|
| How to remove AndromedaAV |
|
| Author:AndromedaAV Hits: UpdateTime:2008-8-29 9:48:40 |
|
|
For remove AndromedaAV virus,please clean/delete all AndromedaAV infected files and Delete/Modify any values AndromedaAV added to the registry as following:
Behavior The program must be manually installed.
The program reports false or exaggerated system security threats on the computer.
The user is then prompted to pay for a full license of the application in order to remove the threats.
Installation When the program is executed, it creates the following files:
- C:\Documents and Settings\All Users\Desktop\Andromeda AntiVirus.lnk
- %ProgramFiles%\AndromedaAv\av.exe
- %ProgramFiles%\AndromedaAv\DataBases\avd.avp
- %ProgramFiles%\AndromedaAv\DataBases\avhd.avp
- %ProgramFiles%\AndromedaAv\DataBases\avhd1.avp
- %ProgramFiles%\AndromedaAv\DataBases\avm.avp
- %ProgramFiles%\AndromedaAv\DataBases\av_nav_hd.avp
- %ProgramFiles%\AndromedaAv\DataBases\av_nav_m.avp
- %ProgramFiles%\AndromedaAv\Logs\08-2008_AndromedaAvLog.log
- %System%\dllcache\crasctrs.dll
- %System%\dllcache\tnetlogon.dll
- %System%\drivers\winav.sys
- %System%\andrav_inet.dll
- %System%\AndromedaAv.exe
- %System%\bpsnppagn.dll
- %System%\hir50_qcx.dll
- %System%\rqcap.dll
- %System%\settings
- %System%\thunk.dll
- %System%\vCleanUp.exe
Next, the program modifies the following registry entry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page" = "http://andromeda-av.com"
It also creates the following registry subkeys:
- HKEY_CLASSES_ROOT\*\shell\AV
- HKEY_CLASSES_ROOT\Folder\shell\AV
- HKEY_LOCAL_MACHINE\SOFTWARE\AndromedaAv
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AndromedaAVService
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AndromedaAvDrv
For successful remove AndromedaAV virus,you may also need do as following:
1. Temporarily Disable System Restore .
2. Update the virus definitions. Reboot computer in SafeMode;
3. Delete the IE temp files,some AndromedaAV temp file exisit there.
4.If you failed to remove AndromedaAV,please go to our remove help forum:http://help.antiviruses123.com
|
| End Of The Article How to remove AndromedaAV remove process |
|
Bloodhound.Exploit.280 ProtectDefender ArmorDefender DefendAPc Ghost Antivirus Trojan.FakeAV!gen16 Bloodhound.PDF.20 Trojan.Zbot Trojan.FakeAV!gen14 Trojan.Vundo!gen3 Trojan.Vundo!gen4 W32.Changeup!gen Trojan.Skintrim!gen2 PasswordRevealer Trojan.Hydraq!gen1 Trojan.FakeAV!gen15 Trojan.Hydraq Bloodhound.Exploit.289 Trojan.Bredolab!gen6 Trojan.Malscript.B Trojan.FakeAV!gen13 PCAntiMalware removal… Bloodhound.PDF.11 EXEDropper removal in… Bancos LOQ removal in… Norton Anti-Virus 2007… MalwareCleaner Vundo BUK removal ins… Banker btt removal in… Top Antivirus removal… AV Antispyware remova… Banker JR removal ins… Antivirus Agent Pro r… Trojan.Regsubdat.A Droplet EU removal in… Trojan.Ransomlock W32.Dizan.F AdRotator 2.0 removal… Trojan.Bankpatch.D Banker JI removal ins…
|