Friday, September 30, 2011

How to remove Security Sphere 2012 virus (fake anti-spyware)

Security Sphere 2012 activities do not include such operations as scan, restriction of incoming traffic (Firewall feature). To make things clear, useful activities specified in the program description, or which the program menu implies, do not take place in the wild. The program simply does not contain facilities to fulfill the declared tasks. Remove Security Sphere 2012 or else it will keep annoying you with its misleading popups, yet you might believe it actually protects your computer, while your PC is at the extreme of defenselessness with the adware in its memory as faking antivirus.
The software makes necessary amendments into computer system to ensure its launching at each system loading. It also obtains authorities necessary for interrupting other software, as well as it is capable of inducing forced system reboots and connecting to remote server to download updates, which would make it yet more nasty.
Use this activation code\serial number 8945315-6548431 to "register" this malware and than get rid of Security Sphere 2012 running free scan available here (Spyware Doctor) or use manual uninstall guide.

Possible fake security alerts:
Warning: Your computer is infected
Detected spyware infection!
Click this message to install the last update of security software...

Warning!

Application cannot be executed. The file taskmgr.exe is infected.
Please activate your antivirus software.

Security Sphere 2012 Firewall Alert
Security Sphere 2012 has blocked a program from accessing the internet
Internet Explorer Internet browser is infected with worm Lsas.Blaster.Keyloger.

Security Sphere 2012 screenshots:





Manual uninstall guide:
Delete infected files:
%AllUsersProfile%\\
%AllUsersProfile%\\
%AllUsersProfile%\\.exe
%StartMenu%\Programs\Security Sphere 2012.lnk
Delete infected registry entries:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION "svchost.exe"
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings "enablehttp1_1" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce ""

6 comments:

Anonymous said...

Thanks to tou man ! Helps a lot !

Anonymous said...

Thanks a lot dear! It just rescued me. Tonnes of my gratitude.
Vik S

Anonymous said...

Thanks a lot dear! It just rescued me. Tonnes of my gratitude.
Vik S

Anonymous said...

Tonnes of gratitude dear!

Vik S

Anonymous said...

Thank u loads this help me a alot

Shaun said...

The code works. I fought back and forwards for two days on this virus.
Thanks, Shaun