пятница, 1 июня 2012 г.

Windows Malware Firewall malware. The method it can be eliminated with.

Windows Malware Firewall is a new virus inside the web but with the same old issues and goals. The main goal of the virus is your money. And it will try to trick the money out of you. When Windows Malware Firewall penetrates inside the system it installs itself and runs each time you reboot the machine. Each time it will do the same fake scanning without your permission. But be careful with the virus! The list of threats it supposedly finds in your system is totally fake. You do not have any of them in your system.



All you have to do is to eliminate the virus as soon as possible. And the sooner you do that the sooner you will get your computer's stable state back.We recommend you to dele te the virus with the help of ou program Loaris Trojan Remover. This anti-malware program can easily delete the virus in several minutes. Download the program here below, install and run it. Be safe and careful in the web!

Windows Malware Firewall malware remover:

Windows Malware Firewall automatic remover:


Windows Malware Firewall automatic remover

Windows Malware Firewall similar video removal guide:


Windows Malware Firewall manual removal guide:

Delete Windows Malware Firewall files:

  • %AppData%\\Microsoft\\Internet Explorer\\Quick Launch\\Windows Malware Firewall.lnk
  • %AppData%\\Windows Malware Firewall\\Instructions.ini
  • %AppData%\\Windows Malware Firewall\\ScanDisk_.exe
  • %Desktop%\\Windows Malware Firewall.lnk
  • Programs%\\Windows Malware Firewall.lnk
  • %StartMenu%\\Windows Malware Firewall.lnk
  • %CommonAppData%\\58ef5\\SP98c.exe
  • %CommonAppData%\\58ef5\\SPT.ico
  • %CommonAppData%\\SPUPCZPDET\\SPABOIJT.cfg

Delete Windows Malware Firewall registry files:

  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows Malware Firewall "%CommonAppData%\\58ef5\\SP98c.exe" /s /d
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall\\DisplayIcon [unknown dir]\\[unknown file name].exe,0
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall\\DisplayName System Protection Tools
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall\\DisplayVersion 1.1.0.1010
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall\\InstallLocation [unknown dir]\
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall\\Publisher UIS Inc.
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Malware Firewall\\UninstallString "[unknown dir]\\[unknown file name].exe" /del
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32\\ [unknown dir]\\[unknown file name].exe
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID\\ [unknown file name].DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid\\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\ConsoleTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableConsoleTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableFileTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileDirectory %windir%\\tracing
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\MaxFileSize 1048576
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe\\Debugger svchost.exe
  • And many others.

Комментариев нет:

Отправить комментарий