ONLINE ANTIVIRUS REMOVAL

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 18 August 2011

Remove Home Safety Essentials

Posted on 19:20 by Unknown
Home Safety Essentials Removal Guide
Home Safety Essentials is a fake antivirus program that CANNOT DETECT AND REMOVE any kind of virus, malware and trojan. Home Safety Essentials can do nothing but just show pop ups to convince the user that the computer has been infected by malwares and urge the user to purchase the full version of Home Safety Essentials. Home Safety Essentials infections are known to spread by means of fake online system alerts that warn the user about infections that require the user to download Home Safety Essentials to remove them. Home Safety Essentials will start automatically when Windows boot. Then Home Safety Essentials will do a fake scan on the computer and then it will show the fake report. Do not purchase Home Safety Essentials as it can do nothing.The user should switch to Safe Mode to make sure any scans detect Home Safety Essentials and remove Home Safety Essentials with anti-malware applications that are designed to handle such threats.



Home Safety Essentials can be removed by using Emsisoft HiJackFree to stop the processes and kill the files from the hard drive. Then, the user has to restore the registry entries added and modified by Home Safety Essentials. Finally, all the file related to Home Safety Essentials must be deleted from the hard drive. All of them has been shown in the removal guide below.



The computer users should remember that any time when they encounter a web page that states that the computer is infected, they should not believe them as the majority of these pages are scams trying to get them to install the actual infection. The second method that can be used to install this fake antivirus is through hacked web sites that install Home Safety Essentials on to the computer without their knowledge by exploiting vulnerabilities in the outdated programs.



Home Safety Essentials should be removed immediately!




Home Safety Essentials Removal Guide

Kill Process

(How to kill a process effectively?)

HS2d7_231.exe

runddlkey.exe

ScanDisk_.exe





Delete Registry

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"

HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\91\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}\Vid {137E7700-3573-11CF-AE69-08002B2E1262}

HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes\URL http://findgala.com/?&uid=231&q={searchTerms}

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\RunInvalidSignatures 1

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PRS http://127.0.0.1:27777/?inj=%ORIGINAL%

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\URL http://findgala.com/?&uid=231&q={searchTerms}

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\89770803

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\lib/5.00231

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UID 231

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\0 msseces.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1 MSASCui.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\10 avgscanx.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\11 avgcfgex.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\12 avgemc.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\13 avgchsvx.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\14 avgcmgr.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\15 avgwdsvc.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\2 ekrn.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3 egui.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4 avgnt.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\5 avcenter.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\6 avscan.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\7 avgfrw.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\8 avgui.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\9 avgtray.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Home Safety Essentials

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HS2d7_231.DocHostUIHandler

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\CheckExeSignatures "no"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin "2"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorUser "2"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe

... Many more Image File Execution Options entries



Remove Folders and Files

%AllUsersProfile%\\

%AllUsersProfile%\\14.mof

%AllUsersProfile%\\3178.mof

%AllUsersProfile%\\46.mof

%AllUsersProfile%\\6113.mof

%AllUsersProfile%\\HS2d7_231.exe

%AllUsersProfile%\\HSE.ico

%AllUsersProfile%\\HSESys

%AllUsersProfile%\\Quarantine Items

%AllUsersProfile%\HSYITSQGE

%AllUsersProfile%\HSYITSQGE\HSLGILTOGE.cfg

%AppData%\Home Safety Essentials\

%AppData%\Home Safety Essentials\Instructions.ini

%AppData%\Home Safety Essentials\ScanDisk_.exe

%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Safety Essentials.lnk

%AppData%\Microsoft\Windows\Recent\CLSV.tmp

%AppData%\Microsoft\Windows\Recent\DBOLE.dll

%AppData%\Microsoft\Windows\Recent\PE.sys

%AppData%\Microsoft\Windows\Recent\SICKBOY.drv

%AppData%\Microsoft\Windows\Recent\SICKBOY.sys

%AppData%\Microsoft\Windows\Recent\delfile.dll

%AppData%\Microsoft\Windows\Recent\eb.dll

%AppData%\Microsoft\Windows\Recent\eb.sys

%AppData%\Microsoft\Windows\Recent\energy.dll

%AppData%\Microsoft\Windows\Recent\gid.tmp

%AppData%\Microsoft\Windows\Recent\pal.sys

%AppData%\Microsoft\Windows\Recent\ppal.drv

%AppData%\Microsoft\Windows\Recent\runddlkey.exe

%AppData%\Microsoft\Windows\Recent\snl2w.drv

%AppData%\Microsoft\Windows\Start Menu\Programs\Home Safety Essentials.lnk

%AppData%\Microsoft\Windows\Start Menu\Home Safety Essentials.lnk

%UserProfile%\Desktop\Home Safety Essentials.lnk

File Location Notes:



%UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\ for Windows 2000/XP, C:\Users\ for Windows Vista/7, and c:\winnt\profiles\ for Windows NT.



%AllUsersProfile% refers to the All Users Profile folder. By default, this is C:\Documents and Settings\All Users for Windows 2000/XP and C:\ProgramData\ for Windows Vista/7.



%AppData% refers to the current users Application Data folder. By default, this is C:\Documents and Settings\\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\\AppData\Roaming.

Email ThisBlogThis!Share to XShare to Facebook
Posted in Removal Guide | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Remove Windows Internet Guard
    Windows Internet Guard is a fake antivirus that disguises itself to cheat the user that it can detect and remove trojans, viruses, malwares...
  • Remove XP Smart Defender
    XP Smart Defender is a fake antivirus program created to urge the user to buy the full version of XP Smart Defender in order to earn some p...
  • Windows Antidanger Center Removal Guide
    Windows Antidanger Center is an unwanted application which is a rogue computer security program. Windows Antidanger Center is a fake optimi...
  • Don't disable UAC or your computer will be attacked by malwares!
    UAC or User Account Control is one of the very good features provided by Windows Vista and Windows 7. However, many people try to disable ...
  • Remove Ministry of Public Safety Canada Ransomware
    Ministry of Public Safety Canada Ransomware is a virus, malware, trojan family that infect the computer to cheat the hard-earn money of com...
  • Great News
    All your life you have waited for the good news, and that day has finally come. Very soon you will witness large-scale mass arrests all over...
  • Remove Windows Antipiracy Virus
    Windows Antipiracy Virus is a fake antivirus program which intend to urge the user whose computer is infected by Windows Antipiracy Virus t...
  • Remove Windows Foolproof Protector
    Windows Foolproof Protector is a fake antivirus program that cannot detect and remove any kind of virus, malware or trojan. However, Windo...
  • Remove Vista Antispyware Pro 2013
    Vista Antispyware Pro 2013 is a fake antivirus program created to urge the user to buy the full version of Vista Antispyware Pro 2013 in or...
  • Remove Windows Internet Watchdog
    Windows Internet Watchdog is a fake antivirus program that look like a legitimate antivirus such as Kaspersky Antivirus which can protect t...

Categories

  • facebook
  • Kill Process
  • Removal Guide
  • Removal Tool
  • Remove Virus
  • Repair File
  • RFA
  • security
  • System Tool
  • Task Manager

Blog Archive

  • ►  2014 (27)
    • ►  April (3)
    • ►  March (10)
    • ►  February (8)
    • ►  January (6)
  • ►  2013 (66)
    • ►  December (7)
    • ►  November (2)
    • ►  October (4)
    • ►  September (3)
    • ►  August (12)
    • ►  July (5)
    • ►  June (2)
    • ►  May (15)
    • ►  April (3)
    • ►  March (8)
    • ►  February (3)
    • ►  January (2)
  • ►  2012 (224)
    • ►  December (12)
    • ►  November (9)
    • ►  October (23)
    • ►  September (3)
    • ►  August (11)
    • ►  July (15)
    • ►  June (23)
    • ►  May (29)
    • ►  April (29)
    • ►  March (34)
    • ►  February (25)
    • ►  January (11)
  • ▼  2011 (221)
    • ►  December (9)
    • ►  November (11)
    • ►  October (13)
    • ►  September (10)
    • ▼  August (19)
      • Remove OpenCloud Antivirus
      • Remove PC Repair
      • Remove Fast Antivirus
      • Remove HDD Repair
      • Remove Home Safety Essentials
      • Remove Antivirus 2011 Edition limitée
      • Remove Protection Shield Pro
      • Remove Wolfram Antivirus
      • Remove Windows System Manager
      • Remove ESET Smart Security Enhanced Protection Mode
      • Remove Avast Enhanced Protection Mode
      • Remove Norton AntiVirus Enhanced Protection Mode
      • Remove Avira AntiVir Enhanced Protection Mode
      • Remove McAfee Enhanced Protection Mode
      • Remove Microsoft Defender Enhanced Protection Mode
      • Remove Comodo Enhanced Protection Mode
      • Remove Kaspersky Internet Security 2011 Enhanced P...
      • Remove Personal Pro System
      • Remove Alfa Defender Pro
    • ►  July (38)
    • ►  June (60)
    • ►  May (30)
    • ►  April (31)
Powered by Blogger.

About Me

Unknown
View my complete profile