Your best source of information and news about Vista hardware, winvista and hardware on the internet

April 15th, 2009

You are currently browsing the articles from MS Windows Vista Compatible Software written on April 15th, 2009.

Manual Removal of W32/Agent.BG Trojan

Manual Removal of W32/Agent.BG Trojan
W32/Agent.BG is a trojan. The trojan will infect Windows systems.
This trojan information updated on April 13, 2009.
Other names of W32/Agent.BG Trojan:
This trojan is also known as Infostealer, Trj/Spyforms.A, TSPY_SMALL.CLT .

Damage Level : Medium/High
Distribution Level:
Medium
No Removal Tool for W32/Agent.BG Trojan
W32/Agent.BG Trojan Manual Removal Instructions
Recommend Removal from Safe Mode:

How to Start in Safe mode:
Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.
The Infected Files Can be Seen in these folders and names also Running in Tasks
End the Following Active Process Before Removal
  • [ Kill the Process, Use Killbox if your Access Denied ]
Download W32/Agent.BG Trojan Known File Removal Tool

[In Windows Vista Run As Administrator, After Execution System Will Restart]

  • %Documents and Settings\Default User\Start Menu\Programs\Startup\userinit.exe
  • %Documents and Settings\Default User\svchost.exe
  • %Windows\System\Drivers\services.exe
  • %Windows\scvc.exe
  • %WINDOWS\new_drv.sys
  • %Windows\system32\cabpck.dll [ Hidden ]
  • %Windows\system32\krnlcab.sys [ Hidden ]
  • %Windows\system32\k86.bin
    [ No Exact Information about Files, search above related files in Program files Folder ]
    If you have any of these files in running process from task manger, end the process before removal.
    Note: if task manager is disabled, Download the following file, Click to Download - Enable Registry.reg [ Right Click - Save Target As/Linked Content As ]
    Open it with Regedit.exe [%system32\regedit.exe], then it Confirms Add to registry Yes or No, Confirm Yes, then click Ok.
W32/Agent.BG Trojan Entries Manual Removal From Registry
Click Start, Run,Type regedit,Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor.
  • Download this UnHookExec.inf, [ Right Click - Save Target As/Linked Content As ]
    and then continue with the removal. Save it to your Windows desktop. Do not run it at this time, download it only.
  • After booting into the Safe Mode or VGA Mode
  • Right-click the UnHookExec.inf file and click Install. [This is a small file. It does not display any notice or boxes when you run it.]
The W32/Agent.BG Trojan modifies registry at the following locations to ensure its automatic execution at every system startup:
Delete The Entries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
cabpck\Asynchronous: 0×00000001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
cabpck\DllName: “%WinDir%\System32\cabpck.dll”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
cabpck\Impersonate: 0×00000001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
cabpck\Startup: “cabpck”

Hkey_Current_User\Software\Microsoft\Windows\CurrentVersion\Run
ttool=”%WINDIR%\scvc.exe”
hkey_current_user\software\microsoft\inetdata
k1=(Random digits)
hkey_current_user\software\microsoft\inetdata
k2=(Random digits)

Delete file entry from right side
Search Registry For W32/Agent.BG Trojan File Names listed above to remove completely,
Edit Menu - Find
, enter Keyword and remove all value that find in search.

Exit the Registry Editor,
Restart your Computer.

Recommended Removal Tools:
Kaspersky Antivirus or Internet Security (Shareware)
Spyware Doctor (Shareware)
AVG Antivirus (Freeware)
Killbox (Freeware)
Ultimate Links PC Tips

Written by FireFly on April 15th, 2009 with no comments.
Read more articles on w32/agent and scvc.exe and W32/Agent.BG and Services.exe and svchosts.exe and otherSoftware and removal of trojan and manual removal and Windows.

The Joy of Unexpected Interactions…


Today I received a comment on my post from 2 days ago about KVM on Ubuntu. If you missed it, and are interested in virtualization, please go read it, and be sure to check out the comments.

I had a wonderfully unexpected interaction and discussion with a reader named Garry I’m a little strapped for time this evening, but I will continue to keep the blog updated as I learn more about KVM. I did want to take the time this evening to draw attention not to my post, but to his comments, and the excellent questions he posted. If you are interested in virtualization as we are, please post your comments and questions as well, as they will help shape my coming posts.

Some points from the discussion on the other thread that I will be covering here will include discussions around the advantages and disadvantages of KVM over some of the other widely available virtualization solutions including: Xen, VMWare, and VirtualBox.

There are a lot of great options out there that are available for free, so given the price is the same, how do you choose what is right for you?

Hopefully in the coming posts I can  help answer some of those questions for you. Like Garry, I encourage anyone to please comment, and comment in a way that sparks discussion and interaction - that is how we all learn! Make me think! Challenge what I say and together we can learn a lot.

Thanks again Garry, for reading and for posting!

Written by jaysonrowe on April 15th, 2009 with no comments.
Read more articles on otherSoftware and Computing.

Antivirus’09 (Antivirus09)

Description of Antivirus’09 and consequences of its residing on your PC

Antivirus’09 (Antivirus 09 or Antivirus09) is a program classified as a fake antispyware, because it even does not perform actual computer scan for viruses, adware, because it is advertised in annoying manner, and a crashware, because it disorders computer system. It may also be called a trojan due to the way of its downloading as undeclared attachment to files downloaded from Internet, usually free codec or media files.
Antivirus’09 is also advertised through the network of fake online scanners and so called official websites decorating Antivirus’09 with imaginary awards and describing its non-working features.  These websites are supported by many browser hijackers, which make web-browsers of infected computer systems to download websites dedicated to misleading programs like Antivirus’09.
All the trickeries by Antivirus’09 end up with the request to pay for its registration. However, even if a user pays just to get rid of Antivirus’09 repeating scan-show and alerts, Antivirus’09 removal is still needed, if the goal is to get rid of Antivirus’09 advertisements. The problem is that after registration, Antivirus’09 claims extending of the registration and updates in same annoying manner.
Details of  Antivirus’09 behavior are provided in the section below. If you are going to quit the trickery immediately, click here to start free scan and remove Antivirus’09 or please move down to Antivirus’09 manual removal  guidelines.

Antivirus’09 Technical Details

  • Full name: Antivirus’09, Antivirus09, Antivirus 09
  • Version: 2009
  • Type: Rogue anti-spyware
  • Origin: Russian Federation

Antivirus’09 screenshots:

Signs of being infected with Antivirus’09:

Antivirus’09 contains sub-programs responsible for system disordering. They are usually activated prior to those generating fake scan-show and alerts. Such observation leads to the conclusion that hackers’ design is to play some havoc with computer system before starting the advertisement campaign. Supposedly, the idea is to show the timely ads, which are more likely to be accepted by users.
Once installed, regardless of the way of its installation,  Antivirus’09 may remain quiet during several Windows sessions, before some program files are removed so that some programs report errors. However, copies of  Antivirus’09 that do not correspond to this pattern were found, therefore there is no rule in this description, just observation.
The advertisements by Antivirus’09 may be divided into scan and alerts popping up during and in relation to the scan, and other notifications. The scan is played within the nag screen of Antivirus’09, which appears as Windows has just warmed up. The scan is just a short movie with active objects accompanied with alerts invoking user to register this copy Antivirus’09. Alerts unrelated to the scan are displayed during all the time of computer operation. They are divided in two parts: those demanding user’s response to be closed and notifications just prompting to register Antivirus’09 or reporting the infected status of computer system etc. Alerts demanding response has corresponding buttons and may be disguised as Windows Security alerts. If a user does not respond, they remain and block other programs. If user leaves computer system turned on, the alerts are accumulated. Upon return, a user needs to close every alert generated for the period of uncontrolled system operation or reboot like at system freeze.
Click here to start free scan and remove Antivirus’09 which is  a heap of annoying ads and disordering programs establishing a system acting to the purpose of duping and luring users into buying the full version of the fake antispyware.

Automatic Removal of Antivirus’09 from your PC:

Antivirus’09 removal may be a complex task. Hence, complex removal tool is the best solution to remove Antivirus’09. Follow the link below to remove Antivirus’09 malware and get protected from its return and intervention of other rogue programs.

Download Antivirus’09 Removal Tool

Manual Removal of Antivirus’09:

You may remove Antivirus’09 adware manually. Other malware of Antivirus’09 like related backdoor downloader or browser hijacker, unfortunately, is variable and cannot be covered by manual removal instruction. If you still choose to remove Antivirus’09 manually, clicking the link above to start free scan is strongly recommended as you complete Antivirus’09 manual removal. The free scanner will reveal any other infections – if any, so that you may try to find relevant manual in the Internet or continue applying Spyware Doctor to remove them automatically.
Please, reboot and make sure there are no programs running and Internet connection is disabled before and during the process of Antivirus’09 manual removal. That will require you to have these instructions for Antivirus’09 removal printed out, because text editors are also not allowed to run.

Remove Antivirus’09 files and dll’s

AV2009.exe
AV2009_Update.exe
scanopt.sys
Support.url
sysdata.sys
SysShield.exe
Uninstall.exe
SysShield.exe
Antivirus 2009.lnk
Support.lnk
Uninstall Antivirus 2009.lnk
Antivirus 2009.lnk

Unregister Antivirus’09 registry values:

HKEY_CURRENT_USER\SOFTWARE\AVP09
HKEY_CURRENT_USER\SOFTWARE\AV2009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus 2009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform “AVP09″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Antivirus 2009″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Windows applications server”

Antivirus’09 Remover with free scan

Written by admin on April 15th, 2009 with no comments.
Read more articles on Antivirus’09 and Antivirus09 and Antivirus 09 remover and Antivirus’09 removal tool and Antivirus’09 remover and uninstall Antivirus’09 and remove Antivirus’09 and delete Antivirus’09 and Hijacker and Trojan horses and rogue anti-spyware and Adware and otherSoftware and spyware and Manual removal instructions and Spyware reviews and Removal tools and malware.

EPIC Technology Day

Winnipeg ~ On April 21st, 2009, local information technology company EPIC Information Solutions (EPIC) will unveil the latest version of its bi-annual conference, EPIC Technology Day, at the Victoria Inn on Wellington Avenue. Click here to register!

Written by magakos on April 15th, 2009 with no comments.
Read more articles on otherSoftware.

Additional Way to Disable IPv6 over all interfaces and prefer IPv4 to IPv6

Execute the following command through command line or script:

%windir%\system32\REG.EXE ADD HKEY_LOCAL_MACHINE\SYSTEM\
CurrentControlSet\Services\Tcpip6\Parameters /v DisabledComponents /t REG_DWORD /d 0xff /f

Thanks to Greg Stigers for this tip.

Written by magakos on April 15th, 2009 with no comments.
Read more articles on otherSoftware.

Acrylic Cowboy PC Case

Normally, PC owners would want their internal peripherals such as the processor, motherboard and the hard disks to be properly installed and hidden inside the traditional PC casing. However, this casing is somewhat different. Normally we would see the casings coming in the transparent casing but this Acrylic Cowboy PC case certainly goes way beyond that. It exposes the actual parts and surely allows you to see how your computer peripherals are functioning.

Forget sleek aluminum monoliths from Lian-Li or Antec: this is where minimalism is about more than just looking pretty. The Acrylic Cowboy, previously a hard to find oddity, is now available in the U.S. for $76. It holds ATX and Micro-ATX motherboards, power supplies, and peripherals.

Just enough to hold your Motherboard (ATX and Micro ATX), your Power Supply, HDD and ODD, these Acrylic PC Case are extremely popular among Japanese Geeks. With the strict minimum this new DC-ACPCDP/B, give you on top of the basic ATX / Micro ATX 2 LED and a power OFF/ON, a reset button and one holder to carry around your setting.

Source

Written by PC Freak on April 15th, 2009 with no comments.
Read more articles on cowboy and PC casing and Case Mods and otherSoftware and Desktops.

« Older articles

No newer articles