Tampilkan postingan dengan label malware. Tampilkan semua postingan
Tampilkan postingan dengan label malware. Tampilkan semua postingan

Remove Recommended for You Pop ups and Malware Uninstall Guide

Over the last few weeks, some of our readers have alerted us to the fact that they got some kind of malicious software that redirected web browsers to different 3rd party websites and displayed intrusive advertisements in the lower right hand corner of their computer screens. No joke. However, its a very common issue and sometimes its rather difficult to tell whether its caused by malware, browser helper object or just a useless web browser extension. Usually, web browser redirects are indeed caused by malware, mostly rootkits and Trojan horses, but thats not always the case. So, we decided to dig into the issue and trace the root of the problem.

Shortly after we ran a certain set of Trojans on our test machine, we found a sample (Trojan.Small.dac or Troj/RuinDl-Gen) that was responsible for the combination of the Recommended for You pop-ups and web browser redirects. The web browser redirects seem to happen at random or at least they didnt happen all the time. The Trojan horse displayed two different pop-up windows: an iPhone looking box with various advertisements and a smaller one with just random ads. It happened in Internet Explorer, Mozilla Firefox and Google Chrome. Cant blame the browser this time. Its probably a cross platform malware too. Besides, it happened on both 32-bit and 64-bit systems. Ads were not very intrusive, they didnt show up like every two or five minutes. Once you minimize the ad box, it doesnt appear until you restart your computer. Thats right, you cant close the ad box, when you click the "X" it just minimizes into a smaller box that says "Recommended for You".

An-iPhone looking ad box:



A smaller one, but still very annoying:



Recommended for You box:



Now, that we know the root of this problem (malware) we can take the appropriate actions. Running a full virus scan with anti-malware software is essential step towards solving the Recommended for You malware problem. Once the Trojan horse is gone, you need to replace Windows Host file since its partly responsible for web browser redirects and annoying pop-ups as well. Yes, the Trojan modifies Windows Hosts file making web browser inquiries a subject to redirect. To remove this malware from your computer, please follow the steps in the removal guide below. Should you need any further assistance, dont hesitate to contact us or just leave a comment below. Good luck and be safe online!

http://deletemalware.blogspot.com


Recommended for You malware removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this malware from your computer.

3. To reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.

4. Remove files from Windows %Temp% folder.

Tell your friends:
Read More..

Remove File Recovery Malware Uninstall Guide

File Recovery is a rogue PC repair and optimization product, misleading at best and fraudulent at worst, that carries a dangerous payload. This fake system repair application pretends to scan a computer for stuff like invalid Windows registry keys, hard drive reading errors, junk files, critical system errors, RAM failures, and much more. Since it doesn’t actually scan a computer for any of these issues it’s not surprising at all that File Recovery scareware reports a bunch of non-existing system errors and threats on a targeted machine.

The worst part is that it hijacks a compromised computer, intentionally misrepresents the system status and asks user to pay for bogus PC repair software activation to remove non-existing hard drive errors and other risks from the computer. Unlike ransomware, it doesn’t freeze your computer screen (thanks for that). But it does perform actions that prevent user from accessing certain applications and Windows features. In rare cases, it can make computer unstable forcing unexpected reboots and blue screens of death.



If you pay for this rogue application you will lose your money and probably without a chance to get them back. But you can still contact your credit card company and dispute the charges. Who knows it might just work. After all, you don’t have anything to lose. At least you know it’s a scam. Besides, more than 4% of PC users that got infected with scareware think that File Recovery and similar applications are genuine Windows products designed to enhance system protection against viruses and system failures. Bit shocking isnt it.

Scareware infection symptoms are almost identical – fake scanners and misleading security alerts popping up at random intervals. Also, File Recovery is a very generic name and very competitive keyword at the same time. The last one was called Data Recovery. Cyber crooks choose very competitive keywords as their bogus software names making it hard to rank well in search results. It’s a wise move but users will probably search for File Recovery virus or malware or anything like that and we are pretty sure that Google will handle everything just fine.

Cyber crooks use various techniques like spam; drive-by downloads, and fake virus scanners to distribute rogue security applications. Even thought, most of the reports show that Fake AV applications seem to be on decline, they are still a significant threat. There are still many active scareware distribution channels and affiliate networks called ‘partnerka.’ The rules are different now. Two or more years ago, cyber crooks that were promoting scareware earned ~$25 per sale or sometimes even more. Now, they can earn $50 and more. 10k infected machines per day adds additional 10% revenue share. But yeah, in the last few months, there hasnt been much to talk about.

This rogue HDD repair program hides certain files, usually shortcuts and Desktop icons, and moves other files to Windows %Temp%smtmp folder.



Do not delete any files from your Temp folder. We will show you how to restore hidden files in the removal guide below.

Certain fake security applications as well as fake PC repair utilities use very aggressive methods to scare users into believing that their computer are badly infected or damaged while others show up every ten minutes or so and remind you about security issues that need your attention. Recent scareware variants had working uninstallers, so levels of aggressive behavior are clearly different. Unfortunately, File Recovery malware uninstall doesnt work. You can find the uninstaller in your "All Programs" list. Clicking uninstall button calls a fake system error (see the image below). The rogue application claims that you cannot uninstall it because your local disk is not accessible. The funny thing is, you can uninstall whatever program you want but not this one. Coincidence? :) Of course not.



File Recovery removal is relatively easy unless it comes bundled with sophisticated malicious software, very often the ZeroAccess rootkit. When running, the rogue application blocks access to Web pages by showing a warning message in the browser and shuts download running antivirus software. But don’t worry there’s definitely a way to remove File Recovery virus. Scroll down a bit for step-by-step removal instructions. If you need help removing this malware from your PC, please let me know (leave a comment below). Good luck!

Source: http://deletemalware.blogspot.com


Quick File Recovery malware removal:

1. Use the activation key given below to register your copy of File Recovery malware. This will allow you to download and run recommended malware removal software and automatically restore hidden files and shortcuts. Dont worry, youre not doing anything illegal. Select "Trial version. Click to activate" (at the bottom of the fake scanner screen). Use fake email and the following activation key:

fake@mail.com
56723489134092874867245789235982



2. Download TDSSKiller and run a system scan. Remove found rootkits (if any). Reboot your computer if required.

3. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.


Alternate "File Recovery" removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



If you still cant see any of your files, Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter explorer and hit Enter or click OK.



2. Open Internet Explorer. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter iexplore.exe and hit Enter or click OK.

Open Internet Explorer and download TDSSKiller. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller to remove the rootkit.



3. Finally, download recommended anti-malware software (direct download) to remove this virus from your computer.

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Dont forget to update the installed program before scanning.


Manual File Recovery removal instructions:

1. First of all, you need to unhide the files and folders. Select Run... from the Start Menu or just hit the key combination CTRL+R on your keyboard. In the Open: field, enter cmd and hit Enter or click OK.



At the command prompt, enter attrib -h /s /d and hit Enter. Now, you should see all your files and folders. NOTE: you may have to repeat this step because the malware may hide your files again.



2. The rogue application will place an icon or your desktop. Right click on the icon, click Properties in the drop-down menu.



Then click the Shortcut tab.

The location of the malware is in the Target box.



On computers running Windows XP, malware hides in:
C:Documents and SettingsAll UsersApplication Data


On computers running Windows Vista/7, malware hides in:
C:ProgramData


NOTE: by default, Application Data folder is hidden. Malware files are hidden as well. To see hidden files and folders, please read Show Hidden Files and Folders in Windows.

3. Click "Find Target..." button, it will take you to the folder where the malicious files are located. Or you can simply browse to those files manually.

Example Windows XP:
C:Documents and SettingsAll UsersApplication Data2yZ~pcB_RY.exe

Example Windows Vista/7:
C:ProgramData2yZ~pcB_RY.exe

Basically, there will be a couple of  files named with a series of numbers or letters.



For example, rename 2yZ~pcB_RY.exe to virus.vir and click Yes to change it. Please note, your file name will probably be different. 



It should be: C:Documents and SettingsAll UsersApplication Datavirus.vir

Instead of: C:Documents and SettingsAll UsersApplication Data2yZ~pcB_RY.exe

4. Restart your computer. The malware should be inactive after the restart.

5. Open Internet Explorer and download TDSSKiller.This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller and remove the rootkit.



6. Download recommended anti-malware software (direct download) to remove this virus from your computer

NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Dont forget to update the installed program before scanning.


Associated File Recovery files and registry values:

Files:

Windows XP:
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%Application Data[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%DesktopFile Recovery.lnk
  • %UsersProfile%Start MenuProgramsFile Recovery
  • %UsersProfile%Start MenuProgramsFile RecoveryFile Recovery.lnk
  • %UsersProfile%Start MenuProgramsFile RecoveryUninstall File Recovery.lnk
%AllUsersProfile% refers to: C:Documents and SettingsAll Users
%UserProfile% refers to: C:Documents and Settings[User Name]

Windows Vista/7:
  • %AllUsersProfile%[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%DesktopFile Recovery.lnk
  • %UsersProfile%Start MenuProgramsFile Recovery
  • %UsersProfile%Start MenuProgramsFile RecoveryFile Recovery.lnk
  • %UsersProfile%Start MenuProgramsFile RecoveryUninstall File Recovery.lnk
%AllUsersProfile% refers to: C:ProgramData
%UserProfile% refers to: C:Users[User Name]

Registry values:
  • HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[SET OF RANDOM CHARACTERS].exe"
  • HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAssociations "LowRiskFileTypes" = /{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:
  • HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments "SaveZoneInformation" = 1
  • HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "CheckExeSignatures" = no
  • HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Use FormSuggest" = yes
Tell your friends:
Read More..

Remove Win32 Malware gen removal instructions

This page contains removal instructions for the Win32:Malware-gen infection. Please use this guide to remove this infection and any associated malware from your computer. If you have heard of the term Win32:Malware-gen in relation to computers but are not quite certain what it is, what it means and how it can affect you, read on as we will explain what it is, how it attacks your PC or laptop, how you can protect yourself against being affected – and of course, what to do in the unfortunate event that you do contract the Win32:Malware-gen.

This particular infection very often means that your computer is infected with a Trojan horse. It might be any other type of malware because its a generic detection but from my experience most of the time it indicates Trojan infection. Trojan horses are one of the nastiest forms of malware and can seriously threaten your computer’s security. The name comes from the Greek legend in which Greece won the Trojan War by hiding their warriors inside a huge, hollow wooden horse which they wheeled to the gates of the city of Troy, in order to ambush the unsuspecting city’s inhabitants. In computer terms, a Trojan horse is used to define a “malicious, security-breaking program that is disguised as something benign”. In simpler terms, if you download what you think is a music or movie file, and it is actually a Trojan in disguise you will have installed a program on your computer than can erase everything in your system, allow the author of the Trojan to access your computer and control it to attack other users. And perhaps most worryingly of all, it may collect all of your passwords, bank account details and credit card numbers, for instance if you contracted the Zbot malware.


So how does Win32:Malware-gen actually work and how does it infect your computer? Win32 Malware-gen is an executable program which means that when you open a file – the attachment in an email for example - it will perform one or more actions. Just as the Greeks fooled the city of Troy with their wooden Trojan horse, a computer based malware needs to somehow fool you to ensure that you execute it.

This malware will most likely be disguised as something that people want: perhaps a movie, TV series, music or a game. It can be downloaded from an archive on the internet, be obtained from a peer-to-peer file sharing website or simply from an email attachment. The nasty thing about Trojans and similar malware is that you don’t normally even know you’ve been infected and will probably only find out when your contacts complain to you that are trying to infect or attack them!

So how do you avoid falling victim to Win32 Malware gen? Firstly, make sure you have good quality and up to date antivirus software installed on your computer as this will scan all documents that you receive – even ones from senders that you know and trust. This is important as you never know if they have been unwittingly infected! Secondly never even open an email from an unknown source, let alone an attachment.

Even if the sender is a friend, you should still check what the file is before you open it. A lot of these infections spread via email contact lists or address books, so it’s always best to double check, firstly with your friend to see if they intended to send you a file and then to scan the file with your antivirus software. Many Trojans appear to come from a user as they impersonate the infected person once they have control of their computer, so double check. Better safe than sorry!

Lastly, no matter how tempting an executable email attachment might look – whether it’s purporting to be a trailer for the latest big Hollywood blockbuster, a hit song, or a must play game don’t be tempted to ‘just have a quick look’ as once you’ve clicked on it, if it’s infected, that Win32:Malware-gen will be already installed upon your computer and wreaking its damage.

The biggest question is probably whether you should repair your PC or laptop or reformat it. This can be a bit of a tricky decision because as tempting as it is to repair your computer without having to start from scratch and reinstall your system, even experts find it very hard to know whether the malware is completely removed and not still running, hidden, in the background.

On the plus side though the majority of the infections stem from the same few hundred currently-circulating Trojans so experts will be aware of them and able to remove them with the appropriate removal program. Be aware though that to reinstall your system or to clean your computer completely (or as completely as possible) can take anywhere from a couple of hours to several days.

Having said that it is probably best to try and repair your computer first as in most cases it is possible to completely remove Win32:Malware-gen. If the infection does keep returning, however, it is possible that it was not totally removed so you may want to think about deleting and reinstalling your system. If you think that your computer has been infected with Win32:Malware-gen, you should download recommend antimalware software and run full system scan. Very often users say that their antivirus found the infection but cant remove it, in such case please follow the removal instructions below. If you need help, leave a comment below. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Win32:Malware-gen removal instructions:

1. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



2. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.



3. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of this virus from your computer.

Read More..