Home Security Solutions is a dangerous malware that tries to convince its victims that they have numerous viruses on their computers. Being released by Rogue.VirusDoctor family, it is set to start its misleading campaign as soon as it manages to get inside the system. This is done through the backdoors of the system or through the fake pages offering to check the system for free. So, in most of the cases the victims have no idea that Home SecuritySolutions is downloaded or they are simply convinced that they are offered to download legitimate application. Keep in mind that the main aim of Home Security Solutions is to break into the system without any sign and additionally set up everything for swindling victim's out of their money. Please, use a reputable anti-spyware to remove Home Security Solutions malware from your computer.
To make its victims believe that they are dangerously infected, HomeSecurity Solutions starts its campaign by dropping some harmless files on the system that additionally will be 'detected' as malicious ones. Some of these 'dangerous' files are: %UserProfile%\Recent\ANTIGEN.exe; %UserProfile%\Recent\ddv.sys; %UserProfile%\Recent\eb.dll; %UserProfile%\Recent\FW.dll; %UserProfile%\Recent\grid.exe; %UserProfile%\Recent\kernel32.exe; %UserProfile%\Recent\kernel32.tmp; %UserProfile%\Recent\pal.exe; %UserProfile%\Recent\tjd.exe. You can also find some new Registry keys that make your infected OS to run corrupt processes of the virus.
After making all these preparations, Home Security Solutions starts displaying falsified alerts in the form of popup ads and scan reports that have nothing to do with a real situation on your computer. The real intention of doing so is to convince unaware PC user that he is dangerously infected and that only Home Security Solutions is powerful enough to remove all those viruses for him. However, those removal services are paid. Keep in mind that the only thing that must be eliminated is the same Home Security Solutions. This rogue anti-spyware is all about making users pay for the fake 'full' version, so remove Home Security Solutions immediately after you notice it on your machine. If you have already paid for it, contact your credit card company to dispute the charges. In addition, use the tips below to get rid of Home Security Solutions as soon as possible.
Home Security Solutions manual removal:
Kill processes:
[random].exe, starting from %AppData% or Application Data
HSa76.exe
grid.exe
std.exe
tjd.exe
pal.exe
kernel32.exe
ANTIGEN.exe
Delete registry values:HKEY_CLASSES_ROOT\HSS.DocHostUIHandler
HKEY_CLASSES_ROOT\HSS.DocHostUIHandler\Clsid
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://findgala.com/?&uid=7&q={searchTerms}”
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://findgala.com/?&uid=7&q={searchTerms}”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer “PRS” = “http://127.0.0.1:27777/?inj=%ORIGINAL%”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “DisallowRun” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “0″ = “msseces.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “1″ = “MSASCui.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “10″ = = “avgscanx.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “11″ = “avgcfgex.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “12″ = “avgemc.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “13″ = “avgchsvx.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “14″ = “avgcmgr.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “15″ = “avgwdsvc.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “2″= “ekrn.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “3″= “egui.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “4″= “avgnt.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “5″= “avcenter.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “6″ = “avscan.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “7″ = “avgfrw.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “8″ = “avgui.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun “9″ = “avgtray.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Home Security Solutions”
HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://findgala.com/?&uid=7&q={searchTerms}”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
Unregister DLLs:eb.dll
FW.dll
Delete files:[random].exe, starting from %AppData% or Application Data
%AppData%\Home Security Solutions\
%AppData%\Home Security Solutions\cookies.sqlite
%AppData%\Home Security Solutions\Instructions.ini
%AppData%\Home Security Solutions\ScanDisk_.exe
%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Security Solutions.lnk
%CommonAppData%\79b35\
%CommonAppData%\79b35\HSa76.exe
%CommonAppData%\79b35\HSS.ico
%CommonAppData%\HSALJNS\
%CommonAppData%\HSALJNS\HSGZLIDJFOS.cfg
%Desktop%\Home Security Solutions.lnk
%UserProfile%\Recent\ANTIGEN.exe
%UserProfile%\Recent\CLSV.drv
%UserProfile%\Recent\CLSV.sys
%UserProfile%\Recent\ddv.sys
%UserProfile%\Recent\eb.dll
%UserProfile%\Recent\FW.dll
%UserProfile%\Recent\grid.exe
%UserProfile%\Recent\kernel32.exe
%UserProfile%\Recent\kernel32.tmp
%UserProfile%\Recent\pal.exe
%UserProfile%\Recent\snl2w.sys
%UserProfile%\Recent\std.exe
%UserProfile%\Recent\tjd.exe
%UserProfile%\Start Menu\Home Security Solutions.lnk
%UserProfile%\Start Menu\Programs\Home Security Solutions.lnk
Post Comment: