| DisableSpyware removal process |
|
| Author:admin CopyFrom:web Hits: UpdateTime:2008-5-23 15:30:03 |
Begin of the article DisableSpyware removal process
1.DownloadGoogle recommend safer browser Web browser, For more safe , Stay Secure on the Web and stay far away virus,Download URL http://www.oral8.net/firefox/firefox.htm
2. Temporarily Disable System Restore (Windows Me/XP).
3. Update the virus definitions. Reboot computer in SafeMode
4. Run a full system scan and clean/delete all DisableSpyware infected files and Delete/Modify any values added to the registry.
Navigate to the subkey and delete the valuesas following:
Behavior The program must be manually installed. It can be downloaded from the following location: DisableSpyware.com
The program reports false or exaggerated system security threats on the computer.
The user is then prompted to pay for a full license of the application in order to remove the errors.
Installation When the program is executed, it creates the following folder: %UserProfile%\Application Data\Microsoft\Installer
It also creates the following files:
- %UserProfile%\Desktop\Disable Spyware Demo.lnk
- %UserProfile%\Start Menu\Programs\Coding Elite Software\Disable Spyware Demo\Disable Spyware Demo.lnk
- %UserProfile%\Start Menu\Programs\Coding Elite Software\Disable Spyware Demo\DisableSpyware.com.url
- %UserProfile%\Start Menu\Programs\Coding Elite Software\Disable Spyware Demo\Readme-Help.lnk
- %UserProfile%\UserData\[RANDOM NAME]\[RANDOM NAME][1].xml
- %ProgramFiles%\Disable Spyware Demo\DisableSpywareDemo.exe
- %ProgramFiles%\Disable Spyware Demo\help.chm
- %ProgramFiles%\Disable Spyware Demo\Localization.txt
- %ProgramFiles%\Disable Spyware Demo\Localization.xml
- %ProgramFiles%\Disable Spyware Demo\riched32.dll
- %ProgramFiles%\Disable Spyware Demo\RunAtStartupTool.exe
- %Windìr%\Installer\[RANDOM NAME].msi
- %System%\actskn43.ocx
- %System%\Memman.vxd
- %System%\skinboxer43.dll
- %UserProfile%\Application Data\AntiSpywareDAT\BlockedCookies.dat
- %UserProfile%\Application Data\AntiSpywareDAT\date.dat
- %UserProfile%\Application Data\AntiSpywareDAT\DirectoryDefinition.dat
- %UserProfile%\Application Data\AntiSpywareDAT\ENoSignature.dat
- %UserProfile%\Application Data\AntiSpywareDAT\ExeDefinition.dat
- %UserProfile%\Application Data\AntiSpywareDAT\FileDefinition.dat
- %UserProfile%\Application Data\AntiSpywareDAT\RegistryDefinition.dat
- %UserProfile%\Application Data\AntiSpywareDAT\Safety.dat
- %UserProfile%\Application Data\AntiSpywareDAT\Scan_Log.txt
Next, the program creates the following registry entry/ies so that it executes whenever Windows starts:
It also creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Disable Spyware
- HKEY_LOCAL_MACHINE\SOFTWARE\Coding Elite
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2122F7FF-DF7B-4B6E-9E3B-19656320B2D2}
5. Exit registry editor .
6.delete the IE temp files or you may download ATF temp files cleaner to run a full cleaning.and restart the computer.
8. Now you may remove DisableSpyware successfully.
|
| howtoremoveInputer:admin Editor:admin |
| End Of The Article how to remove DisableSpyware |
|
Back 个howtoremove:Bloodhound.Exploit.192
Next 个howtoremove: Frethog AWB removal instruction |