<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; rogue antivirus</title> <atom:link href="http://www.ghacks.net/tag/rogue-antivirus/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 17:32:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>How To Remove XP Internet Security 2012</title><link>http://www.ghacks.net/2011/08/16/how-to-remove-xp-internet-security-2012/</link> <comments>http://www.ghacks.net/2011/08/16/how-to-remove-xp-internet-security-2012/#comments</comments> <pubDate>Tue, 16 Aug 2011 01:56:37 +0000</pubDate> <dc:creator>Melanie Gross</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[internet security]]></category> <category><![CDATA[rogue antivirus]]></category> <category><![CDATA[rogue-remover]]></category> <category><![CDATA[windows security]]></category> <category><![CDATA[xp internet security 2012]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=49148</guid> <description><![CDATA[In this post I’m going to tell you how to remove XP Internet Security 2012. If you didn’t know, this is a fake security tool that produces fake pop-ups, and fake scan results, with the sole purpose of intimidating you into buying the software. All the viruses and security issues it finds are simply made [...]]]></description> <content:encoded><![CDATA[<p>In this post I’m going to tell you how to remove XP Internet Security 2012. If you didn’t know, this is a fake security tool that produces fake pop-ups, and fake scan results, with the sole purpose of intimidating you into buying the software. All the viruses and security issues it finds are simply made up, and you’ll find this software takes over your computer and won’t allow you to do many things until you purchase the software to get rid of all those mythical bugs. You’ll find that it activates in safe mode, and safe mode with networking, and also disables Internet Explorer, making it very hard to remove.</p><p>The first program you need is called RogueKiller, which is free to download and run. You can download this by going to your browser and typing <a
href="http://tigzy.geekstogo.com/Tools/RogueKiller.exe">http://tigzy.geekstogo.com/Tools/RogueKiller.exe</a> Don’t worry if you get some pop-ups generated by the malware when you open IE because it’s been hijacked, just close them until you get to your browser and copy and paste that link in. You’ll find the browser won’t block a direct link. Go ahead and save that file to your desktop. Before you save it however, change the name of the file from RogueKiller to Winlogon. If your browser really isn’t happy because of all the bugs, you can also paste that link into a run window. Go to start and then run, and paste the link. This will again open your browser and you may have to close a few windows before you can save the file.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/08/xp-internet-security-2012.png" alt="xp internet security 2012" title="xp internet security 2012" width="600" height="424" class="alignnone size-full wp-image-49149" /></p><p>Run the file on your desktop called Winlogon, and you’ll be presented with a DOS screen with some information and six options. RogueKiller will already have identified the process that is causing the problem, so the option you want is number two, for delete. This deletes the process that is locking up your computer. You’ll see a few screens flash by, and you’ll be presented with a report. You don’t need to view the report, it’s just for information, and so close it and you’ll be back at the desktop.</p><p>The next piece of free software you need is called Malwarebytes. You can download this by going to <a
href="http://www.myantispyware.com/mbam">http://www.myantispyware.com/mbam</a> You should find you have the use of your browser back, so go ahead and copy and past this into the address bar of IE and download the software. Again, copy it to your desktop, as this is a logical place to find it easily. Run the installation program and just follow the prompts, as it’s all fairly self-explanatory. When you get to two checkboxes at the end asking if you want to run the program and do an update, leave them checked and click finish. You may be asked if you want to buy the full version of Malwarebytes. At this point just decline and you can continue to use the free version.</p><p>Once the update has completed, you can go ahead and do a full scan. It will ask which drives to scan, uncheck everything except the C drive and run the scan. This may take some time, so go and do something else. Once it’s finished though, you can reboot your computer, and with fingers crossed your computer will be back to normal. Now’s a great time to update your antivirus software!!</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/08/16/how-to-remove-xp-internet-security-2012/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>Remove Rogue Antivirus Defense Center (defcnt.exe)</title><link>http://www.ghacks.net/2010/07/19/remove-rogue-antivirus-defense-center-defcnt-exe/</link> <comments>http://www.ghacks.net/2010/07/19/remove-rogue-antivirus-defense-center-defcnt-exe/#comments</comments> <pubDate>Mon, 19 Jul 2010 08:01:07 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Tutorials Basic]]></category> <category><![CDATA[defense center]]></category> <category><![CDATA[rogue antivirus]]></category> <category><![CDATA[windows security]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=28381</guid> <description><![CDATA[Rogue antivirus programs like Defense Center look on first glance as valid security software that protects a computer system from threats. On second glance though they usually displays non-existing infections deliberately, usually to convince the user to upgrade to a premium version to remove those infections or to buy another software that cleans them. Defense [...]]]></description> <content:encoded><![CDATA[<p>Rogue antivirus programs like Defense Center look on first glance as valid security software that protects a computer system from threats. On second glance though they usually displays non-existing infections deliberately, usually to convince the user to upgrade to a premium version to remove those infections or to buy another software that cleans them.</p><p>Defense Center is just one of the many rogue antivirus available on the Internet. The interface looks like that of legit security programs, displaying security status, firewall, antivirus and antispyware protection, and more.</p><p>The program scans the computer system and display a number of non-existing infections to the user. Users can verify that the listed files are not infected by uploading them to services such as Virustotal, which checks the files in more than 40 different antivirus engines.</p><p><span
id="more-28381"></span><div
id="attachment_28382" class="wp-caption alignnone" style="width: 508px"><img
src="http://www.ghacks.net/wp-content/uploads/2010/07/defense-center.jpg" alt="defense center" title="defense center" width="498" height="370" class="size-full wp-image-28382" /><p
class="wp-caption-text">defense center</p></div></p><p>Defense Center displays a variety of warnings and alerts to the user, including:</p><ul><li>Warning! Virus threat detected! Virus activity detected!</li><li>Warning! Adware detected! Adware module detected on your PC!</li><li>Warning! Network attack detected! Network intrusion detected!</li><li>Danger! A security threat detected on your computer.</li><li>Danger! Harmful viruses detected on your computer.</li></ul><p>The fake antivirus software is either installed deliberately by the user, or by trojans and other security exploits. The program tries to remove existing antivirus solutions from the operating system, to make the detection and removal more difficulty.</p><p>Defense Center can be removed manually or automatically.</p><h3>Defense Center Automatic Removal</h3><p>Automatic removal of Defense Center is usually the better option, considering that it may be that additional malicious software has been loaded onto the computer system.</p><p>Free security tools that detect and remove Defense Center are for instance:</p><ul><li><a
href="http://www.malwarebytes.org/mbam.php">Malwarebytes&#8217; Anti-Malware</a></li><li><a
href="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE">SuperAntiSpyware</a></li></ul><p>Please note that you may need to start your computer in Safe Mode to get rid of Defense Center completely. This can be done by pressing F8 during boot. Just tap the key until you see the Windows Advanced Options Menu, select Safe Mode from the list to boot into Safe Mode.</p><h3>Defense Center Manual Removal</h3><p>This requires the deletion of files and Registry entries. Some of these files may be locked if they are in use. The best option is to use a boot CD or boot the computer into Safe mode to remove the files and Registry entries:</p><p>Defense Center processes that may be running and need to be stopped: This can be done by pressing Ctrl-Shift-Esc to fire up the Windows Task Manager, switching to the Processes tab, selecting the processes and clicking End Process.</p><blockquote><p>Uninstall.exe<br
/> spam001.exe<br
/> spam003.exe<br
/> defcnt.exe<br
/> troj000.exe</p></blockquote><p>Make sure to delete all files in the commonprograms and programfiles directories.</p><blockquote><p>%appdata%&#92;microsoft&#92;internet explorer&#92;quick launch&#92;Defense Center.lnk<br
/> %desktop%&#92;Defense Center support.lnk<br
/> %desktop%&#92;Defense Center.lnk<br
/> %commonprograms%&#92;Defense Center&#92;<br
/> %programfiles&#92;Defense Center\</p></blockquote><p>Open the Registry Editor with the shortcut Windows-R, type regedit in the runbox and hit enter.</p><blockquote><p>HKLM&#92;SOFTWARE&#92;Defense Center<br
/> HKLM\SOFTWARE&#92;Microsoft&#92;Windows&#92;CurrentVersion&#92;Uninstall&#92;Defense Center<br
/> HKCU&#92;Software&#92;Microsoft&#92;Windows&#92;CurrentVersion&#92;Run “Defense Center”<br
/> HKCR&#92;CLSID&#92;{5E2121EE-0300-11D4-8D3B-444553540000}</p></blockquote><p><strong>Security Precautions</strong></p><p>Defense Center managed to get on your computer once, chance is that the security solutions in place are not efficient enough. Take a look at the following security measures to avoid future infections:</p><ul><li>Make sure your operating system and the software installed is up to date. This is especially important for the web browser used to surf the Internet.</li><li>If you do not have security software installed, do so immediately. Free options are <a
href="http://www.microsoft.com/security_essentials/market.aspx">Microsoft Security Essentials</a>, <a
href="http://www.avast.com/free-antivirus-download">Avast Antivirus</a> or <a
href="http://free.avg.com/de-en/homepage">AVG</a></li></ul> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/07/19/remove-rogue-antivirus-defense-center-defcnt-exe/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Security Tool Removal Instructions</title><link>http://www.ghacks.net/2009/12/09/security-tool-removal-instructions/</link> <comments>http://www.ghacks.net/2009/12/09/security-tool-removal-instructions/#comments</comments> <pubDate>Wed, 09 Dec 2009 12:29:50 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[rogue antivirus]]></category> <category><![CDATA[rogue av]]></category> <category><![CDATA[security tool]]></category> <category><![CDATA[security tool removal]]></category> <category><![CDATA[security tool virus]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=21217</guid> <description><![CDATA[Security Tool is a so called rogue antivirus software that is distributed by various means including malicious software like trojans but also popups on the Internet which will display a fake message that the computer is infected and needs to be secured by downloading the rogue security program. Security Tool will perform a series of [...]]]></description> <content:encoded><![CDATA[<p>Security Tool is a so called rogue antivirus software that is distributed by various means including malicious software like trojans but also popups on the Internet which will display a fake message that the computer is infected and needs to be secured by downloading the rogue security program. Security Tool will perform a series of tasks once it is running on a computer system. This includes blocking legit software from being executed and displaying false security warnings to promote a &#8220;full&#8221; version of the program that the PC user should buy to protect the computer system. The files that it displays as malicious or infected are not in fact which can be proven by testing them with a legit antivirus software.</p><p>Security Tool will add itself to the list of autostart programs in Windows. It will automatically perform a scan upon startup that will display the fake infections in the end. The &#8220;make money&#8221; part comes into play when the user tries to remove the infections with the rogue program. The rogue AV will notify the user that a license needs to be purchased before the infections can be removed.</p><p><span
id="more-21217"></span><img
src="http://www.ghacks.net/wp-content/uploads/2009/12/security_tool-500x371.jpg" alt="security tool" title="security tool" width="500" height="371" class="alignnone size-medium wp-image-21218" /></p><p>Some of the fake security warnings that Security Tool will display to the user include the following:</p><blockquote><p>Security Tool Warning<br
/> Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs.<br
/> Click here to remove it immediately with SecurityTool.</p></blockquote><blockquote><p>Security Tool Warning<br
/> Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss.<br
/> Click here to block unauthorised modification by removing threats (Recommended)</p></blockquote><p>To make matters worse Security Tool will also manipulate installed web browsers and block them from accessing websites. This usually is implemented by rogue software to make it harder for the computer user to download legit security software that can be used to remove the rogue software.</p><p><strong>Manual Removal of Security Tool:</strong></p><p>Security Tool uses random numbers to make the identification and removal instructions complicated.</p><ul><li>Step 1: Remove the Security Tool startup entry which is listed as number.exe where number is a random number.</li><li>Step 2: Identify and stop the Security Tool process by pressing [Windows Alt Del] to bring up the Windows Task Manager. The process is listed as number.exe where number is a random number</li><li>Step 3: Remove Security Tool related files. These are stored in two locations<br
/> C:\Documents and Settings\All Users\Application Data\number\<br
/> C:\Documents and Settings\All Users\Application Data\number\number.exe<br
/> where number is again a random number.</li><li>Step 4: Remove Security Tool Registry entries. Those again are stored in two different Registry keys.<br
/> HKEY_CURRENT_USER\Software\Security Tool<br
/> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Tool</li></ul><p><strong>Automatic Removal:</strong></p><p>Most legit antivirus software, like <a
href="http://www.malwarebytes.org/">Malwarebytes&#8217; Anti-Malware</a> is able to detect and remove Security Tool automatically. This process is usually faster and the better choice especially for inexperienced computer users.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/12/09/security-tool-removal-instructions/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>Remove Fake Antivirus Software Programs</title><link>http://www.ghacks.net/2009/10/19/remove-fake-antivirus-software-programs/</link> <comments>http://www.ghacks.net/2009/10/19/remove-fake-antivirus-software-programs/#comments</comments> <pubDate>Mon, 19 Oct 2009 12:51:04 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[portable software]]></category> <category><![CDATA[remove fake antivirus]]></category> <category><![CDATA[rogue antivirus]]></category> <category><![CDATA[rogue security software]]></category> <category><![CDATA[security-software]]></category> <category><![CDATA[windows software]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17454</guid> <description><![CDATA[Fake antivirus software programs, also called rogue security software, are programs that seem to be antivirus programs when in fact they are not. They either are disguised viruses, trojans or try to sale another product to the user. Like &#8220;normal&#8221; trojans rogue security software is often difficulty to remove from a computer system as it [...]]]></description> <content:encoded><![CDATA[<p>Fake antivirus software programs, also called rogue security software, are programs that seem to be antivirus programs when in fact they are not. They either are disguised viruses, trojans or try to sale another product to the user. Like &#8220;normal&#8221; trojans rogue security software is often difficulty to remove from a computer system as it usually uses background processes to protect uninstallation or tampering. Remove Fake Antivirus is a portable software program for the Windows operating system that has been designed to uninstall 27 different rogue antivirus software programs from the computer system. The following rogue security software programs can currently be removed with Remove Fake Antivirus:</p><p><span
id="more-17454"></span><ul><li>Cyber Security</li><li>Alpha Antivirus</li><li>Braviax</li><li>Windows Police Pro</li><li>Antivirus Pro 2010</li><li>PC Antispyware 2010</li><li>FraudTool.MalwareProtector.d</li><li>Winshield2009.com</li><li>Green AV</li><li>Windows Protection Suite</li><li>Total Security 2009</li><li>Windows System Suite</li><li>Antivirus BEST</li><li>System Security</li><li>Personal Antivirus</li><li>System Security 2009</li><li>Malware Doctor</li><li>Antivirus System Pro</li><li>WinPC Defender</li><li>Anti-Virus-1</li><li>Spyware Guard 2008</li><li>System Guard 2009</li><li>Antivirus 2009</li><li>Antivirus 2010</li><li>Antivirus Pro 2009</li><li>Antivirus 360</li><li>MS Antispyware 2009</li></ul><p><img
src="http://www.ghacks.net/wp-content/uploads/2009/10/remove_fake_antivirus.jpg" alt="remove fake antivirus" title="remove fake antivirus" width="426" height="293" class="alignnone size-full wp-image-17455" /></p><p>A click on the start button will initiate the process of removing these rogue security software programs from the computer system if they are installed. It starts by stopping running processes and removing the programs from the computer. The program seems to be updated fairly regularly by the software developer which makes it likely that new rogue antivirus programs will be added to future versions. Remove Fake Antivirus is <a
href="http://freeofvirus.blogspot.com/">available</a> for download at the developer&#8217;s website. (via Raymond)</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/19/remove-fake-antivirus-software-programs/feed/</wfw:commentRss> <slash:comments>15</slash:comments> </item> </channel> </rss>
