{"id":90589,"date":"2019-02-09T22:40:33","date_gmt":"2019-02-09T19:40:33","guid":{"rendered":"http:\/\/greatis.com\/blog\/how-to\/remove-atabencot-net-virus.htm"},"modified":"2019-02-09T22:40:33","modified_gmt":"2019-02-09T19:40:33","slug":"remove-atabencot-net-virus","status":"publish","type":"post","link":"https:\/\/greatis.com\/blog\/guide-how-to\/remove-atabencot-net-virus.htm","title":{"rendered":"Remove ATABENCOT.NET virus"},"content":{"rendered":"<div class=\"wpInsert wpInsertInPostMy wpInsertAbove\" style=\"padding: 0px;\"><\/div><a name=\"whatis\"><\/a><div class=\"intro description\"><h1><img class=\"icenter\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/question-red.png\"> What is ATABENCOT.NET?<\/h1>\n\r\n\r\n  <div class=\"macbook\">\r\n  <div class=\"screen\">\r\n   <a href=\"http:\/\/greatis.com\/unhackme\/download.htm?pk_campaign=blog&pk_kwd=topimg\"> <div class=\"viewport\"><img src=\"https:\/\/greatis.com\/blog\/wp-content\/uploads\/2019\/02\/remove-atabencot.net.png\" alt=\"Remove ATABENCOT.NET push notification virus\" class=\"responsive-img\" \/><\/div><\/a>\r\n  <\/div>\r\n  <div class=\"base\"><\/div>\r\n  <div class=\"notch\"><\/div>\r\n<\/div>\r\n\r\n  \r\n  <p class=\"imgcaption\">ATABENCOT.NET push notification virus<p><strong>ATABENCOT.NET<\/strong> is a web site, used social engineering tricks, to subscribe you to get its browser push notifications.Later you will see ATABENCOT.NET spam popup-ads directly on your desktop or in your browser.<p>ATABENCOT.NET tells you to click on the <strong>Allow<\/strong> button to grant full access to the Extentive TV & Movies Catalog.<p>Also, ATABENCOT.NET uses another tricks to force you click Allow button<ul><li> Click to install missed video codec.\n<li> Press Allow to close this window.\n<li> Click to confirm that you are not robot.<li> Confirm age: click if you are 18+.<\/ul><p><strong>Do not click Allow<\/strong> in the Show Notifications dialog if you are not fully sure that the web site is trustworthy!<\/div><div class=\"intro description\">ATABENCOT.NET also known as <b>ADWARE.ATABENCOT.NET<\/b>.<p><img class=\"icenter\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/exclamation.png\"> ATABENCOT.NET is able to infect your installed web browsers, including Google Chrome, Microsoft Edge, Safari, Mozilla Firefox and Internet Explorer.<br><div class=\"imggray\"><div class=\"animation swing\"><img class=\"displayed\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/infected_browsers.png\" alt=\"$key infects web browsers\"><\/div><p class=\"imggray\">ATABENCOT.NET infects web browsers.<\/div>ATABENCOT.NET is often found on Windows 10 systems, but it is also discovered on Windows 7,8, and XP.<p>ATABENCOT.NET has a Medium risk level.<br><div class=\"chart-div\"><ul class=\"chart\"> <li> <span style=\"height:50%\" title=\"Medium\"><\/span><\/li><\/ul><\/div>The common symptoms for the ATABENCOT.NET:<ul><li> Ads messages are displayed directly on your desktop.\n<li> Annoyns pop-up ads<li> Advertisement with banners: Ads by ATABENCOT.NET.<\/ul><p><\/div>\r\n<a name=\"howinfected\"><\/a>\r\n<h2>How did you get infected by ATABENCOT.NET virus?<\/h2>\r\n\r\n<div class=\"infe\">\r\n\r\nYou can easily get ATABENCOT.NET virus during searching for a free video, music, keygen, software or photos.\r\nThese sites claims that you will get you a free access to the paid content.\r\nBut they will use your PC for their needs. You will get a lot of ads in your browsers.\r\nThey will offer you to download a free Adblocker (of course, fake software), but use your PC for coin mining, steal your personal information.\r\n\r\n<p>\r\n<div class=\"intro\">\r\nUsers, who have the similar problem, complain about:<ul><li> Unwanted software, installed without user permission.\n<li> Trojans.\n<li> Hidden Coin-miners.<li> Ransomware.<\/ul><p><\/div><\/div>\r\n<a name=\"automode\"><\/a>\r\n<h2>How to easily remove ATABENCOT.NET virus?<\/h2>\r\n\r\nI have enough computer skill to remove virus manually using only my hands and internal Windows utilities.\r\n<p>\r\nBut it takes a lot of time. It's not easy. Use the manual removal instruction it at <a href=\"#manualmode\">your own risk<\/a>.\r\n<p>\r\n\r\nSomeone told me about <b>UnHackMe<\/b>.\r\n<p>\r\nUnHackMe follows the same remove steps, as I do manually. \r\n<p>\r\nBut UnHackMe is better, because it:\r\n<h3><img class=\"icenter\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/unhackme-saves-2-hours.png\"> Works very fast.<\/h3><br>You can save about 2 hours of your life!<h3><img class=\"icenter\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/antivirus-database.png\"> Knows about new virus tricks!<\/h3>It has a large, constantly updated, virus database.<h3><img class=\"icenter\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/unhackme-specials-tools.png\"> Includes powerful tools.<\/h3> \r\n <p>\r\n UnHackMe fixes <strong>access-denied files<\/strong>, cleans <strong>protected registry keys<\/strong>, scans in <strong>off-line Windows mode<\/strong>.\r\n<p>\r\nI asked <strong>Dmitry, author of UnHackMe<\/strong>, some questions and I found that he is a nice gay, always ready to help.\r\n<p>\r\nHe offers a service, called '<b>Help in removal<\/b>'. <h3><img class=\"icenter\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/help-in-removal.png\"> Use Help-In-Removal service<\/h3><br>if you have troubles in virus removal or you afraid to damage your computer just click <strong>Help in Removal<\/strong>.\r\n<p>\r\nUnHackMe is fully free for 30-days without limitations.\r\n<p>\r\n<h3>Why I don't offer an antivirus for malware removal?<\/h3>\r\nAntivirus is <b>good in removing file viruses<\/b>. \r\n<p>\r\nBut the modern malware are <b>fileless<\/b>. \r\n<br>\r\nVirus simply adds its link to your browser and you will see a lot of pop-up ads, redirects, notifications, etc.\r\nAlso, malware uses the legitimate programs to download and execute malicious code.\r\n<p>\r\n<h3>UnHackMe is good in removing Adware\/Fileless malware\/Unwanted programs\/Spyware<\/h3>\r\nUnHackMe was <b>created in 2005<\/b> to remove rootkits - invisible\/stealth viruses.\r\n<br>\r\nNow it removes all types of malicious software.\r\n<p>\r\nYou can check the <a href=\"https:\/\/www.facebook.com\/remove.malware.with.unhackme\">real reviews of UnHackMe on the Facebook<\/a>.\r\n<div style=\"margin-left: 0px;\"><div style=\"margin-left: 0px;\"><a href=\"https:\/\/www.facebook.com\/remove.malware.with.unhackme\/\"><img src=\"https:\/\/greatis.com\/blog\/include2\/fb\/9.png\" border=no><\/a><\/div>\r\n<\/div>\r\n\r\n\r\n\r\n<div class=\"unhackme\">\r\n<h3>Here&rsquo;s how to remove ATABENCOT.NET virus:<\/h3>\r\n<div class=\"steps\">\r\n<p><strong><a href=\"#step1\">STEP 1: Install UnHackMe. (1 minute)<\/a><\/strong>\r\n<p><strong><a href=\"#step2\">STEP 2: Scan for ATABENCOT.NET malware using UnHackMe. (1 minute)<\/a><\/strong>\r\n<p><strong><a href=\"#step3\">STEP 3: Remove ATABENCOT.NET malware. (3 minutes)<\/a><\/strong>\r\n<p><strong><a href=\"#step4\">STEP 4: (optional) Clean up after virus.<\/a><\/strong>\r\n<\/div>\r\n\r\n\r\n\r\n<div class=\"step1s\">\r\n\r\n<a name=\"step1\"><\/a><h3>STEP 1: Install UnHackMe (1 minute).<\/h3>\r\n        <ol>\r\n         <li><a href=\"http:\/\/greatis.com\/unhackme\/download.htm?pk_campaign=blog&amp;pk_kwd=goto\" class=\"font22r\">Download UnHackMe from the official web site.<\/a>\r\n         <br>\r\n         <a href=\"https:\/\/greatis.com\/unhackme\/download.htm?pk_campaign=blog&amp;pk_kwd=step1\" class=\"clear-link hvr-wobble-vertical\"><img src=\"https:\/\/greatis.com\/blog\/include2\/img\/download_unhackme.png\" class=\"responsive-img\" border=\"no\"><\/a>\r\n         <li>Double click on UnHackMe.zip. <br><strong>Unzip all files<\/strong> from the zip to a new folder.\r\n         <li>Double click on the '<strong>unhackme_setup.exe<\/strong>'.\r\n         <p>\r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"start-install\">\r\n             <label for=\"start-install\">\r\n               <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/start-install-unhackme.png\" alt=\"Start installing UnHackMe\" \/>\r\n            <\/label>\r\n          <\/div>\r\n         <\/li>\r\n         <li>You will see a confirmation screen with verified publisher: <strong>Greatis Software<\/strong>.<br>Choose 'Yes'.\r\n        <li>Then you have to accept the license agreement.\r\n        <p>\r\n\r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"license-agreement\">\r\n             <label for=\"license-agreement\">\r\n                 <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/proceed-install-unhackme.png\" alt=\"UnHackMe license agreement\" \/>\r\n            <\/label>\r\n          <\/div>\r\n        <\/li>\r\n\r\n        <li>After that choose a destination folder.\r\n        <p>\r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"choose-folder\">\r\n             <label for=\"choose-folder\">\r\n                <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/choose-install-unhackme.png\" alt=\"Choose destination directory for UnHackMe\" \/>\r\n            <\/label>\r\n          <\/div>\r\n        <\/li>\r\n        <p>\r\n         Complete UnHackMe installation.\r\n        <\/ol>\r\n\r\n<a name=\"step2\"><\/a><h3>STEP 2: Scan for ATABENCOT.NET malware using UnHackMe (1 minute).<\/h3>\r\n <ol>\r\n        <li>First scan will start automatically.\r\n        <p>\r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"scan\">\r\n             <label for=\"scan\">\r\n               <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/scan-virus-with-unhackme.png\" alt=\"Remove malware with UnHackMe\" \/>\r\n            <\/label>\r\n          <\/div>\r\n        <\/li>\r\n<\/ol>\r\n\r\n<a name=\"step3\"><\/a><h3>STEP 3: Remove ATABENCOT.NET malware (3 minutes).<\/h3>\r\n<ol>\r\n        <li>Carefully inspect found items.  \r\n        <br>Malicious items are marked by red shield.\r\n        <br>Suspicious items are yellow.\r\n        <p><strong>UnHackMe automatically creates a System Restore point before fixing!<\/strong>\r\n        <br>It is important to have System Restore active in case of recovering deleted files.\r\n        <p>Next click the red button: <strong>Remove Checked!<\/strong>\r\n        <p> \r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"use-unhackme\">\r\n             <label for=\"use-unhackme\">\r\n               <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/remove-using-unhackme.png\" alt=\"Remove a virus using UnHackMe\" \/>\r\n            <\/label>\r\n          <\/div>\r\n        <\/li>  \r\n\r\n\r\n \t<li><a href=\"http:\/\/greatis.com\/unhackme\/download.htm?pk_campaign=blog&amp;pk_kwd=close\">UnHackMe<\/a> may ask your confirmation to close all browsers.<p><strong>Do it!<\/strong><\/li>\r\n        <li>If you want to quarantine files before deleting, check the box 'Use file safe deleting'. \r\n        <p>\r\n\r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"fix-virus\">\r\n             <label for=\"fix-virus\">\r\n                 <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/fix-virus-with-unhackme.png\" alt=\"Fixing options\" \/>\r\n            <\/label>\r\n          <\/div>\r\n         <\/li>\r\n\r\n        <li>And after all you will see the results of your scanning and fixing process:\r\n        <p>\r\n          <div class=\"container\">\r\n           <input type=\"checkbox\" id=\"fixed\">\r\n             <label for=\"fixed\">\r\n                <img class=\"responsive-img shadowed-img\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/fixed-using-unhackme.png\" alt=\"Finish of removal process!\" \/>\r\n            <\/label>\r\n          <\/div>\r\n        <\/li>  \r\n\r\n<\/ol>\r\n\r\n<\/div>\r\n<\/div>\r\n\r\n<div class=\"additional\">\r\n<a name=\"additional\"><\/a><h3>STEP 4: (optional) Clear your browser cache, delete temporary files, clean Recycle Bin.<\/h3>\r\n<ul>\r\n  <li>If you use Mozilla Firefox as I do, just go to menu Tools and run Options. \r\n      Open Privacy tab and check option 'Clear history when Firefox closes'\r\n  <\/li>\r\n  <p>\r\n<div class=\"container\">\r\n  <input type=\"checkbox\" id=\"zoomCheck\">\r\n  <label for=\"zoomCheck\">\r\n      <img src=\"https:\/\/greatis.com\/blog\/include2\/img\/clear-history-after-remove-malware-virus-firefox.png\" alt=\"clear history after removed malware virus in firefox\" class=\"responsive-img shadowed-img\" \/>\r\n  <\/label>\r\n<\/div>\r\n    <p>\r\n  <li>Then click Settings at this screen and check options 'Cookies' and 'Cache' as shown at picture.<\/li>\r\n  <p>\r\n<div class=\"container\">\r\n  <input type=\"checkbox\" id=\"zoomCheck1\">\r\n  <label for=\"zoomCheck1\">\r\n        <img src=\"https:\/\/greatis.com\/blog\/include2\/img\/clear-cache-firefox-remove-virus.png\" alt=\"clear cache firefox remove virus\" class=\"responsive-img shadowed-img\" \/>\r\n  <\/label>\r\n<\/div>  \r\n    <p>\r\n  <li>After that click OK and close your browser's pages. All information in cache will be removed.<\/li>\r\n  <li>Switch to desktop, find a Recycle Bin icon.\r\n Right click on it and choose \"Clear\".<\/li>\r\n<\/ul>\r\n\r\nSo after all these steps you will have absolutely clean system without any trace of ATABENCOT.NET virus. Start using <a href=\"http:\/\/greatis.com\/unhackme\/download.htm?pk_campaign=blog&amp;pk_kwd=end2\">UnHackMe<\/a> right now to completely protect your PC from malware and unwanted programs!\r\n<\/div>\r\n\r\n<div class=\"manual\">\r\n<a name=\"manualmode\"><\/a>\r\n<h2>How to remove ATABENCOT.NET virus manually?<\/h2>\r\n<ol>\r\n\r\n        <a name=\"notifi\"><\/a>\r\n\t<li>Disable Web Push Notifications in your browser.<\/li>\r\n        <a href=\"https:\/\/info.greatis.com\/manage-notifications-in-browsers\" class=\"clear-link\"><img src=\"https:\/\/greatis.com\/blog\/include2\/img\/chrome-notifications.png\" alt=\"How to Manage Notifications in Your Browsers\" class=\"responsive-img shadowed-img margin-image\" \/><\/a>\r\n        <br><a href=\"https:\/\/info.greatis.com\/manage-notifications-in-browsers\" class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a>\r\n        <a name=\"resetbrow\"><\/a>\r\n        <li>After that, check settings of search and homepage of your browser. Reset them if needed.<\/li>\r\n        <img class=\"responsive-img shadowed-img margin2r\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/set-chrome-search-homepage.png\" alt=\"Set Chrome Search Engine and Homepage\" \/>\r\n        <a name=\"uninstall\"><\/a>\r\n        <li>Check recently installed apps and uninstall unknown apps.<\/li>\r\n        <a href=\"http:\/\/info.greatis.com\/uninstall-program-windows-710\" class=\"clear-link\"><img src=\"https:\/\/greatis.com\/blog\/include2\/img\/uninstall-apps.png\" alt=\"Uninstall Unwanted Apps\" class=\"responsive-img shadowed-img margin-image\" \/>\r\n        <br><a href=\"http:\/\/info.greatis.com\/uninstall-program-windows-710\" class=\"pt-cv-readmore btn btn-success  margin2r-left\">More info...<\/a>\r\n        <a name=\"taskman\"><\/a>\r\n        <li>Open Task Manager and close all unused programs. \r\n        <br>Use the Details tab in the Task amanager.\r\n        <br>Customize columns to display the \"Command line\".\r\n        <br> Virus programs often use random filenames.<\/li>\r\n        <a href=\"http:\/\/info.greatis.com\/how-to-kill-process-using-task-manager\" class=\"clear-link\"><img class=\"responsive-img shadowed-img margin-image\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/close-tasks.png\" alt=\"Close Malware Processes using Task Manager\" \/>\r\n        <br><a href=\"http:\/\/info.greatis.com\/how-to-kill-process-using-task-manager\"  class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a>\r\n        <a name=\"services\"><\/a>\r\n        <li>Stop and disable unknown services. Be careful! Do it only if you are fully sure that you do!<\/li>\r\n        <a href=\"http:\/\/info.greatis.com\/how-to-stop-disable-a-windows-service\" class=\"clear-link\"><img class=\"responsive-img shadowed-img margin-image\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/disable-services.png\" alt=\"Stop and Disable Malware Services\" \/>\r\n        <br><a href=\"http:\/\/info.greatis.com\/how-to-stop-disable-a-windows-service\" class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a>\r\n        <a name=\"tasks\"><\/a>\r\n \t<li>Delete virus scheduled tasks.<\/li>\r\n        <a href=\"http:\/\/info.greatis.com\/delete-scheduled-task\" class=\"clear-link\"><img class=\"responsive-img shadowed-img margin-image\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/remove-scheduled-tasks.png\" alt=\"Remove malicious scheduled tasks\" \/>\r\n        <br><a href=\"http:\/\/info.greatis.com\/delete-scheduled-task\" class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a>\r\n        <a name=\"registry\"><\/a>\r\n \t<li>Find and delete all keys with virus name in it's content.<\/li>\r\n        <a href=\"http:\/\/info.greatis.com\/delete-key-windows-registry\" class=\"clear-link\"><img class=\"responsive-img shadowed-img margin-image\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/win10-registry-delete-key.png\" alt=\"run registry editor to find\" \/>\r\n        <br><a href=\"http:\/\/info.greatis.com\/delete-key-windows-registry\"  class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a>\r\n        <a name=\"shortcuts\"><\/a>\r\n       <li>After that, check shortcuts of your browsers if they have additional addresses at the end of command line. Check if shortcuts runs real browsers, not fakes. Remember: Chromium is fake browser, real name have to be Chrome.<\/li>\r\n       <img class=\"responsive-img shadowed-img margin-image\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/check-shortcut-end.png\" alt=\"check shortcut's end for additional line\" \/>\r\n        <a name=\"plugins\"><\/a>\r\n \t<li>Remove all unused extensions (or plug-ins) in your browsers: Firefox, Internet Explorer, Chrome, etc., if they have our virus name in their names or directory. You may need to uninstall suspisious exgtensions or totally reset your browser.<\/li>\r\n        <a href=\"http:\/\/info.greatis.com\/reset-mozilla-firefox-settings\" class=\"clear-link\"><img class=\"responsive-img shadowed-img margin-image\" src=\"https:\/\/greatis.com\/blog\/include2\/img\/check-plugins.png\" alt=\"check plugins\" \/>\r\n        <br><a href=\"http:\/\/info.greatis.com\/reset-mozilla-firefox-settings\"  class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a>\r\n        <a name=\"dns\"><\/a>\r\n        <li>Next, you have to check your DNS settings. Follow your provider's instructions, delete all unknown DNS addresses.\r\n        <br><a href=\"http:\/\/info.greatis.com\/change-dns-settings\"  class=\"pt-cv-readmore btn btn-success disable-trans margin2r-left\">More info...<\/a> <\/li>\n<div class=\"wpInsert wpInsertInPostMy wpInsertBelow\" style=\"padding: 0px;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>This page contains an easy guide how to remove ATABENCOT.NET redirect virus from Chrome, Microsoft EDGE, Mozilla Firefox and Internet Explorer   <br \/><a style=\"color: #42A2CE\" href=\"https:\/\/greatis.com\/blog\/guide-how-to\/remove-atabencot-net-virus.htm\"><u>More&#8230;<\/u><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[92462],"tags":[94742],"_links":{"self":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/posts\/90589"}],"collection":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/comments?post=90589"}],"version-history":[{"count":0,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/posts\/90589\/revisions"}],"wp:attachment":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/media?parent=90589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/categories?post=90589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/tags?post=90589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}