How to remove SysinternalsAntivirus
SysinternalsAntivirus description
SysinternalsAntivirus is a misleading application which is also a copy of such malwares as Your PC Protector and AKM Antivirus 2010 Pro. All these applications are fraudulent and malicious. SysinternalsAntivirus gains to pilfer money from unwary users. One and the most common malware’s property is to scan your computer automatically after the PC is started. Furthermore, it displays rogue scan results stating your computer is at the highest security risk.
You do not need to panic. These security threats are fictitious. The best you can do is to ignore those fake reports. This rogue anti-spyware program will suggest you to pay small fees for “full” version of SysinternalsAntivirus. It is all scam. We recommend you to remove the parasite quickly.
How to get rid of SysinternalsAntivirus
This infection can be removed using Spyware Doctor.
Spyware Doctor is widely valued as one of the best AntiSpyware programs available to protect you from SysinternalsAntivirus and the latest internet security threats. If your computer is infected with SysinternalsAntivirus we strongly recommend automatic spyware scanner.
How to manually remove SysinternalsAntivirus
To get rid of spyware such as SysinternalsAntivirus you need to remove processes, search and delete registry keys, DLL and other SysinternalsAntivirus related files from your computer.
Take Note: The manual process of removing spyware from your computer is difficult and puts you at risk of damaging your computer. We advise using our automatic SysinternalsAntivirus remover.
- Uninstall SysinternalsAntivirus from Control Panel
Start > Settings > Control Panel > Add/Remove Programs. Double click to uninstall. - End these SysinternalsAntivirus processes:
alggui.exe
svchost.exe
dbsinit.exe
Sysinternals Antivirus.exe
ccsmn.exe
ccsrr.exe
To stop processes press Ctrl + Alt + Del or click Start > Run > type "taskmgr". Select malicious process in the list and click "End Process" button. -
Unregister SysinternalsAntivirus DLL files:
adc_w32.dll
To unregister DLL click Start > Run > type "regsvr32 /u PATH_TO_FILE/FILE.dll" -
Delete SysinternalsAntivirus registry entries:
HKEY_CURRENT_USER\Software\Sysinternals Antivirus
HKEY_CLASSES_ROOT\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavapp"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavappr"
To open registry editor click Start > Run > type "regedit".
Warning! Manual registry entries editing may cause damage to your system.
Download Uniblue RegistryBooster 2010 to scan for registry errors. -
Search and delete these SysinternalsAntivirus related files:
c:\Program Files\adc_w32.dll
c:\Program Files\alggui.exe
c:\Program Files\extra1.dat
c:\Program Files\extra2.dat
c:\Program Files\nuar.old
c:\Program Files\skynet.dat
c:\Program Files\svchost.exe
c:\Program Files\wp3.dat
c:\Program Files\wp4.dat
c:\Program Files\scdata
c:\Program Files\scdata\dbsinit.exe
c:\Program Files\scdata\wispex.html
c:\Program Files\scdata\images
c:\Program Files\scdata\images\i1.gif
c:\Program Files\scdata\images\i2.gif
c:\Program Files\scdata\images\i3.gif
c:\Program Files\scdata\images\j1.gif
c:\Program Files\scdata\images\j2.gif
c:\Program Files\scdata\images\j3.gif
c:\Program Files\scdata\images\jj1.gif
c:\Program Files\scdata\images\jj2.gif
c:\Program Files\scdata\images\jj3.gif
c:\Program Files\scdata\images\l1.gif
c:\Program Files\scdata\images\l2.gif
c:\Program Files\scdata\images\l3.gif
c:\Program Files\scdata\images\pix.gif
c:\Program Files\scdata\images\t1.gif
c:\Program Files\scdata\images\t2.gif
c:\Program Files\scdata\images\Thumbs.db
c:\Program Files\scdata\images\up1.gif
c:\Program Files\scdata\images\up2.gif
c:\Program Files\scdata\images\w1.gif
c:\Program Files\scdata\images\w11.gif
c:\Program Files\scdata\images\w2.gif
c:\Program Files\scdata\images\w3.jpg
c:\Program Files\scdata\images\word.doc
c:\Program Files\scdata\images\wt1.gif
c:\Program Files\scdata\images\wt2.gif
c:\Program Files\scdata\images\wt3.gif
c:\Program Files\Sysinternals Antivirus
c:\Program Files\Sysinternals Antivirus\Sysinternals Antivirus.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.acf
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.ltd
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.lti
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.acb
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.aci
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.mt
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\lleod150
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmharun.log
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmrun.log
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk


July 6th, 2010 00:04
Man, they nailed me for $92.85! Wonder if I can get my money back?
[Reply]
August 6th, 2010 11:35
[...] that come from fake antispyware online scanners. It is also a copy of Windows Antivirus Pro and Sysinternals Antivirus rogue applications. Once installed Wireshark Antivirus starts its malicious activities. However, [...]