|
Free removal tool for Advanced PC Shield 2012
|
|
Written by Administrator |
Saturday, 01 October 2011 18:15
|
|
Advanced PC Shield 2012 is a another rogue Antispyware, it's a malware that pretends to be an Antivirus. Advanced PC Shield 2012 conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Advanced PC Shield 2012. Advanced PC Shield 2012 invites you to purchase a license to remove malware, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall Advanced PC Shield 2012 immediately from your system.

To remove Advanced PC Shield 2012 (Uninstall Advanced PC Shield 2012)
- Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
- Choose Start computer in SAFE MODE with network support
- Open Internet Explorer
- Go to Tools => Internet Options => Connections Tab => LAN Settings
- Uncheck "Use a proxy server"
- Recheck "Automatically detect settings"
- Download this free removal tool for Advanced PC Shield 2012
- Extract it
- Launch
- Click on the delete button
Advanced PC Shield 2012 will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :
Files :
- %Programs%\Advanced PC Shield 2012
- %Desktop%\Buy Advanced PC Shield 2012.lnk
- %Programs%\Advanced PC Shield 2012\Buy Advanced PC Shield 2012.lnk
- %Programs%\Advanced PC Shield 2012\Launch Advanced PC Shield 2012.lnk
- %System%\drivers\[random].sys
- %AppData%\[random].exe
- %Temp%\VGX1.tmp
- ...
- %Temp%\VGX8.tmp
Registry
- HKEY_CURRENT_USER\Software\Advanced PC Shield 2012
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
- [random]= "%AppData%\[random]\[random].exe"
Registry keys created
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_1ADA0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_1ADA0\0000
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_1ADA0\0000\Control
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_[Random]
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_[Random]\0000
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_[Random]\0000\Control
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\[Random]
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_1ADA0
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_1ADA0\0000
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_1ADA0\0000\Control
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[Random]
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[Random]\0000
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[Random]\0000\Control
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[Random]
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1
One of the hundres of values created
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- [random].exe = "%AppData%\[random].exe"

Remove Advanced PC Shield 2012 Software manually :
- Restart your computer in safe mode :
- Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
- Choose Start computer in SAFE MODE
- Open the infected account
- Open explorer, paste into the address bar the text %Temp% then press enter, it will open C:\Documents and Settings\Christian\Local Settings\Temp on my computer
- Remove all .exe files and all random folders under this path
- Open explorer, paste into the address bar the text %AppData% then press enter, it will open C:\Documents and Settings\Christian\Local Settings\Application Data on my computer
- Remove all .exe files and all random folders under this path
- Remove Advanced PC Shield 2012.lnk from your desktop
- Remove Advanced PC Shield 2012.lnk from your start menu
- Click on the start menu button then click on run
- Type msconfig and press enter
- Go to the Startup tab
- Uncheck all random character keys in it and click on the OK button
- Restart your computer in normal mode
This will solve the problem but you can run the removal tool to remove the other registry keys and values.
|