Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post. - BleepingComputer Management |
This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.
If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic: Preparation Guide For Use Before Posting A Hijackthis Log
![]() ![]() |
May 1 2007, 02:31 PM
Post
#1
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 29,367 Joined: 24-January 04 From: USA Member No.: 3 |
How to remove ExpertAntivirus (Removal Instructions) What this programs does: ExpertAntvirus, is a rogue anti-spyware program which displays fake and exaggerated scan results. When this program is installed on a computer it creates fake Windows Registry keys and fake files that are completely safe, but are reported by the program as malware. In this way, you can have a completely clean computer, yet the program will still find these files and Windows Registry entries and declare them to be malware related. In order to remove these fake infections you are prompted to purchase the commercial version of this software. Needless to say, you should not fall for this scam and purchase it. The guide below will walk you through the removal of the program and the fake malware files and entries it creates. ![]() ExpertAntivirus Screenshot Tools Needed for this fix:
Symptoms in a HijackThis Log: O4 - HKLM\..\Run: [ExpertAntivirus] C:\Program Files\ExpertAntivirus\ExpertAntivirus.exe /s Fake infection files, folders, and Registry keys that are created (these may change over time): HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoader HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7\tracer HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoader HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7 c:\Documents and Settings\ c:\WINDOWS\wincom137.dll c:\WINDOWS\system\ext32inc.dll Add/Remove Programs control panel entry: ExpertAntivirus v4.1 Guide Updates: 05/01/07 - Initial guide creation. Manual Removal Instructions for ExpertAntivirus: These steps may appear to be long and daunting. They are, though, quite easy to do and consist of so many steps only because I have written them in an extremely detailed manner.
Your computer should now be free of the Expert Antivirus program. If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Posting A Hijackthis Log This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you. -------------------- Lawrence
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2008 - 06:55 PM |