Info: Antivirus Soft is a variant of the notorious fake anti-spyware known as Antivirus Live. Just like its predecessor, Antivirus Soft uses scare tactics to try and get users to purchase a software license. Antivirus Soft gets installed via Trojans that exploit security loopholes in the system or via porn websites. Once installed, it enters a number of registry keys in to the Windows Registry, as well as creating a number of harmless files on the hard disk. Then Antivirus Soft performs a series of fake virus scans, coming up with false results that state that the previously created files are dangerous viruses. This rogue software also claims that the currently installed ‘trial’ version cannot remove these false threats, and urges the user to purchase a license to the ‘full’ version of Antivirus Soft. However, as Antivirus Soft is a fake program none of its versions can scan or clean any system, therefore no user should allow themselves to be tricked into paying for Antivirus Soft.
Antivirus Soft
As soon as you find a copy of Antivirus Soft on your computer, you should take steps to remove it. In order to remove Antivirus Soft, you must stop its processes, delete its files and folders and remove its registry entries.
Automatic Removal
If you are looking for an automatic solution we recommend Spyware Doctor with Antivirus. You may need to follow the guide bellow to first stop this false software program and then install the client. Be sure to use coupon code “removevirus10” for a great discount. Just remove the quotes.
Antivirus Soft Removal Video
Antivirus Soft File Removal Instructions
The first step you must take in order to remove Antivirus Soft is to stop the following processes: ( Learn how to terminate a running process )
- [random characters]sysguard.exe
- [random characters]sftav.exe
The next step is to delete the following files and folders:
Windows XP:
- %UserProfile%\Local Settings\Application Data\[random characters]\
- %UserProfile%\Local Settings\Application Data\[random characters]\[random characters]sysguard.exe ( PLease note that this last section wil change over time )
- %UserProfile%\Local Settings\Application Data\[random characters]\[random characters]sftav.exe
Windows 7 | Windows Vista:
- %UserProfile%\AppData\Local\[random characters]\
- %UserProfile%\AppData\Local\[random characters]\[random characters]sysguard.exe
- %UserProfile%\AppData\Local\[random characters]\[random characters]sftav.exe
Once these steps have been completed, Antivirus Soft no longer resides on your hard disk.
Antivirus Soft Registry Removal Instructions
File removal alone is not enough to completely remove Antivirus Soft. The following registry keys and settings should also be deleted: (How to Edit Registry Here)
- HKEY_LOCAL_MACHINE\SOFTWARE\avsoft
- HKEY_CURRENT_USER\Software\avsoft
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random charaters]” ( IN OUR CASE THIS WAS lwxicfyh )
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random characters]” ( IN OUR CASE THIS WAS lwxicfyh )
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
Now it is safe to say that you have completely gotten rid of Antivirus Soft. However, in order to be certain of this fact and that no additional malware is left on the system it is recommended to conduct a full system scan using legitimate software such as Spyware Doctor with Antivirus.
Outside Resources:
http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft
http://www.geekpolice.net/t18839-how-to-remove-antivirus-soft-removal-guide
did you try deleting it in Safe mode yet? That is the simplest thing to do first. it may not be deleting because it’s still running. In safe mode you would not have this issue.
It may also be a permisions issues. Depending on your OS there are steps you can take to to over ownership.
Hey,
i cant delete the random character folder or anything inside it, it comes up with “You need permission to perform this action” unless im crazy i have full control of my computer…. you know other than the virus overlord.