Wednesday, March 16, 2011

Remove E-Set Antivirus 2011 fraudware

The purpose of this rogueware propagation is to make users   trust it. This provides a double benefit for hackers pushing it. In the best case, they succeed in selling the counterfeited utility. Even if user refuses buying it, there is still another benefit as the adware opens and maintains a conduit enabling utilization of a compromised machine in a  spybot network  and a range of other tricky actions.
Get rid of E-Set Antivirus 2011 as there is no use trusting it  and  allowing it exploit your PC in tricky schemes.  The program will resist removal attempts unless appropriate precautions are applied for its extermination. It may also upload extra rootkit protection to deal with antivirus tools. That is why you may need to restart computer in safe Mode with Networking. This is possible with Advanced Options Boot Menu. The menu is available on system restart by  pressing  F8 (Windows).
Click here to try launching E-Set Antivirus 2011 removal tool. Should its installation or download fails, please act as suggested in the paragraph above (set safe Mode with Networking).

E-Set Antivirus 2011 screenshot:


E-Set Antivirus 2011 removal tool:


E-Set Antivirus 2011 manual removal guide:
Delete E-Set Antivirus 2011 files:
 %ProgramFiles%\E-Set 2011\
%ProgramFiles%\E-Set 2011\e-set.exe
%UserProfile%\Desktop\E-Set Antivirus 2011.lnk
%System%\msiexecs.exe
c:\Documents and Settings\All Users\Start Menu\E-Set 2011\
c:\Documents and Settings\All Users\Start Menu\E-Set 2011\E-Set Antivirus 2011.lnk
c:\Documents and Settings\All Users\Start Menu\E-Set 2011\Uninstall.lnk
Delete E-Set Antivirus 2011 registry entries: 
HKEY_CURRENT_USER\Software\A88246
HKEY_CURRENT_USER\Software\Mon246
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "E-Set 2011" = '%ProgramFiles%\E-Set 2011\e-set.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "WinNT-A8I 16.03.2011"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe "Debugger" = 'msiexecs.exe -sb'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe "Debugger" = 'msiexecs.exe -sb'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe "Debugger" = 'msiexecs.exe -sb'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe "Debugger" = 'msiexecs.exe -sb'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safari.exe "Debugger" = 'msiexecs.exe -sb' 


1 comment:

Rob said...

Dude thanks so fucking much. That program was really fucking with my computer and I knew I could go into the registry to take it out somehow, but I'm just not a computer whiz. I knew that when I went into the program files folder for E-Set and it said I can't delete it I would have to go into registry. Thanks a lot for these instructions. Saved my life.