Wednesday, June 15, 2011

Windows Stability Alarm Removal Guide

Windows Stability Alarm Removal Guide
Windows Stability Alarm is a fake antivirus program which try to make money from the users of infected computers. Windows Stability Alarm display fake warnings and scans the computers that return false results only to urge the users to buy the full version of Windows Stability Alarm. Windows Stability Alarm claims that it can remove computer viruses, spyware or other types of malware if the users buy the full version of Windows Stability Alarm. Don't be cheated by what it has claimed as all of them is a lie! Windows Stability Alarm blocks the running of other programs to intimidate targeted computer users into thinking that their systems are corrupted with malware.

Windows Stability Alarm can be removed first by stopping its processes and then kill its files by using Emsisoft HiJackFree. Then the user has to remove all the related files and folder. Finally, restore the registry entries added and modified by Windows Stability Alarm (Read the removal guide below to remove Windows Stability Alarm successfully).

Windows Stability Alarm should be removed immediately!


Windows Stability Alarm Removal Guide
Read How to remove virus effectively before following the guide below.
Kill Process
[random].exe
all process which has the name of Windows Stability Alarm.

Delete Registry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "DisableSR " = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'

Remove Folders and Files
all files stated in the autorun settings.
%UserProfile%\Application Data\[random].exe
%UserProfile%\Application Data\Microsoft\[random].exe

No comments:

Post a Comment