The is a fake application that presents itself as a legitimate security tool, but in reality this is a virus that causes considerable damage to your system along with important data files. Once installed, it directly affects the performance of your system, and makes your computer slow in responding. This malicious application enters in the windows based computers secretly, and hide itself wisely along with the sensitive system files. The creates a startup key in the windows registry due to which it starts automatically every time you starts your windows. Once installed, it will immediately starts sending you the fake security alerts which shows that your PC is at high risk, and when you try to fix this problem, you will be asked to buy the paid version of the You are also unable to execute the important system application, and the purpose of sending this virus is to steal your confidential data which is being used in the cyber crimes.

The Manual Removal of

After confirming that the system is compromised to the, you have to find a way to delete this deadly dangerous parasite effectively, and immediately. You can remove it both ways, automatically as well as manually. The manual removal method is a bit complicated for the novice users. The steps involved in the manual removal are mentioned below:-

Start the System in Safe Mode

Before start removing the virus, you have to reboot the infected computer, and start it in the safe mode by using the F8 key. Once the system restarted in the safe mode, you can proceed towards the manual removal process.

Kill the Associated Processes

You have to delete the associated processes of this threat by starting the windows task manager that can be accessed by using the Ctrl+Alt+Delete keys together. Once the task manager is visible on the screen, you have to click on the processes tab where you can see a long list of running processes. You have to find and delete the following associated processes of


Delete the Associated Files

You have to remove the following associated files from the system files folder by using the Delete key:-

  • %Desktopdir%\Http:// .lnk
  • %Programs%\Http:// \Http:// .lnk

Reverse the Modification in the Windows Registry

Once done with the above mentioned steps, you have to get rid of the corrupt entries created by this virus. Start the registry editor by using the “regedit” command that can be executed through Run option available in the start menu. Remove the following entries from the windows registry by using the registry editor :-

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Http:// \DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Http://
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Http:// \UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Http:// \ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Http:// \DisplayName Http://

Restart the machine in the normal mode to check the effectiveness of the manual removal process. Update the existing antivirus program and run a complete system scan on your computer to remove the infections.



How to Remove ?
Tagged on:                                 

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>