Saturday, June 20, 2009

Removal of Contraviro Malware

Remove Contraviro, because this is a program advertised by trojans in extremely annoying manner. Remove Contraviro related trojans at once. Contraviro is installed either manually by user from one of its websites or secretly with trojan of Vundo type. Probably, all ways of Contraviro infiltration into targeted machine are not known to us yet and there are likely to be other tricky ways of Contraviro shadowed installation. Contraviro pretends to scan computer for viruses and malware. In reality, though, it finds only files installed in one pack with its trialware or by related trojans. These files are neither hazardous nor useful. Scan by Contraviro, like any sort of rogue antispyware ads, ends with request to pay the registration fee.
Contraviro presence may also be revealed by fake security alerts stating that your computer is infected with SpamBot and similar scaring info.
Instead of buying malware, click here to scan computer for free and get rid of Contraviro scam.

Contraviro screenshots:


Contraviro removal tool (Spyware Doctor):

Contraviro manual removal instructions:
Delete Contraviro files:
Contraviro.exe
daily.cvd
Drvfltip.sys
hjengine.dll
IEAddon.dll
main.cvd
MFC71.dll
MFC71ENU.DLL
msvcp71.dll
msvcr71.dll
pthreadVC2.dll
shellext.dll
siglsp.dll
uninstall.exe
Contraviro.lnk
How to Register Contraviro.lnk
Register Contraviro.lnk

Delete Contraviro registry entries:
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\AppID\{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}
HKEY_CLASSES_ROOT\AppID\IEAddon.DLL
HKEY_CLASSES_ROOT\CLSID\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}
HKEY_CLASSES_ROOT\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\Drives\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}
HKEY_CLASSES_ROOT\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}
HKEY_LOCAL_MACHINE\SOFTWARE\Contraviro
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\Contraviro
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
Winlogon "Shell"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\User Agent\Post Platform "Contraviro"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Contraviro"

No comments: