May 31, 2009

Remove Fast Antivirus 2009 - FastAntivirus 2009 Removal Instructions

Fast Antivirus 2009 is new rogue antispyware application from the same family as Virusdoctor, VirusMelt, VirusAlarm, MalwareCatcher, VirusShield, Extra Antivirus, Virus Sweeper, Ultra Antivir 2009. As its predcestors Fast Antivirus uses Google Code page: hxxp://favprj1.googlecode.com. Fast Antivirus is advertised through the use of misleading online antimalware scanners that detects nonexistent infections on your computer. Also Fast Antivirus is promoted with a help of Trojan horses that will display fake security alert on your PC. Once inside and active Fast Antivirus will perform full system scan and list you variety of infections that cannot be remove until you buy full version. Also Fast Antivirus will generate fake security alerts and pop-ups informing that your computer is seriously infected. In that way parasite can dramatically slow your computer performance. We strongly recommend you to remove Fast Antivirus manually or using automatic removal tool.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Fast Antivirus manually:
It's possible to remove Fast Antivirus manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Documents and Settings\All Users\Application Data\9adee5b
c:\Documents and Settings\All Users\Application Data\9adee5b\17.mof
c:\Documents and Settings\All Users\Application Data\9adee5b\FastAV.exe
c:\Documents and Settings\All Users\Application Data\9adee5b\mozcrt19.dll
c:\Documents and Settings\All Users\Application Data\9adee5b\sqlite3.dll
c:\Documents and Settings\All Users\Application Data\9adee5b\SysFld
c:\Documents and Settings\All Users\Application Data\9adee5b\SysFld\vd952342.bd
c:\Documents and Settings\All Users\Application Data\SysFld
c:\Documents and Settings\All Users\Application Data\SysFld\fastav.cfg
%UserProfile%\Application Data\Fast Antivirus 2009
%UserProfile%\Application Data\Fast Antivirus 2009\cookies.sqlite
%UserProfile%\Application Data\Fast Antivirus 2009\Instructions.ini
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Fast Antivirus 2009.lnk
%UserProfile%\Desktop\Fast Antivirus 2009.lnk
%UserProfile%\Recent\ANTIGEN.sys
%UserProfile%\Recent\cid.dll
%UserProfile%\Recent\CLSV.dll
%UserProfile%\Recent\CLSV.tmp
%UserProfile%\Recent\ddv.dll
%UserProfile%\Recent\dudl.dll
%UserProfile%\Recent\eb.drv
%UserProfile%\Recent\eb.tmp
%UserProfile%\Recent\energy.sys
%UserProfile%\Recent\fix.drv
%UserProfile%\Recent\gid.exe
%UserProfile%\Recent\hijackthis.log.lnk
%UserProfile%\Recent\PE.drv
%UserProfile%\Recent\PE.sys
%UserProfile%\Recent\PE.tmp
%UserProfile%\Recent\SICKBOY.dll
%UserProfile%\Recent\tempdoc.sys
%UserProfile%\Start Menu\Fast Antivirus 2009.lnk
%UserProfile%\Start Menu\Programs\Fast Antivirus 2009.lnk


Remove registry entries:

HKEY_CLASSES_ROOT\FastAV.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "898701124903"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Fast Antivirus 2009"


Please be careful because manual removal of Fast Antivirus may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

No comments:

/