Monday, November 24, 2008

New rogue to remove: AntivirusTrigger to substitute annoying VirusTrigger malware

Remove AntivirusTrigger or Antivirus Trigger, just like its notorious predecessor, VirusTrigger. Despite of unusual denomination, this program is ordinary misleading virus removal tool that relies on trojans and scaring invocations in its tricky business. The goal of hackers is known, it is to make you buy registered copy of AntivirusTrigger. You would do the best thing for computer safety if perform AntivirusTrigger removal after screening of alert of following content:
System Alert!
Your system might be infected with malicious software that may impact the performance of your computer. Click the icon for a free scan to detect any active spyware applications.
The alert is generated by trojan; it is used in both AntivirusTrigger and VirusTrigger propagation. Clicking on this alert redirects browsing to either Antivirus-Trigger.com or Virus-Trigger.com. This alert is, of course, important part of AntivirusTrigger’s trickery, but there are schemes without this alert which work successfully as well.
Download and install Spyware Doctor + antivirus to start AntivirusTrigger removal after scanning computer free of charge.
The tool we are offering to get rid of Antivirus Trigger is well-known and the best, as to our opinion, malware removal tool from legitimate developers. If you have doubts, just consult Internet, for instance Google, to get familiar with the independent references.

AntivirusTrigger screenshot:


AntivirusTrigger automatical remover:

AntivirusTrigger manual removal guide:
Delete AntivirusTrigger files:
AvirTr.exe
AvirTrWarning.dll
uninst.exe
AntivirusTrigger 2.1.lnk
browseu.exe
browseul.dll
hpmom.exe
hpmon.exe
hpmun.dll
hpmun.exe
myd.ico
mym.ico
myp.ico
myv.ico
ot.ico
qttask.exe
qttaskm.exe
qttasku.exe
ts.ico
512686.dll
algg.exe
tiltmeo.dll
Antivirus Scan.url
Online Antispyware Test.url
Antivirus Scan.url
My Documents.url
My Music.url
My Pictures.url
My Video.url
Delete AntivirusTrigger registry entries:
HKEY_CURRENT_USER\Software\AvirTrsoft
HKEY_CURRENT_USER\Software\AvirTrsoft\Update
HKEY_CLASSES_ROOT\AvirTrWarning.WarningBHO
HKEY_CLASSES_ROOT\AvirTrWarning.WarningBHO.1
HKEY_CLASSES_ROOT\CLSID\{22C447D3-73A8-E1C7-C391-21BE4338CEBC}
HKEY_CLASSES_ROOT\CLSID\{3A267370-076E-4af4-B986-77626B8E89DF}
HKEY_CLASSES_ROOT\Interface\{764BC8B4-1159-4736-8AF1-F124A7C8C3A8}
HKEY_CLASSES_ROOT\Interface\{DF3F06C6-D443-48A8-BDF2-4E31F0554EBF}
HKEY_CLASSES_ROOT\TypeLib\{3ED86073-2FA7-4CF4-810B-28B030671678}
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AvirTrsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{3A267370-076E-4af4-B986-77626B8E89DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\AvirTrsoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run “AvirTr”
HKEY_CLASSES_ROOT\webmedia.chl
HKEY_CLASSES_ROOT\z444.z444mgr
HKEY_CLASSES_ROOT\z444.z444mgr.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3B8FB116-D358-48A3-A5C7-DB84F15CBB04}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{096CBA44-4A4C-49f7-8903-1E75550ABCB7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{51B15F5A-E98B-4658-B9CB-9307B74773A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\Browser Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\IExplorer add-on
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\Online Alert Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\System Alert Popup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “wblogon”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusTriggerBin “(Default)”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\SharedTaskScheduler “{e0feeb92-908e-46d2-8a66-88c5295f2629}”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
policies\explorer\run “QuickTime Task”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
policies\explorer\run “VMware hptray”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
WebBrowser “ITBar7Layout”

No comments: