How to remove Home Malware Cleaner
Home Malware Cleaner description
Home Malware Cleaner is rogue anti-spyware tool which spreads via trojan horse. Trojan comes to the system via its vulnerabilities and makes a perfect background for the parasite to sneak. Home Malware Cleaner is a scam which pretends being legitimate computer protections tool. Do not fall for this fraud.
Malware tries to trick user into purchasing its “registered” version but in fact this is a scam and should be ignored. The parasite will imitate computer scans and show numerous fake warning messages that state about computer infections. Do not fall for this blatant scam because it is malicious and fraudulent. Home Malware Cleaner may redirect your browser to counterfeit websites that sell the program. Ignore it and all its security alerts but use decent anti-spyware application and get rid of the scam indefinitely.
How to get rid of Home Malware Cleaner
This infection can be removed using Spyware Doctor.
Spyware Doctor is widely valued as one of the best AntiSpyware programs available to protect you from Home Malware Cleaner and the latest internet security threats. If your computer is infected with Home Malware Cleaner we strongly recommend automatic spyware scanner.
How to manually remove Home Malware Cleaner
To get rid of spyware such as Home Malware Cleaner you need to remove processes, search and delete registry keys, DLL and other Home Malware Cleaner related files from your computer.
Take Note: The manual process of removing spyware from your computer is difficult and puts you at risk of damaging your computer. We advise using our automatic Home Malware Cleaner remover.
- Uninstall Home Malware Cleaner from Control Panel
Start > Settings > Control Panel > Add/Remove Programs. Double click to uninstall. - End these Home Malware Cleaner processes:
PE.exe
grid.exe
CLSV.exe
HMa76.exe
ScanDisk_.exe
To stop processes press Ctrl + Alt + Del or click Start > Run > type "taskmgr". Select malicious process in the list and click "End Process" button. -
Unregister Home Malware Cleaner DLL files:
sqlite3.dll
mozcrt19.dll
To unregister DLL click Start > Run > type "regsvr32 /u PATH_TO_FILE/FILE.dll" -
Delete Home Malware Cleaner registry entries:
HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\dumped_patched.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=8010&q={searchTerms}"
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=8010&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "IIL" = 0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "ltHI" = 0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "ltTST"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "UID" = 8010
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "runtime 13.08010"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "DisallowRun" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "0" = "msseces.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "1" = "MSASCui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "2" = "ekrn.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "3" = "egui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "4" = "avgnt.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "5" = "avcenter.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "6" = "avscan.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "7" = "avgfrw.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "8" = "avgui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "9" = "avgtray.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "10" = "avgscanx.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "11" = "avgcfgex.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "12" = "avgemc.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "13" = "avgchsvx.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "14" = "avgcmgr.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "15" = "avgwdsvc.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Home Malware Cleaner"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe
To open registry editor click Start > Run > type "regedit".
Warning! Manual registry entries editing may cause damage to your system.
Download Uniblue RegistryBooster 2010 to scan for registry errors. -
Search and delete these Home Malware Cleaner related files:
%AppData%\Home Malware Cleaner\
%AppData%\Home Malware Cleaner\cookies.sqlite
%AppData%\Home Malware Cleaner\Instructions.ini
%AppData%\Home Malware Cleaner\ScanDisk_.exe
%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Malware Cleaner.lnk
%CommonAppData%\79b35\
%CommonAppData%\79b35\HMa76.exe
%CommonAppData%\79b35\HMC.ico
%CommonAppData%\79b35\6543.mof
%CommonAppData%\79b35\mozcrt19.dll
%CommonAppData%\79b35\sqlite3.dll
%CommonAppData%\79b35\BackUp\
%CommonAppData%\79b35\HMCSys\
%CommonAppData%\79b35\Quarantine Items\
%CommonAppData%\HMJFZWC\
%CommonAppData%\HMJFZWC\HMXBXWJCMC.cfg
%StartMenu%\Home Malware Cleaner.lnk
%StartMenu%\Programs\Home Malware Cleaner.lnk
%UserProfile%\Desktop\Home Malware Cleaner.lnk
%UserProfile%\Recent\ANTIGEN.drv
%UserProfile%\Recent\CLSV.exe
%UserProfile%\Recent\DBOLE.tmp
%UserProfile%\Recent\eb.tmp
%UserProfile%\Recent\energy.tmp
%UserProfile%\Recent\exec.drv
%UserProfile%\Recent\fix.drv
%UserProfile%\Recent\grid.exe
%UserProfile%\Recent\PE.drv
%UserProfile%\Recent\PE.exe
%UserProfile%\Recent\PE.tmp
%UserProfile%\Recent\SICKBOY.tmp
%UserProfile%\Recent\tempdoc.drv
%UserProfile%\Recent\tempdoc.sys
%UserProfile%\Recent\tjd.drv


February 21st, 2012 13:25
[...] Malware Defender is a fake security tool which is also a copy of Home Malware Cleaner malware. As common for malware, Strong Malware Defender also spreads via trojan horse. Trojan [...]