Been infected with spyware? Tell us about your problem.
For fast automatic spyware removal, try CounterSpy, SUPERAntiSpyware

XLGuarder - fresh rogue antispyware | How to remove

XLGuarder is a rogue antispyware. The program uses scare tactics (such as pop-ups and fake system notifications), infects systems via misleading advertising on free download, warez and porn websites, trojans and browser security holes. XLGuarder put popups looks like a Microsoft Security Center screen.

rogue antispyware

HijackThis shows infections:

O2 - BHO: (no name) - {D032570A-5F63-4812-A094-87D007C23012} -

How to remove xlguarder and xlg security center:
Go to Start > Control Panel > Add or Remove Programs and remove the XLGuarder.

Download Avenger and unzip to your desktop.

Open notepad and copy/paste the text in the quotebox below into it:

Windows Registry Editor Version 5.00

[HKEY_ALL_USERS\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\]
“Shell”=-
[-HKEY_ALL_USERS\Software\sysutils]
[-HKEY_CLASSES_ROOT\CLSID\{D032570A-5F63-4812-A094-87D007C23012}]
[-HKEY_CLASSES_ROOT\iebho.TIEAdvBHO]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D032570A-5F63-4812-A094-87D007C23012}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sysutils]

Save this as fix.reg to your Desktop (remember to select Save as file type: All files in Notepad.).
Double-click on the fix.reg. When it asks if you would like to merge the information, press the Yes button and then the OK button when it is done.

Run Avenger, copy,then paste the following text in Input script Box:

Files to delete:
%Windir%\iebho.dll
%Windir%\sysutils\settings.ini
%Windir%\sysutils\sounds\01.wav
%Windir%\sysutils\sounds\02.wav
%Windir%\sysutils\sounds\03.wav
%Windir%\sysutils\sysutil.exe
%Windir%\sysutils\sysutil_s.exe
%Windir%\sysutils\uninstall.exe
%Windir%\sysutils\warning\alertpage.jpg
%Windir%\sysutils\warning\spacer.gif
%Windir%\sysutils\warning\warningpage.html
%Windir%\sysutils\winsystip.exe
%UserProfile%\Start Menu\Programs\Protection\Uninstall XLG.lnk

Then click on ‘Execute’.

Your computer will be reloaded.

If you are still having problems with your PC after completing these instructions, then I would recommend you follow these instructions - How to use Spyware Removal Forum .

July 24, 2008 on 6:55 am | In Rogue Anti Spyware, Spyware protection and removal, Tutorials - HowTo | No Comments |
Submit to: Digg | SlashDot | Del.icio.us

VirusRemover2008 - fake antispyware | How to remove

VirusRemover2008 is a rogue antispyware. Usuallly, rogue antispyware infects systems via misleading advertising on free download, warez and porn websites, trojans and browser security holes. VirusRemover2008 reports false or exaggerated system security threats on the computer. The user is then prompted to pay for a full license of the application in order to remove the errors.

virusremover2008 rogue antispyware

Hijackthis shows infection

O4 - HKLM\..\Run: [VirusRemover2008] C:\Program Files\VirusRemover2008\VRM2008.exe


How to remove VirusRemover2008

  • Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.
  • Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select “Perform Quick Scan”, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

If you are still having problems, then please follow the steps: How to use Spyware Removal Forum.

July 22, 2008 on 8:43 pm | In Rogue Anti Spyware, Spyware protection and removal, Tutorials - HowTo | 2 Comments |
Submit to: Digg | SlashDot | Del.icio.us

Fresh rogue antispyware: WistaAntivirus, WinDefender, SpywareScanner2008

Found new fake/rogue antispyware tools: WistaAntivirus, WinDefender, SpywareScanner2008.
These programs uses scare tactics (such as pop-ups and fake system notifications), infects systems via misleading advertising on free download, warez and porn websites, trojans and browser security holes.

WistaAntivirus

WistaAntivirus reports false or exaggerated system security threats on the computer.

Viruses have been detected!
Spyware has been detected at your PC!
Last scan with Wista Antispyware has
detected the traces of infections.

The user is then prompted to pay for a full license of the application in order to remove the errors.

Hijackthis shows infection:

O4 - HKLM\..\Run: [wistaantivirus] C:\Program Files\WistaAntivirus\wistaantivirus.exe

WinDefender
rogue antispyware

Hijackthis shows infection:

O4 - HKLM\..\Run: [WinDefender 2008] C:\Program Files\WinDefender 2008\WDefDemo.exe

SpywareScanner2008
rogue antispyware

Hijackthis shows infection:

O4 - HKLM\..\Run: [spywarescanner] C:\Program Files\SpywareScanner\spywarescanner.exe

How to remove rogue antispyware:
I would recommend that you follow the instructions - how to use Spyware Removal Forum and post your logs in the spyware removal forum. I will check your logs and advise you on rogue antispyware removal.

July 7, 2008 on 7:26 am | In Rogue Anti Spyware | No Comments |
Submit to: Digg | SlashDot | Del.icio.us


MY ANTI SPYWARE Powered by WordPress with Pool theme design by Borja Fernandez.
Entries and comments feeds. Valid XHTML and CSS. ^Top^