Sunday, July 17, 2011

Remove Windows Vista Home System Repair fantasy scanner

Windows Vista Home System Repair depicts any computer system as a nursery of infections. The description is limited only by fantasy of the program developers.
Get rid of Windows Vista Home System Repair or it will keep notifying you of imaginary detections in the most inappropriate moments. That is not a coincidence, but a tactic of the adware to select the busiest time for users to suddenly remind of security issues. Perhaps the design o the hackers is that users would be more inclined to take the program into consideration and to follow its suggestion, if they get irritated with its popups interrupting other programs.
To introduce the misleading detector of threats, hackers follow such common tactics of malware distribution as trojan based backdoor introduction and misleading online ads. In the former case, removal of Windows Vista Home System Repair needs to cover the trojan that is used to distribute its copies.
Windows Vista Home System Repair uninstaller:

Manual removal guide:
Delete infected files:
Delete infected registry entries:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = ‘”C:\Documents and Settings\[CurrentUser]\Local Settings\Application Data\[random].exe” -a “%1″ %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = ’1′
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe”‘
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”C:\Documents and Settings\[CurrentUser]\Local Settings\Application Data\[random].exee” -a “%1″ %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = ’1′
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%LocalAppData%\kdn.exe” -a “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation “TLDUpdates” = ’1′
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”C:\Documents and Settings\[CurrentUser]\Local Settings\Application Data\[random].exe” -a “%1″ %*’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”C:\Documents and Settings\[CurrentUser]\Local Settings\Application Data\[random].exe” -a “C:\Program Files\Internet Explorer\iexplore.exe”‘

