How to remove Wireshark Antivirus

Friday, August 6th, 2010 at 7:29 am
Home » Rogue Antispyware » Wireshark Antivirus

Wireshark Antivirus description

Wireshark Antivirus is a ridiculously named rogue tool. Once it gets on your computer, you will notice disabled programs, restricted internet access, browser redirections and other problems. Nevertheless, WiresharkAntivirus claims it is there to help you. It will offer you paying for a “full version” of a program and then it is supposed to delete the “viruses”. If you find yourself in that situation, keep in mind that Wireshark Antivirus is the source of the trouble going on. Purchasing  the program will only make the scammers richer but it won’t help your computer.

Wire Shark Antivirus is able to mimic various system notifications. It also display multiple fabricated security alerts. None of the information delivered by Wireshark Antivirus should be trusted. The fraud usually falsifies the following warning, but it displays other counterfeit messages as well:

Security Warning
There are critical system files on your computer that were modified by malicious program. It will cause unstable work of your system and permanent data loss. Click here to undo performed modifications and remove malicious software (Highly recommended).

Security Alert
Infiltration Alert

Your computer is being attacked by an Internet Virus. It could be a password-stealing attack, a trojan-dropper or simular.
Details
Attack from: 239.80.11.105, port 58962
Attacked port: 41567
Threat: HalfLemon

svchost.exe
svchost.exe has encountered a problem and needs to close. We are sorry for inconvenience.

Warning!
Running of application is impossible.
The file C:\Windows\System32\notepad.exe is infected.

Wireshark Antivirus is a Rogue Antispyware software

How to manually remove Wireshark Antivirus

To remove Wireshark Antivirus spyware you must block Wireshark Antivirus sites, stop and remove processes, unregister DLL files, search and delete all other Wireshark Antivirus files and registry utility. Follow the Wireshark Antivirus detection and removal instructions below.

The most typical software removal method is to remove Wireshark Antivirus by using "Add or Remove Programs" service. However there may be hidden Wireshark Antivirus files, running processes and registries in your computer, so Wireshark Antivirus may recreate all other files after reboot.

Wireshark Antivirus manual removal instructions

Stop and remove Wireshark Antivirus processes:
Wireshark Antivirus.exe
alggui.exe
svchost.exe
dbsinit.exe
ccsmn.exe
ccsrr.exe
Read more how to kill Wireshark Antivirus processes

Locate and delete Wireshark Antivirus registry entries:
HKEY_CURRENT_USER\Software\Wireshark Antivirus
HKEY_CLASSES_ROOT\CLSID{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ExplorerBrowser Helper Objects{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SYSTEM\Current\Control\SetServices\AdbUpd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavapp"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavappr"
Read more how to delete Wireshark Antivirus registry entries
Download RegistryBooster 2010 to scan errors caused by Wireshark Antivirus

Search and unregister Wireshark Antivirus DLL libraries:
adc_w32.dll
adc32.dll
Read more how to unregister Wireshark Antivirus DLL files

Detect and delete other Wireshark Antivirus files:
C:\Program Files\Wireshark Antivirus\Wireshark Antivirus.exe
c:\Program Files\adc_w32.dll
c:\Program Files\alggui.exe
c:\Program Files\extra1.dat
c:\Program Files\extra2.dat
c:\Program Files\nuar.old
c:\Program Files\skynet.dat
c:\Program Files\svchost.exe
c:\Program Files\wp3.dat
c:\Program Files\wp4.dat
c:\Program Files\scdata
c:\Program Files\scdata\dbsinit.exe
c:\Program Files\scdata\wispex.html
c:\Program Files\scdata\images
c:\Program Files\scdata\images\i1.gif
c:\Program Files\scdata\images\i2.gif
c:\Program Files\scdata\images\i3.gif
c:\Program Files\scdata\images\j1.gif
c:\Program Files\scdata\images\j2.gif
c:\Program Files\scdata\images\j3.gif
c:\Program Files\scdata\images\jj1.gif
c:\Program Files\scdata\images\jj2.gif
c:\Program Files\scdata\images\jj3.gif
c:\Program Files\scdata\images\l1.gif
c:\Program Files\scdata\images\l2.gif
c:\Program Files\scdata\images\l3.gif
c:\Program Files\scdata\images\pix.gif
c:\Program Files\scdata\images\t1.gif
c:\Program Files\scdata\images\t2.gif
c:\Program Files\scdata\images\Thumbs.db
c:\Program Files\scdata\images\up1.gif
c:\Program Files\scdata\images\up2.gif
c:\Program Files\scdata\images\w1.gif
c:\Program Files\scdata\images\w11.gif
c:\Program Files\scdata\images\w2.gif
c:\Program Files\scdata\images\w3.jpg
c:\Program Files\scdata\images\word.doc
c:\Program Files\scdata\images\wt1.gif
c:\Program Files\scdata\images\wt2.gif
c:\Program Files\scdata\images\wt3.gif
c:\Program Files\Sysinternals Antivirus
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.acf
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.ltd
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.lti
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.acb
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.aci
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.mt
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\lleod150
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmharun.log
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmrun.log
%UserProfile%\Start Menu\Programs\Wireshark Antivirus
%UserProfile%\Start Menu\Programs\Wireshark Antivirus\Wireshark Antivirus.lnk

We strongly recommend you to use spyware remover to track Wireshark Antivirus and automaticaly remove Wireshark Antivirus processes, registries and files as well as other spyware threats.

Download does not start? Try a mirror download here

Tags: , , ,

Leave a Reply

Download does not start? Try a mirror download here