Home    Forum    Search    FAQ    Register    Log in
Post new topic  Reply to topic Page 1 of 1
 
AntivirusPlasma
Author Message
Reply with quote
Post AntivirusPlasma 
 
Type: Misleading Application
Name: AntivirusPlasma
Version: 1.3.1
Risk Impact: Medium
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000
Behavior: AntivirusPlasma is a misleading application that may give exaggerated reports of threats on the computer.

TECHNICAL DETAILS

The program reports false or exaggerated system security threats on the computer.

Image


The user is then prompted to pay for a full license of the application in order to remove the threats.

Image


Installation

When the program is executed, it creates the following files:

* %UserProfile%\Start Menu\Programs\Antivirus Plasma\Antivirus Plasma.lnk
* %ProgramFiles%\Antivirus Plasma\Antivirus.exe


Next, the program creates the following registry entry so that it executes whenever Windows starts:

HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\"avpl" = "C:\Program Files\Antivirus Plasma\Antivirus.exe"

It also creates the following registry subkey:

HKEY_CURRENT_USER\Software\Antivirus Plasma


REMOVAL

   1. Disable System Restore (Windows Me/XP).
   2. Update the virus definitions.
   3. Run a full system scan.
   4. Delete any values added to the registry.

To delete the value from the registry

Important: We strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only.

   1. Click Start > Run.
   2. Type regedit
   3. Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Download 3rd party registry editor, install and run the tool, and then continue with the removal.

   4. Navigate to and delete the following registry entry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"avpl" = "C:\Program Files\Antivirus Plasma\Antivirus.exe"

   5. Navigate to and delete the following registry subkey:

HKEY_CURRENT_USER\Software\Antivirus Plasma

   6. Exit the Registry Editor.





____________________
The more you lose yourself in something bigger than yourself, the more energy you will have!!
Offline Yahoo Messenger View user's profile Send private message Visit poster's website
Download Post Back to top Page bottom
Display posts from previous:   
HideWas this topic useful?

 

You are not authorized to rate this topic

Average Rate Minimum Rate Maximum Rate Number Of Rates
0.00 0 0 0
Share this topic
blinkslist.com blogmarks.net co.mments.com del.icio.us digg.com newsvine.com facebook.com fark.com feedmelinks.com furl.net google.com linkagogo.com ma.gnolia.com meneame.net netscape.com reddit.com shadows.com simpy.com slashdot.org smarking.com spurl.net stumbleupon.com technorati.com favorites.live.com yahoo.com DIGG ITA Fai Informazione KiPapa Ok Notizie Segnalo

Post new topic  Reply to topic  Page 1 of 1
 

Users browsing this topic: 0 Registered, 0 Hidden and 1 Guest
Registered Users: None


 
Permissions List
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum
You cannot post calendar events in this forum