How to remove Antivir Solution Pro rogue anti-spyware

Malware Description:
Antivir Solution Pro (aka Antivir Solution) is an extremely aggressive program that inherits all the worst traits of AV Security Suite rogue security software. Once Antivir Solution Pro came into active rotation, it invaded thousands of computers within one night. Such unbelievable propagation rate is explained by the fact that the hackers who are responsible for Antivir Solution Pro malvertising are really good at blackhat SEO and fraudulent social engineering. So you should beware as there is a trojan virus around these days which is distributing the trial version of Antivir Solution Pro malware. If this scareware manages to break through your system authentication, it will promptly change some of your system settings and modify the Registry. If all goes well for the rogue, it will completely take over your computer. Since there will be a new startup entry, Antivir Solution Pro will be launched every time you start your workstation. A new boot-up will be followed by a new scanner from Antivir Solution Pro – of course, a bogus one reporting dozens of highly dangerous items on your computer. This scareware will be additionally issuing tons of popup warnings and infiltration alerts that claim your system has been compromised by trojans like BankerFox.A or Win32/Nuqel.E (which are not there in fact). This is all being done for you to start believing you actually have multiple computer problems to take care of and click on the corresponding buttons linking to Antivir Solution Pro payment processor page. In other words, the hackers want you to buy their offspring, so you’d better be smarter than them. So be sure to abstain from purchasing Antivir Solution Pro on any of its affiliate websites. It’s also critical to remove this nasty utility before it gets too deep into your Operating System and devours it from the inside.
Here are some tips to help you out with that. Once you start your computer, you got a few seconds before Antivir Solution Pro loads and makes your PC trigger its executable. So once you reboot, you should quickly do the following:
- Click ‘Start’ menu and choose ‘Run’ there. Then, type ‘msconfig’ (without quotes) in the command line there. You should now see a system configuration GUI that has a couple of tabs.
- Please select ‘Startup’ tab. Under ‘Startup’, you must find the process being exploited by Antivir Solution Pro. As a rule, it is a process that has an Unknown publisher (it’s mentioned next to it in that window), ending in tssd. So on ‘Startup’ tab, try finding something with Unknown publisher or some suspicious process, possibly one that has tssd symbols in the end of it.
You should now untick this process (processes), save the changes and exit the ‘msconfig’ window. Windows OS will prompt you to restart the machine so go ahead and agree. After reboot, Antivir Solution Pro will not be launched because we had disabled it on the Startup list. It’s still inside your computer though so you need to remove all of its files, each one of them otherwise the malware will find a way to keep destroying your PC. This is why please follow the instructions listed below for Antivir Solution Pro complete removal.
Also, in case your Internet connection has been disabled by Antivir Solution Pro malware, please do the following to restore it. Open Internet Explorer, go to ‘Tools’, click ‘Internet Options’, then ‘Connections’, ‘Lan settings’. Now, if the ‘Use a proxy server for your LAN’ option is selected, go ahead and unselect it. Or you can choose the ‘Automatically detect settings’ option. Save the changes and restart Internet Explorer – you should be back online now.

Malware Type: Rogue Anti-Spyware

Malware Author: Antivir Solution Inc.

Threat Level: Critical

Advice: Immediately remove and scan for additional malware

Antivir Solution Pro Free Scanner and Remover: Download Now

Antivir Solution Pro Screenshot:

Antivir Solution Pro

How to remove Antivir Solution Pro manually:
Manual removal of Antivir Solution Pro is a feasible objective if you have sufficient expertise in dealing with program files, processes, .dll files and registry entries.

The files to be deleted are listed below:

  • %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string].exe

The registry entries that need to be removed are as follows:

  • HKEY_CURRENT_USER\Software\AVSolution
  • HKEY_CURRENT_USER\Software\AVSuitE
  • HKEY_LOCAL_MACHINE\SOFTWARE\AVSolution
  • HKEY_LOCAL_MACHINE\SOFTWARE\AVSuitE
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5643″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “

Please, be aware that manual removal of Antivir Solution Pro is a cumbersome process and does not always ensure complete deletion of the malware, due to the fact that some files might be hidden or may get reanimated automatically afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal Antivir Solution Pro, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.

Download Antivir Solution Pro Automatic Remover

Like This Article? Let Others Know!

Reader's Comments:

  1. www.FarhangOnline.com |

    First, thank you for the very useful information.
    Second, we did not find the exe-file under
    %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string].exe

    but we found it under
    documents and settings\networkservice\local settings\application data\[random string]\[random string].exe

    Regards,
    Farhangonline.com

  2. www.FarhangOnline.com |

    You need also to replace or clean up the HOST file in the Windows folder.

  3. m |

    great stuff — thanks a lot.

Post a Comment: