Saturday, December 13, 2008

AntiVirusPro Ransomware

Removing AntiVirusPro
Categories: Ransomware
A cryptovirus, cryptotrojan or cryptoworm is a type of
malware that encrypts the data belonging to an individual on a computer,
demanding a ransom for its restoration.

The term ransomware is commonly used to describe software that encrypts the data
belonging to an individual on a computer, demanding a ransom for its restoration.
Although the field known as cryptovirology predates the term "ransomware".

Visible Symptoms:
Files in system folders:
[%COMMON_DESKTOPDIRECTORY%]\Anti Virus Pro spyware remover.lnk
[%COMMON_DESKTOPDIRECTORY%]\Anti Virus Pro spyware remover.lnk

How to detect AntiVirusPro:

Files:
[%COMMON_DESKTOPDIRECTORY%]\Anti Virus Pro spyware remover.lnk
[%COMMON_DESKTOPDIRECTORY%]\Anti Virus Pro spyware remover.lnk

Folders:
[%PROGRAM_FILES%]\AntiVirusPro
[%COMMON_PROGRAMS%]\Anti Virus Pro spyware remover

Registry Keys:
HKEY_LOCAL_MACHINE\software\antiviruspro
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\anti virus pro spyware remover

Registry Values:
HKEY_CLASSES_ROOT\clsid\{dc021780-0db9-4c74-831d-64a68cd4a5fa}\inprocserver32
HKEY_CLASSES_ROOT\interface\{0afe119f-479b-4653-973a-5b3524e05f53}\typelib
HKEY_CLASSES_ROOT\interface\{0b885854-9680-4bc1-993b-6461721e51b8}\typelib
HKEY_CLASSES_ROOT\interface\{0d8054c9-db72-4928-a394-9f1f99adc842}\typelib
HKEY_CLASSES_ROOT\interface\{14ea9080-bb0b-4d10-b824-eb664d188d83}\typelib
HKEY_CLASSES_ROOT\interface\{2d9e3feb-9ad7-4ffe-934d-99f11c158cd3}\typelib
HKEY_CLASSES_ROOT\interface\{311c9076-5ea9-46b5-8cdd-df2b21a63bc6}\typelib
HKEY_CLASSES_ROOT\interface\{3cc3b165-76b5-4881-89cc-b9b2e371deba}\typelib
HKEY_CLASSES_ROOT\interface\{40d229a3-8fab-447b-b745-593bcc978e7e}\typelib
HKEY_CLASSES_ROOT\interface\{40f19c94-b585-40e3-9215-734af0797831}\typelib
HKEY_CLASSES_ROOT\interface\{45eacac4-484c-488b-b6f3-70f85078cc1e}\typelib
HKEY_CLASSES_ROOT\interface\{534b9356-604e-4694-8148-0e80c0767b28}\typelib
HKEY_CLASSES_ROOT\interface\{6a5a0886-c3e8-4539-a10d-1906fb26e992}\typelib
HKEY_CLASSES_ROOT\interface\{6b309cfd-a70c-4240-8c81-9f6122f25894}\typelib
HKEY_CLASSES_ROOT\interface\{6e976666-3e65-496f-aef6-3611c85f21b1}\typelib
HKEY_CLASSES_ROOT\interface\{7e4f3e28-a761-4783-9d78-813e84b9adbf}\typelib
HKEY_CLASSES_ROOT\interface\{7f455837-276a-4738-9fd1-423d55a85450}\typelib
HKEY_CLASSES_ROOT\interface\{84aeea7e-dfb2-49fa-b13d-24b757989300}\typelib
HKEY_CLASSES_ROOT\interface\{853237ac-2445-4088-b5b6-da59fe490a99}\typelib
HKEY_CLASSES_ROOT\interface\{89350442-aa5d-448a-b1f1-8ef4a6b2793f}\typelib
HKEY_CLASSES_ROOT\interface\{9cf67df1-b070-4dbb-938c-e6b65f89650a}\typelib
HKEY_CLASSES_ROOT\interface\{aa3241f3-db02-49dc-8c10-1edd594b00d9}\typelib
HKEY_CLASSES_ROOT\interface\{ba41251e-4ccb-4c12-9d60-88d3bb8cd40e}\typelib
HKEY_CLASSES_ROOT\interface\{c1cff37f-b3da-445d-8df0-f0e0d184e374}\typelib
HKEY_CLASSES_ROOT\interface\{c1d797e3-23f0-435a-a180-d5fee6659add}\typelib
HKEY_CLASSES_ROOT\interface\{cf4293ee-46d3-4a59-b3c6-97a65e289ae9}\typelib
HKEY_CLASSES_ROOT\interface\{cfd72227-d4d3-4163-9a1d-c59025c963d6}\typelib
HKEY_CLASSES_ROOT\interface\{e555bdbf-3cd2-4006-b09a-ba23b77ff1b1}\typelib
HKEY_CLASSES_ROOT\interface\{e98c98a2-5066-428d-9baa-ad700d0560f7}\typelib
HKEY_CLASSES_ROOT\interface\{ea069128-b49c-4be8-ba45-539a2585dfaf}\typelib
HKEY_CLASSES_ROOT\interface\{f123d718-0bcf-489d-9158-140d73b3fd96}\typelib
HKEY_CLASSES_ROOT\interface\{f257b6f7-bfcd-43a7-8900-10fc96b7dd90}\typelib
HKEY_CLASSES_ROOT\interface\{f7d58870-0d07-4ffe-b5da-0aade1fc35f8}\typelib
HKEY_CLASSES_ROOT\interface\{fa94f25b-9c28-4c74-9167-4e053e0e2e3b}\typelib
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing AntiVirusPro:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Noscid Trojan Removal instruction
Backdoor.Pigeon Trojan Removal instruction
BuddyLinks Adware Information
Adtraffic Hijacker Removal instruction
TrojanDropper.Win32.VB.aa Trojan Removal instruction

No comments: