воскресенье, 27 мая 2012 г.

Windows Defence Counsel virus. The removal guide.

Windows Defence Counsel is one more fake antivirus program you can easily catch in the web at present time. When such rogue penetrates into your system it automatically begins to act like an antivirus. That is why you should be careful. It scans your system and shows you the list of threats you sypposedly have inside your machine. But this is not what you think. You do not have any of those threats inside your system. Windows Defence Counsel virus creates its own fake names of rogues and scams for you to believe that your system is really infected and needs to be repaired.


The only thing left for you to do is to eliminate Windows Defence Counsel virus from your system as soon as possible. Each time you restart your pc Windows Defence Counsel will run itself without your permission. We recommend you to delete the virus with the help of Loaris Trojan Remover. You can download the program here below. Be safe and careful in the web!

Windows Defence Counsel malware remover:

Windows Defence Counsel automatic removal:


Windows Defence Counsel automatic remover

Windows Defence Counsel similar video removal guide:


Windows Defence Counsel manual remover:

Delete Windows Multi Control System files:
  • %AppData%\\Microsoft\\Internet Explorer\\Quick Launch\\Windows Defence Counsel.lnk
  • %AppData%\\Windows Defence Counsel\\Instructions.ini
  • %AppData%\\Windows Defence Counsel\\ScanDisk_.exe
  • %Desktop%\\Windows Defence Counsel.lnk
  • Programs%\\Windows Defence Counsel.lnk
  • %StartMenu%\\Windows Defence Counsel.lnk
  • %CommonAppData%\\58ef5\\SP98c.exe
  • %CommonAppData%\\58ef5\\SPT.ico
  • %CommonAppData%\\SPUPCZPDET\\SPABOIJT.cfg
Delete Windows Defence Counsel registry entries:
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows Defence Counsel "%CommonAppData%\\58ef5\\SP98c.exe" /s /d
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel\\DisplayIcon [unknown dir]\\[unknown file name].exe,0
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel\\DisplayName System Protection Tools
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel\\DisplayVersion 1.1.0.1010
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel\\InstallLocation [unknown dir]\
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel\\Publisher UIS Inc.
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Defence Counsel\\UninstallString "[unknown dir]\\[unknown file name].exe" /del
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32\\ [unknown dir]\\[unknown file name].exe
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID\\ [unknown file name].DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid\\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\ConsoleTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableConsoleTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableFileTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileDirectory %windir%\\tracing
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\MaxFileSize 1048576
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe\\Debugger svchost.exe
  • And many others.

Комментариев нет:

Отправить комментарий