Security Archives

Make Sure to Follow all steps exactly below.

STEP 1: Download the Antispyware Tool Below

free download spyware doctor

STEP 2: Download the Following two Registry Fix Files

Enable-Task-Manager.reg
Enable-Executables.reg

STEP 3: Read ALL Details Below

If you see a window pop-up like the picture below, it means that you are infected with the Windows Police Pro virus, and this is not good at all!!! Read more details below to learn how to Remove Windows Police Pro both manually and automatically.

As you can see from the picture above, Windows Police Pro looks like a legitimate antivirus software, but this is not true. It is a rogue program that claims to be genuine antivirus software in order to convince the computer user to purchase it. Of course, if you fall in the trap and pay for it, you will just lose your money because Windows Police Pro is a virus itself. For a free scan of your system to verify if you are indeed infected with Windows Police Pro, download the Antispyware tool that I mention in Step1 above, install it and perform a full system scan. If you are unable to run the Antispyware tool I suggest, Download and run also the two Registry Fix Files that I mention in Step 2 above. More Details in the Automatic Removal section below.

If you got infected with this pesky malware, it will block your PC from running various windows legitimate programs stating that they are infected with viruses and thus you can not execute them. Furthermore, various bogus windows warnings and system alerts will start showing up stating that your computer is under attack and that you should purchase Windows Police Pro to fix your system.

You MUST take action immediately to get rid of this scam parasite as soon as possible. You can remove Windows Police Pro either manually or automatically (recommended). Manual removal requires you to be expert in computers and is not recommended since you have to delete entries in the Registry or delete files under “Program Files” folder which makes it kind of dangerous if you don’t know what you are doing. Anyhow, read below for both methods of removing Windows Police Pro permanently.

Remove Windows Police Pro Automatically (Recommended)

Since Windows Police Pro will not allow you to run any programs on your PC and also will disable your task manager, you need to download the following two files and save them on your desktop.

Enable-Task-Manager.reg
Enable-Executables.reg

First double click on the first file (Enable-Task-Manager.reg) and press YES when it asks you to merge the data into your current registry. After you do that, you will be able to start the Task Manager as following:

Press Start + R and then type “taskmgr” and press Enter. This will open the Task Manager window. Put a checkmark on “Show processes from all users”. Then go to “Processes” tab and find the process WindowsPolicePro.exe. Right click on it and select “End Process”. Using the same procedure, stop also the following processes (some processes might not be present on your own system):

svchast.exe or svchasts.exe
ANTI_files.exe
dbsinit.exe
minix32.exe

After you terminate the processes, you need to enable again the ability to execute windows programs on your computer. Double click on the second file that you downloaded above (Enable-Executables.reg) and select YES when it asks you to merge the data into your current registry. After you do that, you will be able to run antispyware tools to clean the infection as described below.

To safely remove Windows Police Pro and any remnants of it, or any other malware and viruses residing on your computer, I would recommend to Download the Free Trial of Spyware Doctor Here, or visit the Spyware Doctor Website for more information. If you have already downloaded and installed the Spyware Doctor in Step 1 at the beginning of this guide then you can skip this step.

free download spyware doctor

You can download the free version of Spyware Doctor and perform a system scan. Spyware Doctor free version is for spyware detection only. If the computer scan confirmed that you are infected, you can register the full version of Spyware Doctor to remove Windows Police Pro permanently.

Remove Windows Police Pro Manually

The following steps are not guaranteed to always work and we take no responsibility for any computer damage. You should proceed only if you know what you are doing. Backup your registry first before proceeding by going to Start>Run>regedit and then File>Export to save the registry.

Step1: Stop Windows Police Pro Processes
Press Start + R and then type “taskmgr” and press Enter. This will open the Task Manager window. Put a checkmark on “Show processes from all users”. Then go to “Processes” tab and find the process WindowsPolicePro.exe. Right click on it and select “End Process”. Using the same procedure, stop also the following processes (some processes might not be present on your own system):

svchast.exe or svchasts.exe
ANTI_files.exe
dbsinit.exe
minix32.exe

Step2: Delete the following Registry Values
Press Start + R and then type “regedit” and press Enter. Delete the following registry keys: (Your system might not contain all the registry keys shown below)

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “minix32″
HKEY_CURRENT_USER\SOFTWARE\Windows Police Pro
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win Police Pro
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\antippro2009_100

Step3: Delete the following files and folders
c:\WINDOWS\system32\dddesot.dll
c:\WINDOWS\system32\desote.exe

Delete the following folder with all files inside the folder:

c:\program files\windows police pro\

Delete also the following:

%UserProfile%\start menu\Programs\windows police pro\Windows Police Pro.lnk
%UserProfile%\Desktop\Windows Police Pro.lnk
c:\WINDOWS\svchasts.exe

How to Remove Antivirus 2009

Downloading free videos or other freeware or pirated software programs is a common activity of internet users, but unfortunately it carries its own risks related to computer security. Usually those freeware programs come bundled with hidden trojan viruses and other malware that get installed on your computer together with the freeware software without noticing. This is the main method that computer users get infected with the Antivirus 2009 malware. Another common infection method of Antivirus 2009 is by visiting warez or adult websites which usually host those kind of rogue antivirus programs. For a Free Scan of your computer to verify if you are infected with Antivirus 2009, download the Antispyware tool below.

free download spyware doctor

So what is actually Antivirus 2009? It is a rogue antivirus program which is categorized as “scareware” malware because it scares users to purchase the program by generating fake virus alarm messages. It is a successor of the older Antivirus 2008 which infected millions of computers worldwide. Basically Antivirus 2009 is a virus itself. After infecting your computer it will start generating fake alerts and system warning messages claiming that your computer is compromised from numerous viruses and spyware. It might also perform a fake scan of your computer and present you with false results showing infections from various viruses. Then the program will keep asking you to purchase the full version of it so that to remove all “viruses and spyware” from your system. Of course, if you fall in the trap and pay the asked fee, you will just lose your money because Antivirus 2009 is just a scam.

Moreover, Antivirus 2009 hijacks your internet explorer settings and also infects several parts of your system causing computer slowness and system crashes. It sometimes installs other spyware scripts on your PC with the intention to steal personal information such as passwords, credit card numbers etc. If you are a victim of this scam, then you need to take action and remove Antivirus 2009 immediately. A picture of Antivirus 2009 is shown below:

There are two ways to remove Antivirus 2009. You can get rid of Antivirus 2009 either manually or automatically (recommended). Manual removal requires you to be expert in computers and is not recommended since you have to delete entries in the Registry or delete files under “Program Files” and “System32″ folders which makes it kind of dangerous if you don’t know what you are doing. Anyhow, read below for both methods of removing Antivirus 2009 once and for all.

Remove Personal Antivirus Automatically (Recommended)

To safely remove Antivirus 2009 or any other malware and viruses residing on your computer, I would recommend to Download the Free Trial of Spyware Doctor Here, or visit the Spyware Doctor Website for more information.

free download spyware doctor

Spyware Doctor has been used to successfully remove Antivirus 2009 from millions of computers. After Downloading Spyware Doctor, run it and have it scan your PC for free. The free version of Spyware Doctor is for malware detection only. After detecting Antivirus 2009, you can purchase the full version to automatically clean up your PC from Antivirus 2009 or from any other possible malware hiding in your system.

Remove Personal Antivirus Manually
Before proceeding any further, I suggest you to backup everything and especially your computer registry. You need to know what you are doing before manually removing Antivirus 2009. Another thing to keep in mind is that scanning your computer with your currently installed antivirus program will most probably fail since most antivirus programs do not detect Antivirus 2009. You need a dedicated Antispyware program as the one I suggested in the Automatic Removal section above. Anyway, read below for the manual removal steps.

Step1: Stop the following processes

Antivirus2009.exe
AV2009Install.exe
av2009.exe
av2009[1].exe
Note: Some of the processes mentioned above might not be present in your system

Step2: Delete the following Registry entries

First backup your registry before proceeding. Some of the following registry keys might be different in your system.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Antivirus” = “%ProgramFiles%\Antivirus 2009\Antvrs.exe”
HKEY_CURRENT_USER\Software\Antivirus
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run\15358943642955870504508370025739
HKEY_CURRENT_USER\Software\75319611769193918898704537500611
HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “75319611769193918898704537500611″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “ieupdate”
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus

Step3: Delete the following files and folders

%UserProfile%\Desktop\Antivirus 2009.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\S96PZM7V\winsrc[1].dll
%UserProfile%\Start Menu\Antivirus 2009
%UserProfile%\Start Menu\Antivirus 2009\Antivirus 2009.lnk
%UserProfile%\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk
c:\Program Files\Antivirus 2009
c:\Program Files\Antivirus 2009\av2009.exe
c:\WINDOWS\system32\ieupdates.exe
c:\WINDOWS\system32\scui.cpl
c:\WINDOWS\system32\winsrc.dll
C:\Program Files\Antivirus 2009

Another member of the so called “scareware” viruses is the “Personal Antivirus” malware which infected millions of computers worldwide. The Personal Antivirus is a fake antivirus application which gets installed on user’s computers usually when they download warez software from peer-to-peer networks or when they visit malicious websites. Personal Antivirus is categorized as scareware because it generates fake and misleading alert messages warning the user that their computer is “infected” with hundreds of viruses in order to scare the user and make him/her to purchase the scareware program. Ofcourse, after purchasing Personal Antivirus, hoping that it will clean all your “viruses”, you just lose your money simply because Personal Antivirus is just not a real Antivirus. For a Free Scan of your computer to verify if you are infected with Personal Antivirus, download the Antispyware tool below.

free download spyware doctor

Even worse, the program is a virus itself. It installs keyloggers and other spyware programs on your PC to steal sensitive information such as passwords, credit card numbers etc. It also infects your browser settings to redirect you to websites promoting the malware in order to convince you to buy it. So, when you see the following image popping up on your screen, you MUST take action immediately to remove Personal Antivirus program from your computer.

Now, you can remove Personal Antivirus either manually or automatically (recommended). Manual removal requires you to be expert in computers and is not recommended since you have to delete entries in the Registry or delete files under “Program Files” folder which makes it kind of dangerous if you don’t know what you are doing. Anyhow, read below for both methods of removing personal antivirus permanently.

Remove Personal Antivirus Automatically (Recommended)

To safely remove Personal Antivirus or any other malware and viruses residing on your computer, I would recommend to Download the Free Trial of Spyware Doctor Here, or visit the Spyware Doctor Website for more information.

free download spyware doctor

After Downloading Spyware Doctor, run it and have it scan your PC for free. The free version of Spyware Doctor is for malware detection only. After detecting Personal Antivirus, you can purchase the full version to automatically clean up your PC from any malware including Personal Antivirus.

Remove Personal Antivirus Manually

Before proceeding any further, I suggest you to backup everything and especially your computer registry. You need to know what you are doing before manually removing Personal Antivirus:

Step1: Stop the following processes

unins000.exe
PerAvir.exe
pav.exe
winlogon.exe
services.exe
iv.exe
PersonalAv.exe

Note: Some of the processes mentioned above might not be the same in your case

Step2: Remove the following Registry Entries

You must back up your registry first.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer “PrS”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Personal Antivirus”

Step3: Remove the following Files

PersonalAv.exe
c:\Documents and Settings\All Users\Desktop\Personal Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
%UserProfile%\Application Data\Personal Antivirus
%UserProfile%\Application Data\Personal Antivirus\settings.ini
%UserProfile%\Application Data\Personal Antivirus\uill.ini
%UserProfile%\Application Data\Personal Antivirus\unins000.exe
%UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
%UserProfile%\Application Data\Personal Antivirus\db
%UserProfile%\Application Data\Personal Antivirus\db\config.cfg
%UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
%UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
c:\Program Files\Personal Antivirus
c:\Program Files\Personal Antivirus\activate.ico
c:\Program Files\Personal Antivirus\Explorer.ico
c:\Program Files\Personal Antivirus\PerAvir.exe
c:\Program Files\Personal Antivirus\unins000.dat
c:\Program Files\Personal Antivirus\uninstall.ico
c:\Program Files\Personal Antivirus\working.log
c:\Program Files\Personal Antivirus\db
c:\Program Files\Personal Antivirus\db\DBInfo.ver
c:\Program Files\Personal Antivirus\db\ia080614.db
c:\Program Files\Personal Antivirus\db\ia080618x.db
c:\Program Files\Personal Antivirus\Languages
c:\Program Files\Personal Antivirus\Languages\IAEs.lng
c:\Program Files\Personal Antivirus\Languages\IAFr.lng
c:\Program Files\Personal Antivirus\Languages\IAGer.lng
c:\Program Files\Personal Antivirus\Languages\IAIt.lng
c:\WINDOWS\system32\log.txt
%UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe

I bet you must have been in the situation where you downloaded a file from the Internet or maybe you found a suspicious file on your computer and you want to verify if it contains a virus or malware in it. Well, you could of course scan it with your locally installed antivirus software, but this is not enough anymore. Even if your installed antivirus finds the file as clean, this does not mean it actually is. Newer malware and virus scripts can encrypt and hide themselves such that many antivirus programs can not detect them. Fortunately there are a couple of online “Multiple Antivirus Engine” websites which allow you to upload a file and have it scanned with several antivirus programs (for FREE) to verify if the file is safe or not.

  1. VirusTotal (http://www.virustotal.com/)
  2. This is the most popular online “multiple antivirus engine” site. Taken from the website itself, “VirusTotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines“.

    The website uses several command line versions of antivirus programs to scan your uploaded file for any kind of malware. The signatures of the antivirus engines are updated regularly. The uploaded file is scanned from 39 different antivirus engines including AVG, ClamAV, Comodo, ESET NOD32, F-Secure, McAfee, Kaspersky, Microsoft, Panda, Sophos, Symantec, TrendMicro etc.

    After scanning, the website will give you a report from each antivirus engine whether the uploaded file was found clean or not.

  3. VirScan (http://www.virscan.org/)

 This is similar with the above. It has an upload file limit of 20Mb. Taken from the website itself, “VirSCAN.org is a FREE on-line scan service, which checks uploaded files for malware, using antivirus engines, indicated in the VirSCAN list“.

The site scans your uploaded file with 37 different antivirus engines including the most popular ones (same as those in VirusTotal website).

Have those websites in mind before installing any program that you have downloaded from the Internet.

Information security is not a technology problem. It is an economic problem and in order to improve information security we will have to correct the economic problem first. Let’s do this and all others will follow.

The lack of security in computer software products costs us billions. We pay tons of money in information theft, financial theft etc. We pay lots of money when productivity is lost, when networks stop working and when dozens of other major or minor problems of security arise in our work and home environments. We have also major financial losses when we are forced to pay and buy security products and services to reduce all those information security issues. We pay for the security year after year.

The problem is that all the money we spend does not solve the problem. We pay, but still end up with security holes. The problem is BAD and INSECURE SOFTWARE. Due to bad software coding practices, poor software embedded features, inadequate software testing and security weaknesses in software programming cause all the problems with information security. The money we spend on security are intended to address the consequences of unsafe software.

That is the actual problem. We don’t pay to actually improve the security of the underlying software. We pay to temporarily cope with the problem and not to correct it. The only way to correct the problem of security is to convince the vendors to correct their software by incorporating proper secure software coding techniques. The only way to convince the software vendors to develop secure software is to force them to take up the costs and responsibility of security breaches and holes in their product.

There are many parties involved in a typical software attack. There is the company that originally sold the software with the security weakness, the person who created the tool of attack, the attacker himself that used the tool to break into the network, the network operator, who had been assigned to protect the network etc. 100 percent of the responsibility of an attack should not be borne by the vendor of the software, but it should be shared among all the parties including the attacker or the network operator. But these days, 100% of the cost goes solely to the owner of the network and this should stop happening.

Liability changes everything. At present, there is no reason for a software company not to offer one feature after another after another. Liability in security however will force software companies to better reflect a change of a software characteristic or feature. Liability forces companies to protect the data on which they are responsible. Liability means that those who are able to correct the problem, are also responsible for the problem. Software vendors should therefore have liability on the security of their software product.

The information security is not a technological problem. It is an economic problem and to improve information technology we will have to correct the economic problem first. Let’s do this and all others will follow.

 Page 4 of 5 « 1  2  3  4  5 »