AntivirusPro
Last Updated on Friday, 15 January 2010 13:26 Wednesday, 15 July 2009 04:34
AntivirusPro is reported to be a rogue application. There are several ways for a fake/rogue application to enter into your computer.
Recently I have noticed that the malware authors are also keeping track of the removal instructions published on the internet. As soon as they think that the malware is exposed, they change the file/folder names and the locations where they are saved on the hard disk. So keeping this in mind you will require the latest information of the malware in order to be able to remove it. You can see the analysis report of
|
Trying system restoreIf you know the duration since your computer is infected, you can try to restore your computer at a prior date, that will work like a miracle in removing the infection
|
Using free removal tools
|
Removing files manuallyThe steps to be taken to remove the infected files manually |
View Hidden Files Before you could delete AntivirusPro and its associated files you need to search for them, and before doing that you need to enable to view hidden files and folders
|
Boot in safe mode If you are not able to delete the files and folders of this rogue application, in that case you should boot in safe mode and then try to delete it.
|
Remove Processes from Task Manager Press Ctrl Shift Esc to open Task Manager. See in the list of the processes for a processe/s named AntiVirus_Pro.exe or Antivirus Pro.exe, select if found and press the End Process button, confirm and then close the Task Manager.Optionally you can use Windows Defender to see the path of a currently running program/ process and its publisher, so as to differentiate malware processes from windows genuine processes.
|
Removing entry from windows startup The system configuration can be started in xp and in vista by typing msconfig in the run box/ start menu search box. In xp by clicking on Start > run . The windows startup is reversible, therefore you can check / uncheck any entry from windows startup any number of times. After the system configuration utility window is open, Click on the Startup tab, that will list all the programs that are scheduled to start when you turn your computer On. Expand the middle column using your mouse pointer so that you can see the path of the program on the hard disk, that will give you a clear idea, what program that is. Locate and uncheck the entries if found "Antivirus Pro" (look for any suspicious name) Press Apply , Press Close/Ok , at the next prompt select "Restart the computer" |
Unregister DLL The first variation (antivirus_pro) saves a dll file in the location C:\Windows\system32\MSVolume.dll Therefore you need to unregister it first before deleting it from the hard disk. To do that, Click on Start > Run (in XP, whereas in Vista you can use the box that is already open) Now type the following, or copy paste the command below |
Delete Folder The first variation creates following folders delete these folders if found. It is also found that it creates the following files in legitimate windows folders (in order to delete the files in the temp folder, it will be helpful to run a freeware temp files cleaner like CCleaner) %Windir% By default C:\Windows\ %System% is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP). %AppData% is C:\Documents and Settings\[UserName]\Application Data. |
Run CCleaner Even if you manage to find and delete Antivirus Pro and its associated files , there will be leftover entries in the windows registry. If you run a free temp files/registry cleaner called CCleaner, that will help you to automatically clean the registry from the virus entries as well as the temp folder . Click here to read more |
Edit registry If you are comfortable with regedit. You can edit the registry by using the windows built in registry editor. Click here to read more The registry keys are given fore Variation1) report Variation2) report |
More ProblemsIf you are unable to open Task Manager, registry editor, system restore, Folder Options etc If the virus has disabled them. There are free tools and techniques to solve this problem. They are listed here. Tools for Windows XP Tools for Windows Vista Using the system file checker If the windows is not functioning normally, you need to make sure if the genuine windows system files are not altered by the virus, you can use the system file checker utility to find it out and in case if they are altered then to repair them. See the appropriate link for your version of windows.
Unable to access security related sites It can happen if your Hosts file has been altered. To repair/ edit the hosts file. Login as administrator. open the following file in notepadC:\ WINDOWS \system32 \drivers \etc \hosts remove anything other than 127.0.0.1 Localhost, and save and close the file. Using Firewall Check your firewall for any suspicious communication from your computer to the internet and block it using firewall. |
| Reference of threatexpert reports with permission from threatexpert.com |

Sanjay C Rajure