• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Antivirus Plus (Uninstall instructions)

Myantispyware team April 12, 2009    

Antivirus Plus is rogue antivirus/antispyware program that uses fake alerts and false positives to trick you into buying the software. The rogue is distributed through the use trojans and fake online malware scanners that tells you that your computer is infected and that you must install Antivirus Plus to protect your computer.

During installation, Antivirus Plus configures itself to run automatically every time, when you start your computer.

antivirusplus
Antivirus Plus

Once running, it will scan your computer and list a large amount of infections, but these “infections” are fake.

While Antivirus Plus is running your computer will display fake Windows Security Center, that will recommend you register Antivirus Plus, and fake security alerts from your Windows taskbar. Please ignore these alerts. Computer users are urged to avoid purchasing this bogus program! Use the free removal instructions below in order to remove Antivirus Plus.

More screen shoots of Antivirus Plus




Symptoms in a HijackThis Log

O1 – Hosts: 94.247.2.216 www.google.com
O1 – Hosts: 94.247.2.216 www.google.de
O1 – Hosts: 94.247.2.216 www.google.fr
O1 – Hosts: 94.247.2.216 www.google.co.uk
O1 – Hosts: 94.247.2.216 www.google.com.br
O1 – Hosts: 94.247.2.216 www.google.it
O1 – Hosts: 94.247.2.216 www.google.es
O1 – Hosts: 94.247.2.216 www.google.co.jp
O1 – Hosts: 94.247.2.216 www.google.com.mx
O1 – Hosts: 94.247.2.216 www.google.ca
O1 – Hosts: 94.247.2.216 www.google.com.au
O1 – Hosts: 94.247.2.216 www.google.nl
O1 – Hosts: 94.247.2.216 www.google.co.za
O1 – Hosts: 94.247.2.216 www.google.be
O1 – Hosts: 94.247.2.216 www.google.gr
O1 – Hosts: 94.247.2.216 www.google.at
O1 – Hosts: 94.247.2.216 www.google.se
O1 – Hosts: 94.247.2.216 www.google.ch
O1 – Hosts: 94.247.2.216 www.google.pt
O1 – Hosts: 94.247.2.216 www.google.dk
O1 – Hosts: 94.247.2.216 www.google.fi
O1 – Hosts: 94.247.2.216 www.google.ie
O1 – Hosts: 94.247.2.216 www.google.no
O1 – Hosts: 94.247.2.216 search.yahoo.com
O1 – Hosts: 94.247.2.216 us.search.yahoo.com
O1 – Hosts: 94.247.2.216 uk.search.yahoo.com
O2 – BHO: (no name) – {D032570A-5F63-4812-A094-87D007C23012} – D:\WINDOWS\system32\InternetExplorer.dll
O2 – BHO: Antivirus Plus BHO – {C2B5AAB8-2183-4be7-81A6-F11493C45872} – C:\Documents and Settings\comp\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll
O4 – HKLM\..\Run: [shell] D:\WINDOWS\system\rundll32.exe 1
O4 – HKLM\..\Run: [se] D:\WINDOWS\system\se.exe
O4 – HKLM\..\Run: [AntiVirus Plus] C:\Program Files\AntiVirus Plus\AntiVirus Plus..exe
O4 – HKCU\..\Run: [AntiVirus Plus] C:\Program Files\AntiVirus Plus\AntiVirus Plus..exe
O4 – Startup: AntiVirus Plus.lnk = C:\Program Files\AntiVirus Plus\AntiVirus Plus..exe
O4 – Global Startup: AntiVirus Plus.lnk = C:\Program Files\AntiVirus Plus\AntiVirus Plus..exe
O4 – HKLM\..\Run: [AntiVirus Plus] “C:\WINDOWS\system32\rundll32.exe” “C:\Documents and Settings\comp\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll”, start 1
O4 – HKCU\..\Run: [AntiVirus Plus] “C:\WINDOWS\system32\rundll32.exe” “C:\Documents and Settings\comp\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll”, start 1
O4 – Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe
O4 – Global Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe

Use the following instructions to remove Antivirus Plus (Uninstall instructions)

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for Antivirus Plus infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

antivirusplus-mbam
Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected for start Antivirus Plus removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Antivirus Plus creates the following files and folders

HKEY_CLASSES_ROOT\CLSID\{c2b5aab8-2183-4be7-81a6-f11493c45872}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c2b5aab8-2183-4be7-81a6-f11493c45872}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2b5aab8-2183-4be7-81a6-f11493c45872}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiVirus Plus
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiVirus Plus

Antivirus Plus creates the following registry keys and values

C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus
C:\Program Files\Antivirus Plus
C:\WINDOWS\system\se.exe
C:\WINDOWS\system\dop.exe
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\NL4W0S8R\se[1].exe
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\PKR1WLV2\setup[1].exe
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\Antivirus Plus.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus Plus\EULA.lnk
C:\Program Files\Antivirus Plus\AntivirusPlus.exe
C:\Program Files\Antivirus Plus\AntivirusPlus.grn
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus Plus.lnk
C:\Documents and Settings\All Users\Desktop\Antivirus Plus.lnk
%UserProfile%\Application Data\AntiVirus Plus\AntiVirus Plus.1.dll

Rogue Anti Spyware Tutorials - HowTo

 Previous Post

How to remove Virus Sweeper (Uninstall instructions)

Next Post 

How to remove PAntispyware09 or P Antispyware 09 (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

9 Comments

  1. SThompson
    ― November 8, 2009 - 3:35 pm  Reply

    I am using Windows 2000 Professional and have followed all the steps on removing the antivirus plus roguescanner yet I am still getting bogus security warnings when using my interenet what steps should i try to remove the rest of this threat. I think the required files and steps are made for win xp and up.

  2. Patrik
    ― November 9, 2009 - 5:30 am  Reply

    SThompson, probably your PC is infected with a new version of the rogue. Ask for help in our Spyware removal forum.

  3. darmin
    ― November 15, 2009 - 11:36 pm  Reply

    the antivirus plus was not removed

  4. Patrik
    ― November 16, 2009 - 6:17 am  Reply

    darmin, make a new topic in our Spyware removal forum. I will help you.

  5. Bingo
    ― November 20, 2009 - 11:19 am  Reply

    I’m not able to install the MalwareBytes software. Will Antivirus Plus prevent my installing it?

  6. Bingo
    ― November 20, 2009 - 11:28 am  Reply

    Saw suggestion to use safe mode if unable to install MalwareBytes. When I attempt to enter safe mode, I get a blue screen telling me I need to check for Viruses. 🙁 These guys are real jerks.

    I sent them an email complaining and they sent me a link with a removal software explaining this is the work of overzealous web masters. Unfortunately I don’t trust them so I’ll never try that link.

  7. Patrik
    ― November 20, 2009 - 9:30 pm  Reply

    Bingo, looks like an unknown trojan blocks Malwarebytes Antimalware. Try another way.
    1. Download HijackThis from here and run it.
    2. Click “Do a system scan only” button. Now select the entries that looks like what you see in the “Symptoms in a HijackThis Log” above by placing a tick in the left hand check box (if still present).
    3. Once you have selected all entries, close all running programs then click once on the “fix checked” button.
    4. Reboot your computer.
    5. Try run MalwareBytes once again.

    If these steps does not help you, then make a new topic in our Spyware removal forum.

  8. Manick
    ― December 12, 2009 - 1:00 pm  Reply

    A big thanks to this website. I followed the instruction and the the bloody Antivirus plus got successfully removed. Once again my thanks. Manick

  9. Mars
    ― May 22, 2010 - 9:01 pm  Reply

    Just a quick update and new solution:

    Antispyware Plus now blocks just about all files from opening to stop people getting rid of it with virus scanners.

    The solution is in what files it allows: Download Malwarebites Anyspyware as above, then rename the file to “firefox.exe”.

    Run and clear as instructed above.

Leave a Reply to Mars Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

How to reset Google Chrome settings to default
adwcleaner
AdwCleaner – Review, How to use, Comments
Malwarebytes won’t install, run or update – How to fix it
search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024
remove android virus
How to remove virus from Android phone

Recent Guides

How to remove Virus Sweeper (Uninstall instructions)
How to remove XP-Shield (Uninstall instructions)
How to remove WinPC Antivirus (Uninstall instructions)
How to remove Registry Defender Platinum (Uninstall instructions)
How to remove System Protector (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.