How to Get Rid of Google Malware
Google malware refers to the "Google has detected" malware program. This fictitious malware program is generated by the rogue anti-malware program, System Protector. Thus, the good news is that your computer is not infected with Google malware. The bad news is that your computer is infected with System Protector. You can remove the rogue anti-malware program, which slows the computer and launches fake system scans and malware warnings. The removal process applies to Windows Vista and 7 operating systems.
Instructions
-
End Processes
-
1
Press "Ctrl," "Shift" and "Escape" to open the Task Manager.
-
2
Click the "Processes" tab of the Task Manager.
-
-
3
Click the "Show Processes From All Users" button. Click the "Image Name" heading. A list of processes appears in alphabetical order.
-
4
End active processes. To end a process, right-click the process. Select "End Process."
install.exe
lsascs.exe
windll32.exe
-
5
Close the Task Manager.
Delete Registry Entries
-
6
Click "Start." Type "regedit" into the "Search" box. Press "Enter." The Registry Editor opens.
-
7
Delete the following registry values from the left pane of the Registry Editor. To delete a registry value, right-click the value and select "Delete."
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"
-
8
Close the Registry Editor.
Unregister DLLs
-
9
Click "Start." Type "cmd" into the "Search" box. Press "Enter." The Command Prompt opens.
-
10
Type "regsvr32 /u shellex.dll" (without the quotation marks) into the Command Prompt and press "Enter."
-
11
Close the Command Prompt.
Delete Files and Directories
-
12
Click "Start." Click the "Search" box.
-
13
Search for and delete the following files and directories. To delete a file or directory, right-click the file or directory and select "Delete."
SpyProtectorSC_Base_new.dat
SpyProtectorSC_Config.ini
Purchase License.url
Support Page.url
System Protector.lnk
spyprotector.cpl
C:\Program Files\System Protector
-
14
Restart the computer.
-
1
References
- Photo Credit credit cards image by Aleksandr Lobanov from Fotolia.com