вторник, 29 мая 2012 г.

Windows Ultimate Security Patch rogue. The tips for removal.

There is a new virus called Windows Ultimate Security Patch in the web. If you have this program in your system you should be very careful. It is a virus not a good program. Windows Ultimate Security Patch claims to be an antivirus for you to believe in it. That is why it acts like one. When you receive this rogue inside your system it automatically begins to scan it and provides you with the list of threats it supposedly finds. But do not think that this program can do something good and useful to your system.


If you do the purchase of Windows Ultimate Security Patch you will get nothing but lost time and money. And the virus will achieve its goal. So, the only way out is to eliminate the virus as soon as possible. Here you can find the similar video removal guide with the help of Loaris Trojan Remover. Watch it.

Be safe and careful in the web!

Windows Ultimate Security Patch malware remover:

Windows Ultimate Security Patch automatic remover:


Windows Ultimate Security Patch automatic remover

Windows Ultimate Security Patch similar video removal guide:


Windows Ultimate Security Patch manual removal guide:

Delete Windows Ultimate Security Patch files:

  • %AppData%\\Microsoft\\Internet Explorer\\Quick Launch\\Windows Ultimate Security Patch.lnk
  • %AppData%\\Windows Ultimate Security Patch\\Instructions.ini
  • %AppData%\\Windows Ultimate Security Patch\\ScanDisk_.exe
  • %Desktop%\\Windows Ultimate Security Patch.lnk
  • Programs%\\Windows Ultimate Security Patch.lnk
  • %StartMenu%\\Windows Ultimate Security Patch.lnk
  • %CommonAppData%\\58ef5\\SP98c.exe
  • %CommonAppData%\\58ef5\\SPT.ico
  • %CommonAppData%\\SPUPCZPDET\\SPABOIJT.cfg

Delete Windows Ultimate Security Patch registry files:

  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows Ultimate Security Patch "%CommonAppData%\\58ef5\\SP98c.exe" /s /d
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch\\DisplayIcon [unknown dir]\\[unknown file name].exe,0
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch\\DisplayName System Protection Tools
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch\\DisplayVersion 1.1.0.1010
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch\\InstallLocation [unknown dir]\
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch\\Publisher UIS Inc.
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Ultimate Security Patch\\UninstallString "[unknown dir]\\[unknown file name].exe" /del
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32\\ [unknown dir]\\[unknown file name].exe
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID\\ [unknown file name].DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid\\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\ConsoleTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableConsoleTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableFileTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileDirectory %windir%\\tracing
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\MaxFileSize 1048576
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe\\Debugger svchost.exe
  • And many others.

Комментариев нет:

Отправить комментарий