How to Remove SecuritySoldier | Security Soldier Removal



SecuritySoldier is the latest in the WiniGuard Family (SecurityFIghter, SaveArmor, SaveDefender are just the names that came out in the last week.) These busy bees have pretty much just renamed the program and files. It looks the same as each of the recent previous rogues. Just as those do it may install via trojans or web exploits and claim that you have security problems on your computer that it will then be able to fix if you pay for their software. All warnings are trumped up, i.e. not legitimate and it really doesn’t clean up anything. Read on for How to Remove SecuritySoldier.


One thing I should mention about so many of these rogue antivirus programs. Once they are on your system they can do most anything. So, for instance links on webpages can be hijacked and redirected to pages that they want you to see. I noticed an odd exit link in my logs last night and on investigation it was a page to receive payments for alpha antivirus. So, I went to the alpha antivirus removal page to see if there was any link with that address on the page. There wasn’t, there were only links to the tutorial itself, other removal guides and the page for my virus removal toolkit. So, I can only assume someone was browsing from a machine with alpha antivirus already installed and it hijacked the link. It’s usually best to look for removal help from a machine that’s not infected. You really never know what other things it could do after it’s installed on the system. The malwarebytes antimalware download could be substituted or altered with something else – so download your cleanup tools on a clean system if at all possible.

First I would download malwarebytes antimalware from my virus removal toolkit page. Try installing that and run an update and then scan. Alternatively you may boot into safe mode and try scanning if the first fails to work.

The following domain should be blocked.

securitysoldier.com

The following processes should be found and killed off in task manager. The process names are:

securitysoldier.exe
uninstall.exe

These processes could interfere with cleanup. If you have failed with the automatic removal with malwarebytes you might retry after this is done.

The following dll needs to be unregistered and removed:

1044zhackt9ol5b2.dll

(Possibly randomized name – look for similar patterns to dll names.)

Then remove the following files and folders:

%ProgFiles%SecuritySoldier Software
%ProgFiles%SecuritySoldier SoftwareSecuritySoldier
%ProgFiles%SecuritySoldier SoftwareSecuritySoldierlicense.txt
%ProgFiles%SecuritySoldier SoftwareSecuritySoldiersecuritysoldier.exe
%ProgFiles%SecuritySoldier SoftwareSecuritySoldieruninstall.exe
%WIN%102z6w59m3c4.cpl
%WIN%1044zhackt9ol5b2.dll
%WIN%10683v9rzs656.cpl
%WIN%10915hief309z.cpl
%DocRoot%All UsersDesktopSecuritySoldier.lnk
%DocRoot%All UsersStart MenuProgramsSecuritySoldier
%DocRoot%All UsersSt

The above filenames may include some randomization so use what you see above as a pattern to find the files that SecuritySoldier has dropped. You may need to use what you find to then go back and remove the dll file listed above. For complete securitysoldier removal you should run malwarebytes antimalware (and update it) again after removing files manually to ensure that you have removed it from your system.

Related Posts

Blog Traffic Exchange Related Posts
  • How to Remove ProtectPCs | ProtectPCs Removal Guide ProtectPCs is a rogue antivirus application from the Wini family of rogues. It will push itself through claims of it being a video codec update or flash player update. Usually these appear on a site that shows up in the search results for whatever latest greatest sought after video clip......
  • How to Remove AntiTroy | AntiTroy Removal Guide AntiTroy is a rogue antivirus application that is usually installed through trojans that are masquerading as a video codec update or flash player update. It usually installs without the computer users permission and will complain about many security issues with your pc. It will claim that there are virus infected......
  • How to Remove GuardPCs | GuardPCs Removal Guide GuardPCs looks like the latest entry from the wini family of rogues. (They just keep churning out new ones every other day it seems.) They're using the same template these days of course, just the names change. This one, as the others, is pushed through bogus video codec or flash......
Blog Traffic Exchange Related Websites
  • Trojan Horse Protection - Antivirus Trojan Software In today’s online environment it’s important to know what risks lie ahead at each click. This paper will describe so of the malicious kinds of attacks your Home/Office PC may encounter online. Now I’m sure we have all heard of Viruses online and some of you have heard of Trojans.......
  • Panda AntiVirus free 1 year License give away Last week, I posted about ZoneAlarm's free 1 year license. This week again I am posting about a free AntiVirus License give away! This time it's Panda AntiVirus. The license give away will be on 22nd October, 2009. Also on the same day, Windows 7 is going to be launched!......
  • World Wide Web Security Essentials Is Not A Real Spyware Remover. It Resembles The Functions And Looks World wide web Security Essentials is not a real spyware remover. It resembles the functions and looks of genuine spyware removal software but has no capacity to eliminate any virus, trojan or malware. Web Security Essentials is the newest addition to the growing list of rogue Antivirus programs. Internet Security......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site