What is CaptureItPlus?
CaptureItPlus is open source software that allows you to capture computers’ screen in various modes (Active window, fixed region, etc.). It is a useful application, but recently it has been injected with malware in an attempt to extort valuable information from users. The main reason for this scheme is to gain access to user’s bank account. Therefore, it is very important to learn how it works and how to protect yourself, because it might happen to you. If you have the CaptureItPlus version with a modified source code, you should use our removal instructions below the article and delete it immediately.
How does CaptureItPlus work?
While using the CaptureItPlus that's source code is modified, you will receive a notification that looks like a report from the McAfee antivirus application. To make it clear, the notification is fake and it only imitates the McAfee software looks. So, if you do not panic and look at it carefully you will see a few things, which proves the notification is fraudulent. For starters, the report will say that suddenly your computer got infected with Trojans and other malware, which can be suspicious. Then it will display a telephone number which is supposed to connect you with a support team. Conveniently, it says that the given phone number is toll-free, but that could be a lie too. This is very unusual for a legitimate antimalware program to rush you into calling them for any detections. Usually, the security tool itself removes malware automatically or suggests upgrading your current version if it is a limited one. It seems like there is a link to get the full McAfee protection, but you cannot click this element or any other button. The criminals behind this scheme are trying to scare you, but you should not give in. If you called this number, they would find ways to make you reveal sensitive information such as credit card PIN numbers, passwords, etc. As a result, they could gain access to your bank account and steal your savings.
Due to the fact that the CaptureItPlus is an open source program, it is possible for anyone to change and distribute it anywhere. Meaning that the original application can be downloaded only from the official website. So if you want to keep the program, you should delete the current one and download it again from captureitplus.codeplex.com.
How to remove CaptureItPlus?
Sadly, it is not possible to delete this program simply via Control Panel. Therefore, you will have to work a little harder if you want to get rid of the infected application and scary notification. Firstly, you should remember the folder where you saved the CaptureItPlus installer file, because as you launched it, another executable file was created in the same directory. It is crucial to find this file and erase it, but it should not be difficult, because it will have the same icon as the installer. The next step would be to remove the remaining files and folders that appeared after installation. You will find more detailed removal steps below the article. Follow them carefully and you should not have any trouble. Also, you can leave us a comment if you have any questions regarding CaptureItPlus.
Delete CaptureItPlus from your computer
- Locate CaptureItPlus installer in this path: C:\Users\[unique user name]\Download.
- Find second executable file with identical icon to CaptureItPlus installer.
- Right-click on executable file and select delete to erase it.
- Remove the installer same way.
Erase CaptureItPlus files and folders
- Press Windows Key+R to launch RUN.
- Copy and insert the listed directories one at a time:
%UserProfile%\Local Settings\Application Data
- Locate these folders: gltstech.net, PopupAlert.
- Right-click to delete them.
Remove CaptureItPlus keys from Windows Registry
- Launch the RUN (Windows Key+R).
- Type regedit and press OK.
- Navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PopupAlert.
- Right-click on PopupAlert key and click Delete.
tested removal of CaptureItPlus*100% FREE spyware scan and