|
Free malware removal tool to remove Antispyware Soft
|
|
Written by Administrator |
Thursday, 22 April 2010 00:00
|
|
Antispyware Soft is another rogue Antispyware, a scareware, that tries to get money from users by prompting them to register and buy their fake products. Some old malwares often return to the front of the stage and Antispyware Soft is replacing Antivirus Live and Antivirus Soft. Remove Antispyware Soft immediately from your system.

To remove Antispyware Soft (Uninstall Antispyware Soft)
- Download this free removal tool for Antispyware Soft
- Extract it
- Launch
- Click on the delete button
Antispyware Soft will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :
- [random]sysguard.exe
- [random]sftav.exe
- [random]tssd.exe
Files :
- %AppData%\[random]\[random]sftav.exe
- %AppData%\[random]\[random]sysguard.exe
- %AppData%\[random]\[random]tssd.exe
- %AppData%\[random]
Registry
Registry keys created
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings
- HKEY_CURRENT_USER\Software\avsoft
- HKEY_CURRENT_USER\Software\avsuite
- HKEY_LOCAL_MACHINE\Software\avsoft
- HKEY_LOCAL_MACHINE\Software\avsuite
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- evbogtwv = "%AppData%\agolui\ceycsftav.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
- RunInvalidSignatures = 0x00000001
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- LowRiskFileTypes = ".exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
- SaveZoneInformation = 0x00000001
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- evbogtwv = "%AppData%\agolui\ceycsftav.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings
- HKEY_CURRENT_USER\Software\avsoft
Registry value deleted
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Registry value modified
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
- CheckExeSignatures = ""/ Original value =" yes"

|
Comments
RSS feed for comments to this post.