UnHackMe
•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  Outsourcing
UnHackMe
UnHackMe - First BootWatch AntiRootkit
 UnHackMe     Entire site
Choose one
For home users

Professional - for anticrime squad

Roaming - for admins

Corporative - for small and large business

Education

Info
Benefits

ScreenShots

How it works

Download

Rootkit Testing

FAQ

UnHackMe for beginners...

One-click purchase
UnHackMe Single

UnHackMe Family

UnHackMe Business

UnHackMe Family+Business

UnHackMe Roaming

UnHackMe Pro

Download trial
UnHackMe
Forums
Greatis Forum

Home Download Order Support Press Room   Newsletter Your shopping cart ?
How to remove cnprov.sys related to Baidu rootkit

Baidu search toolbar allows using Chinese domain names during browsing web sites.
All information about visited web sites are collected and may be used by the manufacturer of the toolbar.
What's wrong?
The toolbar is useless for non-Chinese users and we don't know why the different web sites offer to download this software.
Baidu software doesn't hide their files and registry keys.

But the Baidu kernel driver "cnprov.sys" prevents the Baidu's files and registry keys from deletion.
A user has a right to uninstall toolbar using included uninstaller.

cnprov.sys
It looks good but I don't like that the simple toolbar uses the kernel driver that hooks the registry and files operations on the kernel level.

Each kernel driver decreases performance and increases the risk of BSOD. The kernel drivers are good for hardware devices or in the antiviral software. But it is absolutely not allowed for standard Windows software.
Why the Baidu uses the kernel driver in this version of this software?
The answer is one. It's hard in removal and some of the users couldn't do it.
They will be under the Chinese watch or they need to format their computers. Annoying procedure isn't?


UnHackMe detects and removes Baidu software.


Removal

UnHackMe detects the "cnprov.sys" driver and it removes the driver from the registry at the next reboot.

But you need to repeat the deletion procedure at next check. This why the driver is already loaded in memory.

We need using reboot to unload the driver.

Also, we need to remove idnsvr.exe and cnprovh.dll from Windows startup.

After that we can simply delete Program Files\OCINS subfolder and the %SysDir%\cnprov.dat.

Purchase
UnHackMe

Supported Windows NT4/2000/XP(64)/2003(64)/Vista.

Compatible with all known antiviral software.

Free updates. On-line support.

System Requirements.

What's new?
August 28 2008
Released UnHackMe 4.8 Russian Edition
Free for non-commercial use! Download

July 18 2008
UnHackMe 4.8 release
wwe Free for registered users! Download

February 14 2008
UnHackMe 4.7 release

December 19 2007
UnHackMe 4.6 release

October 17 2007
UnHack your computer!

October 8 2007
Rootkit Removal using UnHackMe - Master Class

September 19 2007
UnHackMe Russian Edition 4.5 released for free

September 11 2007
UnHackMe 4.5 release

Read the press release

See the rootkit tests

Educational discount...

Rootkit Tests
Spooldr rootkit is No 1 in August

See more...

Send us a rookit
Rename your file to the "txt" extension.

File Search

They say
If your tool had not worked, I was going to rebuild my disk from scratch, loading all my apps, downloads, etc. This would have cost me probably 2 days of work.

Great news! What I did last night with UnHackMe just stumbling around the system has cleared the problem!!

I can't tell you how delighted I am.

All the best... Dave Gardner

Testimonials
Bob Schmulian:
Absolutely love it and have recommended to many people!

Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since I purchased it less than 6 months ago. I now would not run my system without it... it's worth many times the cost! The service and support are terrific. Helpful - friendly - and accommodating; and generally a reply is received within 12 hours. Just great.

Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.

Awards
Paul's Picks
Shareware Winner  

More...


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | Outsourcing

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2008 Greatis Software

eXTReMe Tracker