email attachments. The author will attach the file containing the malware to a mail and then spam hundreds or even thousands of people. And if you're unlucky enough that your name is on the list – one of them could be you.

Likewise if you've been sucked in to downloading something less than reputable – i.e. through social engineering – you may also find yourself on the receiving end of MalSign.Generic.

Is it a threat?

MalSign.Generic can be particularly nasty. Although not technically a virus, they are still a very unpleasant strain of malware and they can cause untold damage to your computer, your hard drive and your files and data. They can corrupt data on your system and make it inaccessible – and you probably don't need me to tell you how much of a nuisance that will be.

What can I do to remove MalSign.Generic and protect myself from such threats?

Luckily there are a few steps you can take to protect yourself from MalSign.Generic. Probably the most obvious one being to never open emails from an unknown sender. And if you do open one in error – definitely do NOT open any attachments. All you need to do in this situation is to delete the message. You should, it goes without saying, also install a reputable anti-malware on your system as this will scan any files you download – even those that are sent by someone in your contact list.

If you do find you've been infected by MalSign.Generic, scan your computer with anti-malware software and delete the questionable files. If you are unlucky enough, you may have to reinstall your operating system too, which is not fun. Therefore, it makes all the sense in the world to have a decent anti-malware installed and to exercise a little caution when opening emails.

To remove MalSign.Generic and other malware, including rootkits, that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


MalSign.Generic removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. As this infection is known to be installed by vulnerabilities in out-dated and insecure programs, it is strongly suggested that you use an automatic software update tool to scan for vulnerable programs on your computer.

3. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



4. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Remove TR/Patched.Ren.Gen (Uninstall Guide)

TR/Patched.Ren.Gen is a Trojan horse malware that convinces you it is safe and then insidiously attacks you from the inside. If your computer is infected with this malware, please remove it using the removal guide below.

Although a Trojan horse is not, technically speaking a virus (more on that later) it can be similarly defined as a computer program which is normally hidden within another seemingly innocent program that then replicates itself and inserts itself into other programs or files. The intention of this being to perform a malicious function, such as stealing or simply destroying data. However, unlike a regular computer virus, Trojan horses are slightly different as they do not reproduce themselves naturally – they need you to help them with that.

TR/Patched.Ren.Gen detection in Windows temp folder
Put simply, TR/Patched.Ren.Gen is a program that performs an untoward action which was fully intended by the programmer - but something that the user – i.e. you or I - would not be at all happy about and would not accept if we knew of its existence. The majority of people use the term 'Trojan horse' when talking about a program that has been created to cause damage or harm, but that is not replicating.

So what does TR/Patched.Ren.Gen do and how dangerous is it to the average PC user?

At their least harmful (but still annoying) it may install its server on to your PC and then bombard you with pop-up adverts for products or websites that you probably have no interest in. However, at its worst, this Trojan horse can infiltrate your hard drive and then monitor the websites you visit and log your keystrokes (with the aim of stealing your personal data and passwords). Obviously this is online fraud at its nastiest, but some Trojans merely take pleasure in causing you harm for no better reason than their own pleasure. These might corrupt your data and files, locking them so they're inaccessible or they may just delete them altogether.

Tell me; how does it infiltrate my computer?

There are a number of ways that you may end up with this Trojan horse on your PC. Some come attached as .exe files in spam emails, and some may be cunningly disguised as a piece of software that is just begging you to download it – a new episode of your favorite TV show for example. The whole art of the Trojan is to convince you – the unsuspecting citizen of Troy – to let it in and wreak havoc in your personal space.

How can I protect myself against this Trojan infection?

The ways that Trojans install themselves should give you the answer to that question. Obviously you should make sure your PC is up to date with the latest Windows security patches and you should run your (reputable!) anti-malware software regularly, but you should always think twice about downloading something that's screaming at you to install it – no matter how tempting! Finally, spam emails? Don't open them. And if you do so by accident, whatever you do – don't click on any attachments. Furthermore, don't download software from unreliable sources, warez and cracks sites.

How can I remove TR/Patched.Ren.Gen?

To remove TR/Patched.Ren.Gen and other malware, including rootkits, that may have been installed on your computer, please follow the removal guide below. If you have questions, leave a comment below. I will be more than happy to help you. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


TR/Patched.Ren.Gen removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



Chủ Nhật, 1 tháng 6, 2014

Remove Hacktool:Win32/Gendows (Uninstall Guide)

Hacktool:Win32/Gendows is a malicious tool often used to activate illegal versions of Windows. The problem is that cyber crooks use it as a bait to install Trojans, rootkits and other malware. It's not a secret that some users try to 'crack' Windows instead of buying it. Very often, they end up installing malware on their computers. Anyone who spends much time online (hang on, isn't that all of us?) needs to be aware of the threats posed by such malware. The problem is, there are so many different varieties out there it can be a little tricky to keep up with all the latest bad guy news. With that in mind, this article is going to take a fairly brief look at a type of malicious software called Hacktool:Win32/Gendows.

This especially nasty malware has a very sneaky way of installing itself on your PC and it's made all the worse by the fact that it had a helping hand to do so – a helping hand by you. Hacktool:Win32/Gendows can have some disturbing and extremely inconvenient knock on effects on your computer – and on your life, so read on to find out exactly what, and how you can protect yourself from them.

Hacktool:Win32/Gendows detection by MSE
Hacktool:Win32/Gendows may be attached to a file received in an email or it may have come disguised as a program that you downloaded. In its simplest terms, the authors of Trojan horses surreptitiously encourage you to download and install them on your PC by making them appear to be very tempting: perhaps they're an email attachment that has a title that's just too good to ignore.

The main trait of Trojan horses is that once they've wormed their way onto your PC they will begin to attack and destroy your files and documents.

If you think that malware won't bother you, you should not be so complacent. It's not enough to merely have an antivirus installed on your machine and think that's the be all and end all. You need to manually run it regularly and you should also turn on your computer's firewall. Because malware is constantly being upgraded, that means that Windows and other software is too – therefore you should always make sure you have the latest security patches installed on your PC too.

Having said that, Hacktool:Win32/Gendows can slip through the net, so you need to exercise extra caution when you're using the Internet. Don't download gimmicky looking programs that you know in your heart of hearts you don't need – stick with the big names of antivirus programs, viewers and the like. And also stay extra alert when opening emails. Don't open mails (or instant messages) from senders you don't know and never ever click on a link or open an attachment if you don't know where it's come from.

The Trojan horse malware is far more serious than many other types of malware so you really should take all the steps you can to protect yourself against this sneaky and unscrupulous online parasite. If your computer is already infected, please follow the steps in the removal guide below. If you have any questions, please leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com


Hacktool:Win32/Gendows removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.