Type: Rogue Anti-Spyware
Malware Author: Unknown
Threat Level: Critical
Screenshot:

How to remove Virus Sweeper manually:
It's possible to remove Virus Sweeper manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.
The files to be deleted:
c:\Documents and Settings\All Users\Application Data\7c69f0c
c:\Documents and Settings\All Users\Application Data\7c69f0c\LoopSystem
c:\Documents and Settings\All Users\Application Data\LoopSystem
c:\Documents and Settings\All Users\Application Data\7c69f0c\VSweep.exe
c:\Documents and Settings\All Users\Application Data\7c69f0c\LoopSystem\vd952342.bd
c:\Documents and Settings\All Users\Application Data\LoopSystem\swcfg.ini
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Virus Sweeper.lnk
%UserProfile%\Application Data\Virus Sweeper
%UserProfile%\Application Data\Virus Sweeper\Instructions.ini
%UserProfile%\Desktop\Virus Sweeper.lnk
%UserProfile%\Recent\ANTIGEN.drv
%UserProfile%\Recent\cb.dll
%UserProfile%\Recent\CLSV.dll
%UserProfile%\Recent\energy.exe
%UserProfile%\Recent\exec.dll
%UserProfile%\Recent\fix.sys
%UserProfile%\Recent\PE.exe
%UserProfile%\Recent\PE.sys
%UserProfile%\Recent\ppal.tmp
%UserProfile%\Recent\snl2w.drv
%UserProfile%\Recent\tjd.exe
%UserProfile%\Recent\tjd.tmp
%UserProfile%\Start Menu\Virus Sweeper.lnk
%UserProfile%\Start Menu\Programs\Virus Sweeper.lnk
Remove registry entries:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\VSweep.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "97680312703"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Sweeper"
Please be careful because manual removal of Virus Sweeper may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
No comments:
Post a Comment