Showing posts with label warning. Show all posts
Showing posts with label warning. Show all posts

Wednesday, April 8, 2009

Firewall Warning popup as misleading WinPC Antivirus ad and a crafty trap leading to another malware

Lots of users are familiar with behavior of malware, as they have read somewhere something about such sort of programs that may be identified by annoying ads and destructive effect on the targeted computer. However, they do a common mistake seeking the way to remove symptoms of malware, e.g. to remove Firewall Warning popup, instead of rooting out the true malware which is a real source of security risk and fake notifications.
It is a real example of latest trickery of this kind with the fake Firewall Warning popup that reads as follows:
“FIREWALL WARNING. Hidden file transfer to remote host was detected. WinPCAntivirus has detected that somebody is trying to transfer your private data via Internet. We strongly recommend you to block the attack immediately. Details of the attack: remote host transfer IP 97.216.34.74; remote user computer name ‘FORENSICS’”
Hackers offer the solutions through the Internet using all legitimate and illegitimate methods to redirect users’ requests to Google and other popular search engines regarding the removal of above fake Firewall Warning popup to the websites offering the Firewall Warning popup removal solution, which is a malware very similar to the one generating fake firewall popup and needs to be purchased for the price from 30 to 50 dollars.
Remove the root of Firewall Warning popup removing the malware generating it. This malware is normally the malware of WinPC Antivirus. Click here to start free scan in order to get rid of Firewall Warning popup using Spyware Doctor with antivirus.

Firewall Warning screenshot:


Firewall Warning removal tool:

Monday, February 2, 2009

Internet Explorer Warning - another technique of malware of Antivirus 360 adverting

Blocking Internet browsing is another tactic applied by the malware of Antivirus 360. A user may see the following alert surfing the web. “Internet Explorer Warning - visiting this web site may harm your computer!” This is a true sign of infection. The infection is either trojan responsible only for generating this alerts or trialware of Antivirus 360 – or both the infections may be present. It is also dangerous to ask Google or another search engine how to remove “Internet Explorer Warning - visiting this web site may harm your computer!” alert, because hackers have predicted this and created numerous fake Internet security blogs suggesting to remove “Internet Explorer Warning - visiting this web site may harm your computer!” by installing fake removal tools like Antivirus 360. Click here to download Spyware Doctor with antivirus start free scan to identify and get rid of “Internet Explorer Warning - visiting this web site may harm your computer!” source.

Thursday, January 8, 2009

Correct removal of “Warning Dangerous Spyware” background is the trojan removal

If your desktop background or / and image has suddenly or after system reload turned to black theme with popping up window at the center with inscription at its top in red capital letters “WARNING” and “Dangerous Spyware” below, and then some text of scaring and adverting sort (varies), there is a spyware agent (trojan) at your PC that was a generator for such alert.
The change of desktop theme and the pop-up are usually strengthened in their effect with snowy spots covering desktop shortcuts and black spots in white rectangle at the desktop toolbar.
We are recommending to remove “Warning Dangerous Spyware” desktop background using trusted application for malware / trojan / viruses / etc. removal - Spyware Doctor with antivirus. Follow the link below to start scan and get rid of “Warning Dangerous Spyware” backgrund at its root, i.e. remove trojan responsible for its generation (using Spyware Doctor with antivirus). The scan is free and would definitely indicate the source of danger, though manual removal of “Warning Dangerous Spyware” pop-up is not recommended as there is a threat of trojan’s intervention with consequent system collapse and even disk formatting. It is thus recommended to continue using security program recommended here for removal of rogues found in the scan and for future system protection.

“Warning Dangerous Spyware” desktop background text:
Warning
Dangerous Spyware
Many viruses were found on your computer such as: Trojan Horse, PassCapture, etc.
Your personal information can fall into in the "third hands".
Please check up the computer with a special software, Thank
“Warning Dangerous Spyware” desktop background screenshot:

“Warning Dangerous Spyware” desktop background automatical remover:

Monday, December 15, 2008

How to remove “Warning. There are serious threats detected on your computer” popup with all its roots

It is important to remove “Warning. There are serious threats detected on your computer” popup. Needless to say, this pop-up that pretends to be generated by your own system is a fake alert. It is easy to recognize that something wrong if your system is set to use other language than English, because the popup is not adjustable to be translated, of course. At the same time, users very rarely make any effort to analyze whether such like this alert is not tricking them and, unfortunately, thousands of users, according to the very conservative estimate, have paid for installation of recommended protection, malware of MS AntiSpyware 2009. For those who belong to that number there is bad information. They need to remove MS AntiSpyware 2009 as this malware includes trojans and dll files hardly compatible by their nature with Windows. What is worse, MS AntiSpyware 2009 soon claims for updates and start bothering users again unless the removal of MS AntiSpyware 2009 is performed.
“Warning. There are serious threats detected on your computer” popup is to be removed properly, i.e. not just blocked, since the trojan responsible for its appearance may be blocked in this “popping-up activity” but it thus would attempt to download trialware of MS AntiSpyware 2009 through other methods, e.g. connecting itself to remote server and downloading the malware trial from there. Start identifying scams for free right (using Spyware Doctor + antivirus) now and get rid of “Warning. There are serious threats detected on your computer” popup, as well as eliminate any other treat, following the link below.

“Warning. There are serious threats detected on your computer” popup screenshot:



“Warning. There are serious threats detected on your computer” automatical remover:


Wednesday, November 12, 2008

"Warning! Potential Spyware Operation" popup removal instructions

Many users complained on this pop up to appear frequently especially when PC is overloaded. There are two variants of this pop-up with slight differences, the one above with two mistakes, one seems to be mistyped another either misspelled or mistyped; except terrible noises this pop up indirectly slows down computer, i.e. trojan adware producing this message also intentionally binds system resources to enlarge scaring effect.

Trojan FakeAValert removal ensures that you remove
“Warning! Potential Spyware Operation. Your computer is making unauthorized copies of your system and Internet files. Run full scan now to pervent any unathorised access to your files! Click YES to download spyware remover …”
and
"Warning! Potential Spyware Operation. Your computer is making unauthorized copies of your system and Internet files. run full scan now to prevent any unauthorised access to your files. Click here to download spyware remover”,
as well as that you stop system destruction.
We recommend using true virus and malware removal tool (Spyware Doctor + antivirus) to get rid of Trojan FakeAValert, i.e. to eliminate “Warning! Potential Spyware Operation …” pop-up or its variants. Follow the link below to start free download of relevant Trojan FakeAValert removal tool.

Trojan FakeAValert screenshot:


Trojan FakeAValert automatical remover (free scan):

Trojan FakeAValert manual removal guide:
Delete Trojan FakeAValert files:
system.exe
autorun.exe
printer.exe
WinAvXX.exe
Delete Trojan FakeAValert registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run\”WinAVX” = “%System%\WinAvXX.exe”
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run\”WinAVX” = “%System%\WinAvXX.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Shell” = “Explorer.exe”

Tuesday, October 21, 2008

Trusted medicine to remove av-check-online-scan.com malware and hijacker

If you have visited web-site Av-check-online-scan.com, you may still remember how it works. WARNING! Do not download this page any more or at all as it may contain malicious scripts and this is a real challenge to your safety! However, that is easy to say that the site must not be visited while it is a hijacker, i.e. your browser home-page may be set as av-check-online-scan.com and anytime launching web-browser you are drawn to the same page, av-check-online-scan. Honestly, too many people allow such treatment, they simply say “damn hackers’ and… forget this. If this case is yours, trialware of some rogue might have been residing for few ages in terms of computer industry at your local disks. This application collects and sends any data that it finds useful to the remote server. Stop this trickery, remove av-check-online-scan.com related scamware right now!
One may say “come on, man, what are you messing about. I know this site pushes certain scam, I know its name – WinSpywareProtect!”. And I would agree – you are right, but is there are any conflict with my explanation of av-check-online-scan.com? I have just complained that not only this is a single reason to get rid of av-check-online-scan.com. Moreover, WinSpywareProtect is not a single malware promoted by av-check-online-scan.com so that complex tool should be used for your PC scan and cleanup. Follow the link below to scan computer free of charge and to perform av-check-online-scan.com removal and get rid of related threats with help of trusted malware removal tool (Spyware Doctor + antivirus).

Av-check-online-scan.com screenshot:


Av-check-online-scan.com removal tool:

Wednesday, July 2, 2008

Topvirusscan.com and Scanner.wspscanner.com Removal Tool

Topvirusscan.com and Scanner.wspscanner.com are ,alicious web-sites, hosted on the same web-server. They use trojan horse (usually Zlob or Vundo) to hijack your homepage and display fake malware scanners and security warnings forcing you to download and purchase WinSpywareProtect and Antivirus 2008 scamware. We recomend to install Spyware Doctor + antivirus to remove these annoying hijackers and Trojan installer from your computer.

Topvirusscan.com and Scanner.wspscanner.com screenshots:



Topvirusscan.com and Scanner.wspscanner.com automatical remover:

Wednesday, March 26, 2008

How to remove MalwareWar 7.3

MalwareWar 7.3 is a rogue (corrupt) anti-spyware with deceptive detection mechanism. It will generate fake spyware detection reports to trick you into buying full version of this useless crap. MalwareWar is a clone of well known MalwareWipe rogue, they have similiar interface and behaviour. We recomend to use automatical removal tool to get rid of this annoying program.

MalwareWar Remover for Windows Vista and XP

MalwareWar 7.3 screenshot:


MalwareWar 7.3 manual removal instructions:
Remove MalwareWar 7.3 files:
MalwareWar 7.3 MalwareWar 7.3.exe MalwareWar 7.3.url msvcp71.dll msvcr71.dll mwdb.dat uninst.exe Lang Lang\English.ini Quarantine MalwareWar 7.3.lnk MWLanguage.ini MalwareWar 7.3.lnk MalwareWar 7.3 MalwareWar 7.3 Website.lnk Uninstall MalwareWar 7.3.lnk Quick Launch\MalwareWar 7.3.lnk

Remove MalwareWar 7.3 registry entries:
HKEY_CLASSES_ROOT\AppID\{C291DEE7-D4B6-42d8-A016-302E6141D63B}
HKEY_CLASSES_ROOT\AppID\MalwareWar.EXE
HKEY_CLASSES_ROOT\CLSID\{13901470-5BCF-0EA6-A762-AD195455772B}
HKEY_CLASSES_ROOT\Interface\{195EA874-7AD8-4BE2-A1D1-ADDFFDC66DCA}
HKEY_CLASSES_ROOT\Interface\{2568D1BF-6D5E-4B17-81E5-7A97EF5D8F05}
HKEY_CLASSES_ROOT\Interface\{2F9DB89F-7F95-4C69-B775-A0C6C01DACE1}
HKEY_CLASSES_ROOT\Interface\{3CDB3874-DC96-4890-A786-4B6089E10980}
HKEY_CLASSES_ROOT\Interface\{5C03DE51-7AB7-41FC-8D50-ECDF39BA2DC0}
HKEY_CLASSES_ROOT\Interface\{5EFA24D1-944B-4ED8-99F1-2283F79E4136}
HKEY_CLASSES_ROOT\Interface\{65605733-BE0B-445A-B221-3C82A6BB1EE0}
HKEY_CLASSES_ROOT\Interface\{90E3F5BF-324B-433F-96C6-E272F2040D6B}
HKEY_CLASSES_ROOT\Interface\{B3FC6AF3-D3F4-496F-B8BF-8373BACE33F1}
HKEY_CLASSES_ROOT\Interface\{B6CB3B36-6134-45B8-83F0-6907B2538890}
HKEY_CLASSES_ROOT\Interface\{B71726E1-CBFE-425D-8446-15B51F54E493}
HKEY_CLASSES_ROOT\Interface\{C68F00CE-07D1-48AB-830E-D311D255C894}
HKEY_CLASSES_ROOT\Interface\{C9605621-B932-4359-AB54-5D88EB56A2A3}
HKEY_CLASSES_ROOT\Interface\{C9686C59-8568-40B1-9468-15446A529354}
HKEY_CLASSES_ROOT\Interface\{DAFAF86D-9B59-48C1-895F-4FF84A794675}
HKEY_CLASSES_ROOT\Interface\{E0394CFD-D54D-4826-932D-8379AB554882}
HKEY_CLASSES_ROOT\TypeLib\{2108EBD7-160B-4C23-A99F-1F559DDD320A}
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses
HKEY_LOCAL_MACHINE\SOFTWARE\MalwareWar 7.3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MalwareWar 7.3.exe 7.3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "MalwareWar 7.3"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MalwareWar 7.3

Wednesday, March 5, 2008

How to get rid of InfeStop crap?

InfeStop is a rogue anti-spyware program that may appear as an icon in your Windows tray and show a fake notification with a message that your computer system is in danger. InfeStop may then offer to download its application in order to remove the threat. If you follow the instructions, InfeStop will be installed and may redirect your Internet Explorer home page and search results to other unsolicited websites. Download InfeStop remover to clean your computer from this crapware.

InfeStop screenshot:

InfeStop automatical removal tool:


InfeStop manual removal instructions:
Delete InfeStop files:
Start InfeStop.lnk
Register InfeStop.lnk
InfeStop.lnk
InfeStopRemover.exe
InfeStopRemoverInstaller[1].exe
InfeStop
Remove InfeStop registry entries:
7ED16CC4-DA2C-47D5-8DFA-48F24C3D72C0
D07EDFBB-78CC-4CDF-AC18-9E4423CD6AC9
CB885521-F95A-489F-9300-D0443F5E0E63
B8800CB9-C55D-400F-8EC1-636C3F20AF4E
B8558FC6-A319-406A-BC04-D513CBD927A2
B4F6B8AE-A29B-40BF-BDBA-EFBDCE905597
AFE97E34-87D8-437D-AD1B-16E6849B2DB3
ABB527C6-0091-4E57-AAB0-9E3E5C08D3EC
AAEEE5AC-BF59-454E-B588-DAE798A47FA0
A40C59B2-E095-4026-A511-927414DC0739
A1871947-01AA-42E5-8425-BF66263F1930
91C695CC-FDA8-465A-8EAA-BBE958489FE1
90D5E019-A94C-417F-BC23-48A1CA7E72C5
7CECEB3B-14B1-4276-9400-4D8E0AB5C97C
77D58FB7-C0B6-44E7-8F84-D8CC9C5EFD9C
6880073E-4FBE-4E1A-BC0A-1ADD894A51FE
5EF97410-6B36-472D-85B8-28BD4DAA58FF
587BF857-3A33-4699-B46A-EBC49D2756A7
56AFBC76-4327-4714-ADCD-73F1DF6C06F8
558179B8-3924-4F90-B66C-1399DCB33E35
4F84A444-C316-4CF1-B140-C0A003A0E116
4AF4BD0E-B5FF-4524-AD24-7A7E92578A91
431BF761-BCD2-4B84-973D-AE58FA05327F
3C3034C0-29D9-4E44-8E08-E06CC81C57CE
366B5B4A-B2E0-4432-B3DA-DF92C41D2B1F
34F7A1B0-5C20-4FC2-83B0-DCC2A53EA4FA
2D5C7C0C-41FB-42EA-9D39-2AE4B946627B
1C257B5F-692F-424C-A7C9-142391B6EEA4
1178BF07-D400-401D-A70E-BE9A31E1291B
0F6C71AB-3052-4A2F-8CF0-59E89CF15C38
F32EF34A-3F7A-4D83-A8FF-DF48DDEC3211
EE23CE87-A04A-4D80-9BDC-ABA9FEF7BA17
DED690A6-0502-4527-B77C-ACD11C5B4FC3
C4554BDD-2562-4DA2-83BD-E347C154C88F
BAFC1A0F-BA7E-43DF-82B1-94E46896F961
B9EBB25F-99EC-43A2-9749-95C4515C0F3C
B0006330-DA13-4760-B50F-126864DA3AEE
AA05541F-27CC-4CB7-B918-E00FCA75862D
A55EE3A4-9E3D-4E92-8187-7961D7C47D96
A17F5211-3FFF-48DF-BF0D-89678B328AED
9BE8C57E-83B9-4F5D-81C3-F78200D43566
8897C37E-F484-41D5-90BF-8527E4B3E59B
73720165-4593-4323-ADD8-ED3CFD9B5268
5E317E31-3F40-40FB-8C19-3DEC7FD7346F
5580A51D-B549-41F8-899E-7290E9D8D9C9
407442F6-B7ED-4397-95FE-357F8E4112C5
38A951D6-F7B2-4857-8FAF-9E36F3BF451D
2882FD1F-1C1D-4354-B795-F045DCD6CA6D
20DA3F8E-A2B6-4B15-9A3E-4CD780919880
1661DF56-5F37-43DB-A34E-265084F989A6
InfeStop