Showing posts with label Windows Police Pro family. Show all posts
Showing posts with label Windows Police Pro family. Show all posts

Friday, August 6, 2010

Remove Wireshark Antivirus (Uninstall guide)

Wireshark Antivirus is a new fake security program from the same family of malware as Sysinternals Antivirus, XJR Antivirus, AKM Antivirus 2010, etc. This program looks like a real antispyware or antivirus application, but unlike it, can not remove viruses and trojans, as well as protect your computer from possible infections. This malicious program is created with one purpose, to force you to buy its full version.

HijackThis shows Wireshark Antivirus infection:

O2 – BHO: ADC PlugIn – {149256D5-E103-4523-BB43-2CFB066839D6} – C:\Program Files\adc_w32.dll
O23 – Service: Adobe Update Service (AdbUpd) – Unknown owner – C:\Program Files\svchost.exe

What Wireshark Antivirus does


Wireshark Antivirus infiltrate computers through the use of trojans.When the fake antivirus is started, it will begin a system scan and list a lot of trojans, viruses and other malicious programs. Of course, the scan and its results are a fake. The rogue uses the false scan results as method to trick you into purchase the full version of this program. So you can freely ignore all that Wireshark Antivirus will give you.

Screen shoot of Wireshark Antivirus from S!Ri.URZ blog


While Wireshark Antivirus is running, it will display various misleading notifications and fake security alerts from Windows taskbar. However, all of these alerts and notifications is a fake and like false scan result should be ignored.

As you can see, Wireshark Antivirus is absolutely useless and what is more, even dangerous software. Most importantly, do not purchase it! Instead, please use the Wireshark Antivirus removal guide or the instructions below to remove this malware from your computer for free.

How to remove Wireshark Antivirus


Download fix.zip from here. Unzip it. Double Click fix.reg and click YES for confirm. Reboot your computer.

Download Malwarebytes Anti-malware. Double click mbam-setup.exe to install the application. When installation is complete, make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. If an update is found, it will download and install the latest version.

Once the program has loaded you will see a screen like below.

Malwarebytes' Anti-Malware

Select "Perform Quick Scan", then click Scan. When the scan is done, click OK, then Show Results to view the results. You will see a list of malware that  Malwarebytes' Anti-Malware found on your computer. Note: list of malware may be different than what is shown in the screen below.

Malwarebytes' Anti-Malware - lists of malicious software

Make sure that everything is checked, and click Remove Selected. Once disinfection is finished, a log will open in Notepad and you may be prompted to Restart.

Note: if you can`t download or run these suggested program above, boot your computer in Safe mode with networking and repeat the above steps once again.

If the instructions does not help you, then ask for help in the Spyware removal forum.

Tuesday, June 8, 2010

Sysinternals Antivirus removal instructions

Sysinternals Antivirus is a new rogue antispyware from the same family of rogues as XJR Antivirus, AKM Antivirus 2010, etc.

HijackThis shows Sysinternals Antivirus infection

O2 – BHO: ADC PlugIn – {149256D5-E103-4523-BB43-2CFB066839D6} – C:\Program Files\adc_w32.dll
O23 – Service: Adobe Update Service (AdbUpd) – Unknown owner – C:\Program Files\svchost.exe

What Sysinternals Antivirus does

The design of Sysinternals Antivirus looks like a normal antispyware tool, but in reality, this program can not remove viruses, trojans, etc., nor will be protect your computer from legitimate future infections. Sysinternals Antivirus created with one purpose to trick you into purchasing the full version of the software.

Sysinternals Antivirus is promoted and installed through the use of trojans. When the trojan is activated, it will download and install the rogue onto your PC without your permission and knowledge.

Screen shoot of Sysinternals Antivirus

Once started, Sysinternals Antivirus will add itself into Windows registry to run automatically every time when your computer starts. After that, it starts scanning procedure, which results in finding a lot of trojans, viruses and other malicious programs. Obviously, such results are a fraud, the program want to force you to believe that your computer is infected.

While Sysinternals Antivirus is running, it will flood your computer with fake security alert and notifications from Windows task bar that stats:

Warning: Infection is Detected. Windows has found spyware infection on your computer! Click here to update your Windows antivirus software…

Internet attack attempt detected: Somebody is trying to attack your PC: This can result in loss of your personal information and infection other computers connected to your network. Click here to prevent attack


Warning. Unwanted software (malware) or tracking cookies have been found during last scan. It is highly recommended to remove it from your computer.


Furthermore, the rogue may disable Task Manager and block legitimate Windows applications from running. If you will try to run an application you will see a warning as shown below and this application will be stopped.

Warning! Running of application is impossible. The file C:\Windows\System32\notepad.exe is infected.

From the above, obviously, Sysinternals Antivirus is a dangerous program, whose presence on your computer is absolutely undesirable. Use the removal instructions below to remove this malware for free.

How to remove Sysinternals Antivirus


Download fix.zip from here. Unzip it. Double Click fix.reg and click YES for confirm. Reboot your computer.

Download Malwarebytes Anti-malware. Double click mbam-setup.exe to install the application. When installation is complete, make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. If an update is found, it will download and install the latest version.

Once the program has loaded you will see a screen like below.

Malwarebytes' Anti-Malware

Select "Perform Quick Scan", then click Scan. When the scan is done, click OK, then Show Results to view the results. You will see a list of malware that  Malwarebytes' Anti-Malware found on your computer. Note: list of malware may be different than what is shown in the screen below.

Malwarebytes' Anti-Malware - lists of malicious software


Make sure that everything is checked, and click Remove Selected. Once disinfection is finished, a log will open in Notepad and you may be prompted to Restart.

Note: if you can`t download or run these suggested program above, boot your computer in Safe mode with networking and repeat the above steps once again.

If the instructions does not help you, then ask for help in the Spyware removal forum.

Thursday, June 3, 2010

Sysinternals Antivirus - rogue antispyware program

Sysinternals Antivirus is a rogue antispyware application from Windows Police Pro family of malware as XJR Antivirus, AKM Antivirus 2010 Pro, Your PC Protector, Windows Antivirus Pro and Windows Police Pro.


Screen shoot of Sysinternals Antivirus

Sysinternals Antivirus is promoted and installed through the use of trojans. Once installed, the rogue will detect false infections to scare user you into thinking that the computer in danger.

While Sysinternals Antivirus is running, it will flood the computer with fake security alerts and notifications.

If your computer is infected with this malware, then follow the Sysinternals Antivirus removal guide.

Friday, May 21, 2010

How to remove XJR Antivirus (XJR Antivirus Removal guide)

XJR Antivirus is a new rogue antispyware from the same family of rogues as AKM Antivirus 2010 Pro, Your PC Protector, Windows Antivirus Pro and Windows Police Pro.

HijackThis shows XJR Antivirus infection:

O2 – BHO: ADC PlugIn – {149256D5-E103-4523-BB43-2CFB066839D6} – C:\Program Files\adc_w32.dll
O23 – Service: Adobe Update Service (AdbUpd) – Unknown owner – C:\Program Files\svchost.exe

What XJR Antivirus does

XJR Antivirus is not a legitimate security tool. It looks like a normal antispyware tool, but in reality, this program can not remove viruses, trojans, etc., nor will be protect your computer from legitimate future infections. XJR Antivirus created with one purpose to trick you into purchasing the full version of the software.

XJR Antivirus is promoted and installed through the use of trojans. When the trojan is activated, it will download and install the rogue onto your computer without your permission and knowledge.

XJR Antivirus - process of scanning

During installation, XJR Antivirus will configure itself to run automatically every time when your computer starts. After that, it will simulate a system scan and detect numerous infections (worms, trojans, viruses, so on). These fake infection can only be removed with a full version of the program. Obviously, such results are a fake, XJR Antivirus want to scare you into thinking that your computer is infected with malicious software.

While XJR Antivirus is running, it will flood your computer with fake security alert and notifications from Windows task bar. Furthermore, the rogue may disable Task Manager, block antivirus and antispyware tools from running and hijack Internet Explorer so, that it will display various misleading notifications about unsafe websites and other security threats.

As you can see, XJR Antivirus is absolutely useless and what is more, even dangerous software. Most importantly, do not purchase it. Instead, please use the XJR Antivirus removal guide or the instructions below to remove this malware from your computer manually for free.

How to remove XJR Antivirus

1. Download fix.zip from here, unzip it. Double Click fix.reg and click YES for confirm. Reboot your computer.
2. Download Malwarebytes Anti-malware.
3. Double click mbam-setup.exe to install the application.
4. When installation is complete, make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
5. If an update is found, it will download and install the latest version.
6. Once the program has loaded, select "Perform Quick Scan", then click Scan.
7. When the scan is done, click OK, then Show Results to view the results.
8. Make sure that everything is checked, and click Remove Selected.
9. Once disinfection is finished, a log will open in Notepad and you may be prompted to Restart.

Note: if you can`t download or run these suggested program above, boot your computer in Safe mode with networking and repeat the above steps once again.

If the instructions does not help you, then ask for help in the Spyware removal forum.

Sunday, May 2, 2010

How to remove AKM Antivirus 2010 Pro (Removal guide)

AKM Antivirus 2010 Pro is a rogue antispyware program, which is an update to previously published malicious program called Your PC Protector.

HijackThis shows AKM Antivirus 2010 Pro infection:

O2 – BHO: ADC PlugIn – {77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02} – C:\Program Files\adc32.dll
O23 – Service: Adobe Update Service (AdbUpd) – Unknown owner – C:\Program Files\svchost.exe

What AKM Antivirus 2010 Pro does

AKM Antivirus 2010 Pro is not a legitimate security tool. It looks like a normal antispyware tool, but in reality, this program can not remove viruses, trojans, etc., nor will be protect your computer from legitimate future infections. AKM Antivirus 2010 Pro created with one purpose to trick you into purchasing the full version of the software.

Wednesday, February 3, 2010

Your PC Protector

Your PC Protector is a rogue antispyware application from the same family of rogues as Windows Antivirus Pro and Windows Police Pro.

Screen shoot of Your PC Protector

Your PC Protector is promoted and installed through the use of trojans. Once installed, the rogue will detect false infections to scare user you into thinking that the computer in danger.

While Your PC Protector is running, it will flood the computer with fake security alerts and notifications.

If your computer is infected with this malware, then follow the Your PC Protector removal guide.