<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Virus &#8211; techspeeder</title>
	<atom:link href="http://techspeeder.com/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://techspeeder.com</link>
	<description>Troubleshooting Helps and Tips for the Geek</description>
	<lastBuildDate>Tue, 20 Jan 2015 23:25:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
<site xmlns="com-wordpress:feed-additions:1">54126538</site>	<item>
		<title>Tips to Identify and Remove Poweliks Virus</title>
		<link>http://techspeeder.com/2015/01/15/tips-to-identify-and-remove-poweliks-virus/</link>
					<comments>http://techspeeder.com/2015/01/15/tips-to-identify-and-remove-poweliks-virus/#respond</comments>
		
		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Thu, 15 Jan 2015 22:18:41 +0000</pubDate>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Poweliks]]></category>
		<category><![CDATA[Process Explorer]]></category>
		<category><![CDATA[Rogue Killer]]></category>
		<category><![CDATA[Virus]]></category>
		<guid isPermaLink="false">http://techspeeder.com/?p=1298</guid>

					<description><![CDATA[Some more new malware that is hitting computers today. Thankfully there is a tool that can remove this one (or at least in my case). This blog post is about the Poweliks virus. You can find more detailed information about this virus on a couple other sites. I have the links at the bottom of [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Some more new malware that is hitting computers today. Thankfully there is a tool that can remove this <a title="C:\Windows\Explorer.exe is acting as a Virus, Windows 7" href="http://techspeeder.com/2014/12/17/cwindowsexplorer-exe-is-acting-as-a-virus-windows-7/">one</a> (or at least in my case). This blog post is about the Poweliks virus. You can find more detailed information about this virus on a couple other sites. I have the links at the bottom of the article.</p>
<blockquote><p>The G DATA SecurityLabs have analyzed persistent malware which resides in the registry only and therefore does not create any file on the infected system. An overview of this mechanism was firstly described quite recently in the KernelMode.info forum. The analyzed sample is dropped by a Microsoft Word document which exploits the vulnerability described in <a class="external-link-new-window" title="Information about the vulnerability described in CVE-2012-0158" href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158" target="_blank">CVE-2012-0158</a>. The document <a class="external-link-new-window" title="Reports about the Word document origin" href="http://techhelplist.com/index.php/spam-list/483-scheduled-package-delivery-failed-date-multi-malware" target="_blank">was reported</a> to be found as an attachment of fake Canada Post and/or USPS email which claims to hold information about ordered items for the recipient of the spam.</p>
<p><a href="https://blog.gdatasoftware.com/blog/article/poweliks-the-persistent-malware-without-a-file.html">Source</a></p></blockquote>
<p>I connected to a customer&#8217;s computer the other day. The laptop&#8217;s CPU usage was near 100% and had all kinds of crazy processes running. One process in particular was named inobbcrsb.exe. <a href="http://techspeeder.com/wp-content/uploads/2015/01/screenshote.bmp"><img fetchpriority="high" decoding="async" class="alignleft size-full wp-image-1300" src="http://techspeeder.com/wp-content/uploads/2015/01/screenshote.bmp" alt="inobbcrsb.exe virus" width="715" height="627" /></a>This process was posing as a Google Chrome process. Also fixmapi.exe and msfeedssync.exe were using up an incredible amount of processing power.</p>
<p>First off download <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx">Process Explorer</a>. You can see way more information on what is exactly happening with the processes on your computer. I knew inobbcrsb.exe had to be no good! I right-clicked on the process tree and suspended the process.<a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/googlechrome-process1.jpg"><img data-recalc-dims="1" decoding="async" class="alignleft wp-image-1302 size-large" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/googlechrome-process1.jpg?resize=625%2C229" alt="Inobbcrsb.exe Posing as Google Chrome" width="625" height="229" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/googlechrome-process1.jpg?resize=1024%2C375 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/googlechrome-process1.jpg?resize=300%2C110 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/googlechrome-process1.jpg?resize=624%2C228 624w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/googlechrome-process1.jpg?w=1161 1161w" sizes="(max-width: 625px) 100vw, 625px" /></a> I checked the path where this executable was<span id="more-1298"></span></p>
<p>launching from. It was launching from a really weird path underneath, C:\Users\{username}\Appdata\LocalLow\AskToolbar\bshycmeply\Hwexraefdcm . <a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Chrome-Path.jpg"><img data-recalc-dims="1" decoding="async" class="alignleft size-full wp-image-1303" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Chrome-Path.jpg?resize=625%2C440" alt="Virus Path" width="625" height="440" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Chrome-Path.jpg?w=771 771w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Chrome-Path.jpg?resize=300%2C211 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Chrome-Path.jpg?resize=624%2C439 624w" sizes="(max-width: 625px) 100vw, 625px" /></a>In the</p>
<p>Hwexraefdcm folder was the inobbcrsb.exe file. I decided to rename the executable to something different- ( inobbcrsb.exe5). You may need to use this <a href="http://www.emptyloop.com/unlocker/">program </a>to rename this file if it is running on your computer.</p>
<p><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/virus.jpeg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1306" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/virus.jpeg?resize=625%2C377" alt="Inobbcrsb.exe Virus in Windows" width="625" height="377" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/virus.jpeg?w=876 876w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/virus.jpeg?resize=300%2C181 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/virus.jpeg?resize=624%2C376 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>In the Hwexraefdcm folder I found a executable, called rundll32.exe. I decided to check the properties of this executable. I found underneath the details tab the original file name was rundll.exe instead of rundll32.exe. This confirmed my suspicion that this file was bad. I renamed this file as well.</p>
<p>I checked process explorer and task manager. The processes had cleared up somewhat but the CPU usage was still quite high. I noticed Power Shell would randomly start up and use processor power. I also noticed msfeedssync.exe, dvdupgrd.exe, and dllhst3g.exe processes were uploading all kinds of traffic to the web.<a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/msfeedssync.exe_.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1310" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/msfeedssync.exe_.jpg?resize=625%2C364" alt="msfeedssync.exe Internet Traffice" width="625" height="364" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/msfeedssync.exe_.jpg?w=810 810w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/msfeedssync.exe_.jpg?resize=300%2C175 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/msfeedssync.exe_.jpg?resize=624%2C364 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a> <a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Internet-Traffic.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1309" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Internet-Traffic.jpg?resize=625%2C387" alt="Internet Traffic" width="625" height="387" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Internet-Traffic.jpg?w=784 784w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Internet-Traffic.jpg?resize=300%2C186 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Internet-Traffic.jpg?resize=624%2C387 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a> <a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/dvdupgrd.exe_.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1308" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/dvdupgrd.exe_.jpg?resize=625%2C396" alt="dvdupgrd.exe" width="625" height="396" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/dvdupgrd.exe_.jpg?w=682 682w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/dvdupgrd.exe_.jpg?resize=300%2C190 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/dvdupgrd.exe_.jpg?resize=624%2C395 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>Another suspicious file I found was stored under C:\users\{username}\AppData\LocalLow . There was a dll named juxcini.dll .<a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/screenshot11.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1311" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/screenshot11.jpg?resize=528%2C668" alt="juxcini.dll " width="528" height="668" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/screenshot11.jpg?w=528 528w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/screenshot11.jpg?resize=237%2C300 237w" sizes="auto, (max-width: 528px) 100vw, 528px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Again, I checked the original file name under details. The original file name was SDL_net.dll .<a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/SDL_net.dll_.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1312" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/SDL_net.dll_.jpg?resize=522%2C652" alt="SDL_net.dll" width="522" height="652" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/SDL_net.dll_.jpg?w=522 522w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/SDL_net.dll_.jpg?resize=240%2C300 240w" sizes="auto, (max-width: 522px) 100vw, 522px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>I renamed this dll as well. If you can&#8217;t rename this file because it is in use, download <a href="http://www.emptyloop.com/unlocker/">Unlocker</a> and you will be able to rename the file.</p>
<p>After watching processes and finding files that I knew were malicious I was still grasping at straws on where exactly the virus was starting from.</p>
<p>I then downloaded<a href="http://www.adlice.com/softwares/roguekiller/"> Rogue Killer</a>. I never used the program before, but I am sold on it now. I ran a scan and it found a couple processes that the virus was using. I cleaned the computer and rebooted. I took a look at the processes but they were still a couple eating up CPU ( most notably fixmapi.exe and msfeedssync.exe processes).</p>
<p>I visited<a href="http://www.adlice.com/poweliks-removal-with-roguekiller/"> adlice.com</a> and found the solution. I ran Rogue Killer once more. Rogue Killer detected malicious processes and registry files. However, before I clicked clean computer I went to Process Explorer. In Process Explorer, I killed the dllhost.exe process tree. I then clicked clean computer. I rebooted the computer. Presto, the virus was removed!! This tool saved me lots of time. I then ran Malwarebytes to make sure everything was removed.<a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/RogueKiller.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1314" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/RogueKiller.jpg?resize=625%2C259" alt="RogueKiller" width="625" height="259" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/RogueKiller.jpg?w=1020 1020w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/RogueKiller.jpg?resize=300%2C124 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/RogueKiller.jpg?resize=624%2C258 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>You will also find this on the adlice website, but my Internet Explorer wouldn&#8217;t allow me to download any files. Click on the <strong>gear</strong> icon in Internet Explorer and then Internet Options.    <a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Internet-Settings.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class=" size-full wp-image-495 alignleft" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Internet-Settings.jpg?resize=519%2C112" alt="Internet Settings" width="519" height="112" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Internet-Settings.jpg?w=519 519w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Internet-Settings.jpg?resize=300%2C64 300w" sizes="auto, (max-width: 519px) 100vw, 519px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Next go to the <strong>Advanced</strong> tab. <a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1319" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture.jpg?resize=441%2C569" alt="Reset Internet Explorer Settings" width="441" height="569" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture.jpg?w=441 441w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture.jpg?resize=233%2C300 233w" sizes="auto, (max-width: 441px) 100vw, 441px" /></a>Click <strong>Reset</strong> Internet Explorer settings.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Once you reset the browser go to the Security tab and select Reset all zones to default level. <a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture1.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignleft size-full wp-image-1320" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture1.jpg?resize=440%2C569" alt="Reset Internet Explorer Security" width="440" height="569" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture1.jpg?w=440 440w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2015/01/Capture1.jpg?resize=232%2C300 232w" sizes="auto, (max-width: 440px) 100vw, 440px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>You will want to reset all zones to default level for Internet, Local intranet, Trusted Sites, and Restricted Sites. This virus messes with your security settings and won&#8217;t allow you to download anything.</p>
<p>This enabled me to initiate a download in Internet Explorer. Something is still wrong with Internet Explorer since it will start a download and then say &#8220;Download couldn&#8217;t be completed&#8221;. If anyone else runs into this problem I would be glad to hear what you did to fix it.</p>
<p>I monitored the computer for a while and no weird processes started up and everything was fine. Thanks so much to the <a href="http://www.adlice.com/poweliks-removal-with-roguekiller/">adlice </a>website and <a href="http://www.adlice.com/softwares/roguekiller/">Rogue Killer</a> tool for making my day easier.</p>
<p>Here is some more additional reading about this virus.</p>
<p><a href="https://blog.gdatasoftware.com/blog/article/poweliks-the-persistent-malware-without-a-file.html">Gdatasoftware</a>  ;  <a href="http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;t=3377">KernelMode</a></p>
<p>I hope this helps. Let me know by posting in the comments.</p>
<p>This was posted by techspeeder.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://techspeeder.com/2015/01/15/tips-to-identify-and-remove-poweliks-virus/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1298</post-id>	</item>
		<item>
		<title>Clean Computer to Prevent System Breakage &#8211; Windows Accelerator Pro Virus</title>
		<link>http://techspeeder.com/2014/01/22/clean-computer-to-prevent-system-breakage-windows-accelerator-pro-virus/</link>
					<comments>http://techspeeder.com/2014/01/22/clean-computer-to-prevent-system-breakage-windows-accelerator-pro-virus/#comments</comments>
		
		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Thu, 23 Jan 2014 00:56:27 +0000</pubDate>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[guard-sald]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Windows Accelerator Pro]]></category>
		<guid isPermaLink="false">http://techspeeder.com/?p=649</guid>

					<description><![CDATA[In the recent past I received an email from someone that was wondering what he should do about the following pop-up. Before I got a chance to email him back, he hit OK on that pop-up. He then received this pop-up. I quickly emailed him back and told him that it was a fake anti-virus [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>In the recent past I received an email from someone that was wondering what he should do about the following pop-up.</p>
<div id="attachment_651" style="width: 488px" class="wp-caption aligncenter"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-651" class="size-full wp-image-651 " style="font-size: 1rem; line-height: 1;" alt="SystemBreakage " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/SystemBreakage.jpg?resize=478%2C187" width="478" height="187" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/SystemBreakage.jpg?w=478 478w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/SystemBreakage.jpg?resize=300%2C117 300w" sizes="auto, (max-width: 478px) 100vw, 478px" /><p id="caption-attachment-651" class="wp-caption-text"><strong>Microsoft Antivirus has found critical process activity on your PC. You need to clean your computer to prevent the system breakage.</strong></p></div>
<p>Before I got a chance to email him back, he hit OK on that pop-up. He then received this pop-up.</p>
<div id="attachment_652" style="width: 608px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/FakeAVmessage.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-652" class="size-full wp-image-652" alt="FakeAVmessage" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/FakeAVmessage.jpg?resize=598%2C337" width="598" height="337" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/FakeAVmessage.jpg?w=598 598w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/FakeAVmessage.jpg?resize=300%2C169 300w" sizes="auto, (max-width: 598px) 100vw, 598px" /></a><p id="caption-attachment-652" class="wp-caption-text"><strong>Take note of the misspelling of the word, might</strong>.</p></div>
<p>I quickly emailed him back and told him that it was a fake anti-virus message. If he would have clicked clean computer, he would probably have gotten infected. I told him to run a full scan with his antivirus software. Thankfully, he wasn&#8217;t infected.</p>
<p>I decided I would have a little fun with this virus. I have a virtual machine for technical purposes, so I decided I would try to infect my virtual machine with this virus. I found the website that was infected. <span id="more-649"></span><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/malwareahead.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-full wp-image-653" alt="malware ahead " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/malwareahead.jpg?resize=625%2C418" width="625" height="418" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/malwareahead.jpg?w=979 979w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/malwareahead.jpg?resize=300%2C200 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/malwareahead.jpg?resize=624%2C417 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>I soon downloaded a malicious script from the website and I was infected with the virus. Here are a couple screenshots of the Windows Accelerator Pro virus.</p>
<div id="attachment_657" style="width: 624px" class="wp-caption alignnone"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-657" class=" wp-image-657  " style="font-size: 1rem; line-height: 1;" alt="Fake Security Center " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV4.png?resize=614%2C461" width="614" height="461" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV4.png?w=1024 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV4.png?resize=300%2C225 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV4.png?resize=624%2C468 624w" sizes="auto, (max-width: 614px) 100vw, 614px" /><p id="caption-attachment-657" class="wp-caption-text">It tried to pose as a legit anti-virus, security software.<span style="line-height: 1.714285714; font-size: 1rem;">     </span><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-large wp-image-656" style="font-size: 1rem; line-height: 1;" alt="AV3" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV3.png?resize=625%2C468" width="625" height="468" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV3.png?w=1024 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV3.png?resize=300%2C225 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV3.png?resize=624%2C468 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></p></div>
<p><span style="line-height: 1.714285714; font-size: 1rem;">The virus tries to force you to pay for its &#8220;anti-virus protection&#8221;</span><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-full wp-image-655" style="font-size: 1rem; line-height: 1;" alt="Payment Required" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV2.png?resize=625%2C469" width="625" height="469" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV2.png?w=1024 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV2.png?resize=300%2C225 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/AV2.png?resize=624%2C468 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></p>
<p><span style="line-height: 1.714285714; font-size: 1rem;">Here is how I removed Windows Accelerator Pro. </span></p>
<p><strong>Step One:</strong> I started the computer and hit <strong>F8</strong> until I got to the screen that I chose <strong>Safe Mode with Command Prompt</strong>.  Note: Safe Mode and Safe Mode with Networking will still allow the virus to work and you can&#8217;t get around it.</p>
<p><strong>Step Two:</strong> I typed <strong>explorer</strong> in the command prompt.</p>
<p>I have met a couple other viruses similar to this one and a common place to store the executable file is <strong>C:\ Users\&lt;Username\AppData\Roaming</strong>. I decided to browse to that location using Windows Explorer and sure enough there was a weird file called <strong>guard-sald</strong> there. I removed that file and another file called<strong> GDIPFONTCACHEV1.DAT</strong>.  I then browsed to <strong>C:\ Users\&lt;Username\AppData\Local</strong> and removed a file called<strong> result1</strong>.</p>
<p><strong>Attn:</strong> Your virus file names may be different than these. I am just stating what worked for me. To make sure you don&#8217;t mess up the Windows file structure, by deleting something good, I would encourage you to cut and paste your virus files to the desktop. I pasted my viruses to the desktop and they didn&#8217;t start, at start-up since they weren&#8217;t in their correct folders.</p>
<p>I then rebooted the computer.</p>
<p><strong>Step Three:</strong> I started Windows normally and it came up fine. I downloaded <a href="http://www.malwarebytes.org/">Malwarebytes</a> and <a href="http://www.malwarebytes.org/antirootkit/">Malwarebytes Anti-RookitBeta</a><span style="line-height: 1.714285714; font-size: 1rem;">. </span><span style="line-height: 1.714285714; font-size: 1rem;"> </span></p>
<p><span style="line-height: 1.714285714; font-size: 1rem;"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/removalJPG.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-full wp-image-659" alt="removal" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/removalJPG.jpg?resize=625%2C536" width="625" height="536" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/removalJPG.jpg?w=674 674w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/removalJPG.jpg?resize=300%2C257 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/removalJPG.jpg?resize=624%2C535 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></span></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-full wp-image-658" style="font-size: 1rem; line-height: 1;" alt="Show Results" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/infected.jpg?resize=625%2C492" width="625" height="492" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/infected.jpg?w=796 796w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/infected.jpg?resize=300%2C236 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/infected.jpg?resize=624%2C491 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone  wp-image-660" style="font-size: 1rem; line-height: 1;" alt="Remove Viruses " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/RemoveViruses.jpg?resize=625%2C476" width="625" height="476" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/RemoveViruses.jpg?w=793 793w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/RemoveViruses.jpg?resize=300%2C228 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2014/01/RemoveViruses.jpg?resize=624%2C475 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></p>
<p><span style="line-height: 1.714285714; font-size: 1rem;">I removed the viruses and malware these programs found and I was back in business. </span></p>
<p>This was posted by techspeeder.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>http://techspeeder.com/2014/01/22/clean-computer-to-prevent-system-breakage-windows-accelerator-pro-virus/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">649</post-id>	</item>
		<item>
		<title>Antivirus Security Pro Virus (Trojan.Agent.rfz)  Removal Instructions</title>
		<link>http://techspeeder.com/2013/10/28/antivirus-security-pro-virus-trojan-agent-rfz-removal-instructions/</link>
					<comments>http://techspeeder.com/2013/10/28/antivirus-security-pro-virus-trojan-agent-rfz-removal-instructions/#respond</comments>
		
		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Mon, 28 Oct 2013 23:04:16 +0000</pubDate>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Trojan.Agent.rfz]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Windows 7]]></category>
		<guid isPermaLink="false">http://techspeeder.com/?p=542</guid>

					<description><![CDATA[Monday Morning: Today I visited a customer that was infected with the &#8220;Antivirus Security Pro&#8221; virus. Our customer was using Windows Intune for antivirus protection on a Windows 7 computer. Here are a couple screenshots of the virus. It tries to pose as a legit antivirus program, when in fact it is infecting your PC. It [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Monday Morning: Today I visited a customer that was infected with the &#8220;Antivirus Security Pro&#8221; virus. Our customer was using Windows Intune for antivirus protection on a Windows 7 computer. Here are a couple screenshots of the virus. It tries to pose as a legit antivirus program, when in fact it is infecting your PC. It then tries to make you pay for the antivirus software to fix all of &#8220;the problems&#8221; it is finding.</p>
<p><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone  wp-image-556" title="Antivirus Security Pro" alt="Antivirus Security Pro" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture.jpg?resize=625%2C460" width="625" height="460" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture.jpg?w=882 882w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture.jpg?resize=300%2C220 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture.jpg?resize=624%2C459 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p><span id="more-542"></span></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-full wp-image-559" alt="Warning! Infected file detected!" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/vCapture.png?resize=494%2C361" width="494" height="361" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/vCapture.png?w=494 494w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/vCapture.png?resize=300%2C219 300w" sizes="auto, (max-width: 494px) 100vw, 494px" /></p>
<p>&nbsp;</p>
<p><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture1.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-large wp-image-557" title="Payment Needed" alt="Payment Needed " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture1.jpg?resize=625%2C374" width="625" height="374" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture1.jpg?resize=1024%2C613 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture1.jpg?resize=300%2C179 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture1.jpg?resize=624%2C373 624w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Capture1.jpg?w=1277 1277w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>Here is how I removed it.</p>
<p>Download <a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx"> Autoruns for Windows</a> on a flash drive .</p>
<p>Step One: Reboot and press F8 until you get to the Advanced Boot Options screen. Select <strong>Safe Mode with Networking</strong>. Then log into your account. Stick your flash drive in your computer and run Autoruns.</p>
<p>Click the <strong>&#8220;Everything&#8221;</strong> tab. I scrolled down till I saw the following entry: <strong>HKCU\Software\Microsoft\Windows\CurrentVersion\Run</strong></p>
<p><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-large wp-image-543" alt="Antivirus Security Pro" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg?resize=625%2C320" width="625" height="320" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg?resize=1024%2C525 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg?resize=300%2C153 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg?resize=624%2C320 624w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg?w=1250 1250w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Antivirus-Pro-Security.jpg?w=1875 1875w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>Step Two: I unchecked <strong>AS2014</strong> entry (Antivirus Security 2014). You will notice the executable file is <strong>7advrrps.exe</strong> &#8211; that doesn&#8217;t sound very legit.  You can delete the AS2014 entry. I just unchecked the AS2014 entry since I wasn&#8217;t sure if it was the virus. <!--more--> Close out of the program and reboot your computer and log normally into Windows.</p>
<p>Step Three: I then ran <a href="http://www.malwarebytes.org/">Malwarebytes</a>, <a href="http://www.superantispyware.com/">SuperAntispywar</a>e, and Windows Intune. I also started a scan with <a href="http://www.malwarebytes.org/products/mbar/">Malwarebytes Anti-Rootkit </a>but that scan froze before it completed.  The scans found the viruses and successfully removed them.  (Note) You will want to reboot your computer after removing those viruses.</p>
<div id="attachment_545" style="width: 573px" class="wp-caption alignnone"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-545" class=" wp-image-545" style="font-size: 1rem; line-height: 1;" alt="Super Antispyware" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/SuperAntispyware.jpg?resize=563%2C379" width="563" height="379" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/SuperAntispyware.jpg?resize=1024%2C691 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/SuperAntispyware.jpg?resize=300%2C202 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/SuperAntispyware.jpg?resize=624%2C421 624w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/SuperAntispyware.jpg?w=1250 1250w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/SuperAntispyware.jpg?w=1875 1875w" sizes="auto, (max-width: 563px) 100vw, 563px" /><p id="caption-attachment-545" class="wp-caption-text">Super Antispyware found the 7advrrps.exe (that I unchecked using Autoruns). It turned out to be the Antivirus Security Pro virus.</p></div>
<p><span style="line-height: 1.714285714; font-size: 1rem;"> </span></p>
<p><a style="line-height: 1.714285714; font-size: 1rem;" href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class=" wp-image-544" alt="Malwarebytes Anti-Rootkit" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg?resize=563%2C471" width="563" height="471" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg?resize=1024%2C858 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg?resize=300%2C251 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg?resize=624%2C523 624w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg?w=1716 1716w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/Malwarebytes-Anti-Rootkit.jpg?w=1250 1250w" sizes="auto, (max-width: 563px) 100vw, 563px" /></a>Malwarebytes Anti-Rootkit found a Trojan.Agent.rfz</p>
<p>Update: Monday Evening</p>
<p><span style="line-height: 1.714285714; font-size: 1rem;">Apparently Windows Intune is missing this virus because another customer called in with the same virus. This one was removed with much of the same troubleshooting steps. One difference was that the executable file was called <strong>hVrVnngp.exe</strong> instead of <strong>7advrrps.exe.</strong></span></p>
<p><span style="line-height: 1.714285714; font-size: 1rem;"><strong><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/malwarebytes-found-hVrVnngp.exe_.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone  wp-image-547" alt="Malwarebytes found hVrVnngp.exe" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/malwarebytes-found-hVrVnngp.exe_.jpg?resize=625%2C478" width="625" height="478" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/malwarebytes-found-hVrVnngp.exe_.jpg?w=831 831w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/malwarebytes-found-hVrVnngp.exe_.jpg?resize=300%2C229 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/10/malwarebytes-found-hVrVnngp.exe_.jpg?resize=624%2C477 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><br />
</strong></span></p>
<p>This was posted by techspeeder.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>http://techspeeder.com/2013/10/28/antivirus-security-pro-virus-trojan-agent-rfz-removal-instructions/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">542</post-id>	</item>
		<item>
		<title>United States Department of Justice Virus Removal Guide</title>
		<link>http://techspeeder.com/2013/07/19/united-states-department-of-justice-virus-removal-guide/</link>
					<comments>http://techspeeder.com/2013/07/19/united-states-department-of-justice-virus-removal-guide/#respond</comments>
		
		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Fri, 19 Jul 2013 23:16:02 +0000</pubDate>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Autoruns]]></category>
		<category><![CDATA[Department of Justice Virus]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<guid isPermaLink="false">http://techspeeder.com/?p=267</guid>

					<description><![CDATA[One of our customers contacted us today about the &#8216;The United States Department of Justice&#8217; virus their computer got. This is the pop-up that came up, and would prevent them from doing anything. Here are the steps I used to remove this virus. Step One: Download Autoruns to a flash drive. Step Two: Start the computer [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>One of our customers contacted us today about the &#8216;The United States Department of Justice&#8217; virus their computer got. This is the pop-up that came up, and would prevent them from doing anything.</p>
<p><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/1.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class=" wp-image-269 " alt="The United States Department of Justice Virus" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/1.jpg?resize=625%2C469" width="625" height="469" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/1.jpg?w=1000 1000w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/1.jpg?resize=300%2C225 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/1.jpg?resize=624%2C468 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a></p>
<p>Here are the steps I used to remove this virus.</p>
<p><strong>Step One:</strong> Download <strong><a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx">Autoruns</a></strong> to a flash drive.<img data-recalc-dims="1" decoding="async" title="More..." alt="" src="https://i0.wp.com/techspeeder.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif?w=625" /></p>
<p><span id="more-267"></span></p>
<p><strong>Step Two:</strong> Start the computer up and hit you <strong>F8</strong> key on your keyboard continually until you get the following screen:</p>
<div id="attachment_252" style="width: 716px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-252" class=" wp-image-252 " alt="Safe mode with Command Prompt" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?resize=625%2C474" width="625" height="474" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?w=1009 1009w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?resize=300%2C227 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?resize=624%2C472 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><p id="caption-attachment-252" class="wp-caption-text">Safe mode with Command Prompt</p></div>
<p>then boot into Windows by selecting <strong>Safe Mode with Command Prompt</strong>.</p>
<p><strong>Step Three:</strong> Type <strong>Explorer</strong> in Command Prompt.</p>
<p><strong>Step Four:</strong> Use the Windows interface to browse to your flash drive that has<strong><a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx"> autoruns</a>.</strong></p>
<p><strong>Step Five:</strong>  Run <strong>autoruns</strong>. Then select <strong>Options</strong> &gt; <strong>Filter Options</strong> on the menu bar to filter out all Microsoft and Windows entries. Once that is done look for these files, if any show up, delete them by right-clicking on the file and hitting delete.</p>
<p>1: Under <strong>HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run</strong>   Delete the <strong>VProtect Application</strong></p>
<p>2:Under<strong> HKLM\SOFTWARE\Microsoft\Active Setup\Installed Component</strong>  Delete the<strong> Internet Explorer file</strong> that is there.</p>
<p>3: Under<strong> HKCU\Software\Microsoft\Windows\CurrentVersion\Run</strong> Delete the<strong> DisplaySwitch executable file</strong>. If you browse to the location of the Display Switch File, you will find the United States Department of Justice images and the virus file.</p>
<div id="attachment_271" style="width: 460px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-271" class=" wp-image-271   " alt="Viruses Spotted" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited-1024x694.jpg?resize=450%2C305" width="450" height="305" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited.jpg?resize=1024%2C694 1024w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited.jpg?resize=300%2C203 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited.jpg?resize=624%2C423 624w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited.jpg?w=1250 1250w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Viruses-edited.jpg?w=1875 1875w" sizes="auto, (max-width: 450px) 100vw, 450px" /></a><p id="caption-attachment-271" class="wp-caption-text">Viruses Spotted</p></div>
<p>Once these files are deleted the virus should be mostly removed. Reboot and boot into Windows normally.</p>
<p><strong>Step Seven:</strong> Run a virus scan with <a href="http://www.malwarebytes.org/">Malwarebytes</a> and <a href="http://www.superantispyware.com/">SuperAntiSpyware</a> to ensure all viruses and malware is removed.</p>
<p>This worked for me. If this helped you or you were not able to use this method to remove this virus please leave a comment below. Thank you. This was posted by techspeeder.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>http://techspeeder.com/2013/07/19/united-states-department-of-justice-virus-removal-guide/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">267</post-id>	</item>
		<item>
		<title>Removal Guide for the Ransomware MoneyPak Virus,Trojan:Win32/Urausy.C</title>
		<link>http://techspeeder.com/2013/07/08/removal-guide-for-the-ransomware-moneypak-virustrojanwin32urausy-c/</link>
					<comments>http://techspeeder.com/2013/07/08/removal-guide-for-the-ransomware-moneypak-virustrojanwin32urausy-c/#respond</comments>
		
		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Mon, 08 Jul 2013 22:02:29 +0000</pubDate>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[MoneyPak Virus]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[Win32/Urausy.C]]></category>
		<guid isPermaLink="false">http://techspeeder.com/?p=254</guid>

					<description><![CDATA[Many people panic when they see this virus. This virus pops up with a dialogue box saying that your computer has been locked because you were viewing adult material that potentially breaches the Obscene Publications Act in the U.S., your computer contains images of child abuse, and so on. This virus holds your computer ransom [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Many people panic when they see this virus.</p>
<div id="attachment_251" style="width: 605px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Pay-Money.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-251" class=" wp-image-251 " alt="Trojan:Win32/Urausy.C" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Pay-Money.jpg?resize=595%2C432" width="595" height="432" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Pay-Money.jpg?w=991 991w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Pay-Money.jpg?resize=300%2C217 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Pay-Money.jpg?resize=624%2C453 624w" sizes="auto, (max-width: 595px) 100vw, 595px" /></a><p id="caption-attachment-251" class="wp-caption-text">Trojan:Win32/Urausy.C</p></div>
<p>This virus pops up with a dialogue box saying that your computer has been locked because you were viewing adult material that potentially breaches the Obscene Publications Act in the U.S., your computer contains images of child abuse, and so on. This virus holds your computer ransom till you send them money through MoneyPak. (When they get the money they won&#8217;t unlock it!) Here are the <strong>REAL</strong> instructions for removing this nasty virus.</p>
<p><span id="more-254"></span></p>
<p><strong>Step One</strong>: Tap the <strong>F8</strong> key on your keyboard to boot into<strong> Safe Mode with Command Prompt</strong>.</p>
<div id="attachment_252" style="width: 615px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-252" class=" wp-image-252 " alt="Safe mode with Command Prompt " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?resize=605%2C458" width="605" height="458" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?w=1009 1009w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?resize=300%2C227 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/Safemode-with-commandprompt.jpg?resize=624%2C472 624w" sizes="auto, (max-width: 605px) 100vw, 605px" /></a><p id="caption-attachment-252" class="wp-caption-text">Safe mode with Command Prompt</p></div>
<p><strong>Step Two:</strong> In command prompt type <strong>explorer .</strong></p>
<div id="attachment_250" style="width: 544px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/command-prompt-explorer.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-250" class=" wp-image-250  " alt="Type Explorer" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/command-prompt-explorer.jpg?resize=534%2C270" width="534" height="270" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/command-prompt-explorer.jpg?w=667 667w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/command-prompt-explorer.jpg?resize=300%2C152 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/command-prompt-explorer.jpg?resize=624%2C316 624w" sizes="auto, (max-width: 534px) 100vw, 534px" /></a><p id="caption-attachment-250" class="wp-caption-text">Type Explorer</p></div>
<p><strong>Step Three:</strong> Browse to drive<strong> C:\Users\&lt;YourUsername&gt;\AppData\Roaming</strong>. Once in the Roaming folder you will find a file named<strong> skype.dat</strong> and <strong>skype</strong>. These files are the viruses that start when your computer boots up. Select those two files and delete them permanently.(Make sure to remove them from your recycle bin). (Revision) 7/19/2013 You may also find a windows update and/or a defender file. Remove them also. Reboot.</p>
<div id="attachment_253" style="width: 614px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/skype-marked-.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-253" class=" wp-image-253   " alt="Virus Spotted " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/skype-marked-.jpg?resize=604%2C457" width="604" height="457" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/skype-marked-.jpg?w=799 799w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/skype-marked-.jpg?resize=300%2C226 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/skype-marked-.jpg?resize=624%2C471 624w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a><p id="caption-attachment-253" class="wp-caption-text">Virus Spotted</p></div>
<p><strong>Step Four:</strong> Boot into Windows normally and run a scan for viruses with <a href="http://www.malwarebytes.org/">Malwarebytes</a>,<a href="http://www.microsoft.com/en-us/download/details.aspx?id=5201"> Microsoft Security Essentials</a> and<a href="http://www.superantispyware.com/"> SuperAntiSpyware</a>. Run these scans till they return clean. After they return clean you will be virus-free and back in business!</p>
<div id="attachment_258" style="width: 643px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/virus.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-258" class=" wp-image-258 " alt="Trojan:Win32/Urausy.C" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/virus.jpg?resize=625%2C420" width="625" height="420" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/virus.jpg?w=791 791w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/virus.jpg?resize=300%2C201 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/07/virus.jpg?resize=624%2C418 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><p id="caption-attachment-258" class="wp-caption-text">Trojan:Win32/Urausy.C</p></div>
<p>Thank you for reading this post. If this helped you please leave a comment.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>http://techspeeder.com/2013/07/08/removal-guide-for-the-ransomware-moneypak-virustrojanwin32urausy-c/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">254</post-id>	</item>
		<item>
		<title>How to Remove the Fake Security Protection Virus (Win32/FakeRean)</title>
		<link>http://techspeeder.com/2013/06/29/how-to-remove-the-fake-security-protection-virus/</link>
					<comments>http://techspeeder.com/2013/06/29/how-to-remove-the-fake-security-protection-virus/#respond</comments>
		
		<dc:creator><![CDATA[Merlin Halteman]]></dc:creator>
		<pubDate>Sat, 29 Jun 2013 14:13:57 +0000</pubDate>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Fake Security Protection]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virus Removal]]></category>
		<guid isPermaLink="false">http://techspeeder.com/?p=230</guid>

					<description><![CDATA[Viruses attack our computers in many ways. Some viruses work in the background disabling your antivirus software and corrupting your files but other viruses, such as the fake Security Protection virus take a different approach and pose as a antivirus software designed to protect your computer, when in fact it is installing viruses. The Security [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Viruses attack our computers in many ways. Some viruses work in the background disabling your antivirus software and corrupting your files but other viruses, such as the fake Security Protection virus take a different approach and pose as a antivirus software designed to protect your computer, when in fact it is installing viruses.</p>
<p>The Security Protection virus is an exceptionally brilliant virus. Once this virus is installed it will do a &#8220;full PC scan for viruses&#8221; when in fact, it is infecting your computer. This virus will block all other programs from running, even the calculator (smiles).</p>
<div style="width: 781px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Bogus-Security.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" class="size-full wp-image-221" alt="Fake Security Protection " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Bogus-Security.jpg?resize=625%2C478" width="625" height="478" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Bogus-Security.jpg?w=771 771w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Bogus-Security.jpg?resize=300%2C229 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Bogus-Security.jpg?resize=624%2C477 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><p class="wp-caption-text">Fake Security Protection</p></div>
<p><span id="more-230"></span></p>
<div id="attachment_228" style="width: 633px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-2-.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-228" class=" wp-image-228   " alt="Activate Security Protection " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-2-.jpg?resize=623%2C488" width="623" height="488" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-2-.jpg?w=786 786w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-2-.jpg?resize=300%2C235 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-2-.jpg?resize=624%2C489 624w" sizes="auto, (max-width: 623px) 100vw, 623px" /></a><p id="caption-attachment-228" class="wp-caption-text">Activate for Security Protection</p></div>
<p>After the scan is done, the Security Protection virus says that you need to activate its software to remove all the viruses.</p>
<p>If you select &#8220;Activate Now&#8221;, you will get a very official looking pop-up asking for your email address and a registration key.  Warning: Do not activate! It will only install more viruses and now the hackers know your email address.</p>
<div id="attachment_227" style="width: 458px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-1-.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-227" class="size-full wp-image-227" alt="Active Now" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-1-.jpg?resize=448%2C384" width="448" height="384" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-1-.jpg?w=448 448w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-1-.jpg?resize=300%2C257 300w" sizes="auto, (max-width: 448px) 100vw, 448px" /></a><p id="caption-attachment-227" class="wp-caption-text">Bogus: DO NOT ACTIVATE</p></div>
<p>At this point, your computer is nearly useless, you can&#8217;t uninstall the program and neither can you run programs. However, there is still a way to remove this virus. Here are the steps I used to remove the virus.</p>
<p><strong>Step One:</strong> Restart your computer and boot into<strong> &#8216;Safe Mode with Networking&#8217;</strong> by tapping the <strong>F8</strong> key. Once you are in Safe Mode you will have basic Windows functionality.</p>
<p><strong>Step Two:</strong> Download <a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx" target="_blank">Autoruns</a> for Windows.</p>
<div id="attachment_234" style="width: 711px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Autoruns.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-234" class=" wp-image-234 " alt="Autoruns " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Autoruns.jpg?resize=625%2C399" width="625" height="399" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Autoruns.jpg?w=973 973w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Autoruns.jpg?resize=300%2C191 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Autoruns.jpg?resize=624%2C398 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><p id="caption-attachment-234" class="wp-caption-text">Autoruns for Windows</p></div>
<p><strong>Step Three:</strong> Run the Autoruns tool and you will see all the processes that start up when you boot into Windows. Select the &#8216;Everything&#8217; tab and wait for all the processes to load. When all the process are loaded, click on<strong> &#8216;Options&gt;Filter&#8217;</strong> and select Hide Microsoft and Windows entries.</p>
<div id="attachment_232" style="width: 598px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Filter-Options-for-Autoruns.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-232" class="size-full wp-image-232" alt="Filter Options for Autoruns" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Filter-Options-for-Autoruns.jpg?resize=588%2C349" width="588" height="349" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Filter-Options-for-Autoruns.jpg?w=588 588w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Filter-Options-for-Autoruns.jpg?resize=300%2C178 300w" sizes="auto, (max-width: 588px) 100vw, 588px" /></a><p id="caption-attachment-232" class="wp-caption-text">Filter Options for Autoruns</p></div>
<p><strong>Step Four:</strong> With all the Microsoft and Windows entries filtered out, start browsing down the list of all the programs that start up. You will find Security Protection starting up. Deselect that box and reboot.</p>
<div id="attachment_233" style="width: 816px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Found-it_edited.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-233" class=" wp-image-233" alt="Virus Spotted" src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Found-it_edited.jpg?resize=625%2C384" width="625" height="384" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Found-it_edited.jpg?w=806 806w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Found-it_edited.jpg?resize=300%2C184 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Found-it_edited.jpg?resize=624%2C383 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><p id="caption-attachment-233" class="wp-caption-text">Security Protection Virus Spotted</p></div>
<p><strong>Step Five: </strong>Boot into Windows normally and download <a href="http://www.malwarebytes.org/" target="_blank">Malwarebytes</a> and <a href="http://support.kaspersky.com/5350?el=88446" target="_blank">TDSSKiller</a>. Run full system scans with both softwares. These scans will find the virus files and then you can remove them.</p>
<div id="attachment_218" style="width: 791px" class="wp-caption alignnone"><a href="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-5.jpg"><img data-recalc-dims="1" loading="lazy" decoding="async" aria-describedby="caption-attachment-218" class=" wp-image-218" alt="Malwarebytes found Viruses " src="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-5.jpg?resize=625%2C484" width="625" height="484" srcset="https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-5.jpg?w=781 781w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-5.jpg?resize=300%2C232 300w, https://i0.wp.com/techspeeder.com/wp-content/uploads/2013/06/Virus-Security-Warning-5.jpg?resize=624%2C483 624w" sizes="auto, (max-width: 625px) 100vw, 625px" /></a><p id="caption-attachment-218" class="wp-caption-text">Malwarebytes found Viruses. Remove Them.</p></div>
<p>Run these scans until they both come back without any results.</p>
<p><strong>Step Seven:</strong> After all the viruses are removed, download and run <a href="http://www.piriform.com/ccleaner" target="_blank">CCleaner</a> to remove any registry keys that the virus left behind. Make sure to install an antivirus software to protect against future attacks.</p>
<p>You now should be virus-free and good-to-go! Thank you for reading this post. If this helped you please leave a comment.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://techspeeder.com/2013/06/29/how-to-remove-the-fake-security-protection-virus/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">230</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 

Served from: techspeeder.com @ 2026-06-04 09:12:18 by W3 Total Cache
-->