There is a new form of ransomware also called crapware or scareware that is now infecting computer systems. This particular variant appears to be aimed at Microsoft Windows 7 systems. The infection exploits a weakness in Sun Java. As of this writing, this particular variant is not detected by all antivirus applications possibly because the infection is a simple registry hijack.
Win 7 Security 2012 performs the following:
Removal of Win 7 Security 2012 is actually quite simple. Following are the steps:
http://www.smartnetadmin.com
Win 7 Security 2012 performs the following:
- Disables and corrupts existing antivirus application.
- Installs fake antivirus application.
- Prompts for credit card number.
- Takes control of Windows GUI.
- Prevents execution of any application ending in EXE.
- Prevents System Restore.
Removal of Win 7 Security 2012 is actually quite simple. Following are the steps:
- Reboot.
- Hit F8 repeatedly.
- Select Safe Mode and hit Enter.
- Hit CTRL-ALT-DEL and End Task on any three-letter application. Example: tpq.exe
- Quickly browse to C:\Users\[Username]\AppData\Local.
- Delete any three-letter applications in this directory. Example: tpq.exe. You must act quickly in order to delete the three-letter application as the system will attempt to re-open the application which prevents its deletion. If you have not moved quickly enough, simply perform End Task again and then immediately delete the application.
- Install Ccleaner. Run Ccleaner.
- Install Malwarebytes Anti-Malware.
- Browse to C:\Program Files\Malwarebytes' Anti-Malware.
- Copy mbam.exe. Paste mbam.exe.
- Rename Copy of mbam.exe to Copy of mbam.com.
- Run Malwarebytes Anti-Malware. Remove all found instances of malware.
- When prompted, click Yes to restart computer.
- Create a new file entitled: fix.reg
- Copy and paste the following text into fix.reg:
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"
[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
[HKEY_CLASSES_ROOT\exefile]
@="Application"
"EditFlags"=hex:38,07,00,00
"FriendlyTypeName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,\
00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,\
32,00,5c,00,73,00,68,00,65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,\
00,2c,00,2d,00,31,00,30,00,31,00,35,00,36,00,00,00
[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"
[HKEY_CLASSES_ROOT\exefile\shell]
[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00
[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile\shell\runas]
"HasLUAShield"=""
[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile\shell\runasuser]
@="@shell32.dll,-50944"
"Extended"=""
"SuppressionPolicyEx"="{F211AA05-D4DF-4370-A2A0-9F19C09756A7}"
[HKEY_CLASSES_ROOT\exefile\shell\runasuser\command]
"DelegateExecute"="{ea72d00e-4960-42fa-ba92-7792a7944c1d}"
[HKEY_CLASSES_ROOT\exefile\shellex]
[HKEY_CLASSES_ROOT\exefile\shellex\ContextMenuHandlers]
@="Compatibility"
[HKEY_CLASSES_ROOT\exefile\shellex\ContextMenuHandlers\Compatibility]
@="{1d27f844-3a1f-4410-85ac-14651078412d}"
[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"
[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers]
[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps]
@="{86F19A00-42A0-1069-A2E9-08002B30309D}"
[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]
@="C:\Program Files\Mozilla Firefox\firefox.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command]
@="C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
@="C:\Program Files\Internet Explorer\iexplore.exe"
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\UserChoice]
[-HKEY_CURRENT_USER\Software\Classes\.exe]
[-HKEY_CURRENT_USER\Software\Classes\pezfile]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command] - Double-click fix.reg
- Reboot.
- Using Programs and Features, uninstall your antivirus application.
- Reinstall your antivirus application.
http://www.smartnetadmin.com
Comments
Post a Comment