|
Remove Mega Antivirus 2012 easily from your system
|
|
Written by Administrator |
Wednesday, 23 February 2011 15:09
|
|
Mega Antivirus 2012 is a rogue Antispyware, a scareware, it's a malware that pretends to be an Antivirus. Mega Antivirus 2012 a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm telling that there are some malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is this Mega Antivirus 2012. Mega Antivirus 2012 invites you to purchase a license for this bogus program to remove malware, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall Mega Antivirus 2012 as soon as possible from your system with this removal tool for Mega Antivirus 2012.

To remove Mega Antivirus 2012 (Uninstall Mega Antivirus 2012)
- Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
- Choose Start computer in SAFE MODE with network support
- Open Internet Explorer
- Go to Tools => Internet Options => Connections Tab => LAN Settings
- Uncheck "Use a proxy server"
- Recheck "Automatically detect settings"
- Download this free removal tool for Mega Antivirus 2012
- Extract it
- Launch
- Click on the delete button
Mega Antivirus 2012 will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :
- addon.exe
- ma2012.exe
- install.exe
Files :
- %AppData%\%UserName%log.dat
- %Temp%\%UserName%7
- %Windows%\addons\addon.exe
- %Windows%\addons\base\license.pwd
- %Windows%\addons\ma2012.exe
- %Windows%\install.exe
Registry
- HKCU\Software\Antivirus .NET
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- ProxyEnable = 1
- ProxyServer = http=127.0.0.1:33921
- HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- HKCU\Software\Microsoft\Internet Explorer\PhishingFilter
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mega Antivirus 2012
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run
- Mega Antivirus 2012 = %AppData%\[random]\[random].exe
Registry keys created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45O3M0BQ-217X-LR5A-LU8X-18207F677R23}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
- HKEY_CURRENT_USER\Software\hun
- HKEY_CURRENT_USER\Software\WinRAR SFX
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{45O3M0BQ-217X-LR5A-LU8X-18207F677R23}
- StubPath = "%Windows%\addons\addon.exe Restart"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
- Policies = "%Windows%\addons\addon.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- addons = "%Windows%\addons\addon.exe"
- SystemStart = "%Windows%\addons\ma2012.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
- Policies = "%Windows%\addons\addon.exe"
- HKCU = "%Windows%\addons\addon.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
- HKEY_CURRENT_USER\Software\hun
- FirstExecution = "22/02/2011 -- 08:34"
- NewIdentification = "hun"
- NewGroup = ""
- HKEY_CURRENT_USER\Software\WinRAR SFX
- C%%WINDOWS%addons = "%Windows%\addons"

Remove Mega Antivirus 2012 manually :
- Restart your computer in safe mode :
- Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
- Choose Start computer in SAFE MODE
- Open the infected account
- Open explorer and open the windows path
- Remove the addons folder, don't worry it's not a legit Windows folder
- Remove also the file install.exe in the Windows path
- Click on the start menu button then click on run
- Type msconfig and press enter
- Go to the Startup tab
- Uncheck these keys from the list :
- Policies
- addons
- SystemStart
- Click again on the start menu and the run button
- This time, type regedit
- Find the key Installed Components under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup and remove the key {45O3M0BQ-217X-LR5A-LU8X-18207F677R23}
- Restart your computer in normal mode
This will solve the problem but you can run the removal tool to remove the other registry keys and values.
|