Tuesday, March 24, 2009

How to remove Yourstabilitysystem.com hijacker

Malware Description:

Yourstabilitysystem.com is yet another one of the numerous hijackers trying to pimp the System Security rogue anti-spyware. Yourstabilitysystem.com is known to use illicit techniques to provide income to the fraudsters who developed System Security scam. These misleading tactics involve the use of Trojan viruses that drop into the compromised computer aiming to attack the web browser. Once inside and acting, the Trojans modify browser configuration and therefore provide hits to Yourstabilitysystem.com. The malicious website under described here looks as if it were the My Computer interface with a system scan running there. The popup warnings and scanners you get on Yourstabilitysystem.com are fake. They report infections that either do not exist or have hardly anything to do with your computer. You may have predicted by now that System Security will be the featured spyware remover promoted on Yourstabilitysystem.com to prevent the above-mentioned “detections” from spreading inside your system. It’s critical to acknowledge that Yourstabilitysystem.com is a hijacker developed by hackers to trick people into purchasing System Security rogue. So stay away from both of them to keep your PC safe. If detected, you should immediately remove Yourstabilitysystem.com hijacker.

How to remove Yourstabilitysystem.com hijacker manually:

Manual removal of Yourstabilitysystem.com hijacker and attendant malware is feasible if you have sufficient expertise in dealing with program files, system processes, .dll files and registry entries.

The associated files to be deleted are listed below:

%\Documents and Settings%\All Users\Application Data\538654387
%\Documents and Settings%\All Users\Application Data\538654387\Languages
%\Documents and Settings%\All Users\Application Data\538654387\1632575944.exe
%\Documents and Settings%\All Users\Application Data\538654387\config.udb
%\Documents and Settings%\All Users\Application Data\538654387\init.udb
%\Documents and Settings%\All Users\Application Data\538654387\Languages\English.lng
%\Documents and Settings%\All Users\Application Data\538654387\Languages\German.lng
%\Documents and Settings%\All Users\Application Data\538654387\Languages\Spanish.lng
%UserProfile%\Desktop\System Security.lnk
%UserProfile%\Start Menu\Programs\System Security
%UserProfile%\Start Menu\Programs\System Security\System Security.lnk

The related registry entries to be removed are as follows:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “1632575944″

No comments:

Post a Comment