Posts Tagged ‘fake’

Fake Security Essentials 2010 virus removal

Thursday, February 18th, 2010


Security Essentials 2010 (SecurityEssentials2010)

Security Essentials 2010, also known as SecurityEssentials2010, is a fake antivirus program. The program can generally infect systems running any version of the Windows operating system. Security Essentials 2010 is one of many fake antivirus programs; other fake antivirus programs include Internet Security 2010 and XP Guardian. Security Essentials 2010 hopes to trick the user into thinking that it is a real program by using various tactics such as creating fake virus scans. The program is generally installed through the use of a trojan horse; therefore, the program is generally installed with user permission. Security Essentials 2010 is fake and doesn’t work. The program will generally modify system settings to the block the user from accessing webpages and opening programs. The virus may also modify Internet Explorer connection settings.
fake-security-essentials-2010-virus
Security Essentials 2010 itself doesn’t work to remove viruses and therefore should be removed immediately. It has a website which it uses to advertise the fake program.

Manual Security Essentials 2010 Removal

In order to manually remove Security Essentials 2010, the processes associated with Security Essentials 2010 must be stopped, the files associated with the processes must be removed, and the registry entries must be corrected to the previous state before Security Essentials 2010 entered the computer.

Stop Security Essentials 2010 Processes
SE2010.exe

Delete Associated Security Essentials 2010 Files:

c:\s
c:\Program Files\Securityessentials2010\
c:\Program Files\Securityessentials2010\SE2010.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security essentials 2010.lnk
%UserProfile%\Desktop\Security essentials 2010.lnk
%UserProfile%\Start Menu\Security essentials 2010.lnk
c:\WINDOWS\system32\41.exe
c:\WINDOWS\system32\helpers32.dll
c:\WINDOWS\system32\smss32.exe
c:\WINDOWS\system32\warnings.html
c:\WINDOWS\system32\winlogon32.exe

Delete Associated Security Essentials 2010 Windows Registry Information:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-security-essentials.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-soft-package.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-software-package.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download.com
HKEY_CURRENT_USER\Software\SE2010
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-security-essentials.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallpaper” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoActiveDesktopChanges” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoSetActiveDesktop” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Security essentials 2010″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “smss32.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop “NoChangingWallpaper” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer “NoActiveDesktopChanges” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer “NoSetActiveDesktop” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “smss32.exe”


Download
Super Anti Spyware
OR

Download
Malware Bytes Anti-Malware


Fake antivirus soft

Thursday, February 4th, 2010


Remove Fake Antivirus Soft rogue spyware

Antivirus Soft is a rogue anti-spyware and ransomware program from the same family as Antivirus Live. These infections are installed on to your computer through the use of malware that installs the program onto your computer without your permission or knowledge. It is also common for this rogue to be installed on your computer through the use of malicious PDF files that exploit known vulnerabilities in older versions of Adobe Reader. Once installed, Antivirus Soft will be configured to start automatically when Windows starts. Once running it will scan your computer and display numerous infections, but will state it will not remove them until you purchase the program. In reality, the infected files it detects are all fake and do not actually exist on your computer.
Means
Newsoftspot.microsoft.com (also can be met as Newsoftspot.com) is a malicious domain, browser hijacker which is known to have been distributing Antivirus Soft, one of the latest rogue antispywares. Just like any other earlier variant of browser hijackers, Newsoftspot.microsoft.com is the malicious domain where people are offered to check their computers for viruses. Additionally, victims are redirected straight away to Newsoftspot.com/purchase and asked persistently to make a registration for Antivirus Soft. The “Microsoft” name on the website is expected to trick users into taking this scamware legitimate. However, just after registration it starts messing up the whole PC system, so save your money instead.
fake-antivirus-soft
While Antivirus Soft is running you will also see numerous security warnings and alerts that try to trick you into thinking that you have a security problem on your computer. An example of one of the alerts you will see is a fake Windows Security Center that looks exactly like the legitimate one, but instead suggests that you purchase Antivirus Soft to protect your computer. The infection will also show numerous alerts that state that your computer is infected, that you are sending personal data to a remote location, or a that your computer is being attacked. One of the alerts will have this text:

Antivirus Software Alert
Infiltration Alert
Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan-dropper or similar.
Threat: Win32/Nuqel.E

Just like the fake scan results, these security alerts are all fake and are just being shown to trick you into purchasing the program.

Without a doubt, Antivirus Soft was created solely to try and scam you into thinking that your computer is infected in the hopes that you will then purchase it. It goes without saying that you should not purchase this program, and if you already have, please contact your credit card company and dispute the charges stating the program is a scam. Finally, to remove this infection please use the removal guide below to remove it for free.

How to manually remove Antivirus Soft

Newsoftspot.microsoft.com manual removal:
Kill processes:
[random string]sysguard.exe

Delete registry values:
HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“

Delete files:
%Documents and Settings%\\[UserName]\\Local Settings\\Application Data\\[random string]\\[random string]sysguard.exe

Auto Removal:

Use these great softwares to remove “Antivirus Soft” virus.

Download Super Anti Spyware
OR

Download Malware Bytes Anti-Malware

Antivirus Live 2010 fake virus

Wednesday, January 13th, 2010


Remove Fake Antivirus Live rogue spyware

Antivirus Live is a rogue antispyware program. It is a clone of widely spread rogue called Antivirus System Pro. The software usually spreads with the help of trojans. Once downloaded and installed Antivirus Live will register itself in the Windows registry to run automatically when Windows loads.When running, it will start a scan your computer and reports numerous infections to make you think that your computer is infected with trojans, spyware and other malware. Then Antivirus Live will ask you to pay for a full version of the program to remove these infections. Of course, all of these infections are fake and don’t actually exist on your computer. So you can safely ignore them!
antivirus-live-2010
Antivirus Live blocks the ability to run any programs. The following warning will be shown when you try to run the Notepad:

Application cannot be executed. The file notepad.exe is infected.
Do you want to activate your antivirus software now.

What is more, while Antivirus Live is running , you will be shown fake Windows Security Center, nag screens, warnings and fake security alerts from your Windows taskbar. The rogue will also change the proxy setting of Internet Explorer to redirect you to the Antivirus Live site.


How to Manually remove Antivirus Live 2010

Block Antivirus Live sites:
awareremover2010.com

Stop and remove Antivirus Live processes:
sysguard.exe

Locate and delete Antivirus Live registry entries:
HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “”

Search and unregister Antivirus Live DLL libraries:
iehelper.dll

Detect and delete other Antivirus Live files:
%WINDOWS%\sysguard.exe
%WINDOWS%\system32\iehelper.dll

Auto Removal tools to remove this virus:


Download
Super Anti Spyware
OR

Download
Malware Bytes Anti-Malware

Anti Virus 2010 pro removal

Monday, October 5th, 2009



Remove Fake Antivirus 2010 pro
Antivirus Pro 2010 is a new rogue from the same family as XP AntiSpyware 2009. This program is classified as a rogue because it displays fake scan results, creates fake malware files in order to trick you into thinking you are infected, and is bundled with or installed by malware. When the program is installed, it will be configured to automatically scan your computer when you log into Windows. The installer will also create numerous randomly named files on your hard drive. When Antivirus Pro 2010 scans your computer it will detect these files and state that they are infections, but will not allow you to remove them until you purchase the program. In reality, the files that the installer creates are harmless and pose no threat to your computer. They are only being created to validate the scan results and further trick you into thinking your computer is infected.

As we have already mentioned, AntivirusPro2010 is promoted through the use of Braviax infection. This Trojan virus displays fake security alerts in your Windows task bar that promotes the misleading application. Usually it states that your computer is unprotected and that you should activate your antivirus software. The Trojan may also display warnings about various malware infections. While running, AntivirusPro_2010 will impersonate Windows Security Center and state that anti-virus software is outdated or disabled. Do not trust it, it’s a scam.

SnapShot of Antivirus Pro 2010
antivirus-pro-2010
If you find that Antivirus Pro 2010 is installed on your computer, please ignore the results and do not purchase the program. If you have already purchased the program then you should contact your credit card company and dispute the charges due to this program being a scam. In order to remove this program and any related malware, please follow the steps in the removal guide below.


How to manually remove Antivirus Pro 2010
Kill processes:
AntivirusPro_2010.exe
yxine.exe
Uninstall.exe
mifiryvele.exe

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Extensions

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SQM\PIDs

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Ext\Settings\{DBC80044-A445-435B-BC74-9C25C1C588A9}

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Ext\Settings\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}

HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusPro_2010

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\[ORIGINAL FILE NAME]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\AntivirusPro_2010

Unregister DLLs: AVEngn.dll
htmlayout.dll
pthreadVC2.dll
msvcm80.dll
msvcp80.dll
msvcr80.dll

Delete files:
AntivirusPro_2010.lnk
bojag.dl
aqepe.dat
nyxuj.com
Uninstall.lnk
ebapepyno.db
emuziwe.pif
ugozuf._sy
uxitavo.dl
carugy.com
yquxihet.exe
ojupegos.pif
qanof.bin
yrihoka.lib
zecorykyp.lib
AntivirusPro_2010.cfg
AntivirusPro_2010.exe
AVEngn.dll
daily.cvd
htmlayout.dll
Microsoft.VC80.CRT.manifest
msvcm80.dll
msvcp80.dll
msvcr80.dll
pthreadVC2.dll
Uninstall.exe
wscui.cpl
medoqokeqo.exe
ycevykazu.vbs
yhabozix.vbs
_scui.cpl
azasal.bin
dinubem.dl
exifoton.dll
mifiryvele.exe
ralun.sys

Delete directories:
c:\Program Files\AntivirusPro_2010

Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Alpha Antivirus fake av removal

Thursday, October 1st, 2009



Alpha Antivirus is a misleading anti-virus program that deliberately displays fake security alerts and reports false system security threats to trick you into thinking your computer is infected with spyware, adware, Trojans or other malicious software. The graphical user interface of this bogus application is almost identical to widely spread rogue’s anti-spyware application called Personal Antivirus. When the program is installed it will list a variety of infections and prompt you to pay for a full version of the program to remove infections which do not even exist. You shouldn’t purchase this program. We strongly recommend you to uninstall Alpha Antivirus from your computer upon detection.

The purpose of Alpha Antivirus is not protecting a computer. The goal is making people pay for using non-functional software.

SnapShot of Alpha antivirus
alpha-antivirus- fake rogue spyware program Alpha AV
Alpha Anti Virus is a computer parasite. It displays infection alerts and system scan results to trick users into taking the tool as a real deal. All the messages and warnings loaded by AlphaAntivirus are falsified. Don’t trust this program and don’t spend your money on a malware.

Alpha Antivirus is not only annoying but it’s also dangerous. It redirects web browser to malicious website. Alpha Anti Virus also slows a computer down and it may even disable real security programs. AlphaAntivirus is also capable of stealing passwords.

Alpha Antivirus properties:
• Changes browser settings
• Shows commercial adverts
• Stays resident in background

How to manually remove Alpha Antivirus
Kill processes:
AlphaAntivirus.exe

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Alpha Antivirus”
HKEY_CURRENT_USER\Software\Alpha Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Alpha Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Alpha Antivirus

Delete files:
AlphaAntivirus.exe
Alpha Antivirus.lnk
Uninstall Alpha Antivirus.lnk

Delete directories:
%Program Files%\Alpha Antivirus
%Documents and Settings%\All Users\Start Menu\Programs\Alpha Antivirus
%Documents and Settings%\All Users\Application Data\Alpha Antivirus

Auto Removal tools to remove this virus:

Download Super Anti Spyware

Remove Windows Police Pro virus

Friday, September 18th, 2009



WindowsPolicePRO is a malware and a fraud in a single piece of software. It infects computer with help of trojans or upon visiting malicious websites. When installed, Windows PolicePRO requires purchasing the full version. It uses misleading tactics to make an image of useful and reputable program. Windows Police PRO imitates computer scan and fabricates system infection alerts. All the messages invite buying the application for fixing a PC. None of the alerts should be trusted because WindowsPolice PRO is neither able to detect nor remove computer infections.
SnapShot:
windows-police-pro-virus.jpg
Normally Windows Police Pro can be disabled through the Add/Remove Programs Menu, but to completely get rid of Windows Police Pro you need to remove its corresponding registry entries and hidden files. In addition, Windows Police Pro may be downloaded and installed from various locations and, in many cases, in one kit with trojans and viruses


How to manually remove Windows Police PRO
To remove Windows Police PRO spyware you must block Windows Police PRO sites, stop and remove processes, unregister DLL files, search and delete all other Windows Police PRO files and registry utility. Follow the Windows Police PRO detection and removal instructions below.

The most typical software removal method is to remove Windows Police PRO by using “Add or Remove Programs” service. However there may be hidden Windows Police PRO files, running processes and registries in your computer, so Windows Police PRO may recreate all other files after reboot.

Windows Police PRO manual removal instructions
Block Windows Police PRO sites:

antispyware-scanner2.com

Stop and remove Windows Police PRO processes:
Windows Police Pro.exe
dbsinit.exe

Locate and delete Windows Police PRO registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Windows Police PRO”
HKEY_CURRENT_USER\Software\Windows Police PRO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Police PRO
HKEY_LOCAL_MACHINE\SOFTWARE\Windows Police PRO

Detect and delete other Windows Police PRO files:
C:\Program Files\Windows Police Pro\Windows Police Pro.exe
C:\Program Files\Windows Police Pro\tmp\dbsinit.exe
%System Root%\Samples
%User Profile%\Local Settings\Temp
%Program Files%\Windows Police PRO
%Program Files%\LabelCommand
%Documents and Settings%\All Users\Start Menu\Programs\Windows Police PRO
%Documents and Settings%\All Users\Application Data\Windows Police PRO

Delete Windows Police Pro files:

ANTI_files.exe
svcm80.dll
msvcp80.dll
msvcr80.dll
windows Police Pro.exe
dbsinit.exe
wispex.html
i1.gif
i2.gif
i3.gif
j1.gif
j2.gif
j3.gif
jj1.gif
jj2.gif
jj3.gif
l1.gif
l2.gif
l3.gif
pix.gif
t1.gif
t2.gif
up1.gif
up2.gif
w11.gif
w2.gif
w3.gif
w3.jpg
wt1.gif
wt2.gif
wt3.gif
minix32.exe
dddesot.dll
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

Trojan Unclassified Reg SVR fake process

Friday, July 31st, 2009



Trojan.Unclassified.RegSVR.Fake.Process
Summary : Trojan.Unclassified/RegSVR-Fake.Process

Processes : REGSVR.EXE

Description : Trojan.Unclassified/RegSVR-Fake.Process

Trojans are programs that can appear to serve a legitimate purpose but actually have an unwanted or harmful effect.

A large segment of trojan programs download other harmful software components to a user’s PC without his/her knowledge.

This application is most likely downloaded and installed by another application that is considered to be adware or spyware.



R E M O V A L
NO MANUAL REMOVAL GUIDE and PROPPER REMOVAL TOOL FOR TROJAN UNCLASSIFIED REGSVR FAKE PROCCESS FOUND/AVAILAVLE.

TO REMOVE THIS THREAT FROM YOUR PC, DOWNLOAD MICROSOFT MALICIOUS SOFTWARE REMOVAL TOOL

Trojan WinCod Fake win codec removal

Thursday, July 30th, 2009



WinCod or Trojan.Wincod is trojan behind WinCodecPRO promotions. This trojan sneaks into system with some malicious codec bundles that are distributed freely through file sharing networks. After instalation, WinCod starts showing various popups that promote its main affiliate : WinCodecPro, which is paid fake application. This trojan will disable some existing legitimate codecs in order to prevent you playing movies and other video content before paying for rogue application it promotes. You should remove this trojan as soon as you get seeing popups that tell you that windows cant play particular video files you had no problems playing before.

Wincod is Dangerous

Wincod is a Trojan parasite
Wincod may display fake security & messages
Wincod may display numerous annoying advertisements
Wincod may be remotely controlled by a malicious person
Wincod may spread additional spyware
Wincod may repair its files, spread or update by itself
Wincod may prove difficult or impossible to remove
Wincod violates your privacy and compromises your security

Remove these Wincod Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\GenericMultiMedia

HKEY_LOCAL_MACHINE\SOFTWARE\GenericMultiMedia\WinCoDecPRO

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”WmpTray” = “[PATH TO TROJAN]”

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Image File Execution Options\taskmgr.exe\”Debugger”

HKEY_LOCAL_MACHINE\SOFTWARE\GenericMultiMedia\WinCoDecPRO\”countr” = “[NUMBER OF TIMES TROJAN HAS EXECUTED]”

Remove these Wincod files:
The path to Trojan varies, so you have to check registry before removing trojan manually.

Remove Antivirus System Pro fake program manually

Monday, July 27th, 2009



Antivirus System Pro is classified as a rogue anti-spyware application because it uses misleading methods in order to scare you into purchasing this program. Usually, the rogue uses false scan results and fake security warnings. It states that your computer is infected with Trojans, adware or malware and that you should purchase Antivirus System Pro to remove these infections. Of course, these infections are all fake and don’t actually exist on your computer.

This parasite is advertised through the use of Trojans, such as notorious Zlob or Vundo. It might be also promoted on various malicious websites. Once active, AntivirusSystem Pro will ostensibly scan your computer and list various fake infections or security issues. It will also flood your computer with very annoying pop-ups and security alerts. Here’s an example of a fake Antivirus System Pro alert:
“Windows Security alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan you computer. Your system might be at risk now.”

Obviously, these alerts are also fake. If your computer is infected with Antivirus System Pro, please use the removal guide shown below to remove it immediately. Removal delay will only worsen the situation, because Antivirus System Pro will download even more malware onto your computer.

Antivirus System Pro properties:
• Changes browser settings
• Shows commercial adverts
• Stays resident in background



Antivirus System Pro manual removal:
Kill processes:
sysguard.exe

Delete registry values:
HKEY_CURRENT_USER\Software\AvScan

HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “system tool”

Unregister DLLs:
iehelper.dll

Delete files:
sysguard.exe iehelper.dll
=======================
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

=======================

Fake Antivirus Best removal guide

Monday, July 27th, 2009



Remove Fake Antivirus-Best 2009 virus alert popups
If you’re infected with Antivirus-Best.com, your browser might always redirect to Antivirus-Best.com. To top it off, Antivirus-Best.com offers a fake system scan and a “free” download of Antivirus 2009. And by “free,” I mean the Antivirus-Best.com download will only cost you your sanity, as Antivirus 2009 launches fake system alerts to try to trick you into buying Antivirus 2009. Some of these Antivirus-Best.com popups read:

The page at http://antivirus-best.com says:
“ATTENTION! If your computer is struck by the virus, you could suffer data loss, erratic PC behaviour, PC freezes and creahes. Detect and remove viruses before they damage your computer!
Antivirus 2009 will perform a 100% FREE and quick scan of your computer for Viruses, Spyware and Adware. Do you want to install Antivirus 2009 to scan your computer for malware now? (Recommended)”



How to manually remove Antrivirus Best 2009
Block Antivirus-Best.com sites:
Antivirus-Best.com

Stop Antivirus-Best.com processes:
Antivirus2009.exe
C:\Program Files\Antivirus 2009\av2009.exe

Remove Antivirus-Best.com files:
c:\WINDOWS\system32\scui.cpl
Uninstall Antivirus 2009.lnk
Antivirus 2009.lnk

Unregister Antivirus-Best.com registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run\15358943642955870504508370025739

HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Antivirus” = “%ProgramFiles%\Antivirus 2009\Antvrs.exe”

HKEY_CURRENT_USER\Software\Antivirus

Get rid of Antivirus-Best.com folderss:
C:\Program Files\Antivirus 2009
=======================
Note: Manual removal guide can be confusing if you are a newbie. In that case, manual removal is not recommended. use an auto removal tool instead.
To automatically remove spywares,
use one of these great removal tools

Super Anti Spyware

Malware Bytes anti-malware (mbam.exe)

Spyware Doctor

=======================