AV Protection Online can be removed first by stopping its processes ([random].exe) and then kill its files by using Emsisoft HiJackFree. Then the user has to remove all the related files and folder. Finally, restore the registry entries added and modified by AV Protection Online (Read the removal guide below to remove AV Protection Online successfully).
When AV Protection Online is installed, AV Protection Online will be configured to start automatically installing a file called [random].exe. Once Windows is started, [random].exe will automatically be launched, which will then start the main executable for this infection.
AV Protection Online should be removed immediately!
Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe
Delete Registry
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable=00000001"
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer=http=127.0.0.1:53717"
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections "DefaultConnectionSettings=3C0000000B0000000…"
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections "SavedLegacySettings=3C0000006B0000000…”
HKEY_LOCAL_MACHINE\system\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable=00000001"
Remove Folders and Files
%Documents and Settings%\[UserName]\Start Menu\Programs\AV Protection Online
%Documents and Settings%\[UserName]\Desktop\AV Protection Online.lnk
%Documents and Settings%\[UserName]\Local Settings\Temp\[random].tmp
%Documents and Settings%\[UserName]\Application Data\ldr.ini
%Documents and Settings%\[UserName]\Application Data\[random]
%Documents and Settings%\[UserName]\Start Menu\Programs\AV Protection Online
%Windows%\system32\[random].exe
%AppData%\[random]
No comments:
Post a Comment