Sep 6, 2009

Remove Contraviro - Contraviro Removal Information

Contraviro is a bogus anti-spyware program from the same family as Unvirex. Contraviro uses aggressive and false security alerts in order to convince you that your computer has been seriously infected with spyware, adware and Trojans. Sticking to the conventional principles of rogue anti-spywares functioning, Contraviro makes it on board a new host computer through security exploits or via insecure online downloads. In either case, it’s Trojans that “contribute” to successful installation of Contraviro unregistered version onto random computers. While running, Contraviro will install a DLL file called Layered Service Provider (LSP) on to your computer. It is used mainly to monitor network traffic and detect certain information .Having penetrated into a system or network, Contraviro will create a number of its own registry values in the System Registry thus stuffing it up to slow down the compromised computer considerably. While Contraviro is running the scans, it’s going to fill you up with numerous fake alerts about malicious applications and internet viruses’ attacks. After all, it will make you believe that everything you need for your system protection is to download and installed the full registered version of Contraviro. However, for a big payment you are not going to get anything but useless application, because, as we have already mentioned, Contraviro is nothing more, but the scam. You shouldn't trust it. Instead, remove this parasite form your computer upon detection as soon as possible.

Type: Rogue Anti-Spyware
Malware Author: Unknown

Threat Level: Critical
Screenshot:


How to remove Contraviro manually:
It's possible to remove Contraviro manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Program Files\Contraviro
c:\Program Files\Contraviro\Contraviro.exe
c:\Program Files\Contraviro\daily.cvd
c:\Program Files\Contraviro\Drvfltip.sys
c:\Program Files\Contraviro\hjengine.dll
c:\Program Files\Contraviro\IEAddon.dll
c:\Program Files\Contraviro\main.cvd
c:\Program Files\Contraviro\MFC71.dll
c:\Program Files\Contraviro\MFC71ENU.DLL
c:\Program Files\Contraviro\msvcp71.dll
c:\Program Files\Contraviro\msvcr71.dll
c:\Program Files\Contraviro\pthreadVC2.dll
c:\Program Files\Contraviro\shellext.dll
c:\Program Files\Contraviro\siglsp.dll
c:\Program Files\Contraviro\uninstall.exe
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro
c:\Documents and Settings\All Users\Desktop\Contraviro.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro\Contraviro.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro\How to Register Contraviro.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Contraviro\Register Contraviro.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Contraviro.lnk


Remove registry entries:

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\AppID\{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}
HKEY_CLASSES_ROOT\AppID\IEAddon.DLL
HKEY_CLASSES_ROOT\CLSID\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}
HKEY_CLASSES_ROOT\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\Drives\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\antivirus_contextscan
HKEY_CLASSES_ROOT\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}
HKEY_CLASSES_ROOT\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}
HKEY_LOCAL_MACHINE\SOFTWARE\Contraviro
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Contraviro
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "Contraviro"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Contraviro"


Please be careful because manual removal of Contraviro may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

No comments:

/