Antivirus System provide fake features such as System Scanner, Internet Security, Privacy Security, Proactive Defence, Firewall, Update Database and Configuration. It shows that a lot of files in the computer are infected by trojan, dialer, spyware and so on. It also provide the descriptions of the trojan, dialer, spyware and so on.
Antivirus System can be removed by stop processes and kill all files with random name in the hard drives. The user also must remove the autorun setting added by Antivirus System. These can be done by using Emsisoft HiJackFree.
Antivirus System should be removed immediately!
Antivirus System Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe
Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pavsdata
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = "application/x-m"
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = ""%CommonAppData%\pavsdata\[number].1.exe" /ex "%1" %*"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "avsdsvc" = "%CommonAppData%\pavsdata\[number].1.exe /min"
HKEY_CLASSES_ROOT\.exe "(Default)" = "[random]"
HKEY_CLASSES_ROOT\.exe "Content Type" = "application/x-m"
Remove Folders and Files
%CommonAppData%\pavsdata
%CommonStartMenu%\Programs\Antivirus System
Antivirus System should be removed immediately!
Antivirus System Removal Guide
Kill Process
(How to kill a process effectively?)
[random].exe
Delete Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pavsdata
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = "[random]"
HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = "application/x-m"
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = "%1"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = ""%CommonAppData%\pavsdata\[number].1.exe" /ex "%1" %*"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "avsdsvc" = "%CommonAppData%\pavsdata\[number].1.exe /min"
HKEY_CLASSES_ROOT\.exe "(Default)" = "[random]"
HKEY_CLASSES_ROOT\.exe "Content Type" = "application/x-m"
Remove Folders and Files
%CommonAppData%\pavsdata
%CommonStartMenu%\Programs\Antivirus System
No comments:
Post a Comment