Removal Tools
Moderators: Moderator, Global Moderator
Removal Tools
This is Microsofts release of the Sasser worm fix Here

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Removal Tools
A small utility for removing CoolWebSearch (aka CoolWWWSearch, YouFindAll, White-Pages.ws and its variants.)
Spybot S&D has been found to miss some parts of the CWS trojan, so use this tool to make sure you zap them all. Remember to check the application for updates often.
Variants:
CWS.Datanotary
CWS.Bootconf
CWS.Oslogo
CWS.Msspi
CWS.Vrape
CWS.Oemsyspnp
CWS.Svchost32
CWS.Dnsrelay
CWS.Msinfo
CWS.Ctfmon32
CWS.Tapicfg
CWS.Svcinit
CWS.Msoffice
CWS.Dreplace
CWS.Mupdate
CWS.Addclass
CWS.Googlems
CWS.Xplugin
CWS.Alfasearch
CWS.Loadbat
CWS.Qttasks
CWS.Msconfd
CWS.Therealsearch
CWS.Control
CWS.Olehelp
CWS.Smartsearch
CWS.Yexe
CWS.Gonnasearch
CWS.Smartfinder
CWS.Winproc32
CWS.Msconfig
CWS.Xxxvideo
CWS.Winres
CWS.Xmlmimefilter
CWS.Aboutblank
CWS.Systeminit
CWS.Sounddrv
CWS.Searchx
CWS.Realyellowpage
Affiliate variants:
CWS.Aff.iedll
CWS.Aff.Winshow
CWS.Aff.Madfinder
CWS.Aff.Tooncomics
This tool will find and destroy all traces of the CoolWebSearch (CWS) hijacker on your system, including the following:
· Redirections to CoolWebSearch related pages
· Redirections when mistyping URLs
· Redirections when visiting Google
· Enormous IE slowdowns when typing
· IE start page/search page changing on reboot
· Sites in the IE Trusted Zone you didn't add
· Popups in Google and Yahoo when searching
· Errors at startup mentioning WIN.INI or IEDLL.EXE
· Unable to change or see certain items in IE Options
· Unable to access IE Options at all
There is a variant of the Coolwebsearch trojan spreading that closes several anti-spyware applications when you try to open them. If you are experiencing this problem, download PepiMK's CoolWWWSearch.SmartKiller removal tool and run it. (SmartKiller is also available in Downloads"
After you run SmartKiller, CWShredder and HijackThis will run properly (as will all other removal tools.)
Shredder
SmartKiller Download
Spybot S&D has been found to miss some parts of the CWS trojan, so use this tool to make sure you zap them all. Remember to check the application for updates often.
Variants:
CWS.Datanotary
CWS.Bootconf
CWS.Oslogo
CWS.Msspi
CWS.Vrape
CWS.Oemsyspnp
CWS.Svchost32
CWS.Dnsrelay
CWS.Msinfo
CWS.Ctfmon32
CWS.Tapicfg
CWS.Svcinit
CWS.Msoffice
CWS.Dreplace
CWS.Mupdate
CWS.Addclass
CWS.Googlems
CWS.Xplugin
CWS.Alfasearch
CWS.Loadbat
CWS.Qttasks
CWS.Msconfd
CWS.Therealsearch
CWS.Control
CWS.Olehelp
CWS.Smartsearch
CWS.Yexe
CWS.Gonnasearch
CWS.Smartfinder
CWS.Winproc32
CWS.Msconfig
CWS.Xxxvideo
CWS.Winres
CWS.Xmlmimefilter
CWS.Aboutblank
CWS.Systeminit
CWS.Sounddrv
CWS.Searchx
CWS.Realyellowpage
Affiliate variants:
CWS.Aff.iedll
CWS.Aff.Winshow
CWS.Aff.Madfinder
CWS.Aff.Tooncomics
This tool will find and destroy all traces of the CoolWebSearch (CWS) hijacker on your system, including the following:
· Redirections to CoolWebSearch related pages
· Redirections when mistyping URLs
· Redirections when visiting Google
· Enormous IE slowdowns when typing
· IE start page/search page changing on reboot
· Sites in the IE Trusted Zone you didn't add
· Popups in Google and Yahoo when searching
· Errors at startup mentioning WIN.INI or IEDLL.EXE
· Unable to change or see certain items in IE Options
· Unable to access IE Options at all
There is a variant of the Coolwebsearch trojan spreading that closes several anti-spyware applications when you try to open them. If you are experiencing this problem, download PepiMK's CoolWWWSearch.SmartKiller removal tool and run it. (SmartKiller is also available in Downloads"
After you run SmartKiller, CWShredder and HijackThis will run properly (as will all other removal tools.)
Shredder
SmartKiller Download

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Removal Tools
iSearch Removal
Written By: Melissa Martin
Description:
Isearch Toolbar is a downloaded 'helper' addition for Internet Explorer and installs directly on your web browser.
How do you get it?
The Isearch Toolbar is provided by isearch.com which is actually owned by iDownload.com, based at 701 Brazos, Suite 500, Austin, Texas 78701. It can be installed by downloading the toolbar from the iSearch site. It is also suspected that iSearch can be downloaded and installed on your PC without consent by using a known exploit in the Microsoft Operating System. Once downloaded iSearch also installs 180Search Assistant, another advertising program on your PC. Together, these programs serve to deliver a variety of intrusive advertisements such as numerous popup ads and new browser windows.
Details:
The Isearch Toolbar is a 'Browser Helper Object' meaning that it will load whenever Internet Explorer starts, shares its memory and performs actions in any available windows. It can also detect events, create windows to display additional information on a viewed page, monitor messages and actions.
ISearch made headlines on May 20,2004 when thousands of PC's were hijacked to the iSearch homepage prompting a story by ABC News.
"iSearch works something like this: Some time during the course of surfing the Web, you unknowingly trip over the iSearch applet, which is instantly downloaded — without your knowing it — into your computer.
This program then does two things: 1) It orders your computer to permanently switch to .iSearch.com as your new home page, and 2) Covers its tracks, so that you can't simply go into your computer's utilities and replace it. You are now trapped. "
Although iSearch provides removal instructions on site, several users have experienced substantial difficulty both removing it and turning it off. A user from the DesignTechnica forums indicated that when clicking View>Toolbars the iSearch toolbar was shaded out rendering it impossible to turn it off. It has also become apparent that some automatic removal tools will not remove all of the scummy components of iSearch, crippling the toolbar options menu in Internet Explorer. There are some additional removal instructions provided by Wilders Security Forums if you are experiencing this problem.
ISearch has also been known to close popular Spyware removal tools such as AdAware before starting and even disables programs such as Spybot.
Isearch offers the following information in their Terms of Service:
<img src=\'http://www.killanet.net/forum3/public/s ... shades.gif\' class=\'bbc_emoticon\' alt=\'B)\' /> Licensee shall receive, and desires to so receive, various product/services, marketing ads, and campaigns of third parties through the appearance of links, menus, pop-ups, and other methods on and/or in connection with the Service and the Software (all of the foregoing "Third Party Promotions").
IN NO EVENT SHALL ISEARCH OR ITS LICENSORS OR SUPPLIERS BE LIABLE TO LICENSEE OR ANY THIRD PARTY FOR ANY UNAVAILABILITY, DELAYS, INACCURACIES, ERRORS OR OMISSIONS WITH RESPECT TO ANY OF THE CONTENT (AS DEFINED ABOVE) USED RECEIVED OR TRANSMITTED BY THE SOFTWARE AND/OR SERVICE, OR FOR ANY DAMAGE ARISING THEREFROM OR OCCASIONED THEREBY, OR FOR THE RESULTS OBTAINED FROM THE USE OF SUCH CONTENT INCLUDING WITHOUT LIMITATION ANY RISK OF THE INTRODUCTION OF COMPUTER VIRUSES, INVASION OF PRIVACY, VIOLATION OF APPLCABLE LAW OR ANY PERSON OR ENTITY'S RIGHTS OF WHATEVER TYPE.
How does it Violate Privacy?
To display an advertisement to a user both iSearch and 180Search Assistant matches the keywords entered with an advertiser. The site that is visited and the keywords that are entered can be tracked by cookies. Although both programs indicate in their respective privacy policies they do not share or retrieve personally identifiable information, the value of the policy itself is questionable. (Especially with iSearch which has been known to install without consent).
Are there any known security issues?
Hidden within their TOS, iSearch explicitly outlines that they aren't responsible for viruses or invasion of privacy in any way.
Stability problems:
iSearch specifically outlines the following clause in their TOS:
The Software and the Service is in a pre-release beta state only and may contain errors or inaccuracies that could cause failures, loss of data, and/or conflicts or problems resulting from the use and/or operation of other software installed on your computer or which you may wish to install in the future, whether used separately or in conjunction with the Software.
Terminating iSearch:
If you choose to click the 'Uninstall' link for iSearch, you'll be in for a scummy little suprise. ISearch offers the 'uninstall' program for sale at $29.95. Manual removal seems to be the only remedy to solve the iSearch problem properly. (I shudder at actually funding a scumware company in any possible way). Both of the following removal instructions are posted on the iSearch and 180 Search sites respectively. It may be necessary to run a program such as "Hijack This" to remove all files properly.
Click on "Start > Run" from the menu that appears.
Type "Command" (without the quotes) in the "Run" dialog.
In the new window that has appeared:
•If you are using Windows XP, type "cd c:\windows\system32" (without the quotes) and press the "Enter" key.
•If you are using Windows 95/98/ME, type "cd c:\windows\system" (without the quotes) and press the "Enter" key.
•If you are using Windows 2000 or Windows NT, type "cd c:\winnt\system32" (without the quotes) and press the "Enter" key.
If you have installed Windows on a different drive (e.g. d:) or directory (e.g. c:\windows2) then you will need to type the appropriate drive letter and/or directory above.
In the same window
•If you are using Windows 95/98/ME , type "regsvr /u /s toolbar.dll" (without the quotes) and press the "Enter" key.
•If you are using Windows NT/2000/XP , type "regsvr32 /u /s toolbar.dll" (without the quotes) and press the "Enter" key.
In the same window type "del toolbar.dll" (without the quotes) and press the "Enter" key.
In the same window type "exit" (without the quotes) and press the "Enter" key.
Removing 180Search Assistant:
You may uninstall via the Add/Remove Programs in the Start Menu
Click on the Start Menu
Under Settings select Control Panel
Select Add or Remove Programs
Click on Uninstall 180search Assistant (If you are running an older version of our software, this will be named PAD Lookups by N-Case)
Select Remove and follow instructions until prompted with "You have successfully uninstalled 180search Assistant"
Source
Written By: Melissa Martin
Description:
Isearch Toolbar is a downloaded 'helper' addition for Internet Explorer and installs directly on your web browser.
How do you get it?
The Isearch Toolbar is provided by isearch.com which is actually owned by iDownload.com, based at 701 Brazos, Suite 500, Austin, Texas 78701. It can be installed by downloading the toolbar from the iSearch site. It is also suspected that iSearch can be downloaded and installed on your PC without consent by using a known exploit in the Microsoft Operating System. Once downloaded iSearch also installs 180Search Assistant, another advertising program on your PC. Together, these programs serve to deliver a variety of intrusive advertisements such as numerous popup ads and new browser windows.
Details:
The Isearch Toolbar is a 'Browser Helper Object' meaning that it will load whenever Internet Explorer starts, shares its memory and performs actions in any available windows. It can also detect events, create windows to display additional information on a viewed page, monitor messages and actions.
ISearch made headlines on May 20,2004 when thousands of PC's were hijacked to the iSearch homepage prompting a story by ABC News.
"iSearch works something like this: Some time during the course of surfing the Web, you unknowingly trip over the iSearch applet, which is instantly downloaded — without your knowing it — into your computer.
This program then does two things: 1) It orders your computer to permanently switch to .iSearch.com as your new home page, and 2) Covers its tracks, so that you can't simply go into your computer's utilities and replace it. You are now trapped. "
Although iSearch provides removal instructions on site, several users have experienced substantial difficulty both removing it and turning it off. A user from the DesignTechnica forums indicated that when clicking View>Toolbars the iSearch toolbar was shaded out rendering it impossible to turn it off. It has also become apparent that some automatic removal tools will not remove all of the scummy components of iSearch, crippling the toolbar options menu in Internet Explorer. There are some additional removal instructions provided by Wilders Security Forums if you are experiencing this problem.
ISearch has also been known to close popular Spyware removal tools such as AdAware before starting and even disables programs such as Spybot.
Isearch offers the following information in their Terms of Service:
<img src=\'http://www.killanet.net/forum3/public/s ... shades.gif\' class=\'bbc_emoticon\' alt=\'B)\' /> Licensee shall receive, and desires to so receive, various product/services, marketing ads, and campaigns of third parties through the appearance of links, menus, pop-ups, and other methods on and/or in connection with the Service and the Software (all of the foregoing "Third Party Promotions").
IN NO EVENT SHALL ISEARCH OR ITS LICENSORS OR SUPPLIERS BE LIABLE TO LICENSEE OR ANY THIRD PARTY FOR ANY UNAVAILABILITY, DELAYS, INACCURACIES, ERRORS OR OMISSIONS WITH RESPECT TO ANY OF THE CONTENT (AS DEFINED ABOVE) USED RECEIVED OR TRANSMITTED BY THE SOFTWARE AND/OR SERVICE, OR FOR ANY DAMAGE ARISING THEREFROM OR OCCASIONED THEREBY, OR FOR THE RESULTS OBTAINED FROM THE USE OF SUCH CONTENT INCLUDING WITHOUT LIMITATION ANY RISK OF THE INTRODUCTION OF COMPUTER VIRUSES, INVASION OF PRIVACY, VIOLATION OF APPLCABLE LAW OR ANY PERSON OR ENTITY'S RIGHTS OF WHATEVER TYPE.
How does it Violate Privacy?
To display an advertisement to a user both iSearch and 180Search Assistant matches the keywords entered with an advertiser. The site that is visited and the keywords that are entered can be tracked by cookies. Although both programs indicate in their respective privacy policies they do not share or retrieve personally identifiable information, the value of the policy itself is questionable. (Especially with iSearch which has been known to install without consent).
Are there any known security issues?
Hidden within their TOS, iSearch explicitly outlines that they aren't responsible for viruses or invasion of privacy in any way.
Stability problems:
iSearch specifically outlines the following clause in their TOS:
The Software and the Service is in a pre-release beta state only and may contain errors or inaccuracies that could cause failures, loss of data, and/or conflicts or problems resulting from the use and/or operation of other software installed on your computer or which you may wish to install in the future, whether used separately or in conjunction with the Software.
Terminating iSearch:
If you choose to click the 'Uninstall' link for iSearch, you'll be in for a scummy little suprise. ISearch offers the 'uninstall' program for sale at $29.95. Manual removal seems to be the only remedy to solve the iSearch problem properly. (I shudder at actually funding a scumware company in any possible way). Both of the following removal instructions are posted on the iSearch and 180 Search sites respectively. It may be necessary to run a program such as "Hijack This" to remove all files properly.
Click on "Start > Run" from the menu that appears.
Type "Command" (without the quotes) in the "Run" dialog.
In the new window that has appeared:
•If you are using Windows XP, type "cd c:\windows\system32" (without the quotes) and press the "Enter" key.
•If you are using Windows 95/98/ME, type "cd c:\windows\system" (without the quotes) and press the "Enter" key.
•If you are using Windows 2000 or Windows NT, type "cd c:\winnt\system32" (without the quotes) and press the "Enter" key.
If you have installed Windows on a different drive (e.g. d:) or directory (e.g. c:\windows2) then you will need to type the appropriate drive letter and/or directory above.
In the same window
•If you are using Windows 95/98/ME , type "regsvr /u /s toolbar.dll" (without the quotes) and press the "Enter" key.
•If you are using Windows NT/2000/XP , type "regsvr32 /u /s toolbar.dll" (without the quotes) and press the "Enter" key.
In the same window type "del toolbar.dll" (without the quotes) and press the "Enter" key.
In the same window type "exit" (without the quotes) and press the "Enter" key.
Removing 180Search Assistant:
You may uninstall via the Add/Remove Programs in the Start Menu
Click on the Start Menu
Under Settings select Control Panel
Select Add or Remove Programs
Click on Uninstall 180search Assistant (If you are running an older version of our software, this will be named PAD Lookups by N-Case)
Select Remove and follow instructions until prompted with "You have successfully uninstalled 180search Assistant"
Source

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Removal Tools
TurboDriver, IEDriver, PopUp Killer
Written By Melissa Martin
Description:
TurboDownload is also known as both PopUp Killer and IE Driver. It displays contextual advertising to the end user, installs software and services and self-updates silently.
IEDriver is bundled with UrlBlaze.
How do you get it?
TurboDownload is bundled with a program called URLBlaze and can also be distributed through any one of their affiliate sites: MP3 MTV, MP3 Media World, and Clustone. It is downloaded from the company website and installed on the users home computer.
Note: I've had an email from the folks at Unite the Cows who were unaware that they were listed as an affiliate at URLBlaze. To that end, I'm not sure if the other sites listed as affiliates are aware of it either. Please let me know if further corrections need to be made by contacting me through the forum's PM system. Sinoed .
Details:
TurboDownload and its variants deliver contextual advertising to the end user. It is displayed on your PC based on a profile it builds about your surfing habits. This means that it collects information from your computer while you browse the internet. It can also detect events, create windows to display additional information on a viewed page, monitor messages and actions. This program even offers the following information about its purpose on your computer, including installing programs without your consent and silently self -updating:
"We may modestly deliver highly relevant offers in many ways including but not limited to the following:
- Embedded offers are displayed within some applications.
- Desktop icons and installation files may be placed on your computer that link to other products and services.
- Modest interstitial windows are displayed on your computer desktop."
There are many exploits of this technology which search all pages you view in IE and replace banner advertisements with other ads, monitor and report on your actions, etc.
How does it Violate Privacy?
To display an advertisement to a user the program matches the keywords entered with an advertiser. The site that is visited and the keywords that are entered can be tracked with cookies. Further, there is no privacy policy on the URL Blaze site, explaining the further use and/or distribution of the information that they collect although it does state some of the other less desirable traits in the EULA.
Are there any known security issues?
TurboDownoad is capable of automatically self-updating silently, installing software programs and services and collecting personal information about your surfing habits.
Stability problems:
None known at this time.
Terminating TurboDownload:
TurboDownload (IEDriver) is known to contain the following files: IEDriver.exe, IEUpdate.exe, IEDriver.bin, iedclean.exe, td.exe, uninstall.exe
Click on START > RUN and type "regedit". Click "OK" to start the registry editor.Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Using the directory tree browse to the key:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
In the right pane, delete the value called IEDriver, if it exists.
Exit the registry editor and restart your computer.
Locate the "IEDriver" directory on your computer, it can usually be found with your system directory followed by \IEDriver\
Delete this folder and its contents.
TurboDownload (IEDriver) can also be removed with both Pest Patrol and Adaware.
Source
Written By Melissa Martin
Description:
TurboDownload is also known as both PopUp Killer and IE Driver. It displays contextual advertising to the end user, installs software and services and self-updates silently.
IEDriver is bundled with UrlBlaze.
How do you get it?
TurboDownload is bundled with a program called URLBlaze and can also be distributed through any one of their affiliate sites: MP3 MTV, MP3 Media World, and Clustone. It is downloaded from the company website and installed on the users home computer.
Note: I've had an email from the folks at Unite the Cows who were unaware that they were listed as an affiliate at URLBlaze. To that end, I'm not sure if the other sites listed as affiliates are aware of it either. Please let me know if further corrections need to be made by contacting me through the forum's PM system. Sinoed .
Details:
TurboDownload and its variants deliver contextual advertising to the end user. It is displayed on your PC based on a profile it builds about your surfing habits. This means that it collects information from your computer while you browse the internet. It can also detect events, create windows to display additional information on a viewed page, monitor messages and actions. This program even offers the following information about its purpose on your computer, including installing programs without your consent and silently self -updating:
"We may modestly deliver highly relevant offers in many ways including but not limited to the following:
- Embedded offers are displayed within some applications.
- Desktop icons and installation files may be placed on your computer that link to other products and services.
- Modest interstitial windows are displayed on your computer desktop."
There are many exploits of this technology which search all pages you view in IE and replace banner advertisements with other ads, monitor and report on your actions, etc.
How does it Violate Privacy?
To display an advertisement to a user the program matches the keywords entered with an advertiser. The site that is visited and the keywords that are entered can be tracked with cookies. Further, there is no privacy policy on the URL Blaze site, explaining the further use and/or distribution of the information that they collect although it does state some of the other less desirable traits in the EULA.
Are there any known security issues?
TurboDownoad is capable of automatically self-updating silently, installing software programs and services and collecting personal information about your surfing habits.
Stability problems:
None known at this time.
Terminating TurboDownload:
TurboDownload (IEDriver) is known to contain the following files: IEDriver.exe, IEUpdate.exe, IEDriver.bin, iedclean.exe, td.exe, uninstall.exe
Click on START > RUN and type "regedit". Click "OK" to start the registry editor.Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Using the directory tree browse to the key:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
In the right pane, delete the value called IEDriver, if it exists.
Exit the registry editor and restart your computer.
Locate the "IEDriver" directory on your computer, it can usually be found with your system directory followed by \IEDriver\
Delete this folder and its contents.
TurboDownload (IEDriver) can also be removed with both Pest Patrol and Adaware.
Source

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Removal Tools
Removing a Trojan Horse
Trojans often modify the startup files of your computer, add or change lines in the system registry and even overwrite system files to make sure they are run every time you boot up. For that reason, removing them by hand takes time, patience and an understanding of what you are doing. It's fraught with dangers, including trashing your registry or loosing the ability to run programs so it's definatly not for everyone - even those who know exactly what they are doing often prefer to use automated tools when removing a trojan horse.
Each trojan has it's own specific removal routine, see the Cleaners & Fixes pages for details on those. They do however all conform to the same basic patterns : They usually insert a line in the run, run once or run services keys in the system registry. This is the principal startup method of most trojans including Back Orifice & Sub7.
Removing the line from the registry and rebooting usually stops the trojan loading. Some alter Win.ini, system.ini or plae themselves in the 'Startup' folder. Again, removing the offending line usually stops the trojan running. Some alter or replace system files. These need careful handling and are best left to experts or automated tools. One in particular can modify a certain setting in the registry, causing it to be executed before ANY program you run. removing this line stops you running ANYTHING!
Again, this is best left to experts or automated tools to deal with. The steps involved in removing a trojan are simple : Identify the trojan horse file on your hard disk. Find out how it is being started and take the necessary action to prevent it being restarted after a reboot. Reboot your machine and delete the trojan horse.
[url=\"http://www.jaddo.net/forums/index.php?showtutorial=235\"]Jaddo.net[/url]
Trojans often modify the startup files of your computer, add or change lines in the system registry and even overwrite system files to make sure they are run every time you boot up. For that reason, removing them by hand takes time, patience and an understanding of what you are doing. It's fraught with dangers, including trashing your registry or loosing the ability to run programs so it's definatly not for everyone - even those who know exactly what they are doing often prefer to use automated tools when removing a trojan horse.
Each trojan has it's own specific removal routine, see the Cleaners & Fixes pages for details on those. They do however all conform to the same basic patterns : They usually insert a line in the run, run once or run services keys in the system registry. This is the principal startup method of most trojans including Back Orifice & Sub7.
Removing the line from the registry and rebooting usually stops the trojan loading. Some alter Win.ini, system.ini or plae themselves in the 'Startup' folder. Again, removing the offending line usually stops the trojan running. Some alter or replace system files. These need careful handling and are best left to experts or automated tools. One in particular can modify a certain setting in the registry, causing it to be executed before ANY program you run. removing this line stops you running ANYTHING!
Again, this is best left to experts or automated tools to deal with. The steps involved in removing a trojan are simple : Identify the trojan horse file on your hard disk. Find out how it is being started and take the necessary action to prevent it being restarted after a reboot. Reboot your machine and delete the trojan horse.
[url=\"http://www.jaddo.net/forums/index.php?showtutorial=235\"]Jaddo.net[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Removal Tools
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom@mm.removal.tool.html\"]W32.MyDoom.M Removal Tool[/url]
[url=\"http://securityresponse.symantec.com/avcenter/tools.list.html\"]Symantec Removal Tools[/url]
[url=\"http://us.mcafee.com/virusInfo/default.asp?id=vrt\"]McAfee Removal Tools[/url]
[url=\"http://www.sophos.com/support/disinfection/\"]Sophos Removal Tools[/url]
[url=\"http://www.grisoft.com/us/us_ts_removers.php\"]Grisoft (AVG) Removal Tools[/url]
[url=\"http://www.pandasoftware.com/download/utilities/\"]Panda Removal Tools[/url]
[url=\"http://www.bitdefender.com/html/free_tools.php\"]Bitdefender Removal Tools[/url]
[url=\"http://www.virusall.com/downrem.html\"]Virusall Removal Tools[/url]
[url=\"http://www.f-secure.com/download-purchase/tools.shtml\"]F-Secure Removal Tools[/url]
[url=\"http://securityresponse.symantec.com/avcenter/tools.list.html\"]Symantec Removal Tools[/url]
[url=\"http://us.mcafee.com/virusInfo/default.asp?id=vrt\"]McAfee Removal Tools[/url]
[url=\"http://www.sophos.com/support/disinfection/\"]Sophos Removal Tools[/url]
[url=\"http://www.grisoft.com/us/us_ts_removers.php\"]Grisoft (AVG) Removal Tools[/url]
[url=\"http://www.pandasoftware.com/download/utilities/\"]Panda Removal Tools[/url]
[url=\"http://www.bitdefender.com/html/free_tools.php\"]Bitdefender Removal Tools[/url]
[url=\"http://www.virusall.com/downrem.html\"]Virusall Removal Tools[/url]
[url=\"http://www.f-secure.com/download-purchase/tools.shtml\"]F-Secure Removal Tools[/url]
Last edited by Tami on Sun Aug 01, 2004 4:55 pm, edited 1 time in total.

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
Removal Tools
a² is a complementary product to antivirus software. It provides specialist protection against harmful software. Antivirus software is not enough! a² provides protection against Trojans, Dialers and Spyware. a² fills the gaps that malware writers exploit.
Trojans
Trojan Horses or Backdoors open your PC from the inside to attackers. Once a trojan is installed, someone can take full control of your computer. Most trojans are delivered via email and just previewing the email can activate the trojan. a² currently detects around 20,000 trojans.
Dialers
Dialers are small programs which reconfigures your dial-up number to a premium rate number. If you use a dial-up modem to connect to your isp you are at risk. Premium rate numbers can cost you hundreds in just a few days! a² detects and blocks dialers immediately when they try to dial.
Worms
Worm-Viruses are the most wide spread hazard on the internet. Worms arrive as emails with harmful attachments. If you open an attachment the worm will then copy and send itself to as many other computers as possible, damaging yours and your friend's systems. a² detects worms on your PC and removes them before they can do any damage .
Spyware
Your personal data and your habits are a goldmine for some advertising companies who seek to infiltrate your computer. Often you are not aware that a spyware program has been downloaded. This software can collect personal information about you and your internet habits, change your home page and even stop you going to some websites! a²removes Spyware programs from your computer.
Scanner
Start - Select folders to scan
You can select the folders to scan for Malware. When the scan starts, a process memory scan is initiated. It is looking for malware in all running programs and services.
Scan - The Malware Search
After that, the a² scanner examines any drive or directory selected for malware. It uses a signature database that stores a kind of fingerprint of each infectious file. At the moment, a² is able to recognize more than 26,000 different malware programs including Trojans, Worms, Dialers and Spyware.
Clean - Get rid of them
When the scan has finished you select the malware items to delete. a² uses our Intelligent Cleaning Engine - malware programs are removed completely without affecting system stability. Even start up and other related entries in the system registry are fixed.
Background Guard
a² Free contains no Background Guard. The Advanced IDS and the System Firewall, which prevents Malware activating are also not included. The Background Guard is only available in a² Personal or higher.
Analysis-Tools
The a² The Analysis Tools (which helps you control the startup programs and running processes) is only included in a² [url=\"http://www.emsisoft.com/en/software/personal\"]Personal[/url] or higher.
Updates
a² Free is not equipped with an automatic update. You can download the free updates manually with the integrated updater. Automatic updates are only included in a² personal.
[url=\"http://www.emsisoft.com/en/software/download\"]Free Download Page[/url]
Preview of a² Personal 2.0:
The IDS (Intrusion Detection System) is always active and protects the operating system. For example, it is able to prevent shutdowns initiated by Trojans, bypassing of desktop firewalls by using the internet browser is prevented.
With IDS, a² sorts the programs into categories (e.g. browser, firewalls, antivirus programs and user defined). That makes it easier for you to choose an installed program - for example your standard browser, and to move it into the category browser. The next option allows you to choose which manipulations you want to shield against. You can select between protection against process termination (another program tries to stop your browser), protection against code injection (a trojan infiltrates your system and brings harmful code along), protection against DLL injection (your browser is used as a tunnel through the firewall) and protection against starting invisible programs.
Advanced IDS
The Advanced IDS mode is a component of a² Personal that analyses the behavior of all running programs If a program shows a Malware like behavior, the program is stopped. Configuring these options is easy.
Analysis-Tools
The Analysis-Tool is designed for intermediate users and is part of a² Personal. The Autostart-Viewer can be used to edit all entries which relate to the startup of a program, service or driver automatically at system startup. Now you can decide what is loaded and what is not. The Process-Viewer shows you all active programs, services and drivers to help you to clean your system and keep it that way.
Updates
a² Personal can be automatically updated. You can define when and how often a² will check an update. The signature database is updated incrementally. This means that a² will only download any changes or new malware definitions and you are not downloading the entire database every time. The updates are tiny and can be downloaded and installedin very quickly. The program components are also updated, if necessary. All you have to do is set it and forget it, the update service does the rest!
Background Guard
The Background Guard of a² personal offers 3-fold protection. Any running program is scanned and if it is a malware program, it is blocked before it becomes active . In addition, each started program will be checked while starting. All running processes are scanned periodically too.
[url=\"http://www.emsisoft.com/en/software/download\"]30 Day Free Personal Version Trial[/url]
[url=\"http://www.emsisoft.com/en/order/homeuser\"]Order Personal Version For $29.95 USD[/url]
Trojans
Trojan Horses or Backdoors open your PC from the inside to attackers. Once a trojan is installed, someone can take full control of your computer. Most trojans are delivered via email and just previewing the email can activate the trojan. a² currently detects around 20,000 trojans.
Dialers
Dialers are small programs which reconfigures your dial-up number to a premium rate number. If you use a dial-up modem to connect to your isp you are at risk. Premium rate numbers can cost you hundreds in just a few days! a² detects and blocks dialers immediately when they try to dial.
Worms
Worm-Viruses are the most wide spread hazard on the internet. Worms arrive as emails with harmful attachments. If you open an attachment the worm will then copy and send itself to as many other computers as possible, damaging yours and your friend's systems. a² detects worms on your PC and removes them before they can do any damage .
Spyware
Your personal data and your habits are a goldmine for some advertising companies who seek to infiltrate your computer. Often you are not aware that a spyware program has been downloaded. This software can collect personal information about you and your internet habits, change your home page and even stop you going to some websites! a²removes Spyware programs from your computer.
Scanner
Start - Select folders to scan
You can select the folders to scan for Malware. When the scan starts, a process memory scan is initiated. It is looking for malware in all running programs and services.
Scan - The Malware Search
After that, the a² scanner examines any drive or directory selected for malware. It uses a signature database that stores a kind of fingerprint of each infectious file. At the moment, a² is able to recognize more than 26,000 different malware programs including Trojans, Worms, Dialers and Spyware.
Clean - Get rid of them
When the scan has finished you select the malware items to delete. a² uses our Intelligent Cleaning Engine - malware programs are removed completely without affecting system stability. Even start up and other related entries in the system registry are fixed.
Background Guard
a² Free contains no Background Guard. The Advanced IDS and the System Firewall, which prevents Malware activating are also not included. The Background Guard is only available in a² Personal or higher.
Analysis-Tools
The a² The Analysis Tools (which helps you control the startup programs and running processes) is only included in a² [url=\"http://www.emsisoft.com/en/software/personal\"]Personal[/url] or higher.
Updates
a² Free is not equipped with an automatic update. You can download the free updates manually with the integrated updater. Automatic updates are only included in a² personal.
[url=\"http://www.emsisoft.com/en/software/download\"]Free Download Page[/url]
Preview of a² Personal 2.0:
The IDS (Intrusion Detection System) is always active and protects the operating system. For example, it is able to prevent shutdowns initiated by Trojans, bypassing of desktop firewalls by using the internet browser is prevented.
With IDS, a² sorts the programs into categories (e.g. browser, firewalls, antivirus programs and user defined). That makes it easier for you to choose an installed program - for example your standard browser, and to move it into the category browser. The next option allows you to choose which manipulations you want to shield against. You can select between protection against process termination (another program tries to stop your browser), protection against code injection (a trojan infiltrates your system and brings harmful code along), protection against DLL injection (your browser is used as a tunnel through the firewall) and protection against starting invisible programs.
Advanced IDS
The Advanced IDS mode is a component of a² Personal that analyses the behavior of all running programs If a program shows a Malware like behavior, the program is stopped. Configuring these options is easy.
Analysis-Tools
The Analysis-Tool is designed for intermediate users and is part of a² Personal. The Autostart-Viewer can be used to edit all entries which relate to the startup of a program, service or driver automatically at system startup. Now you can decide what is loaded and what is not. The Process-Viewer shows you all active programs, services and drivers to help you to clean your system and keep it that way.
Updates
a² Personal can be automatically updated. You can define when and how often a² will check an update. The signature database is updated incrementally. This means that a² will only download any changes or new malware definitions and you are not downloading the entire database every time. The updates are tiny and can be downloaded and installedin very quickly. The program components are also updated, if necessary. All you have to do is set it and forget it, the update service does the rest!
Background Guard
The Background Guard of a² personal offers 3-fold protection. Any running program is scanned and if it is a malware program, it is blocked before it becomes active . In addition, each started program will be checked while starting. All running processes are scanned periodically too.
[url=\"http://www.emsisoft.com/en/software/download\"]30 Day Free Personal Version Trial[/url]
[url=\"http://www.emsisoft.com/en/order/homeuser\"]Order Personal Version For $29.95 USD[/url]

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]

