PC Self Help Guides

How to Remove Vundo.GC free

[#: The article How to Remove Vundo.GC free is an article in Spyware Removal Instructions, the original author is egomoo .you can read more articles at Manual removal instructions> PC Self Help Guides> Removal Tools> Rogue Anti Spyware> Trojan> Virus,the next article:.#]

How to get rid of Vundo.GC or Trojan.Vundo.H using HijackThis

recently a greate number people have got lots of pop up ads witha very slow computer,it has infected Trojan.Vundo.H or Trojan Vundo.GC which was quite difficult to remove it. There are vundo.gc, pop ups, slow running system,or Vundo.GC removal help ,Trojan Horse Vundo. GC adn so on.


here are steps by HijackThis to manually remove Vundo.GC

1.The first step is to download HijackThis to your computer in a location that you know where to find it again. This program does not have an installation to it, so you need to remember where you downloaded it to in order to launch it in the future.

You can download HijackThis here: HijackThis Download Link

2.Once it is downloaded navigate through Windows Explorer or My Computer to the location your downloaded it to and double click on the icon for HijackThis.exe When it is launched the first time, you will see a screen similar to the figure below:

HijackThis Tutorial and Guide

Figure 1. HijackThis Startup screen when run for the first time

3.To have HijackThis scan your computer for possible Hijackers, click on the “Do a system Scan only ” button . You will then be presented with a screen listing all the items found by the program as seen in Figure 2.

HijackThis Tutorial and Guide
Figure 2. Scan Results

At this point, you will have a listing of all items found by HijackThis.

4. To find 8 Symptoms that may be in a HijackThis

mark it checked to remove as this is the spyware Vundo.GC key file.

Some examples:

O2 – BHO: (no name) – {46b9ebe6-63d8-4000-9111-8d9360b343d5} – C:\WINDOWS\system32\hufebido.dll
O4 – HKLM\..\Run: [wemohosego] Rundll32.exe “C:\WINDOWS\system32\roweyubo.dll”,s
O4 – HKLM\..\Run: [50e15a92] rundll32.exe “C:\WINDOWS\system32\zofemake.dll”,b
O4 – HKLM\..\Run: [CPM53d2690e] Rundll32.exe “c:\windows\system32\lasozozo.dll”,a
O20 – AppInit_DLLs: c:\windows\system32\wekewude.dll C:\WINDOWS\system32\rukowebi.dll
O20 – Winlogon Notify: avgrsstarter – C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 – SSODL: SSODL – {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} – c:\windows\system32\lasozozo.dll
O22 – SharedTaskScheduler: STS – {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} – c:\windows\system32\lasozozo.dll

another hijackthis log:

O2 – BHO: (no name) – {0ead6069-d2f3-4874-aa1a-77a05ee41b80} – C:\WINDOWS\system32\weziroze.dll
O4 – HKLM\..\Run: [wavoyesizu] Rundll32.exe “C:\WINDOWS\system32\wotifiri.dll”,s
O4 – HKLM\..\Run: [20ddfb3d] rundll32.exe “C:\WINDOWS\system32\yezedina.dll”,b
O4 – HKLM\..\Run: [CPM23eec8a1] Rundll32.exe “c:\windows\system32\fijapuna.dll”,a
O20 – AppInit_DLLs: C:\WINDOWS\system32\kuzezeve.dll c:\windows\system32\fijapuna.dll
O20 – Winlogon Notify: avgrsstarter – C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 – SSODL: SSODL – {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} – c:\windows\system32\fijapuna.dll
O22 – SharedTaskScheduler: STS – {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} – c:\windows\system32\fijapuna.dll

wohoo,you may find some in the same:

the first Symptom: O2 – BHO: (no name)” 8 letters random.dll file name

the second Symptom:” O4 – HKLM\..\Run: [random letters] Rundll32.exe 8 letters random.dll file name

the third and fourth are like second Symptom: O4 – HKLM\..\Run: [random letters] Rundll32.exe 8 letters random.dll file name” ,the last letter of the three Symptoms are “s,b,a”

the fifth: O20 – AppInit_DLLs:8 letters random.dll file name 8 letters random.dll file name

and then others:

O20 – Winlogon Notify: avgrsstarter – C:\WINDOWS\SYSTEM32\avgrsstx.dll
SSODL: SSODL 8 letters random.dll file name
O22 – SharedTaskScheduler:8 letters random.dll file name

HijackThis Tutorial and Guide

Figure 3. Select an item to Remove

5.using Malwarebytes’Anti-Malware to Remove other spyware ,if you don’t have one,here it is :Malwarebytes’ Anti-Malware Download Link

6.download Registry Easy for other Registry repairing, cleaning errors and problems to optimize your PC. It is an amazing program that I use!

good luck!

Technorati :
Del.icio.us :

Share/Save/Bookmark

Tags: , , , , , , , , , ,

How to get rid of FakeAlert-AB

Anti-virus-1 is a new rogue anti-spyware program from the same family as Antivirus 2010 and Antivirus 360.
Please note that all these programs are funded by the incorrect use of the same anti-spyware scanner. It was also known parasites Trojans (Zlob or Vundo) and other harmful programs. The main objective of the anti-virus-1 is, by the user of the computer with the purchase of the license.the trial version of anti-virus-1, the analysis and the list of false fake scan results from fear and pressure on the full version.

Even if the program is running, see the security as a ball, in the Windows taskbar.

143903a[1].gif

anti_virus_1-300x222[1].jpg

143903b[1].gif

Also shows one of the following warnings:

Windows Security Center
Windows Security Center reports that ‘XP antivirus’ is inable. Antivirus software helps to protect
your computer against viruses and other security threats. Click Recommendations
for the suggested actions. Your system might be at a risk now.

Privacy Violation alert!
XP antivirus detected Privacy Violation. Some program is secretly sending your private data to untrusted internet host. Click here to block this activity by removing threats (Recommended).

System files modification alert!
Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss. Click here to block unathorised modification by removing threats (Recommended).

Internal conflict alert!
XP antivirus detected internal software conflict. Some application tries to get access to system kernel (such behavior is typical to Spyware/Malware). It may cause crash of your computer. Click here to prevent system crash by removing threats (Recommended).

Spyware activity alert!
Spyware.IEMonster activity detected. It is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs, including logins and passwords from online banking sessions, eBay, PayPal. It may also create special tracking files to log your activity and compromise your Internet privacy. It’s strongly recommended to remove this threat as soon as possible. Click here to remove Spyware.IEMonster.

Automated Remove FakeAlert-AB using Malwarebytes’ Anti-Malware:

1.Malwarebytes' Anti-Malware Download Linkcookie,and it's free.

2.After installtion ,make sure update Malwarebytes' Anti-Malware and than make sure the Perform quick scan option is selected ,just click scan button.

MBAM
3.The scanning process may take quite a while, so I suggest you go and do something else or go to setp 4 first to cleaning Registry errors .After the scan is finished,a screenshot shows all the malicious programs found will be shown how has seen in the picture below. Remember that, the infections May vary, what is shown.You should now click on the Remove Selected button to remove all the listed malware.

trojanwin32fung




4.download Registry Easy for other Registry repairing, cleaning errors and problems to optimize your PC. It is an amazing program that I use!

good luck!


Share/Save/Bookmark

Tags: , , , , , , , , , ,


 Powered by Max Banner Ads