How to remove AntiVirusTrigger

Monday, November 3rd, 2008 at 1:42 pm

AntiVirusTrigger description

AntiVirusTrigger is a fake anti-virus distributed by trojans. It usually appears on a computer when user downloads a movie from malicious website and it prompts installing video codec. The codec hides a trojan which brings AntiVirus Trigger. This malware may also be installed when user visits infected internet sources.

AntiVirusTrigger is not a security tool. It mimics functions of anti-virus to make people interested in purchasing the program. AntiVirus Trigger is only capable of loading fabricated security alerts. Do not download this tool and don’t waste your money for a paid version of malware.

Get rid of AntiVirusTrigger

AntiVirusTrigger is a Rogue Antispyware software

How to manually remove AntiVirusTrigger

To remove AntiVirusTrigger spyware you must block AntiVirusTrigger sites, stop and remove processes, unregister DLL files, search and delete all other AntiVirusTrigger files and registry utility. Follow the AntiVirusTrigger detection and removal instructions below.

The most typical software removal method is to remove AntiVirusTrigger by using "Add or Remove Programs" service. However there may be hidden AntiVirusTrigger files, running processes and registries in your computer, so AntiVirusTrigger may recreate all other files after reboot.

AntiVirusTrigger manual removal instructions

Block AntiVirusTrigger sites:
homesiterenew.com
whatwashomepage.com
prevhomepage.com
fronthomepagez.com
virus-trigger.com
Read more how to block AntiVirusTrigger sites

Stop and remove AntiVirusTrigger processes:
AvirTr.exe
uninst.exe
browseu.exe
hpmom.exe
hpmon.exe
hpmun.exe
qttask.exe
qttaskm.exe
qttasku.exe
algg.exe
Read more how to kill AntiVirusTrigger processes

Locate and delete AntiVirusTrigger registry entries:
HKEY_CURRENT_USER\Software\AvirTrsoft
HKEY_CURRENT_USER\Software\AvirTrsoft\Update
HKEY_CLASSES_ROOT\AvirTrWarning.WarningBHO
HKEY_CLASSES_ROOT\AvirTrWarning.WarningBHO.1
HKEY_CLASSES_ROOT\CLSID\{22C447D3-73A8-E1C7-C391-21BE4338CEBC}
HKEY_CLASSES_ROOT\CLSID\{3A267370-076E-4af4-B986-77626B8E89DF}
HKEY_CLASSES_ROOT\Interface\{764BC8B4-1159-4736-8AF1-F124A7C8C3A8}
HKEY_CLASSES_ROOT\Interface\{DF3F06C6-D443-48A8-BDF2-4E31F0554EBF}
HKEY_CLASSES_ROOT\TypeLib\{3ED86073-2FA7-4CF4-810B-28B030671678}
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AvirTrsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A267370-076E-4af4-B986-77626B8E89DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AvirTrsoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AvirTr"
HKEY_CLASSES_ROOT\webmedia.chl
HKEY_CLASSES_ROOT\z444.z444mgr
HKEY_CLASSES_ROOT\z444.z444mgr.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3B8FB116-D358-48A3-A5C7-DB84F15CBB04}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{096CBA44-4A4C-49f7-8903-1E75550ABCB7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51B15F5A-E98B-4658-B9CB-9307B74773A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer add-on
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Online Alert Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Alert Popup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wblogon"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusTriggerBin "(Default)"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler "{e0feeb92-908e-46d2-8a66-88c5295f2629}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run "QuickTime Task"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run "VMware hptray"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser "ITBar7Layout"
Read more how to delete AntiVirusTrigger registry entries
Download RegistryBooster 2010 to scan errors caused by AntiVirusTrigger

Search and unregister AntiVirusTrigger DLL libraries:
AvirTrWarning.dll
browseul.dll
hpmun.dll
512686.dll
tiltmeo.dll
Read more how to unregister AntiVirusTrigger DLL files

Detect and delete other AntiVirusTrigger files:
c:\Program Files\AvirTrsoftware\AvirTr.exe
c:\Program Files\AvirTrsoftware\AvirTrWarning.dll
c:\Program Files\AvirTrsoftware\uninst.exe
%UserProfile%\Start Menu\Programs\AntivirusTrigger 2.1
c:\Program Files\WebMediaViewer\browseu.exe
c:\Program Files\WebMediaViewer\browseul.dll
c:\Program Files\WebMediaViewer\hpmom.exe
c:\Program Files\WebMediaViewer\hpmon.exe
c:\Program Files\WebMediaViewer\hpmun.dll
c:\Program Files\WebMediaViewer\hpmun.exe
c:\Program Files\WebMediaViewer\myd.ico
c:\Program Files\WebMediaViewer\mym.ico
c:\Program Files\WebMediaViewer\myp.ico
c:\Program Files\WebMediaViewer\myv.ico
c:\Program Files\WebMediaViewer\ot.ico
c:\Program Files\WebMediaViewer\qttask.exe
c:\Program Files\WebMediaViewer\qttaskm.exe
c:\Program Files\WebMediaViewer\qttasku.exe
c:\Program Files\WebMediaViewer\ts.ico
c:\WINDOWS\system32\512686\512686.dll
c:\WINDOWS\system32\algg.exe
c:\WINDOWS\system32\tiltmeo.dll

We strongly recommend you to use spyware remover to track AntiVirusTrigger and automaticaly remove AntiVirusTrigger processes, registries and files as well as other spyware threats.


Tags: , , , , ,

Posted in Rogue Antispyware

7 Responses to

AntiVirusTrigger – dangerous malware

Trackbacks

  1. Homesiterenew.com/security/xp
  2. Homesiterenew.com/security/vista
  3. Virus-Trigger.com
  4. VirTrigger
  5. VirusTrigger and VirusTrigger 2.1
  6. Remove AstrumAntivirus Pro, Astrum Antivirus Pro removal guide
  7. Remove Whatwashomepage.com hijacker

Leave a Reply