<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0"><id>tag:blogger.com,1999:blog-3384466804101984323</id><updated>2012-02-26T08:38:24.156+08:00</updated><category term="facebook" /><category term="Autorun" /><category term="System Tool" /><category term="Download" /><category term="Task Manager" /><category term="security" /><category term="Virus files" /><category term="Popular" /><category term="System File" /><category term="Constant" /><category term="AVG" /><category term="Computer" /><category term="Restore Setting" /><category term="Safe Mode" /><category term="Windows Defender" /><category term="Browser" /><category term="antivirus" /><category term="Remove Virus" /><category term="Command Prompt" /><category term="Repair File" /><category term="Update" /><category term="Removal Guide" /><category term="Pen Drive Virus" /><category term="Removal Tool" /><category term="Kill Process" /><category term="Parasite" /><category term="Delete File" /><title type="text">Free of Virus &amp; Computer Tips</title><subtitle type="html"> </subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/search/label/Removal%20Guide" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/-/Removal+Guide/-/Removal+Guide?start-index=26&amp;max-results=25" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>574</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/blogspot/removalguide" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="blogspot/removalguide" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-8283005450207287501</id><published>2012-02-05T09:06:00.001+08:00</published><updated>2012-02-05T09:07:21.466+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove AV Security Essentials</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove AV Security Essentials" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;AV Security Essentials&lt;/b&gt; is a &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program that try to pretend to be a real antivirus which can remove malware. However, AV Security Essentials does not kill any malware from any computer. AV Security Essentials infects the computer by installing useless program into the computer which will try to disguise itself like a legitimate antivirus. After installation complete, AV Security Essentials will scan the computer and will surely state that the computer is infected by malwares and urge the user to buy the full version of AV Security Essentials.AV Security Essentials states that its trialware is not able to remove malware threats detected and offers you purchasing its full version which is allegedly capable to fix them. AV Security Essentials is a serious risk to any computer system and should be removed immediately.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;AV Security Essentials&lt;/b&gt; can be removed by using &lt;a href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html" target="_blank"&gt;Emsisoft HiJackFree&lt;/a&gt; to stop the process and remove the files. Then the user should remove the registries entries added and modified according to the removal guide stated below.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Security Essentials&lt;/b&gt; displayed fake alert such as "Please tell Microsoft about this problem. We have created an error report that you can send to us. We will treat this report as confidential and anonymous.", "Security Warning Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer. Click here to clean your PC immediately.", "Security Warning There are critical system files on your computer that were modified by malicious software. It may cause permanent data loss. Click here to remove malicious software." and so on.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Security Essentials&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Security Essentials Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;ScanDisk_.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AV Security Essentials" &lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%UserProfile%\Desktop\System Security 2012.lnk&lt;br /&gt;%Temp%\svhostu.exe&lt;br /&gt;C:\Windows\system32\[random].exe&lt;br /&gt;remove the file shown in autorun settings.&lt;br /&gt;%CommonAppData%\[RANDOM]&lt;br/&gt;%StartMenu%\AV Security Essentials.lnk&lt;br/&gt;%Programs%\AV Security Essentials.lnk&lt;br/&gt;%Desktop%\AV Security Essentials.lnk&lt;br/&gt;%AppData%\AV Security Essentials%AppData%\Microsoft\Internet Explorer\Quick Launch\AV Security Essentials.lnk&lt;br/&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-8283005450207287501?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/8283005450207287501/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/02/remove-av-security-essentials.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/8283005450207287501" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/8283005450207287501" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/02/remove-av-security-essentials.html" title="Remove AV Security Essentials" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-3550464035272278860</id><published>2012-01-27T22:10:00.001+08:00</published><updated>2012-01-27T22:14:19.796+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Antivirus Smart Protection</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Antivirus Smart Protection" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Antivirus Smart Protection&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; is a &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;fake antivirus&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; program that try to pretend to be a real antivirus which can remove malware. However, Antivirus Smart Protection does not kill any malware from any computer. Antivirus Smart Protection infects the computer by installing malicious files into the computer which will try to disguise itself like an ultimate antivirus which can protect computer from malwares. After installation complete, Antivirus Smart Protection will scan the computer and will surely state that the computer is infected by malwares and urge the user to buy the full version of Antivirus Smart Protection.&lt;/span&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Antivirus Smart Protection&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; can be removed by stopping the processes and removing the files by using &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Emsisoft HiJackFree&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;. Then the user should remove the registry entries added or modified by Antivirus Smart Protection shown in the removal guide below. All files related to Antivirus Smart Protection must be deleted.&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Antivirus Smart Protection&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Antivirus Smart Protection Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;ScanDisk_.exe&lt;br /&gt;ASa76.exe&lt;br /&gt;eb.exe&lt;br /&gt;runddlkey.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[RANDOM]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus Smart Protection"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM].exe"&lt;br /&gt;HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}&lt;br /&gt;HKEY_CURRENT_USER\Software\[RANDOM]&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;%AppData%\Antivirus Smart Protection&lt;br /&gt;%AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus Smart Protection.lnk&lt;br /&gt;%CommonAppData%\79b35&lt;br /&gt;%CommonAppData%\ASPHEP&lt;br /&gt;%Desktop%\Antivirus Smart Protection.lnk&lt;br /&gt;%UserProfile%\Recent\cb.dll&lt;br /&gt;%UserProfile%\Recent\CLSV.drv&lt;br /&gt;%UserProfile%\Recent\CLSV.sys&lt;br /&gt;%UserProfile%\Recent\eb.exe&lt;br /&gt;%UserProfile%\Recent\exec.drv&lt;br /&gt;%UserProfile%\Recent\FS.tmp&lt;br /&gt;%UserProfile%\Recent\kernel32.tmp&lt;br /&gt;%UserProfile%\Recent\PE.drv&lt;br /&gt;%UserProfile%\Recent\PE.sys&lt;br /&gt;%UserProfile%\Recent\PE.tmp&lt;br /&gt;%UserProfile%\Recent\ppal.tmp&lt;br /&gt;%UserProfile%\Recent\runddlkey.exe&lt;br /&gt;%UserProfile%\Recent\runddlkey.sys&lt;br /&gt;%UserProfile%\Recent\snl2w.sys&lt;br /&gt;%StartMenu%\Antivirus Smart Protection.lnk&lt;br /&gt;%StartMenu%\Programs\Antivirus Smart Protection.lnk&lt;br /&gt;File Location Notes:&lt;br /&gt;&lt;br /&gt;%UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\&lt;current user=""&gt; for Windows 2000/XP, C:\Users\&lt;current user=""&gt; for Windows Vista/7, and c:\winnt\profiles\&lt;current user=""&gt; for Windows NT.&lt;/current&gt;&lt;/current&gt;&lt;/current&gt;&lt;br /&gt;&lt;br /&gt;%Desktop% means that the file is located directly on your desktop. This is C:\DOCUMENTS AND SETTINGS\&lt;current user=""&gt;\Desktop\ for Windows 2000/XP, and C:\Users\&lt;current user=""&gt;\Desktop\ for Windows Vista and Windows 7.&lt;/current&gt;&lt;/current&gt;&lt;br /&gt;&lt;br /&gt;%AppData% refers to the current users Application Data folder. By default, this is C:\Documents and Settings\&lt;current user=""&gt;\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\&lt;current user=""&gt;\AppData\Roaming.&lt;/current&gt;&lt;/current&gt;&lt;br /&gt;&lt;br /&gt;%StartMenu% refers to the Windows Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\&lt;current user=""&gt;\Start Menu\, and for Windows Vista/7 it is C:\Users\&lt;current user=""&gt;\AppData\Roaming\Microsoft\Windows\Start Menu.&lt;/current&gt;&lt;/current&gt;&lt;br /&gt;&lt;br /&gt;%CommonAppData% refers to the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\All Users\Application Data\, and for Windows Vista/7 it is C:\ProgramData.&lt;br /&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-3550464035272278860?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/3550464035272278860/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-antivirus-smart-protection.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/3550464035272278860" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/3550464035272278860" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-antivirus-smart-protection.html" title="Remove Antivirus Smart Protection" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-2780266489649785808</id><published>2012-01-21T14:32:00.001+08:00</published><updated>2012-01-27T22:14:19.788+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Internet Security 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Internet Security 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Internet Security 2012&lt;/b&gt; is another type of &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Internet Security 2012 CANNOT detect and remove any kind of malware, trojan and virus. Internet Security 2012 can only cheat the user to purchase the full version of Internet Security 2012 so that to removed the detected threats. Do not believe any pop ups or report shown by Internet Security 2012. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Internet Security 2012&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Internet Security 2012 must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Internet Security 2012&lt;/b&gt;, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple threats on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of Internet Security 2012. After doing so, users will later find out that Internet Security 2012 is incapable of ridding their system of any type of malware threats and will continually bombard them with deceptive pop-up messages. The only thing to do with Internet Security 2012 is remove either manually or by using an updated spyware detection tool.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Internet Security 2012&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Internet Security 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1? = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1? %*’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;remove the files stated in the autorun setting.&lt;br /&gt;&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%AppData%\Roaming\Microsoft\Windows\Templates\[random]&lt;br /&gt;%AppData%\Local\[random].exe&lt;br /&gt;%AppData%\Local\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-2780266489649785808?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/2780266489649785808/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-internet-security-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2780266489649785808" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2780266489649785808" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-internet-security-2012.html" title="Remove Internet Security 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-4002217367928911442</id><published>2012-01-20T05:33:00.003+08:00</published><updated>2012-01-27T22:14:19.802+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Smart Internet Protection 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Smart Internet Protection 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Smart Internet Protection 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; is a &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;fake antivirus&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; program that try to pretend to be a real antivirus which can remove malware. However, Smart Internet Protection 2012 does not kill any malware from any computer. Smart Internet Protection 2012 infects the computer by installing KB1883574.exe into the computer which will try to disguise itself like a Windows update entitled System Security Pack Update. After installation complete, Smart Internet Protection 2012 will scan the computer and will surely state that the computer is infected by malwares and urge the user to buy the full version of Smart Internet Protection 2012.&lt;/span&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Smart Internet Protection 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; can be removed by stopping the processes and removing the files by using &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Emsisoft HiJackFree&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;. Then the user should remove the registry entries added or modified by Smart Internet Protection 2012 shown in the removal guide below. All files related to Smart Internet Protection 2012 must be deleted.&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Smart Internet Protection 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Smart Internet Protection 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[RANDOM]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM]"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM].exe"&lt;br /&gt;HKEY_CURRENT_USER\Software\[RANDOM]&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%Programs%\Smart Internet Protection 2012\Smart Internet Protection 2012.lnk&lt;br /&gt;%Programs%\Smart Internet Protection 2012&lt;br /&gt;%TempDir%\[random].exe&lt;br /&gt;%TempDir%\[random]&lt;br /&gt;[random].exe in hard drive&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-4002217367928911442?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/4002217367928911442/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-smart-internet-protection-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/4002217367928911442" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/4002217367928911442" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-smart-internet-protection-2012.html" title="Remove Smart Internet Protection 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-4342121088919501349</id><published>2012-01-20T05:33:00.001+08:00</published><updated>2012-01-27T22:14:19.807+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Smart Protection 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Smart Protection 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Smart Protection 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; is a &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;fake antivirus&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; program that try to pretend to be a real antivirus which can remove malware. However, Smart Protection 2012 does not kill any malware from any computer. Smart Protection 2012 infects the computer by installing KB1883574.exe into the computer which will try to disguise itself like a Windows update entitled System Security Pack Update. After installation complete, Smart Protection 2012 will scan the computer and will surely state that the computer is infected by malwares and urge the user to buy the full version of Smart Protection 2012.&lt;/span&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Smart Protection 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; can be removed by stopping the processes and removing the files by using &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Emsisoft HiJackFree&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;. Then the user should remove the registry entries added or modified by Smart Protection 2012 shown in the removal guide below. All files related to Smart Protection 2012 must be deleted.&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Smart Protection 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Smart Protection 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[RANDOM]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM]"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM].exe"&lt;br /&gt;HKEY_CURRENT_USER\Software\[RANDOM]&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%Programs%\Smart Protection 2012\Smart Protection 2012.lnk&lt;br /&gt;%Programs%\Smart Protection 2012&lt;br /&gt;%TempDir%\[random].exe&lt;br /&gt;%TempDir%\[random]&lt;br /&gt;[random].exe in hard drive&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-4342121088919501349?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/4342121088919501349/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-smart-protection-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/4342121088919501349" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/4342121088919501349" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-smart-protection-2012.html" title="Remove Smart Protection 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-525252775932766629</id><published>2012-01-14T14:17:00.001+08:00</published><updated>2012-01-27T22:14:19.825+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Internet Security Guard</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Internet Security Guard" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Internet Security Guard&lt;/b&gt; is another type of &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Internet Security Guard CANNOT detect and remove any kind of malware, trojan and virus. Internet Security Guard can only cheat the user to purchase the full version of Internet Security Guard so that to removed the detected threats. Do not believe any pop ups or report shown by Internet Security Guard. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Internet Security Guard&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Internet Security Guard must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Internet Security Guard&lt;/b&gt;, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple threats on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of Internet Security Guard. After doing so, users will later find out that Internet Security Guard is incapable of ridding their system of any type of malware threats and will continually bombard them with deceptive pop-up messages. The only thing to do with Internet Security Guard is remove either manually or by using an updated spyware detection tool.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Internet Security Guard&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Internet Security Guard Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;scandsk107d_8027.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1? = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1? %*’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;remove the files stated in the autorun setting.&lt;br /&gt;&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%AppData%\Roaming\Microsoft\Windows\Templates\[random]&lt;br /&gt;%AppData%\Local\[random].exe&lt;br /&gt;%AppData%\Local\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-525252775932766629?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/525252775932766629/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-internet-security-guard.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/525252775932766629" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/525252775932766629" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-internet-security-guard.html" title="Remove Internet Security Guard" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-1834438874129562462</id><published>2012-01-12T09:50:00.001+08:00</published><updated>2012-01-27T22:14:19.764+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Windows XP Internet Security 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Windows XP Internet Security 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows XP Internet Security 2012&lt;/b&gt; is another type of &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Windows XP Internet Security 2012 CANNOT detect and remove any kind of malware, trojan and virus. Windows XP Internet Security 2012 can only cheat the user to purchase the full version of Windows XP Internet Security 2012 so that to removed the detected threats. Do not believe any pop ups or report shown by Windows XP Internet Security 2012. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows XP Internet Security 2012&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Windows XP Internet Security 2012 must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows XP Internet Security 2012&lt;/b&gt;, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple threats on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of Windows XP Internet Security 2012. After doing so, users will later find out that Windows XP Internet Security 2012 is incapable of ridding their system of any type of malware threats and will continually bombard them with deceptive pop-up messages. The only thing to do with Windows XP Internet Security 2012 is remove either manually or by using an updated spyware detection tool.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows XP Internet Security 2012&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows XP Internet Security 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1? = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1? %*’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;remove the files stated in the autorun setting.&lt;br /&gt;&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%AppData%\Roaming\Microsoft\Windows\Templates\[random]&lt;br /&gt;%AppData%\Local\[random].exe&lt;br /&gt;%AppData%\Local\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-1834438874129562462?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/1834438874129562462/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-xp-internet-security.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1834438874129562462" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1834438874129562462" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-xp-internet-security.html" title="Remove Windows XP Internet Security 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-7453961912933835047</id><published>2012-01-10T23:37:00.002+08:00</published><updated>2012-01-27T22:14:19.842+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Windows 7 Security 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Windows 7 Security 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Windows 7 Security 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; is a fake antivirus program that perform like a real antivirus such as Kaspersky Anti-Virus, AVG Free Antivirus, Avira AntiVir etc. Windows 7 Security 2012 infects the computer when the user accidentally downloads a trojan from a website which provide online videos. Windows 7 Security 2012 will start automatically when Windows boot. Then, Windows 7 Security 2012 will scan the computer and produce fake scan results and display many fake alerts to urge the user to purchase the full version of Windows 7 Security 2012 in order to remove the detected malwares. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Windows 7 Security 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; provides fake features such as System Scan, Protection, Privacy and Update. None of them can really protect computer from malware, virus or trojans.&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Windows 7 Security 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows 7 Security 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\ah&lt;br /&gt;HKEY_CLASSES_ROOT\ah&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1? %*&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1? %*&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;%AppData%\Microsoft\Windows\Templates\[random]&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\.exe[random]&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;%AppData%\Microsoft\Windows\Templates\[random]&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\.exe[random]&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%Temp%\[random]&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-7453961912933835047?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/7453961912933835047/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-7-security-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/7453961912933835047" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/7453961912933835047" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-7-security-2012.html" title="Remove Windows 7 Security 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-1794429831673217614</id><published>2012-01-10T23:34:00.000+08:00</published><updated>2012-01-27T22:14:19.759+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Windows Vista Security 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Windows Vista Security 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Windows Vista Security 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; is a fake antivirus program that perform like a real antivirus such as Kaspersky Anti-Virus, AVG Free Antivirus, Avira AntiVir etc. Windows Vista Security 2012 infects the computer when the user accidentally downloads a trojan from a website which provide online videos. Windows Vista Security 2012 will start automatically when Windows boot. Then, Windows Vista Security 2012 will scan the computer and produce fake scan results and display many fake alerts to urge the user to purchase the full version of Windows Vista Security 2012 in order to remove the detected malwares. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Windows Vista Security 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; provides fake features such as System Scan, Protection, Privacy and Update. None of them can really protect computer from malware, virus or trojans.&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Windows Vista Security 2012&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Vista Security 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\ah&lt;br /&gt;HKEY_CLASSES_ROOT\ah&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"&lt;br /&gt;HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'ah'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1? %*&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1? %*&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "(Default)" = 'Application'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah "Content Type" = 'application/x-msdownload'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\DefaultIcon "(Default)" = '%1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;%AppData%\Microsoft\Windows\Templates\[random]&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\.exe[random]&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;%AppData%\Microsoft\Windows\Templates\[random]&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\.exe[random]&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-1794429831673217614?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/1794429831673217614/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-vista-security-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1794429831673217614" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1794429831673217614" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-vista-security-2012.html" title="Remove Windows Vista Security 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-2507328122431305341</id><published>2012-01-10T23:28:00.001+08:00</published><updated>2012-01-27T22:14:19.780+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Windows 7 Internet Security 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Windows 7 Internet Security 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows 7 Internet Security 2012&lt;/b&gt; is another type of &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Windows 7 Internet Security 2012 CANNOT detect and remove any kind of malware, trojan and virus. Windows 7 Internet Security 2012 can only cheat the user to purchase the full version of Windows 7 Internet Security 2012 so that to removed the detected threats. Do not believe any pop ups or report shown by Windows 7 Internet Security 2012. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows 7 Internet Security 2012&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Windows 7 Internet Security 2012 must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows 7 Internet Security 2012&lt;/b&gt;, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple threats on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of Windows 7 Internet Security 2012. After doing so, users will later find out that Windows 7 Internet Security 2012 is incapable of ridding their system of any type of malware threats and will continually bombard them with deceptive pop-up messages. The only thing to do with Windows 7 Internet Security 2012 is remove either manually or by using an updated spyware detection tool.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows 7 Internet Security 2012&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows 7 Internet Security 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1? = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1? %*’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;remove the files stated in the autorun setting.&lt;br /&gt;&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%AppData%\Roaming\Microsoft\Windows\Templates\[random]&lt;br /&gt;%AppData%\Local\[random].exe&lt;br /&gt;%AppData%\Local\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-2507328122431305341?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/2507328122431305341/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-7-internet-security-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2507328122431305341" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2507328122431305341" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-7-internet-security-2012.html" title="Remove Windows 7 Internet Security 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-7573867921603558529</id><published>2012-01-07T11:14:00.000+08:00</published><updated>2012-01-27T22:14:19.849+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Windows Vista Internet Security 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Windows Vista Internet Security 2012" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows Vista Internet Security 2012&lt;/b&gt; is another type of &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Windows Vista Internet Security 2012 CANNOT detect and remove any kind of malware, trojan and virus. Windows Vista Internet Security 2012 can only cheat the user to purchase the full version of Windows Vista Internet Security 2012 so that to removed the detected threats. Do not believe any pop ups or report shown by Windows Vista Internet Security 2012. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows Vista Internet Security 2012&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Windows Vista Internet Security 2012 must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Vista Internet Security 2012&lt;/b&gt;, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple threats on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of Windows Vista Internet Security 2012. After doing so, users will later find out that Windows Vista Internet Security 2012 is incapable of ridding their system of any type of malware threats and will continually bombard them with deceptive pop-up messages. The only thing to do with Windows Vista Internet Security 2012 is remove either manually or by using an updated spyware detection tool.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Vista Internet Security 2012&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Vista Internet Security 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CLASSES_ROOT\exefile\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1? = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1?&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)” = ‘”%1? %*’&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1? %*’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”‘&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode’&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”‘&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;remove the files stated in the autorun setting.&lt;br /&gt;&lt;br /&gt;%AllUsersProfile%\[random]&lt;br /&gt;%AppData%\Roaming\Microsoft\Windows\Templates\[random]&lt;br /&gt;%AppData%\Local\[random].exe&lt;br /&gt;%AppData%\Local\[random]&lt;br /&gt;%Temp%\[random]&lt;br /&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-7573867921603558529?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/7573867921603558529/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-vista-internet-security.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/7573867921603558529" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/7573867921603558529" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2012/01/remove-windows-vista-internet-security.html" title="Remove Windows Vista Internet Security 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-1344289184905286237</id><published>2011-12-31T00:26:00.001+08:00</published><updated>2012-01-27T22:14:19.754+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove System Check</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove System Check" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;System Check&lt;/b&gt; is a program that is used to cheat the money of people by showing error message in the computer hard drive, memory and system. System Check adds a registry entries to make itself to start automatically when Windows boot. After that, System Check will do fake scan on the computer and then issue fake warning by showing pop ups to tell the the user that the hard drive, memory and system have serious errors which can only be solved by using the full version of System Check. Thus, the user is urged to purchase it. Do not believe any report given by System Check even the warning look so real. In fact, System Check cannot detect and remove any error of computer.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;System Check&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by System Check must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;System Check&lt;/b&gt; provide fake features such as Computer status, RAM Memory Status, System Drive and System Registry Status. None of them can really protect computer from any kind of malware.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;System Check&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;System Check Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Unregister DLL files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\[random].exe&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%StartMenu%\Programs\System Check&lt;br /&gt;%Temp%\smtmp&lt;br /&gt;%UserProfile%\Desktop\System Check.lnk&lt;br /&gt;File Location Notes:&lt;br /&gt;&lt;br /&gt;%UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\[Current User] for Windows 2000/XP, C:\Users\[Current User] for Windows Vista/7, and c:\winnt\profiles\[Current User] for Windows NT.&lt;br /&gt;&lt;br /&gt;%Temp% refers to the Windows Temp folder. By default, this is C:\Windows\Temp for Windows 95/98/ME, C:\DOCUMENTS AND SETTINGS\[Current User]\LOCAL SETTINGS\Temp for Windows 2000/XP, and C:\Users\[Current User]\AppData\Local\Temp for Windows Vista and Windows 7.&lt;br /&gt;&lt;br /&gt;%LocalAppData% refers to the current users Local settings Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Local Settings\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Local.&lt;br /&gt;&lt;br /&gt;%StartMenu% refers to the Windows Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\[Current User]\Start Menu\, and for Windows Vista/7 it is C:\Users\[Current User]\AppData\Roaming\Microsoft\Windows\Start Menu.&lt;/random&gt;&lt;/random&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-1344289184905286237?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/1344289184905286237/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-system-check.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1344289184905286237" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1344289184905286237" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-system-check.html" title="Remove System Check" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-4809867798031011825</id><published>2011-12-28T21:38:00.001+08:00</published><updated>2012-01-27T22:14:19.817+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Super AV</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Super AV Removal Guide" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Super AV&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; is a fake antispyware that will pretend to protect the system from spyware but eventually will definitely state the user that there are a lot of spyware in hard drive, memory and the system. Super AV produce fake results. Super AV cannot anti, detect or remove any spyware. Super AV is just a SCAM. Super AV continuously produce fake alert to urge the user to purchase the full version of Super AV so that to remove all the spyware. In fact, Super AV cannot detect and remove any spyware. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Super AV&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; can be remove by using &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Emsisoft HiJackFree&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; to stop and remove the processes ([random].exe]), remove the autorun setting and finally all related folders and files stated in the removal guide below.&lt;br /&gt;&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Super AV&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;b&gt;Super AV Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;atexbees.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Unregister DLL files&lt;/u&gt;&lt;br /&gt;%Temp%\[random].dll&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "security" = "C:\Windows\atexbees.exe"&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;C:\Windows\atexbees.exe&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-4809867798031011825?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/4809867798031011825/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-super-av.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/4809867798031011825" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/4809867798031011825" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-super-av.html" title="Remove Super AV" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-9108000005173004320</id><published>2011-12-26T02:04:00.001+08:00</published><updated>2012-01-27T22:14:19.855+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Home Security Solutions</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Home Security Solutions Removal Guide" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Home Security Solutions&lt;/b&gt; is a &lt;a href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa" target="_blank"&gt;fake antivirus&lt;/a&gt; program that CANNOT DETECT AND REMOVE any kind of virus, malware and trojan. Home Security Solutions can do nothing but just show pop ups to convince the user that the computer has been infected by malwares and urge the user to purchase the full version of Home Security Solutions.  Home Security Solutions infections are known to spread by means of fake online system alerts that warn the user about infections that require the user to download Home Security Solutions to remove them. Home Security Solutions will start automatically when Windows boot. Then Home Security Solutions will do a fake scan on the computer and then it will show the fake report. Do not purchase Home Security Solutions as it can do nothing.The user should switch to Safe Mode to make sure any scans detect Home Security Solutions and remove Home Security Solutions with anti-malware applications that are designed to handle such threats. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Home Security Solutions&lt;/b&gt; can be removed by using &lt;/span&gt;&lt;a href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html" target="_blank"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Emsisoft HiJackFree&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Home Security Solutions. Finally, all the file related to Home Security Solutions must be deleted from the hard drive. All of them has been shown in the removal guide below.&lt;br /&gt;&lt;br /&gt;The computer users should remember that any time when they encounter a web page that states that the computer is infected, they should not believe them as the majority of these pages are scams trying to get them to install the actual infection. The second method that can be used to install this fake antivirus is through hacked web sites that install Home Security Solutions on to the computer without their knowledge by exploiting vulnerabilities in the outdated programs.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Home Security Solutions&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Home Security Solutions Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\91\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Vid {137E7700-3573-11CF-AE69-08002B2E1262}&lt;br /&gt;HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes\URL http://findgala.com/?&amp;amp;uid=231&amp;amp;q={searchTerms}&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\CheckExeSignatures "no"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PRS http://127.0.0.1:27777/?inj=%ORIGINAL%&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\URL http://findgala.com/?&amp;amp;uid=231&amp;amp;q={searchTerms}&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\89770803&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\lib/5.00231&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UID 231&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "1"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HS2d7_231.DocHostUIHandler&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin "2"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Enable&amp;nbsp;LUA "1"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Home Security Solutions"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;%AllUsersProfile%\[RANDOM]&lt;br /&gt;%AllUsersProfile%\HSYITSQGE&lt;br /&gt;%AppData%\Home Security Solutions&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\DBOLE.dll&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\CLSV.tmp&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\gid.tmp&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\eb.dll&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\delfile.dll&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\eb.sys&lt;br /&gt;%AppData%\Microsoft\Windows\Recent\energy.dll&lt;br /&gt;%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Security Solutions.lnk&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-9108000005173004320?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/9108000005173004320/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-home-security-solutions.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/9108000005173004320" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/9108000005173004320" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-home-security-solutions.html" title="Remove Home Security Solutions" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-2074939368348213437</id><published>2011-12-23T08:19:00.001+08:00</published><updated>2012-01-27T22:14:19.770+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Click System</title><content type="html">&lt;div style="float: right;"&gt;&lt;img alt="Remove Click System" src="http://olzen.info/rfa.png" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Click System&lt;/b&gt; is a program that is used to cheat the money of people by showing error message in the computer hard drive, memory and system. Click System adds a registry entries to make itself to start automatically when Windows boot. After that, Click System will do fake scan on the computer and then issue fake warning by showing pop ups to tell the the user that the hard drive, memory and system have serious errors which can only be solved by using the full version of Click System. Thus, the user is urged to purchase it. Do not believe any report given by Click System even the warning look so real. In fact, Click System cannot detect and remove any error of computer.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Click System&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Click System must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Click System&lt;/b&gt; provide fake features such as Computer status, RAM Memory Status, System Drive and System Registry Status. None of them can really protect computer from any kind of malware.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Click System&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Click System Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html" target="_blank"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Unregister DLL files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\[random].exe&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%StartMenu%\Programs\Click System&lt;br /&gt;%Temp%\smtmp&lt;br /&gt;%UserProfile%\Desktop\Click System.lnk&lt;br /&gt;File Location Notes:&lt;br /&gt;&lt;br /&gt;%UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\[Current User] for Windows 2000/XP, C:\Users\[Current User] for Windows Vista/7, and c:\winnt\profiles\[Current User] for Windows NT.&lt;br /&gt;&lt;br /&gt;%Temp% refers to the Windows Temp folder. By default, this is C:\Windows\Temp for Windows 95/98/ME, C:\DOCUMENTS AND SETTINGS\[Current User]\LOCAL SETTINGS\Temp for Windows 2000/XP, and C:\Users\[Current User]\AppData\Local\Temp for Windows Vista and Windows 7.&lt;br /&gt;&lt;br /&gt;%LocalAppData% refers to the current users Local settings Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Local Settings\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Local.&lt;br /&gt;&lt;br /&gt;%StartMenu% refers to the Windows Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\[Current User]\Start Menu\, and for Windows Vista/7 it is C:\Users\[Current User]\AppData\Roaming\Microsoft\Windows\Start Menu.&lt;/random&gt;&lt;/random&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-2074939368348213437?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/2074939368348213437/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-click-system.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2074939368348213437" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2074939368348213437" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-click-system.html" title="Remove Click System" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-5622382396958853770</id><published>2011-12-20T23:49:00.000+08:00</published><updated>2011-12-20T23:50:21.949+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Best Antivirus</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Best Antivirus Removal Guide" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Best Antivirus&lt;/b&gt; is another type of &lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Best Antivirus CANNOT detect and remove any kind of malware, trojan and virus. Best Antivirus can only cheat the user to purchase the full version of Best Antivirus so that to removed the detected threats. Do not believe any pop ups or report shown by Best Antivirus. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Best Antivirus&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Best Antivirus must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Best Antivirus&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Best Antivirus Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;BestAntivirusUpdater.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Best Antivirus"&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;C:\Documents and Settings\All Users\Application Data\13077d\[RANDOM CHARACTERS].exe&lt;br /&gt;%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Best Antivirus.lnk&lt;br /&gt;%UserProfile%\Start Menu\Programs\Best Antivirus.lnk&lt;br /&gt;%UserProfile%\Start Menu\Best Antivirus.lnk&lt;br /&gt;%UserProfile%\Desktop\Best Antivirus.lnk&lt;br /&gt;%UserProfile%\Application Data\Best Antivirus\cookies.sqlite&lt;br /&gt;%UserProfile%\Application Data\Best Antivirus\Instructions.ini&lt;br /&gt;%UserProfile%\Application Data\Best Antivirus&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-5622382396958853770?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/5622382396958853770/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-best-antivirus.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/5622382396958853770" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/5622382396958853770" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-best-antivirus.html" title="Remove Best Antivirus" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-8105247375496695831</id><published>2011-12-15T20:29:00.000+08:00</published><updated>2011-11-05T04:28:46.546+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">How to delete trojan virus, open hidden files</title><content type="html">&lt;div style="float: right;"&gt;&lt;img src="http://olzen.info/rfa.png" alt="" /&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;How to delete trojan virus, open hidden files&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;?&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;First of all,  we need to use the latest updated anti-virus to scan the drive so that to detect the name of the Trojan. After getting the name of the Trojan,  we should do a search in Google or other search engine of the name of the Trojan. Usually, we will get the way to remove the trojan manually or by using the removal tool provided. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;It will tell us  the processes of the trojan. Every trojan must have at least a process running behind the OS. Hence, we should &lt;/span&gt;&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Terminate all the processes of the trojans&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;. You can also let me know the name of the trojan and I will show you on how to remove it manually if possible.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Most virus will disable the showing hidden files feature so that we cannot remove it easily. To show hidden file after infected by trojan, we should first kill the trojan first by following the method stated above. Then we need to use some tools to remove the restriction of showing hidden file. The tool I recommend is &lt;/span&gt;&lt;a target="_blank" href="http://www.softpedia.com/get/Security/Security-Related/RRT-Remove-Ristrictions-Tool.shtml"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Remove Restriction Tool&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; (RRT). After removing the restriction, we should kill all the files of the processes of the trojan.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;However, you can also terminate the process and at the same time delete the file too by using &lt;/span&gt;&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/remove-hijackers-spyware-adware-trojans.html"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;a-squared HiJackFree&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-8105247375496695831?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/8105247375496695831/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2009/03/how-to-delete-trojan-virus-open-hidden.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/8105247375496695831" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/8105247375496695831" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2009/03/how-to-delete-trojan-virus-open-hidden.html" title="How to delete trojan virus, open hidden files" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-8562694227005457632</id><published>2011-12-14T21:00:00.002+08:00</published><updated>2011-12-15T08:14:04.370+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Security Monitor 2012</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove Security Monitor 2012" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Security Monitor 2012&lt;/b&gt; is a &lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa"&gt;fake antivirus&lt;/a&gt; program which come with a rootkit to prevent many program from running on the computer. Security Monitor 2012 cannot detect and remove any kind of virus, malware and trojan. What Security Monitor 2012 can do is displaying fake report to tell the user that the computer has been infected by many malwares, trojans and viruses. Security Monitor 2012 will urge the user to purchase the full version of Security Monitor 2012 to remove all the detected malwares, viruses and trojan. Bare in mind that Security Monitor 2012 CANNOT detect and remove any malware, virus and trojan. Security Monitor 2012 may spread through its affiliated Trojans and invades the affected computer system without a PC user owner’s consent and knowledge. &lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Security Monitor 2012&lt;/b&gt; provide fake features such as system scan, firewall, scan option, settings and updates. It scares the users with a lot of malwares detected on the computer such as Adware.Win32/Wheresphere, W32/Rimecud, Exploit-PDF.w etc. It claims itself that it can protect your PC just simple one-click solution. It ask the user to activate Security Monitor 2012 so that to have auto protection on computer. All of them is a lie. Do not believe it.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Security Monitor 2012&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Security Monitor 2012Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;securityhelper.exe&lt;br /&gt;Security Monitor.exe&lt;br /&gt;securitymanager.exe&lt;br /&gt;%Temp%\02c9c3c35bdx5.exe%Temp%\17dkf.exe%Temp%\1iowieoo.exe%Temp%\472a10e2ebxd9.exe%Temp%\56493.exe%Temp%\8gmsed-bd.exe%Temp%\ae0965a7157cd.exe%Temp%\al3erfa3.exe%Temp%\alerfa.exe%Temp%\alerfa2.exe%Temp%\altedf.exe%Temp%\bzqa43d.exe%Temp%\cocksucker.exe%Temp%\cosock.exe%Temp%\format.exe%Temp%\g_dx234.exe%Temp%\ggwwef9752.exe%Temp%\lkhgg_ea.exe%Temp%\lols.exe%Temp%\ploper.exe%Temp%\timem.exe%Temp%\tryh-blv.exe%Temp%\w32-reno-c.exe%Temp%\wrfwe_di.exe%Temp%\wwautrsd.exe%Temp%\wwwsssgen.exe&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "(Default)" = ""&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Security Monitor 2012"&lt;br /&gt;HKEY_CURRENT_USER\Software\Security Monitor 2012&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%userprofile%\Desktop\Security Monitor 2012.lnk&lt;br /&gt;%userprofile%\Local Settings\Temp\[random].*&lt;br /&gt;%userprofile%\Application Data\Security Monitor 2012&lt;br /&gt;%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Monitor 2012.lnk&lt;br /&gt;%userprofile%\Start Menu\Programs\Security Monitor 2012.lnk&lt;br /&gt;%userprofile%\Start Menu\Programs\Security Monitor 2012&lt;br /&gt;%Temp%\02c9c3c35bdx5.exe&lt;br /&gt;%Temp%\17dkf.exe&lt;br /&gt;%Temp%\1iowieoo.exe&lt;br /&gt;%Temp%\472a10e2ebxd9.exe&lt;br /&gt;%Temp%\56493.exe&lt;br /&gt;%Temp%\8gmsed-bd.exe&lt;br /&gt;%Temp%\ae0965a7157cd.exe&lt;br /&gt;%Temp%\al3erfa3.exe&lt;br /&gt;%Temp%\alerfa.exe&lt;br /&gt;%Temp%\alerfa2.exe&lt;br /&gt;%Temp%\altedf.exe&lt;br /&gt;%Temp%\bzqa43d.exe&lt;br /&gt;%Temp%\cocksucker.exe&lt;br /&gt;%Temp%\cosock.exe&lt;br /&gt;%Temp%\format.exe&lt;br /&gt;%Temp%\g_dx234.exe&lt;br /&gt;%Temp%\ggwwef9752.exe&lt;br /&gt;%Temp%\lkhgg_ea.exe&lt;br /&gt;%Temp%\lols.exe&lt;br /&gt;%Temp%\ploper.exe&lt;br /&gt;%Temp%\timem.exe&lt;br /&gt;%Temp%\tryh-blv.exe&lt;br /&gt;%Temp%\w32-reno-c.exe&lt;br /&gt;%Temp%\wrfwe_di.exe&lt;br /&gt;%Temp%\wwautrsd.exe&lt;br /&gt;%Temp%\wwwsssgen.exe&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-8562694227005457632?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/8562694227005457632/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-security-monitor-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/8562694227005457632" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/8562694227005457632" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-security-monitor-2012.html" title="Remove Security Monitor 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-2706397998378847785</id><published>2011-12-12T09:49:00.003+08:00</published><updated>2011-12-12T11:14:19.489+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Antivirii 2011</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove Antivirii 2011" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Antivirii 2011&lt;/b&gt; is another type of &lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa"&gt;fake antivirus&lt;/a&gt; program which will definitely show pop ups to tell the user that the computer has been infected by malwares, trojans and viruses. Antivirii 2011 CANNOT detect and remove any kind of malware, trojan and virus. Antivirii 2011 can only cheat the user to purchase the full version of Antivirii 2011 so that to removed the detected threats. Do not believe any pop ups or report shown by Antivirii 2011. All of them is a lie.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Antivirii 2011&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Antivirii 2011 must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Antivirii 2011&lt;/b&gt;, after installed, usually will display a lot of pop-up alerts that attempt to make users believe that it has detected multiple threats on the system that it is installed on. Naturally, some computer users will try to take action to remove those threats simply by purchasing a full edition of Antivirii 2011. After doing so, users will later find out that Antivirii 2011 is incapable of ridding their system of any type of malware threats and will continually bombard them with deceptive pop-up messages. The only thing to do with Antivirii 2011 is remove either manually or by using an updated spyware detection tool.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Antivirii 2011&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Antivirii 2011 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;antivirii.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Security"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe "Debugger"&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;remove the files stated in the autorun setting.&lt;br /&gt;%WinDir%\antivirii.exe&lt;br /&gt;%WinDir%\[random].exe&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-2706397998378847785?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/2706397998378847785/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-antivirii-2011.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2706397998378847785" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/2706397998378847785" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/12/remove-antivirii-2011.html" title="Remove Antivirii 2011" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-6488298022821745566</id><published>2011-11-23T23:13:00.002+08:00</published><updated>2011-12-05T21:52:52.566+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Cloud AV 2012</title><content type="html">&lt;div style="float: right;"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove Cloud AV 2012" /&gt;&lt;/div&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Cloud AV 2012&lt;/b&gt; is a fake antivirus that infected your computer through a malicious website or Trojan.  Cloud AV 2012 scan the whole infected computer without any notice. After finish scanning, Cloud AV 2012 shows false result that there are a lot of malware infections found on the computer. Moreover, the users of the infected computer will receive several warning alerts trying to force the users to purchase the fake full version of Cloud AV 2012. Cloud AV 2012 cannot detect and remove any kind of virus, malware or trojan. Cloud AV 2012 is a SCAM. Do not believe any warning or alert given by Cloud AV 2012. Most important, do not purchase the full version of Cloud AV 2012 as it really cannot remove any kind of malware! Cloud AV 2012 is delivered through many ways that involve installing via a bogus scanner page created to look like a Windows application screen. Another way of how Cloud AV 2012 spreads is via a Trojan infection generated to look like a flash update or video codec.&lt;br /&gt;&lt;div style="float: left;"&gt;&lt;br /&gt;&lt;b&gt;Cloud AV 2012&lt;/b&gt; can be removed first by stopping its processes  and then kill its files by using &lt;a target="_blank" href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html"&gt;Emsisoft HiJackFree&lt;/a&gt;. Then the user has to remove all the related files and folder. Finally, restore the registry entries added and modified by Cloud AV 2012 (Read the removal guide below to remove Cloud AV 2012 successfully).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Cloud AV 2012&lt;/b&gt; should be removed immediately!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;Cloud AV 2012.exe&lt;br /&gt;dwme.exe&lt;br /&gt;027.exe&lt;br /&gt;Cloud AV 2012v121.exe&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Cloud AV 2012.exe”&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]”&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random]”&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\C0AB6693AB3202B4B9D95716ED5CE4A6\SourceList&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%Documents and Settings%\[User Name]\Local Settings\Application Data\Cloud AV 2012.exe&lt;br /&gt;%AppData%\ldr.ini&lt;br /&gt;%AppData%\[RANDOM]&lt;br /&gt;%DesktopDir%\Cloud AV 2012.lnk&lt;br /&gt;%Programs%\Cloud AV 2012&lt;br /&gt;%Temp%\8.tmp&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-6488298022821745566?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/6488298022821745566/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-cloud-av-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/6488298022821745566" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/6488298022821745566" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-cloud-av-2012.html" title="Remove Cloud AV 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-940016847660424184</id><published>2011-11-23T22:22:00.001+08:00</published><updated>2011-11-23T22:25:48.953+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove AV Protection 2012</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="AV Protection 2012 Removal Guide" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;AV Protection 2012&lt;/b&gt; is a fake antivirus program AV Protection 2012 cannot detect and remove any malware, trojan or virus. AV Protection 2012 can just provide fake alert (e.g. There are many files are infected by malwares). Once AV Protection 2012 is installed in the computer, it will definitely do a fake scan in the computer and will state that the computer is in danger repeatedly so that to urge the user to purchase the full version of AV Protection 2012 which cannot remove any kind of errors found in the system.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;AV Protection 2012&lt;/b&gt; can be removed by stopping all the processes with random name and name which contain "AV Protection 2012". Then the user has to remove the files of the processes. Finally, the registry settings have to be restored by removing the registry keys stated below.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Protection 2012&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Protection 2012 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;svhostu.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_CURRENT_USER\Software\AV Protection 2012&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%UserProfile%\Application Data\Microsoft\[random].exe&lt;br /&gt;%UserProfile%\Application Data\[random].exe&lt;br /&gt;%ALLUserProfile%\Application Data\Microsoft\[random].exe&lt;br /&gt;%ALLUserProfile%\Application Data\[random].exe&lt;br /&gt;%AppData%\ldr.ini&lt;br /&gt;%AppData%\[random]\AV Protection 2012.ico&lt;br /&gt;%AppData%\svhostu.exe&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-940016847660424184?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/940016847660424184/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-av-protection-2012.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/940016847660424184" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/940016847660424184" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-av-protection-2012.html" title="Remove AV Protection 2012" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-1991394053829243428</id><published>2011-11-22T23:49:00.001+08:00</published><updated>2011-11-22T23:51:48.272+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Windows Fix</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove Windows Fix" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows Fix&lt;/b&gt; is a program that is used to cheat the money of people by showing error message in the computer hard drive, memory and system. Windows Fix adds a registry entries to make itself to start automatically when Windows boot. After that, Windows Fix will do fake scan on the computer and then issue fake warning by showing pop ups to tell the the user that the hard drive, memory and system have serious errors which can only be solved by using the full version of Windows Fix. Thus, the user is urged to purchase it. Do not believe any report given by Windows Fix even the warning look so real. In fact, Windows Fix cannot detect and remove any error of computer.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Windows Fix&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Windows Fix must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Fix&lt;/b&gt; provide fake features such as Computer status, RAM Memory Status, System Drive and System Registry Status. None of them can really protect computer from any kind of malware.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Fix&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows Fix Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Unregister DLL files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\[random].exe&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%StartMenu%\Programs\Windows Fix&lt;br /&gt;%Temp%\smtmp&lt;br /&gt;%UserProfile%\Desktop\Windows Fix.lnk&lt;br /&gt;File Location Notes:&lt;br /&gt;&lt;br /&gt;%UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\[Current User] for Windows 2000/XP, C:\Users\[Current User] for Windows Vista/7, and c:\winnt\profiles\[Current User] for Windows NT.&lt;br /&gt;&lt;br /&gt;%Temp% refers to the Windows Temp folder. By default, this is C:\Windows\Temp for Windows 95/98/ME, C:\DOCUMENTS AND SETTINGS\[Current User]\LOCAL SETTINGS\Temp for Windows 2000/XP, and C:\Users\[Current User]\AppData\Local\Temp for Windows Vista and Windows 7.&lt;br /&gt;&lt;br /&gt;%LocalAppData% refers to the current users Local settings Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Local Settings\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Local.&lt;br /&gt;&lt;br /&gt;%StartMenu% refers to the Windows Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\[Current User]\Start Menu\, and for Windows Vista/7 it is C:\Users\[Current User]\AppData\Roaming\Microsoft\Windows\Start Menu.&lt;br /&gt;&lt;/random&gt;&lt;/random&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-1991394053829243428?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/1991394053829243428/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-windows-fix.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1991394053829243428" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/1991394053829243428" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-windows-fix.html" title="Remove Windows Fix" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-7854719008607027295</id><published>2011-11-21T22:03:00.001+08:00</published><updated>2011-11-21T22:08:18.998+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove Computer Fix</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove Computer Fix" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Computer Fix&lt;/b&gt; is a program that is used to cheat the money of people by showing error message in the computer hard drive, memory and system. Computer Fix adds a registry entries to make itself to start automatically when Windows boot. After that, Computer Fix will do fake scan on the computer and then issue fake warning by showing pop ups to tell the the user that the hard drive, memory and system have serious errors which can only be solved by using the full version of Computer Fix. Thus, the user is urged to purchase it. Do not believe any report given by Computer Fix even the warning look so real. In fact, Computer Fix cannot detect and remove any error of computer.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Computer Fix&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by Computer Fix must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Computer Fix&lt;/b&gt; provide fake features such as Computer status, RAM Memory Status, System Drive and System Registry Status. None of them can really protect computer from any kind of malware.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Computer Fix&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Computer Fix Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU "MRUList"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%Documents and Settings%\[User Name]\Local Settings\Temp\smtmp&lt;br /&gt;%Documents and Settings%\[User Name]\Local Settings\Application Data\[random]&lt;br /&gt;%Documents and Settings%\[User Name]\Local Settings\Application Data\[random].exe&lt;br /&gt;%Documents and Settings%\[User Name]\Start Menu\\Programs\Computer Fix&lt;br /&gt;%Documents and Settings%\[User Name]\Desktop\Computer Fix.lnk&lt;br /&gt;%Documents and Settings%\[User Name]\Start Menu\\Programs\Computer Fix&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-7854719008607027295?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/7854719008607027295/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-computer-fix.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/7854719008607027295" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/7854719008607027295" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-computer-fix.html" title="Remove Computer Fix" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-9104798903432809244</id><published>2011-11-18T06:17:00.000+08:00</published><updated>2011-11-18T06:18:00.215+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove AV Protection 2011</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove AV Protection 2011" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;AV Protection 2011&lt;/b&gt; is a &lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html#fa"&gt;fake antivirus&lt;/a&gt; program that try to pretend to be a real antivirus which can remove malware. However, AV Protection 2011 does not kill any malware from any computer. AV Protection 2011 infects the computer by installing useless program into the computer which will try to disguise itself like a legitimate antivirus. After installation complete, AV Protection 2011 will scan the computer and will surely state that the computer is infected by malwares and urge the user to buy the full version of AV Protection 2011.AV Protection 2011 states that its trialware is not able to remove malware threats detected and offers you purchasing its full version which is allegedly capable to fix them. AV Protection 2011 is a serious risk to any computer system and should be removed immediately.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;AV Protection 2011&lt;/b&gt; can be removed by using &lt;a target="_blank" href="http://freeofvirus.blogspot.com/2010/11/emsisoft-hijackfree.html"&gt;Emsisoft HiJackFree&lt;/a&gt; to stop the process and remove the files. Then the user should remove the registries entries added and modified according to the removal guide stated below.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Protection 2011&lt;/b&gt; displayed fake alert such as "Please tell Microsoft about this problem. We have created an error report that you can send to us. We will treat this report as confidential and anonymous.", "Security Warning Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer. Click here to clean your PC immediately.", "Security Warning There are critical system files on your computer that were modified by malicious software. It may cause permanent data loss. Click here to remove malicious software." and so on.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Protection 2011&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AV Protection 2011 Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;svhostu.exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:59232"&lt;br /&gt;HKEY_CURRENT_USER\Software\System Security 2011&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\C0AB6693AB3202B4B9D95716ED5CE4A6\SourceList&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%UserProfile%\Desktop\System Security 2012.lnk&lt;br /&gt;%Temp%\svhostu.exe&lt;br /&gt;C:\Windows\system32\[random].exe&lt;br /&gt;%DesktopDir%\AV Protection 2011.lnk&lt;br /&gt;%AppData%\[random]&lt;br /&gt;%Programs%\AV Protection 2011&lt;br /&gt;%AppData%\ldr.ini&lt;br /&gt;%Temp%\8.tmp&lt;br /&gt;remove the file shown in autorun settings.&lt;br /&gt;&lt;div id="postads"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-9104798903432809244?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/9104798903432809244/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-av-protection-2011.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/9104798903432809244" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/9104798903432809244" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-av-protection-2011.html" title="Remove AV Protection 2011" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3384466804101984323.post-262989532759058354</id><published>2011-11-15T06:42:00.001+08:00</published><updated>2011-11-15T06:46:24.037+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Removal Guide" /><title type="text">Remove System Fix</title><content type="html">&lt;div style="float:right"&gt;&lt;img src="http://olzen.info/rfa.png" alt="Remove System Fix" /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;System Fix&lt;/b&gt; is a program that is used to cheat the money of people by showing error message in the computer hard drive, memory and system. System Fix adds a registry entries to make itself to start automatically when Windows boot. After that, System Fix will do fake scan on the computer and then issue fake warning by showing pop ups to tell the the user that the hard drive, memory and system have serious errors which can only be solved by using the full version of System Fix. Thus, the user is urged to purchase it. Do not believe any report given by System Fix even the warning look so real. In fact, System Fix cannot detect and remove any error of computer.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="float:left;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;System Fix&lt;/b&gt; can be uninstalled by by stopping all processes with random name and also kill its files. Then, all registry entries added and modified by System Fix must be cleared by using Windows Registry Editor.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;System Fix&lt;/b&gt; provide fake features such as Computer status, RAM Memory Status, System Drive and System Registry Status. None of them can really protect computer from any kind of malware.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;System Fix&lt;/b&gt; should be removed immediately!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;System Fix Removal Guide&lt;/b&gt;&lt;br /&gt;&lt;u&gt;Kill Process&lt;/u&gt;&lt;br /&gt;(&lt;a target="_blank" href="http://freeofvirus.blogspot.com/2009/02/how-to-kill-process-effectively.html"&gt;How to kill a process effectively?&lt;/a&gt;)&lt;br /&gt;[random].exe&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Unregister DLL files&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Delete Registry&lt;/u&gt;&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;.exe"&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "&lt;random&gt;"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'&lt;br /&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Remove Folders and Files&lt;/u&gt;&lt;br /&gt;%LocalAppData%\[random]&lt;br /&gt;%LocalAppData%\[random].exe&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%LocalAppData%\~[random]&lt;br /&gt;%StartMenu%\Programs\System Fix&lt;br /&gt;%Temp%\smtmp&lt;br /&gt;%UserProfile%\Desktop\System Fix.lnk&lt;br /&gt;File Location Notes:&lt;br /&gt;&lt;br /&gt;%UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\[Current User] for Windows 2000/XP, C:\Users\[Current User] for Windows Vista/7, and c:\winnt\profiles\[Current User] for Windows NT.&lt;br /&gt;&lt;br /&gt;%Temp% refers to the Windows Temp folder. By default, this is C:\Windows\Temp for Windows 95/98/ME, C:\DOCUMENTS AND SETTINGS\[Current User]\LOCAL SETTINGS\Temp for Windows 2000/XP, and C:\Users\[Current User]\AppData\Local\Temp for Windows Vista and Windows 7.&lt;br /&gt;&lt;br /&gt;%LocalAppData% refers to the current users Local settings Application Data folder. By default, this is C:\Documents and Settings\[Current User]\Local Settings\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\[Current User]\AppData\Local.&lt;br /&gt;&lt;br /&gt;%StartMenu% refers to the Windows Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\[Current User]\Start Menu\, and for Windows Vista/7 it is C:\Users\[Current User]\AppData\Roaming\Microsoft\Windows\Start Menu.&lt;br /&gt;&lt;/random&gt;&lt;/random&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3384466804101984323-262989532759058354?l=freeofvirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://freeofvirus.blogspot.com/feeds/262989532759058354/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-system-fix.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/262989532759058354" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3384466804101984323/posts/default/262989532759058354" /><link rel="alternate" type="text/html" href="http://freeofvirus.blogspot.com/2011/11/remove-system-fix.html" title="Remove System Fix" /><author><name>Olzen</name><uri>http://www.blogger.com/profile/08667460576433825151</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_sxJ9IexA4k8/SVnJm7mZxfI/AAAAAAAABYE/_Nnpe_n60ec/S220/me2.JPG" /></author><thr:total>0</thr:total></entry></feed>

