Friday 12 August 2011

Personal Shield Pro Removal - How To Remove


Personal Shield Pro is a bogus security software that just imitates real anti-virus scans and then report phony infections which actually doesn't exist on one's system. Personal Shield Pro enters in a disguised way to your computer, for example as a Video Codec or Security Update.  When you download the said video codec, Personal Shield Pro installs itself automatically as the installer file is not a video codec but a rogue software named Personal Shield Pro. There are many similar ways which are frequently used by scammers to trick naive consumers into downloading malicious software. These guys also make use of fake on-line scanners and cheat people by selling them a bogus anti-virus software.

Personal Shield Pro is from same tricksters who created System Tool and MS Removal Tools. Both these products literally infected millions of computer's worldwide and now since most anti-spyware products can detect the existence of System Tool and MS Removal tools, these guys changed their product name to Personal Shield Pro to avoid detection from genuine malware scanners. This game has been going on for quite some time now and there is no end in sight. Here is a screen shot of Personal Shield Pro malware doing a fake scan and reporting bogus infections:


Watch The Removal Video Below Before You Start!
1. First you'll be tricked into running a malicious installer file.
2. Once you run this installer file, nothing will happen and your computer will continue to run normally.
3. Next time, whenever you'll reboot your computer, Personal Shield Pro will activate itself and start scanning your computer.
Once this rogue software is up and running in your computer, it will display lots of fake warnings, system tray alerts and repeated messages urging you to purchase full version of the software. If you fall for this scam and use your credit card to pay for this software, your money will go to spammers and your credit card details will be exposed. You should never purchase such fake software at any cost.

Here is what Personal Shield Pro will do to protect itself on your computer:

1. It will block Task Manager and Registry Editor so that you cannot remove it.
2. It will block all other applications on your computer from running. Whenever you'll run an application, say MS Word, nothing will happen because MS Word (or any other application) will get terminated forcefully by Personal Shield Pro.
3. Your computer will slow down a lot and Personal Shield Pro will literally take over your computer.
4. It will also disable System Restore on your computer.

How To Remove Personal Shield Pro

Personal Shield Pro is very stubborn to go out from your computer. Since It blocks all antivirus applications, removing this rogue can be a real challenge for most people. I personally suggest two methods to remove the rogue software:

1. Automatic Removal

This method is the fastest one and it can help you to remove the rogue software very quickly. Since all antivirus products get blocked, I've found a rather unique way to kick out Personal Shield Pro from your computer by following these two simple steps.

A) I discovered that Personal Shield Pro blocks everything on your computer but doesn't block explorer.exe since it is a critical Windows Process. To end the rogue software, first you need to download Process Explorer

Once you click on above link, download will start but keep in mind that the file's name is procexp.exe. When you download this file, please save it as explorer.exe and then you'll be able to run it. See this video to know how I killed Personal Shield Pro and did its removal after that :

B) After ending the rogue software, Download Spyware Doctor immediately and conduct a full scan of your computer. Spyware Doctor will automatically detect Personal Shield Pro in your computer and will remove it automatically. On next reboot, your computer will be clean as always and start functioning normal again. This is the easiest and safest way to remove Personal Shield Pro without any additional headaches.


2. Manual Removal

Manual removing method is very confusing and suitable only for experienced computer users. Manual removal is actually not completely manual since you'll need to use some sort of utility to end the rogue software. If you are not able to terminate Personal Shield Pro, It won't let you run anything and thus manual removal can't help you. To remove the rogue manually, use Process Explorer to end the rogue software.

After that, please correct these registry entries using Registry Editor. (Run Registry Editor by clicking Start/Run, type "regedit" and click OK button)

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[RANDOM]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM].exe"
HKEY_CURRENT_USER\Software\[RANDOM]

After correcting the registry entries, please find and delete these files from your computer. The rogue software uses a random filename which is different for each computer and for this reason; it is not possible to outline the exact filename here.
[random].exe in hard drive
%Temp%\[RANDOM]
%Documents and Settings%\All Users\Desktop\Personal Shield Pro.lnk

After removing above files, your computer should be virus free.  Please keep in mind that manual removal method is prone to mistakes and can have negative effect on your computer. Like your computer may stop working completely or traces of virus may be left on your computer. This is the reason why automatic removal method is highly used and recommended even by experts.

Tuesday 9 August 2011

Zentom System Guard Removal - How To Remove

Zentom System Guard is a fake software and It is from the same family as Antimalware Doctor. This program gets into your computer via fake Windows update alert and unsuspecting users install this update and Zentom System Guard gets installed in their computer.


Once installed, It will show you all sorts of fake alerts and numerous security pop-ups. It will show up as Zentom System Guard Upgrade and the update number is KB904067. This is fake and this update is not coming from Microsoft but from hackers who want to take control over your computer. Once Zentom System Guard virus gets inside your computer, It will do fake scan and show many threats in your computer while in reality, none of the reported threats actually exist on your computer. Here is a screen shot of Zentom System Guard doing a fake scan and showing bogus results just to scare you :


Zentom System Guard will continue to scan your computer without your permission and continue to show many alerts via task bar :

Trojan.Spy threat has been detected.
Warning! Removed attack detected!
Warning! Threat detected!
Network intrusion detected!
Warning! Network attack detected!


All the security alerts shown by this software are fake and you shouldn't pay any attention to these alerts. Such alerts usually pop-up in system tray but you should just close them and do nothing else.



If you have paid for this software in good faith, give a phone call to your credit card company and explain this fraud to them and get your money back. This fake program doesn't offer any value and you should remove it from your computer before it does more harm. Read the steps below to remove Zentom System Guard quickly and easily.

How To Remove Zentom System Guard

A) Automatic Removal Method 

This method is the best one to remove Zentom System Guard from your computer. You'll need to download a genuine spyware remover, scan your computer and then get rid of the infection. Genuine spyware remover products are programmed to detect rogue products and they can easily identify this Zentom System Guard and remove it completely without any problem.


After removing Zentom System Guard, make sure to always have active Spyware Protection on your computer so that threats can be caught before they get installed in your computer and actually damage it.

B) Manual Removal Of Zentom System Guard

Manual removal of Zentom System guard is not easy and since the rogue tend to block some essential programs on your computer, you don't get access to the tools which can help you remove the rogue.


If you are a computer geek and believe that you can conduct manual removal of Zentom System Guard, you can follow these steps : 

1. 
First of all, please identify and end the virus process using Task Manager. Press Alt+CTRL+Delete buttons on your keyboard to access Task Manager. If task manager is blocked, download Process Explorer utility from Microsoft's website. Process Explorer works exactly as Task Manager.


Download Process Explorer and end active process of Zentom System Guard.
2. Now run Registry Editor and repair these registry entries which were manipulated by the rogue software. If you don't know what you need to change in these entries, please don't do that and use automatic removal method instead. You can run registry editor by clicking on Start/Run, type "regedit" and click OK :

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zentom System Guard
HKEY_CURRENT_USER\Software\ZentomSystemGuard
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "<random file name here>.exe" 

 
3. 
Browse this folder and remove all the malicious files. Just for your information, Application data is the folder where most rogue products keep their executable files and dll files. Browse this folder and delete all suspicious files.



C:\Documents and settings\All users\Local Settings\Application Data



You also need to remove Zenton System Guard's registry entry from startup programs list. For that, click on Start/Run, type "msconfig" and edit the startup programs list. 

Please keep in mind that while manual removal can be very effective method to get rid of Zentom System Guard, you should always scan your computer with a genuine Spyware Remover software. It is very likely that manual removal will always leave traces of the rogue on your computer which can be harmful and virus can return back to your machine. 

Tuesday 2 August 2011

Security Protection Removal - How To Guide

Security Protection is a fake product just created to trick you into thinking that your computer is seriously infected with multiple threats. This software is not created by a software company but a group of hackers who are doing this to extort money from average computer users who are not aware of such shady tricks.

Security Protection virus enters in your computer in a stealth way and in most cases, computer users download this program themselves thinking It is something useful. When they double click on the installer file, Security Protection malware appears on the screen and now you need to do a lot of exercise to repair your computer. A screen shot of Security Protection :


When Security Protection malware is active in your computer, It blocks everything you try to run. If you run Task Manager, Security Protection will close it forcefully and show a message saying that Task Manager is infected. This message is not true but this rogue software is blocking everything so that you can not remove it.

Security Protection will do everything It can to stop you from finding a remedy to this problem. The only hope for you is Safe Mode of Windows and this is what you need to do to remove security protection from your computer. Read the instructions below to know how to get rid of security protection easily.

How To Remove Security Protection


Removing Security Protection is not easy as it will not give you a chance.  It will block everything on your computer and won't let you access the Internet. Just think that when you can't access anything on your computer, how will you remove security protection? Don't worry and try following these steps :

1. Remove Security Protection using a Spyware Remover 

If you are not a computer expert and can't deal with fake software yourself, you should download a genuine Spyware Remover to get rid of security protection. Spyware Doctor is capable of removing this software automatically and you need to follow these steps :

A) Boot up your PC in "Safe Mode With Networking".
B) Access the Internet and download Spyware Doctor.
C) Do a Full Scan of your computer and remove all the infections.

You can download Spyware Doctor by clicking the button below :


Spyware Doctor is a very powerful software and will remove the rogue quickly and very easily. Using a Spyware Remover will save you lots of time and headaches. Your computer will return back to normal in no time.

Spyware Doctor will not only remove security protection malware but also scan your computer for thousands of possible threats. It is very likely that lots of threats will get caught on your computer and you'll get surprised and shocked like never before.

2.Remove Security Protection Manually

If you consider yourself a computer expert, you can try to remove security protection manually. Removing security protection manually can be really tough and If you don't know what you are doing, you may damage your computer even further.

When you follow manual removal method, please make sure that :

1. You don't delete system files otherwise you can be in deep trouble.
2. Edit the Registry very carefully as It is heart of Windows.
3. Unregister all DLL files carefully.
4. Remove all executable files related to rogue software.

Run Registry Editor (Click Start/Run, type "regedit" and click OK) and delete these registry entries :

HKEY_CURRENT_USER\Software\Security Protection
HKEY_CLASSES_ROOT\BrcWizApp.BrcWiz
HKEY_CLASSES_ROOT\BrcWizApp.BrcWiz.1
HKEY_CLASSES_ROOT\CLSID\{80c10400-59cb-4c79-97ce-cc693103afca}
HKEY_CLASSES_ROOT\Interface\{4B66E1DF-4DE3-4CDA-83B5-11673EADAB0B}
HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKEY_CLASSES_ROOT\TypeLib\{58B4E0F5-F122-4C02-B038-C482D998486A}
HKEY_CURRENT_USER\Software\Microsoft “adver_id” = “29?
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe;”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Security Protection”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “rundll32? = “”
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell” = “%UserProfile%\Application Data\defender.exe” /sn”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “EnableLUA” = “0?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “rundll32? = “”

Delete These Malicious files from your computer (Search For Infected Files using Windows Search Utility and Delete Them)

%Documents and Settings%\[User Name]\asr.dat
%Documents and Settings%\[User Name]\Application Data\1tmp.bat
%Documents and Settings%\[User Name]\Application Data\defender.exe
%Documents and Settings%\[User Name]\Application Data\scan.dll
%Documents and Settings%\[User Name]\Application Data\[random].tmp

If you follow manual removal steps carefully, you should be above to get rid of security protection quickly and easily. If manual removal steps are ineffective, go for automatic removal method as results are completely guaranteed.