Monday, July 1, 2013

Pricegong malware removal. How to stop PriceGong popups

Pricegong popup virus is a harmful win32 adware infection which is used to deliver Spam content. As soon as your computer has been invaded by Pricegong malware, you will start seeing countless pop-ups on screen. All these popups are third-party paid advertisements associated with the account of the person behind Pricegong virus. Each time the ads are clicked, that malware creator gets paid.
Pricegong malware can get into a computer either downloaded by user or it may come binded with freeware programs. Anyhow, whatever the procedure it used to enter, it will instantly register itself as a browser extension/toolbar and modify default DNS settings in Firefox, Chrome or Internet Explorer. After this, you may experience several strange and annoying activities such as searching on Google leads to wrong websites or Pricegong.com, unwanted pop-up advertisements start appearing out of nowhere, extremely slow down browser and system speed and frequent crashes, etc. Pricegong malware can also record your online activities, collect your personal information and share the stolen data with hackers. You have to uninstall Pricegong pop-up malware immediately before it leads to a big trouble.
Disadvantages and risks of having Pricegong virus:
  • It may change & corrupt default settings of browsers like Firefox, Chrome or Internet explorer
  • Changes home page and displays unwanted pop-ups advertisements
  • Causes frequent web redirects to wrong websites, hijacks search engine settings and leads to unexpected webpages
  • Keeps record of browsing activities and interests
  • Collects Personal user information which may include sensitive financial data such as logins, usernames, accounts
  • It may bring further infections are direct the user to infectious sites
  • Makes the browser run slow, uses a big part of system resources

Want to get rid of Browser Hijack Pricegong malware ads?:
To manually remove Pricegong plugin, follow the instructions.
First of all, Uninstall the program. (Skip to the next step if the application is not listed in Control Panel).
“Start > Settings > Control Panel. Now Locate and open “Add or Remove Programs” or “PROGRAMS AND FEATURES”. Find “Pricegong plugin”. Now click Uninstall/Remove.
Now remove the program from Browser.
Internet Explorer users:
Click “Tools” (if on Internet Explorer 9, click gear icon), Then “Manage Add-ons”. Look for Pricegong plugin. Disable if found any.
Block pop-ups of Pricegong plugin
To stop pop-ups from malware,
Click on TOOLS > POP-UP BLOCKER, then click TURN ON POP-UP BLOCKER. and then go to POP-UP BLOCKER SETTINGS. (Type any website you wish to block popups from)



Still Spyware Pricegong virus lurking in the system? Remove manually
Stop processes of this malware:
Open Task Manager to stop processes.
Remove associated registry settings:
HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook
HKEY_LOCAL_MACHINE\software\classes\urlsearchhook.toolbarurlsearchhook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions,
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0
Delete Pricegong plugin infected files:
%Profile%\Local Settings\Temp\
%ProgramFiles%\
%UserProfile%\

No comments:

Post a Comment