Tuesday, July 29, 2008

Are you a victim of the Win AntiVir 2008

Win AntiVir 2008 is a rogue security application, related to WinFixer. Win AntiVir 2008 will report nonexistent threats to you in an attempt to get you to purchase the full version of the program. WinAntiVir 2008 may be installed through drive-by downloads and other unscrupulous delivery methods. Win AntiVir 2008 program may monitor your websurfing habits through a BHO extension.

The most common spyware removal tactic is to uninstall Win AntiVir 2008 by using the "Add/Remove Programs" utility. However, as there may still be hidden Win AntiVir 2008 files, it's possible that Win AntiVir 2008 will reappear after reboot.

Below is this manual removal process, may be difficult and you run the risk of destroying your computer. Remember to backup your registry before editing it.

Win AntiVir 2008 Manual Removal Instructions
Step 1 : Use Windows File Search Tool to Find Win AntiVir 2008 Path
• Go to Start > Search > All Files or Folders.
• In the "All or part of the the file name" section, type in "Win AntiVir 2008" file name(s).
• To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
• When Windows finishes your search, hover over the "In Folder" of "Win AntiVir 2008", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete Win AntiVir 2008 in the following manual removal steps.

Step 2 : Use Windows Task Manager to Remove Win AntiVir 2008 Processes
• To open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC.
• Click on the "Image Name" button to search for "Win AntiVir 2008" process by name.
• Select the "Win AntiVir 2008" process and click on the "End Process" button to kill it.
• Remove the "Win AntiVir 2008" processes files:
Antvrs.exe
WinAntiVir.exe
Win Antivir 2008.exe

Step 3 : Use Registry Editor to Remove Win AntiVir 2008 Registry Values
• To open the Registry Editor, go to Start > Run > type regedit and then press the "OK" button.
• Locate and delete the entry or entries whose data value (in the rightmost column) is the spyware file(s) detected earlier.
• To delete "Win AntiVir 2008" value, right-click on it and select the "Delete" option.
• Locate and delete "Win AntiVir 2008" registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Antivirus" = "%ProgramFiles%\WinAntiVir\Antvrs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_CURRENT_USER\Software\Antivirus

Step 4 : Detect and Delete Other Win AntiVir 2008 Files
• To open the Windows Command Prompt, go to Start > Run > type cmd and then press the "OK" button.
• Type in "dir /A name_of_the_folder" (for example, C:\Spyware-folder), which will display the folder's content even the hidden files.
• To change directory, type in "cd name_of_the_folder".
• Once you have the file you're looking for type in "del name_of_the_file".
• To delete a file in folder, type in "del name_of_the_file".
• To delete the entire folder, type in "rmdir /S name_of_the_folder".
• Select the "Win AntiVir 2008" process and click on the "End Process" button to kill it.
• Remove the "Win AntiVir 2008" processes files:
Uninstall Antivirus.lnk
WinAntiVir.lnk
Antvrs.exe
WinAntiVir.exe
Win Antivir 2008.exe

0 Comments: