Name: AntivirusPlasma
Version: 1.3.1
Risk Impact: Medium
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000
Behavior: AntivirusPlasma is a misleading application that may give exaggerated reports of threats on the computer.
TECHNICAL DETAILS
The program reports false or exaggerated system security threats on the computer.
The user is then prompted to pay for a full license of the application in order to remove the threats.
Installation
When the program is executed, it creates the following files:
* %UserProfile%\Start Menu\Programs\Antivirus Plasma\Antivirus Plasma.lnk
* %ProgramFiles%\Antivirus Plasma\Antivirus.exe
Next, the program creates the following registry entry so that it executes whenever Windows starts:
HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\"avpl" = "C:\Program Files\Antivirus Plasma\Antivirus.exe"
It also creates the following registry subkey:
HKEY_CURRENT_USER\Software\Antivirus Plasma
REMOVAL
1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.
To delete the value from the registry
Important: We strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only.
1. Click Start > Run.
2. Type regedit
3. Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Download 3rd party registry editor, install and run the tool, and then continue with the removal.
4. Navigate to and delete the following registry entry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"avpl" = "C:\Program Files\Antivirus Plasma\Antivirus.exe"
5. Navigate to and delete the following registry subkey:
HKEY_CURRENT_USER\Software\Antivirus Plasma
6. Exit the Registry Editor.
____________________
















































