skip to main |
skip to sidebar
The new update of PCMAV has been released on this October 2009. In this new version, 2.1a, PCMAV able to detect and remove 2.954 the famous viruses.
Whats new in PCMAV 2.1a:
- UPDATED! Added to database, scanner and cleaner of 71 local viruses/new variants that reported by users in Indonesia and Asia. Total 2954 viruses and its variants, including new variant of Conficker virus.
- IMPROVED! Added the special cleaner for virus smansa.
- IMPROVED! Heuristic engine for detect new variant of some complex polymorphic viruses.
- And other bug fixed and some improvisations.
Download this great and small Anti Virus at Here.
PC Media Antivirus (PCMAV) 2.0b - Valkyrie
New Release May 9, 2009
Kill all Brontok virus, Conficker and all its variants without damaging Operating System and your files

Whats New
- a. Improved! Added a database and virus cleaning 60 local / foreign / new variants have been spread. Total 2720 virus with variannya, including virus Conficker sophisticated, a lot of outstanding and has been known in this version 2.0b by core engine PCMAV.
- b. BuG fixed! In the previous version of RTP running less perfect in Windows XP / Vista, which in some cases to result in some applications can not run perfectly.
- c. BuG fixed! Routine scan memory does not fail again in detecting some types of script viruses.
- d. BuG fixed! Heuristic engine is now more accurate in detecting the suspected file.
- e. NEW! Additional advanced heuristic engine that can detect polymorphic variants of the virus spread much.
- f. BuG fixed! Scan through the right-click "Scan with PCMAV" can now be integrated in Vista without problems.
- g. Improved! Display splash screen Realtime Cleaner and Protector.
- h. BuG fixed! Error detection (false alarm) heuristik on some programs and scripts.
- i. Updated! README.TXT
- j. Improved! Several name changes the virus has found a new variant.
- k. Improved! Some minor improvements and bug improvised code to ensure that internal PCMAV can still be pride.
Minimal System Requirement
Processor: Pentium
RAM: 256 MB
Operating systems: - Windows XP 32-bit
- Window Vista 32-bit
- Windows 7 32-bit
Download this AntiVirus for free at Here or Here.
PCMedia AntiVirus 1.9
The new PCMAV 1.9 has capable to detect and remove new 2254 viruses and its variant that reported and found in the world.
Whats Changed:
- Added, cleaner and removal database for new 95 viruses
- Added, special cleaner for virus Bungas.vbs
- Fixed, false alarm (heuristhic miss detection) for some application and script
- Updated, chanhes for virus names according their new variants
- Fixed, few minor bugs found and internal code improved.
Download at Here or Here.
Sality is a virus that has backdoor capabilities and executes keylogger and may infect executable files by putting its code to host files. Once it is installed, Sality virus will infect local executable files and delete all files that are associated with anti-virus
and anti-spyware
applications, as well as firewalls. After this, Sality runs a keylogging module that gathers all system and network information, records passwords and login names, steals all sensitive information and sends all this collected data to a predefined email address.
In addition, Sality opens a backdoor that allows the remote attacker to get the full control over the infected computer and this places any financial or banking information stored on your computer in severe jeopardy and represents a serious security risk.
Also known as: W32/Sality (McAfee), Virus.Win32.Sality.aa (Kaspersky), W32.Sality.AE (Symantec), Virus:Win32/Sality.AM (MS OneCare), PE_SALITY.EM (Trend)
W32/Sality is a parasitic virus that infects Win32 PE executable files. It is a polymorphic virus that attempts to spread by file infection. It looks for Win32 PE executable files with .EXE or .SCR file extensions, and infects any such files found on the system by appending the virus body to the host file.
The virus also attempts to propagate by copying itself with a random filename to network drives, including all removable disk drives. Sality.AA also creates an "autorun.inf" file in these drives so that the virus executes when it is accessed.
Upon execution, it drops the following files into the Windows system directory:
- %Windir%\System32\Hdaudprop.dll
- %Windir%\System32\Hdaudpropres.dll
- %Windir%\System32\Hdaudpropshortcut.exe
- %Windir%\System32\drivers\Hdaudbus.sys
- %Windir%\System32\drivers\Hdaudio.sys
- %Windir%\System32\drivers\portcls.sys
Creates the following registry keys:
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WMI_MFC_TPSHOCKER_80
- HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\Root\IPFILTERDRIVER
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GlobalUserOffline
and it downloads further malware from the following domains:
- bpowqbvcfds677.info
- aapowqbvcfds677.info
- abpowqbvcfds677.info
- d98dc9.bpowqbvcfds677.info
- bmakemegood24.com
- d99395.bmakemegood24.com
- bbeakemegood24.com
- bperfectchoice1.com
- d998b6.bperfectchoice1.com
- cbparfectchoice1.com
- cbpbrfectchoice1.com
- bcash-ddt.net
- d9aab7.bcash-ddt.net
- pzrk.ru
- dbcabh-ddt.net
- bddr-cash.net
- ebddrbcash.net
It also modifies the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"
and this virus also deletes entries in the following registry subkeys:
- HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Sality.AA bypasses the system firewall by executing the command:
netsh firewall set opmode disable
It may also disable settings related to system security. It does this by adding the following registry entries:
- HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\FirewallOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\UacDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\AntiVirusDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\FirewallOverride = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\UpdatesDisableNotify = dword:00000001
- HKLM\SOFTWARE\Microsoft\Security Center\Svc\UacDisableNotify = dword:00000001
The virus sets the following registry entry so that hidden folders and files are not displayed in Windows Explorer view:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden = 2
It also disables Registry Editor and Task Manager by adding these registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableTaskMgr = dword:00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system\DisableRegistryTools = dword:00000001
Sality.AA terminates all anti virus routine services running on the system, and prevent access to Websites that contain its names, like sality_remove, viruscan
, sophos
, mcafee
, eset.com
, kaspersky
, onlinescan, and more...
The device driver is not dropped and installed onto the system unless there is an active internet connection.
The virus may prevent execution of applications that perform an integrity self-check as a result of them being infected.
So my dear friend the easiest way to tackle this virus is to Remove above mention Virus Entry Doors from registry and Delete those .DLL files from system.
Sality Manual Removal Instructions
Below is a list of Sality manual removal instructions and Sality components listed to help you remove Sality from your PC. Backup Reminder: Always be sure to back up your PC before making any changes.
Note: This manual removal process may be difficult and you run the risk of destroying your computer.
Step 1 : Use Windows File Search Tool to Find Sality Path
- Go to Start > Search > All Files or Folders.
- In the "All or part of the the file name" section, type in "Sality" file name(s).
- To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
- When Windows finishes your search, hover over the "In Folder" of "Sality", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete Sality in the following manual removal steps.
Step 2 : Use Windows Command Prompt
to Unregister Sality DLL Files
- To open the Windows Command Prompt, go to Start > Run > type cmd and then click the "OK" button.
- Type "cd" in order to change the current directory, press the "space" button, enter the full path to where you believe the Sality DLL file is located and press the "Enter" button on your keyboard. If you don't know where Sality DLL file is located, use the "dir" command to display the directory's contents.
- To unregister "Sality" DLL file, type in the exact directory path + "regsvr32 /u" + [DLL_NAME] (for example, :C\Spyware-folder\> regsvr32 /u Sality.dll) and press the "Enter" button. A message will pop up that says you successfully unregistered the file.
- Search and unregister "Sality" DLL files: syslib32.dll, sysdll.dll, oledsp32.dll
Step 3 : Detect and Delete Other Sality Files
- To open the Windows Command Prompt, go to Start > Run > type cmd and then press the "OK" button.
- Type in "dir /A name_of_the_folder" (for example, C:\Spyware-folder), which will display the folder's content even the hidden files.
- To change directory, type in "cd name_of_the_folder".
- Once you have the file you're looking for type in "del name_of_the_file".
- To delete a file in folder, type in "del name_of_the_file".
- To delete the entire folder, type in "rmdir /S name_of_the_folder".
- Select the "Sality" process and click on the "End Process" button to kill it.
- Remove the "Sality" processes files: syslib32.dll, sysdll.dll, oledsp32.dll, oledsp32.dll, sysdll.dll, syslib32.dll
Other simple way, you can use Sality Removal Tool from Grisoft
by downloading at Here.
Autorun Virus Remover can detect and clean hundreds of usb/autorun viruses and it will block viruses and trojans trying to attack when USB device is inserted.
Autorun Virus Remover provides 100% protection against any malicious programs trying to attack via USB storage(USB driveUSB stickpen drive flash drive flash card secure digital card removable storage portable storage;ipod media player).
Compare Autorun Virus Remover with other antivirus solutions, you will find out its highlights:
- Autorun Virus Remover provides 100% protection against any threats via USB drive, however, the majority of other products are unable even to guarantee 90% protection.
- Autorun Virus Remover can detect and clean the usb virus/worm/trojan such as Ravmon,auto.exe in your computer or usb drive,it could solve the problem that unable to open a drive by double clicking. It also removes the leftovers of virus by removing the autorun.inf files and cleaning up your system registry, so you won’t see the autoplay item anymore.
Features:
- 100% protection against any threats via USB drive
- The best solution to protect offline computer
- The world’s fastest and smallest antivirus software
- Require no signature updates
- 100% compatible with all software
- Easy to use
Btw, you can download this antivirus at here or at here.
As I wrote on last posts at here and here, PCMAV or PCMedia Antivirus is free antivirus software that made by Indonesian developer. PCMAV support or compatible with engine Clamav 0.93 (the new generation of antivirus clamav engine).
Now, this new version come with more power for attacking and removing the new viruses and trojans.
Download this new version at Here or Here.
Note: No need to install, just extract from archive to your harddisk.
Whats changed and added:
- Added, 118 new viruses/variant scanner and cleaner.
- Fixed, error of rotine buffering when scanning file.
- Added, special cleaner for virus VBScript FourTwoOne.vbs.
- Added, special cleaner for virus Windx-Maxtrox that infects EXE file.
- Added, special cleaner for virus Microso that injects DLL file.
- Fixed, false alarm heuristik of any program/script.
- Updated, name of some virus according new variants found.
- Fixed of some minor bugs improvisation internal code of PCMAV Cleaner & PCMAV RealTime Protector.
Download this new PCMAV at Here or Here.
PCMAV or PCMedia Antivirus now support or compatible with engine Clamav 0.93 (the new generation of antivirus clamav engine). With this engine, Antivirus PCMAV 1.6 capable to scan 3 times more faster than before. Feel the different. PCMAV 1.4 can integrated as usual with engine Clamav 0.93 if your Window OS supported library MSVCRT80 (Microsoft.VC80.CRT.manifest, msvcm80.dll, msvcp80.dll, and msvcr80.dll).
And now, PCMAV RTP (Real Time Protection) works more accurate to block any virus from vbscript type. Included in memory: Special virus cleaner added for virus Revublik.vbs and more improvisation...
Whats changed and added on new version of PCMAV is 1.6 that released on this month:
- 79 virus cleaner added on local/international/new variant virus in Indonesia. Total 2064 virus.
- Bug fixed on engine heuristic.
- Wrong detection in several application has been fixed by USB Disk filtering as Virus Suspected.
- Bug on engine GetUpdates fixed.
- False alarm fixed on several program or script.
- Improvisation, engine heuristic for Virus Suspected (RD). Now more accurate.
- Improvisation, user-interface from USB Disk Filtering.
You can download PCMAV 1.6 for free at Here or Here.
Beware of new virus W32/Alman. This malware kind virus is not easy to remove or destroy. This virus, size 40kb, run as windows services and run on windows startup too. The virus infects all write accessible Windows executable files (PE-EXE) on all disks on the victim computer and in accessible network folders once it active.
AVG Antivirus can not heal this virus, but Grisoft has released the virus removal application for clean it. The removal has 2 files, rmalman.exe and rmalman.nt, so download these files and save to one folder. You can run rmalman.exe to scan and clean W32/Alman virus.
Anti-Trojan Elite™ (ATE) is a malware remover, it can detect and clean malware in disk or memory. Malware is software designed specifically to damage or disrupt a system, such as a trojan horse, a spyware or a keylogger. ATE contains a Real-Time File Firewall, it monitor system and clean malwares immediately. It is also a system security tools, you can view and control processes and TCP/IP network connections.
Anti Trojan Elite provide a real-time malware firewall for user, once a trojan or keylogger would been loaded, the ATE can detect, block and then clean it in time. The ATE can detect more than 35000 trojans, worms and keyloggers currently, and the number of malware ATE could clean is growing up very quickly, we collect world-wide malwares, user can using our auto live update feature to get the power to clean these new malwares in time.
Anti Trojan Elite has some useful utilities especially. The network utility can been used to disconnect suspicious TCP connections; The process utility can been used to kill suspicious processes even the process has the system privilege, even it has the ability to unload suspicious modules in all processes; The registry repair utility can been used to repair registry altered by malware; The registry monitor utility can been used to repair any change of important registry keys and values with real time.
The Reasons Choose Anti-Trojan Elite™:
- Real-time malware firewall, protecting user's computer in real-time.
- Detecting and cleaning binded malware, doesn't hurt normal file and clean the malware.
- Detecting and cleaning no process malware, some malware don't have a EXE file, they are only some DLL files and running as some threads in other process, ATE can detect and clean this type of malware even it's running.
- Free tools. View the information of Tcp/Ip states and processes informations.
More Features:
- Disk and memory scan supported.
- Real-time malware firewall.
- Compressed files (RAR ZIP CAB) scan supported.
- Backup module: Backup trojan files before killing.
- Network Manager. View the tcp/udp states and the processes they belonged to. User can disconnect any tcp connection and stop the opposite process.
- Process manager. View the processes and its DLL modules' information. User can terminate any process and unload any DLL module.
- Internet Explorer and registry repair utility.
- Updating online supported, and auto check updates when ATE starts.
- Real-time registry monitor utility.
Anti-Trojan Elite™ works best on Microsoft Windows 98, ME, 2000, XP, 2003 and VISTA.
More info about Anti-Trojan Elite™ can be reached at Here.