|
Free virus removal tool for SoftStronghold (SoftStronghold.exe)
|
|
Written by Administrator |
Saturday, 21 November 2009 17:08
|
|
SoftStronghold is another fake Antivirus that install itself on your computer. Once installed, it tries to trick you into buying the full version, that doesn't even exist, because the one you have is just a shareware. It shows you fake alert, don’t worry about that; I’m sure the only malware in your system is SoftStronghold.

To remove SoftStronghold from you system
- Download the free removal tool
- Extract
- Run
- Click on the delete button
After running the patch, your homepage Internet Explorer becomes search.net-studio.org, done deliberately to erase all traces of then malware, BHOs (Browser Helper Object) are also deleted. You can always restore this setting in Internet Explorer options.
- %Temp%\[RANDOM CHARACTERS].tmp.exe
- %system32%\2069sz5mbot179.dll
- %WINDOWS%\system32\205z0sp95ad.exe
- %WINDOWS%\system32\20151worm9z4.ocx
- %WINDOWS%\10520hac5too979z.bin
- %WINDOWS%\1045ztroj92a.ocx
- %WINDOWS%\10246h9zktool4d5.exe
- %ProgramFiles%\SoftStronghold Software\SoftStronghold\uninstall.exe
- %Programs%\SoftStronghold
- %Desktop%\SoftStronghold.lnk
- %ProgramFiles%\SoftStronghold Software\SoftStronghold\SoftStronghold.exe
- %ProgramFiles%\SoftStronghold Software\SoftStronghold
- %ProgramFiles%\SoftStronghold Software
- %Programs%\SoftStronghold\1 SoftStronghold.lnk
- %Programs%\SoftStronghold\3 Uninstall.lnk
- %Programs%\SoftStronghold\2 Homepage.lnk
- [RANDOM CHARACTERS].tmp.exe
- [RANDOM CHARACTERS].exe
- SoftStronghold.exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].tmp.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\SoftStronghold
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftStronghold
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SoftStronghold"
- HKEY_CURRENT_USER\Software\SoftStronghold

|