Showing posts with label Spyware. Show all posts
Showing posts with label Spyware. Show all posts

Friday, December 4, 2009

0

Winsonar 2010 Ultimate Edition

  • Friday, December 4, 2009
  • Runtrailblog
  • Windows has a built-in task monitor, but the user will not be prompted for new-installed tasks and even using the task monitor he won`t able to distinguish normally running modules from new-added ones.

    Winsonar is a process monitor that allows you to monitor which applications and background processes are currently running on your system. It detects new processes that install into memory and can alert you of such actions.The on-line status is also detected,asking then the user if an automatic termination of any unknown processes is desired This leads to an active protection against trojan spyware-infected e-mail attachments.

     

    12-4-2009 21-47-21

     

    Features
    • Customizable periodic scan for unknown processes
    • Learning mode ( only for Windows XP / 2000 )
    • Online /offline shield against unknown processes
    • Tray-icon balloon tips ( only for Windows XP / 2000 )
    • TCP/IP scan for open ports.
    • Optional Web session logging.
    • Port scanning tools, Registry scan, tech tools

     

    WinSonar installs easily and doesn't seem to be a system resource hog.

     

    downloadfile  Winsonar2010 |SysReq:Windows7 RC1, Vista, XP, 2000, 98 | 2.12MB |Freeware

    Read more...

    Tuesday, September 29, 2009

    0

    Glary Utilities 2.16.0.758

  • Tuesday, September 29, 2009
  • Runtrailblog
  • Do you have a Windows PC that seems much slower than it once was?Think of all of the things you do when you are online.  You may download files, share networks, put more things on your hard drive.  Some software files may be huge.  Then after time, when we no longer use these applications, we still leave them setting there, taking up space. Unwanted entries are also accumulates in registry.All these leads to the slowing down of PC.

    If you are looking for complete computer maintenance software  then try  Glary Utilities .Glary Utilities is a freeware with registry and disk cleaning, privacy protection, performance accelerator and amazing multifunctional tools. It can fix dogged registry errors, wipe off clutters, optimize internet speed, safeguard confidential files and maintain maximum performance.This powerful application offers extensive utilities to improve your system's performance and protect your privacy.

     

    9-29-2009 7-46-45 AM 9-29-2009 7-49-14 AM

     

    You  can clean common system junk files,  invalid registry entries and Internet traces with Glary Utilities. You can also manage and delete browser add-ons, analyze disk space usage and find duplicate files,view and manage installed shell extensions, encrypt your files from unauthorized access and use, split large files into smaller manageable files and then rejoin them. It includes the options to optimize memory, find, fix, or remove broken Windows shortcuts, manage the programs that start at Windows startup and uninstall software. Other features include secure file deletion, an Empty Folder finder and more

    • Optimize, clean and boost the speed of your Windows.
    • Protect your privacy and security.
    • Block spyware, trojans, adware, etc.
    • Fix certain application errors.
    • Simple, fast and User friendly interface

    downloadfile  Download| Mirror| SysReq:Windows 7, 2000, XP, Vista. 32/64bit| 5.77MB | Freeware

    Read more...

    Monday, September 21, 2009

    0

    MSCONFIG Access Denied Error

  • Monday, September 21, 2009
  • Runtrailblog
  • Many of us have been  using msconfig  to get rid of unwanted startup programs .It has worked using the startup tab to disable programs until recently . Even though you are logged as a user that has admin privilege ,suddenly when you start the program you may  get 'an access denied error was returned while attempting to change a service. You may need to log on using an Administrator account to make the specified changes'

     

    9-21-2009 4-50-10 PM

     

    Try the following methods to remove this access denied error.

     

    1.This may be due to a malware infection.You can remove certain restrictions on XP systems often disabled by malware by using RatsCheddar.It is a Policy Controller program written by Rathat

    • Download and save  RatsCheddar.zip to your desktop.
    • Extract  the file to the desktop by using WinZip / 7Zip.
    • Launch the tool. by Double-click on RatsCheddar.exe.
    • Select Enable for everything listed, then click Exit.
    • Restart your computer
    9-21-2009 9-35-14 PM

     

    2.FixPolicies utility from  Bill Castner:

    • Download FixPolicies by Bill Castner and save to your desktop
    • Run the  FixPolicies.exe..
    • Click on Install. It will create a folder named FixPolicies on your desktop.
    • Open the FixPolicies folder.
    • Double click on Fix_policies.cmd to run it. Command Prompt will open and close quickly.

    3.If you have or share HP printers, especially the HP PSC 2100, 2200, 4100 and 6100 series, you may receive this  error.The culprit is a security update for the HP printer software.PML Security Update pmsvptch.exe  causes a service "PML Driver HPZ12" to start in services.msc which would interfere with the rights/privileges.

     

    The HP printer software may load a service named PML Driver HPZ12, which is added to the services section of msconfig. This service handles many functions pertaining to the communication between the computer and the printer. However, many of these functions are not related to printing, so you can fix the “Access Denied” error by disabling the service.

     

    1. Srart>Run> regedit
    2. Export registry to make a backup (as a precaution)
    3. Open HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/PmlDriver HPZ12/Start
    4. Right Click and select modify
    5. Change value to 3 for manual (or 4 for disabled )
    6.Restart computer

     

    9-21-2009 8-28-04 PM

     

    As an alternative , try Startup Control Panel , which is a nifty control panel applet that allows you to easily configure which programs run when your computer starts.Download Startup Control Panel 2.8 and you can stop items from starting up.

    Read more...

    Thursday, August 6, 2009

    0

    How to Remove System Security 2009

  • Thursday, August 6, 2009
  • Runtrailblog
  • System Security is a rogue anti-spyware that belongs to family WinwebSecurity. It  uses Trojan or fake video codec to get into the . Once installed on a computer, SystemSecurity will start showing annoying pop-ups with false information about virus infections and serious system risks in order to sell itself.It  starts generate fake security reports about infections. These false security warnings  are intentioned to make people believe  their computer is seriously infected with malicious viruses and  force you to  purchase their  licensed version.

     

    8-6-2009 7-45-34 AM

     

    It affect your internet connection speed and  slowdown the system.It also change your browser settings, leads to system crash.System Security 2009 is a PC parasite, an infection in itself, and should be avoided.

     

    Manual Removal

    Step 1 : By  Using  Windows Task Manager

     

    %PROGRAMDATA%\11769284\11769284.exe
    %PROGRAMDATA%\11846754\11846754.exe
    %PROGRAMDATA%\13701144\13701144.exe
    %ALLUSERSPROFILE%\Application Data\1597884464\83521271.exe
    %PROGRAMDATA%\00184705\00184705.exe
    %PROGRAMDATA%\90188702\90188702.exe
    %ALLUSERSPROFILE%\Application Data\03380828\03380828.exe
    %PROGRAMDATA%\29192498\29192498.exe
    %PROGRAMDATA%\06837430\06837430.exe
    %ALLUSERSPROFILE%\Application Data\14610250\14610250.exe
    %ALLUSERSPROFILE%\Application Data\03326093\03326093.exe
    %ALLUSERSPROFILE%\Application Data\13496218\13496218.exe
    %ALLUSERSPROFILE%\Application Data\52796787\52796787.exe
    %ALLUSERSPROFILE%\Application Data\96484328\96484328.exe
    %ALLUSERSPROFILE%\Application Data\500153984\500153984.exe
    %ALLUSERSPROFILE%\Application Data\00607031\00607031.exe
    %ALLUSERSPROFILE%\Application Data\02686578\02686578.exe
    %ALLUSERSPROFILE%\Application Data\01560265\01560265.exe
    %ALLUSERSPROFILE%\Application Data\847809490\554845319.exe
    %PROGRAMDATA%\991537388\1126514300.exe
    %ALLUSERSPROFILE%\Application Data\947347721\1255330437.exe
    %ALLUSERSPROFILE%\Application Data\646483980\2113272685.exe
    %ALLUSERSPROFILE%\Application Data\1087856298\1725032906.exe
    %ALLUSERSPROFILE%\Application Data\831600033\1354455340.exe
    %ALLUSERSPROFILE%\application data\1838702514\380679599.exe
    %ALLUSERSPROFILE%\Application Data\696273957\25238076.exe
    %ALLUSERSPROFILE%\Application Data\1046175485\801085450.exe
    %ALLUSERSPROFILE%\Application Data\281405228\2084498445.exe
    %ALLUSERSPROFILE%\Application Data\383196232\14894324.exe
    %ALLUSERSPROFILE%\Application Data\2002822718\2029503323.exe
    %ALLUSERSPROFILE%\Application Data\1929861670\498278020.exe
    %ALLUSERSPROFILE%\Application Data\914063820\1573468717.exe
    %ALLUSERSPROFILE%\Application Data\1964289396\375534146.exe
    %ALLUSERSPROFILE%\Application Data\1263973370\1743310514.exe
    %ALLUSERSPROFILE%\Application Data\1340156489\202150970.exe
    %ALLUSERSPROFILE%\Application Data\1217703993\1327825314.exe
    %ALLUSERSPROFILE%\Application Data\568819996\1550536869.exe
    %ALLUSERSPROFILE%\Application Data\771996059\695276073.exe
    %ALLUSERSPROFILE%\Application Data\1095564415\650526885.exe
    %ALLUSERSPROFILE%\Application Data\2018698794\1940874419.exe
    %ALLUSERSPROFILE%\Application Data\1457297881\1947101902.exe
    %ALLUSERSPROFILE%\Application Data\573251351\1431998300.exe
    %ALLUSERSPROFILE%\Application Data\1655800406\2030350728.exe
    %ALLUSERSPROFILE%\Application Data\1357783622\1977868703.exe
    %ALLUSERSPROFILE%\Application Data\2068742222\438978017.exe
    %PROGRAMDATA%\843824418\1591300478.exe
    %ALLUSERSPROFILE%\Application Data\1993373367\613622941.exe
    %ALLUSERSPROFILE%\Application Data\160465659\432632312.exe
    %ALLUSERSPROFILE%\Application Data\988737293\931330021.exe
    %USERPROFILE%\Application Data\1163524634\240844061.exe
    %ALLUSERSPROFILE%\Application Data\194077280\172939276.exe
    %ALLUSERSPROFILE%\Application Data\336546584\431192516.exe
    %ALLUSERSPROFILE%\Application Data\114567299\800990911.exe
    %ALLUSERSPROFILE%\Application Data\2014101429\1610380076.exe
    %ALLUSERSPROFILE%\Application Data\1189037594\372561511.exe
    %ALLUSERSPROFILE%\Application Data\278958024\124517242.exe
    %ALLUSERSPROFILE%\Application Data\1926316989\1625593810.exe
    %ALLUSERSPROFILE%\Application Data\2010372281\1462403437.exe
    %ALLUSERSPROFILE%\Application Data\1193890671\9179499.exe
    %ALLUSERSPROFILE%\Application Data\1256305888\1003720520.exe
    %ALLUSERSPROFILE%\Application Data\1016589770\1714292029.exe
    %ALLUSERSPROFILE%\Application Data\1398798156\788573529.exe
    %ALLUSERSPROFILE%\Application Data\29046618\549344438.exe
    SystemSecurity.exe
    C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe


    Step 2 : By Using  Registry Editor

    Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\System Security
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"

     

    Step 3 : Remove these System Security files

    System Security 2009 Support.lnk
    System Security 2009.lnk
    359F5809-00B8-4455-A73A-9EA62A51101B
    SystemSecurity.exe
    C:\Documents and Settings\All Users\Application Data\538654387\Languages\German.lng
    C:\Documents and Settings\All Users\Application Data\538654387\Languages\English.lng
    C:\Documents and Settings\All Users\Application Data\538654387\Languages\Spanish.lng
    C:\Documents and Settings\All Users\Application Data\538654387\Languages
    C:\Documents and Settings\All Users\Application Data\538654387\init.udb
    C:\Documents and Settings\All Users\Application Data\538654387\config.udb
    C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe
    C:\Documents and Settings\All Users\Application Data\538654387
    %UserProfile%\Start Menu\Programs\System Security\System Security.lnk
    %UserProfile%\Start Menu\Programs\System Security
    %UserProfile%\Desktop\System Security.lnk
    %PROGRAMDATA%\11769284\11769284.exe
    %PROGRAMDATA%\11846754\11846754.exe
    %PROGRAMDATA%\13701144\13701144.exe
    %ALLUSERSPROFILE%\Application Data\1597884464\83521271.exe
    %PROGRAMDATA%\00184705\00184705.exe
    %PROGRAMDATA%\90188702\90188702.exe
    %ALLUSERSPROFILE%\Application Data\03380828\03380828.exe
    %PROGRAMDATA%\29192498\29192498.exe
    %PROGRAMDATA%\06837430\06837430.exe
    %ALLUSERSPROFILE%\Application Data\14610250\14610250.exe
    %ALLUSERSPROFILE%\Application Data\03326093\03326093.exe
    %ALLUSERSPROFILE%\Application Data\13496218\13496218.exe
    %ALLUSERSPROFILE%\Application Data\52796787\52796787.exe
    %ALLUSERSPROFILE%\Application Data\96484328\96484328.exe
    %ALLUSERSPROFILE%\Application Data\500153984\500153984.exe
    %ALLUSERSPROFILE%\Application Data\00607031\00607031.exe
    %ALLUSERSPROFILE%\Application Data\02686578\02686578.exe
    %ALLUSERSPROFILE%\Application Data\01560265\01560265.exe
    %ALLUSERSPROFILE%\Application Data\847809490\554845319.exe
    %PROGRAMDATA%\991537388\1126514300.exe
    %ALLUSERSPROFILE%\Application Data\947347721\1255330437.exe
    %ALLUSERSPROFILE%\Application Data\646483980\2113272685.exe
    %ALLUSERSPROFILE%\Application Data\1087856298\1725032906.exe
    %ALLUSERSPROFILE%\Application Data\831600033\1354455340.exe
    %ALLUSERSPROFILE%\application data\1838702514\380679599.exe
    %ALLUSERSPROFILE%\Application Data\696273957\25238076.exe
    %ALLUSERSPROFILE%\Application Data\1046175485\801085450.exe
    %ALLUSERSPROFILE%\Application Data\281405228\2084498445.exe
    %ALLUSERSPROFILE%\Application Data\383196232\14894324.exe
    %ALLUSERSPROFILE%\Application Data\2002822718\2029503323.exe
    %ALLUSERSPROFILE%\Application Data\1929861670\498278020.exe
    %ALLUSERSPROFILE%\Application Data\914063820\1573468717.exe
    %ALLUSERSPROFILE%\Application Data\1964289396\375534146.exe
    %ALLUSERSPROFILE%\Application Data\1263973370\1743310514.exe
    %ALLUSERSPROFILE%\Application Data\1340156489\202150970.exe
    %ALLUSERSPROFILE%\Application Data\1217703993\1327825314.exe
    %ALLUSERSPROFILE%\Application Data\568819996\1550536869.exe
    %ALLUSERSPROFILE%\Application Data\771996059\695276073.exe
    %ALLUSERSPROFILE%\Application Data\1095564415\650526885.exe
    %ALLUSERSPROFILE%\Application Data\2018698794\1940874419.exe
    %ALLUSERSPROFILE%\Application Data\1457297881\1947101902.exe
    %ALLUSERSPROFILE%\Application Data\573251351\1431998300.exe
    %ALLUSERSPROFILE%\Application Data\1655800406\2030350728.exe
    %ALLUSERSPROFILE%\Application Data\1357783622\1977868703.exe
    %ALLUSERSPROFILE%\Application Data\2068742222\438978017.exe
    %PROGRAMDATA%\843824418\1591300478.exe
    %ALLUSERSPROFILE%\Application Data\1993373367\613622941.exe
    %ALLUSERSPROFILE%\Application Data\160465659\432632312.exe
    %ALLUSERSPROFILE%\Application Data\988737293\931330021.exe
    %USERPROFILE%\Application Data\1163524634\240844061.exe
    %ALLUSERSPROFILE%\Application Data\194077280\172939276.exe
    %ALLUSERSPROFILE%\Application Data\336546584\431192516.exe
    %ALLUSERSPROFILE%\Application Data\114567299\800990911.exe
    %ALLUSERSPROFILE%\Application Data\2014101429\1610380076.exe
    %ALLUSERSPROFILE%\Application Data\1189037594\372561511.exe
    %ALLUSERSPROFILE%\Application Data\278958024\124517242.exe
    %ALLUSERSPROFILE%\Application Data\1926316989\1625593810.exe
    %ALLUSERSPROFILE%\Application Data\2010372281\1462403437.exe
    %ALLUSERSPROFILE%\Application Data\1193890671\9179499.exe
    %ALLUSERSPROFILE%\Application Data\1256305888\1003720520.exe
    %ALLUSERSPROFILE%\Application Data\1016589770\1714292029.exe
    %ALLUSERSPROFILE%\Application Data\1398798156\788573529.exe
    %ALLUSERSPROFILE%\Application Data\29046618\549344438.exe

    Softwares
    Read more...

    Sunday, June 14, 2009

    0

    Search and Locate Suspicious Hidden Files With Hidden File Scanner

  • Sunday, June 14, 2009
  • Runtrailblog
  • Sometimes  virus  may infect your computer it will create some hidden files and other executable which could be responsible to keep the virus active.Main thing is  you cant see those files and cant delete those virus executables.Hidden files are  scattered across your computer and trying to find all hidden files may turn out to be  a tedious work.

     

    6-14-2009 10-39-37 PM If such an autorun.inf file is found, Hidden File Scanner will display a dialog where you can delete, unhide or inspect the content of the autorun.inf. It automatically rate the autorun.inf files as normal, hidden, suspicious or dangerous file.

     

    If you have hidden files , don’t panic and start deleting them! .Its absolutely normal to have hidden files. Its suspicious only when executable files (.exe, .dll, .sys, .drv etc.) are hidden.If you cannot identify the file, right click it and open the file information dialog. You will see for most executable files the copyright of the executable file, which might help you identifying it.Also  you can try  Google search.

     

    ic_download  Hidden File Scanner V1.0.0.14|OS:Windows All|Freeware|474KB

    Read more...

    Friday, January 23, 2009

    0

    Protecting Against the Rampant Conficker Worm

  • Friday, January 23, 2009
  • Runtrailblog
  • Security researchers are reporting that the Conficker worm virus, which preys on a recently reported vulnerability (MS08-067) in the Microsoft Windows server service, is spreading rapidly."Of the two million computers analyzed, around 115,000 were infected with this malware, a phenomenon we haven't seen since the times of the great epidemics of Kournikova or Blaster," Luis Corrons, Technical Director of PandaLabs, said in a report summary.

    computer_virus

     

    When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It then connects to a server, where it receives further orders to propagate, gather personal information, and downloads and installs additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe.

     

    Once this virus infects a computer it does a number of things

    • Extracts all of its files to the %System% directory with random DLL file names, which can wreak havoc on your computer.
    • Deletes the user's Restore Points.
    • Registers a services called Netsvcs
    • Creates scheduled tasks that execute all of the DLL files.
    • Creates it's own simple HTTP server on the infected computer and spreads the worm to other computers in the network through file shares.
    • Creates an Autorun.inf file in file shares to execute the warm files once the share is accessed by another computer.
    • Connects to external sites to download additional files.

     

    The registry entries added by Mal/Confiker-A are under:

     

    HKLM\SYSTEM\CurrentControlSet\Services\<random service name>

     

    The random service name will also be added to the list of services referenced by:

     

    HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SvcHost\netsvcs

     

    Mal/Conficker-A modifies permissions on the service registry entries so that they are not visible to the user.When spreading to removable media Mal/Conficker-A attempts to create the following hidden files:

     

    <Removable Drive Root>\autorun.inf
    <Removable Drive Root>\RECYCLER\S-x-x-x-xxx-xxx-xxx-x\<Random Letters>.dll

     

    Win32/Conficker.A tries to obtain the IP address of the affected system by accessing the following websites:

     

    www.getmyip.org
    getmyip.co.uk
    checkip.dyndns.org

     

    Mal/Conficker-A will attempt to copy itself to the following location:

     

    <System>\<random filename>


    (e.g. C:\windows\system32\zdtnx.g)

     

    Precautions & Removal

    • Ensure Windows is fully updated to fix the MS08-067 vulnerability that the Conficker family of worms uses to spread.
    • Ensure that all removable storage devices are scanned after being connected to a computer infected with the Conficker family of worms.
    • Ensure HIPS and buffer overflow prevention are both turned on and that "alert only" mode is turned off.
    • Ensure the on-access scanner is turned on and that "on write" scanning is enabled.

    If W32/Confick-E is detected on the computer, clean up this item first and then immediately run another full scan. Cleaning up W32/Confick-E removes the worm from memory and allows Sophos Anti-Virus to scan files that may have been locked by the virus while it was running.

    If a full scan reports unscannable files and W32/Confick-E is not found in memory, ensure the on-access scanner is enabled and the virus data is up to date, reboot the computer and immediately perform another full scan. This causes the on-access scanner to prevent the Conficker worm from loading as a service and should unlock those files so they can be scanned. After cleaning up an active infection of the Conficker worm, a reboot may be required.

    To remove the worm and its malicious components completely, it is recommended to use Norman Conficker Cleaner. Removal tools are also available from Microsoft and Symantec.

     

    Since the virus can spread via USB drives that trigger AutoRun, disabling the AutoRun feature for external media through modifying the Windows Registry is recommended.

    arrow How to Diisable Autorun

    Read more...

    Friday, January 16, 2009

    0

    Bot Detector - Trend Micro RUBotted

  • Friday, January 16, 2009
  • Runtrailblog
  • You may have heard about the overwhelming onslaught of 'bots' or 'zombies' Those are a computer or network security threats.A 'bot' is a type of malware which allows an attacker to gain complete control over the affected computer.Computers that are infected with a 'bot' are generally referred to as 'zombies'.Attackers are able to access lists of 'zombie' PC's and activate them to help execute denial-of-service (DoS ) attacks against Web sites, host phishing attack Web sites or send out thousands of spam email messages.

     

     rub3

     

    RUBotted monitors your computer for suspicious activities and regularly checks with an online service to identify behavior associated with Bots.It intelligently monitors your computer's system behavior for activities that are potentially harmful to both your computer and other people's computers.Upon discovering a potential infection, RUBotted prompts you to scan and clean your computer.

     

    RUBotted co-exists with your existing AV software, providing advanced bot specific behavior monitoring. RUBotted does not rely on frequent, network intensive updates to ensure your computer's continued protection.

    download_thumb[1] RUBotted   | 4.94 MB| Freeware

    Read more...

    Thursday, October 30, 2008

    0

    Spybot 2009 – A Fake Spyware

  • Thursday, October 30, 2008
  • Runtrailblog
  • I have just received an email asking me to visit a link and download Spybot 2009. It comes from Spybot in Panama.Spybot 2009 is a fake anti spyware application

    sparks

    The website http://www.spybot.com is REAL, what I am saying is that I have a different IP shown when somebody (scammer) is telling me to download S&D 2009.

    I checked the  IP address of  both .The correct IP for spybot-S&D  is " http://89.238.64.39 “ .

    sparks003

    But IP for the Malware link is shown as below ,”No Domain name……”

    sparks002

    The makers & owners of Spybot Search & Destroy also has been & is 'Safer Networking’ :http://www.safer-networking.org/en/index.html You always be cautious this type of malware /free updating offers.You don't download SPYBOT via links  other than  http://www.spybot.com or http://www.safer-networking.org/en/index.html or http://www.spybot.info.

    Read more...

    Sunday, October 26, 2008

    0

    How to Get Rid of PC Privacy Cleaner

  • Sunday, October 26, 2008
  • Runtrailblog
  • PC Privacy Cleaner is a fake registry cleaner tool, which pretends to be able to clean your registry.PCPrivacyCleaner may spread with trojans, or you can get duped into downloading PCPrivacyCleaner from PCPrivacyCleaner.com. Once you’ve got PCPrivacyCleaner, it pops up annoying messages and runs fake scans.

    sparks021

    sparks022 sparks023

    Symptoms

  • "Critical System Error",
  • "Your computer is infected",
  • Hijacked homepage to obscure webpage.
  • Flashing icons appear on your system tray (Near of your system clock).
  • Manual Removal Steps

    1.Press Ctrl+Alt+Del to open Task Manager,check any process like pcpc.exe/PCPC_Setup_Free.exe running,kill that process

    sparks024

    2.Open C:\Program Files (assuming windows installed in C drive) and delete the folder named PCPrivacyCleaner or To find PCPrivacyCleaner directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.Search and delete the following PCPrivacyCleaner directories:
    C:\ProgramFiles\pcprivacycleaner
    %common_programs%\pcprivacycleaner
    %program_files%\pcprivacycleaner

    3.Remove  PC Privacy Cleaner  short cuts from desktop, start menu and quick launch.Empty Recycle Bin

    4.If PCPrivacyCleaner changed your homepage?Start menu > Control Panel > Internet Options. Next, under Home Page, select the General > Use Default. Type in the URL you want as your home page (e.g., “http://www.google.com”). Then select Apply > OK. You’ll want to open a fresh web page and make sure that your new default home page pops up.

    5.How to remove PCPrivacyCleaner registry keys?

    Start->Run-> type regedit and press enter.Remove following entries

    HKEY_CURRENT_USER\software\pcprivacycleaner
    HKEY_CURRENT_USER\software\pcprivacycleaner activationcode
    HKEY_CURRENT_USER\software\pcprivacycleaner cookieparams
    HKEY_CURRENT_USER\software\pcprivacycleaner installdate
    HKEY_CURRENT_USER\software\pcprivacycleaner lastscantime
    HKEY_CURRENT_USER\software\pcprivacycleaner totalscancount
    HKEY_CURRENT_USER\software\pcprivacycleaner\schedule
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run pcprivacycleaner                                                                                                 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}

    6.How to remove PCPrivacyCleaner DLL files

    To locate the PCPrivacyCleaner DLL path, go to Start > Search > All Files or Folders. Type PCPrivacyCleaner and in the Look in: select either My Computer or Local Hard Drives. Click the Search button.

    Once you have the PCPrivacyCleaner DLL path,Start->Run->type cmd and click “OK.” To change your current directory, type “cd” in the command box, press your “Space” key, and enter the full directory where the PCPrivacyCleaner DLL file is located. (If you’re not sure if the PCPrivacyCleaner DLL file is located in a particular directory, enter “dir” in the command box to display a directory’s contents. To go one directory back, enter “cd ..” in the command box and press “Enter.”)

    Here you type regsvr32 /u [dll_name] and press enter to unregister the DLL.If you accidentally do something wrong, you can register it again by using regsvr32 [dll_name].eg:regsvr32 /u pcpc.dll  .(How to register/unregister a .dll file)

    PCPrivacyCleaner Automatic Removal Instructions

    Print these instructions because you’ll have to reboot into Safe Mode. Also back up your computer in case you make a mistake

    1. Download and save SmitFraudFix to your desktop.
    2. Restart your computer in Safe ModeOnce thedesktop appears, double click on the SmitfraudFix.exe on your desktop.
    3. After the credits screen, you’ll see a menu. Select the option number 2, which is ‘Clean (safe mode recommended)’, and thenpress Enter to delete infect files.
    4. SmitFraudFix will begin cleaning your computer and take a series of cleanup processes. When the process is over, it will automatically begin the Disk Cleanup program.
    5. Once the Disk Cleanup program is complete, you will be prompted with the message ‘Registry cleaning - Do you want to clean the registry’. Answer Y (Yes) and hit Enter. Reboot your computer.
    6. SmitFraudFix will now check if wininet.dll is infected. SmitFraudFix will ask you whether to replace the infected file (if there’s any) ‘Replace infected
      file?’
      Answer by typing Y (Yes) and hit Enter.
    7. Reboot your computer to complete the cleaning process.
    8. After reboot, a Notepad screen may appear containing a log of all the filesremoved from your computer. If it doesn’t appear, a file will be created called rapport.txt in the root of your drive, (Local Disk C:).
    9. Restart your computer in Safe Mode .
    10. Go to C:\Windows\Temp, click Edit, click Select All, press DELETE, and thenclick Yes to confirm that you want all the items to go to the Recycle Bin.
    11. Go to C:\Documents and Settings\[LISTED USER]\Local Settings\Temp, click Edit, click Select All, press DELETE, and then click Yes to confirm that
      you want all the items to go to the Recycle Bin.
    12. Reboot your computer back to normal mode.

    How to use  SmitfraudFix ,detailed instructions here

    Read more...

    Your Links

    .

    Subscribe