• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Antivirus System Pro (Uninstall instructions)

Myantispyware team June 5, 2009    

Antivirus System PRO is rogue antivirus/antispyware program, new version of Spyware protect 2009. Like other fake antispyware programs, it uses fake alerts and false positives to trick you into buying the software. Antivirus System PRO usually installed itself onto your computer without your permission, through trojans and browser security holes.

During installation Antivirus System Pro configures itself to run automatically every time, when your computer starts. Immediately after launch, Antivirus System Pro starts scanning the computer and list a lot of threats to trick you to buy the paid version of the rogue. All of these threats are fake, so you can safely ignore them.

antivirus_system_pro
Antivirus System Pro (more screen shoots 1, 2)

While the Antivirus System Pro is running, your computer will display fake alerts, an example:

Windows Security alert
Windows reports that computer is infected. Antivirus software
helps to protect your computer against viruses and other
security threats. Click here for the scan your computer. Your
system might be at risk now.

Antivirus System Pro Alert
INFILTRATION ALERT
Your computer is being attacked by a Internet
Virus. It could be a password stealing attack, a
trojan – dropper or similar.

DETAILS
Attack from 235.157.169.30, port 40771
Attacked port: 22363
Threat: Win32/Nuqel.E

Do you want to block this attack?

Also Antivirus System Pro will install a Internet Explorer BHO module (iehelper.dll) that will hijack Internet Explorer and randomly shows a “Internet Explorer cannot display the webpage. Needed Powerfull PC Protection” warning page (uses fake address security.microsoft.com), instead of the site you are trying to browse to:

Internet Explorer Warning – visiting this web site may harm your computer!

Most likely causes:
The website contains exploits that can launch a malicious code on your computer
Suspicious network activity detected
There might be an active spyware running on your computer

What you can try:
– Purchase Antivirus System PRO for secure Internet surfing (Recommended).
– Check your computer for viruses and malware.
– More information

The warning is fake and should be ignored! Antivirus System Pro can be safely removed from your computer along with any other trojan infections if the proper steps are taken. If you are a non-techie computer user then this method of removing Antivirus System Pro and any associated malware from your computer is for you.

Symptoms in a HijackThis Log

O1 – Hosts: 209.44.111.57 security.microsoft.com
O1 – Hosts: 209.44.111.57 inetavirus.com
O1 – Hosts: 209.44.111.57 www.inetavirus.com
O1 – Hosts: 91.212.127.227 awareremover2009.microsoft.com
O2 – BHO: BHO – {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} – C:\WINDOWS\system32\iehelper.dll
O4 – HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
O4 – HKLM\..\Run: [servises] C:\Windows\system32\servises.Exe
O4 – HKCU\..\Run: [system tool] C:\Program Files\atkafh\adxlsysguard.exe
O4 – HKCU\..\Run: [servises] C:\Windows\system32\servises.Exe
O4 – HKLM\..\Policies\Explorer\Run: [servises] C:\Windows\system32\servises.Exe
O4 – HKCU\..\Policies\Explorer\Run: [servises] C:\Windows\system32\servises.Exe

Use the following instructions to remove Antivirus System Pro (Uninstall instructions)

Step 1

Download HijackThis from here, but before saving HijackThis.exe, rename it first to explorer.exe and click Save button to save it to desktop.

Doubleclick on the explorer.exe icon on your desktop for run HijackThis.

HijackThis main menu opens.

Click “Do a system scan only” button. Look for lines that looks like:

O4 – HKLM\..\Run: [arlsknkw] C:\Documents and Settings\user\Local Settings\Application Data\lqtwnu\wqcmsysguard.exe
O4 – HKCU\..\Run: [arlsknkw] C:\Documents and Settings\user\Local Settings\Application Data\lqtwnu\wqcmsysguard.exe
O4 – HKCU\..\Run: [wpolkxos] C:\Documents and Settings\user\Local Settings\Application Data\ovugbs\rwjrsysguard.exe

Note: list of infected items may be different, but all of them have “sysguard.exe” string in a right side and “O4” in a left side.

Place a checkmark against each of them. Once you have selected all entries, close all running programs then click once on the “fix checked” button. Close HijackThis.

Step 2

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select “Perform Quick Scan”, then click Scan. The scan may take some time to finish,so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

Antivirus System Pro mbam
Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Antivirus System Pro creates the following files and folders

C:\WINDOWS\system32\iehelper.dll
C:\WINDOWS\sysguard.exe
C:\Windows\system32\servises.Exe
C:\Program Files\[RANDOM]\[RANDOM]guard.exe

Antivirus System Pro creates the following registry keys and values

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
HKEY_CURRENT_USER\SOFTWARE\AvScan
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system tool
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\servises

Rogue Anti Spyware Tutorials - HowTo

 Previous Post

Remove XP Deluxe Protector (Uninstall instructions)

Next Post 

Malwarebytes won’t install, run or update – How to fix it

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

88 Comments

  1. Patrik
    ― August 15, 2009 - 8:32 am  Reply

    Tim, try rename Avenger.exe to explorer.exe and run it again.

  2. akila
    ― August 15, 2009 - 12:48 pm  Reply

    Hi,

    I have tried all means to remove Antivirus system pro( have downloaded spydoctor and run the same, tried manually as well)… While the anti virus system pro doesnt show up on the task bar anymore, it still wouldnt go away when I open any web browser and continutes to trouble me. Please help. Really urgent

  3. Patrik
    ― August 15, 2009 - 11:35 pm  Reply

    akila, please make a new topic at our Spyware removal forum.

  4. brian
    ― August 28, 2009 - 1:50 am  Reply

    i have used pc tools to try and destroy windows antivirus 2010.but im still getting these fake alerts and cannot access my registry.nothing works in my control panel and every time i try to start a program it opens the box “open with”.i cant open programs ive downloaded and cannot use housecall nor windows update.this stuff is still in my comp.can you address these issues? i have windows xp pro on a dell.

  5. Patrik
    ― August 29, 2009 - 4:35 am  Reply

    brian, looks like windows registry is damaged by malware. Ask for help at our spyware removal forum.

  6. Monica
    ― September 8, 2009 - 4:37 am  Reply

    Thanks a lot. I dont know how i got this thing on my computer but with your help it was gone bye bye.

  7. Mark
    ― October 7, 2009 - 8:34 pm  Reply

    Thank you, thank you.

  8. Hank T
    ― October 10, 2009 - 6:00 pm  Reply

    Boy this really worked except I think it removed my Microsoft Office XP. Thank God it’s gone!!!

  9. Braddock
    ― October 14, 2009 - 12:00 am  Reply

    Hi thanks for the download,it really gives a very big help and protection for my pc…more power guys…

  10. Net
    ― October 15, 2009 - 12:58 am  Reply

    Hi,

    Thank you. Your instruction work. Thank you again

  11. carol
    ― October 22, 2009 - 8:56 pm  Reply

    Avenger only removed the iehelper file it did not find sysguard.exe. Do I have a newer version? I noticed bwimsysguard running in my task manager. I can even start in safe mode. I am writing this on a different c0mputer. HELP

  12. Patrik
    ― October 23, 2009 - 7:17 am  Reply

    carol, yes your PC is infected with a new version of the rogue. Ask for help in our Spyware removal forum.

  13. paul
    ― October 24, 2009 - 8:48 am  Reply

    thanks very much – it worked eventually!
    as a non techie just a a couple of things i found.
    initailly i could not open malware, as the virus would not let me. I then could not open Avenger either but managed to if I opened it as soon as I switched computer on.
    was then able to run the avenger followed by malware, which took a couple of hours but did clear this damn virus.
    Many thanks again guys!

  14. Me
    ― October 26, 2009 - 2:35 am  Reply

    WIll not let me bring up !!! Task manager

  15. Me
    ― October 26, 2009 - 2:36 am  Reply

    wont let me delete

  16. Dev Boys
    ― October 28, 2009 - 3:45 pm  Reply

    Works like a charm. The trick to opening OTM is to close all the malware windows asap n then start OTM. Once your r done with OTM the stupid popups stops!!!

    And then i guess the anti-malware software jus gets rid of the traces.

    Works like a charm.

    When i installed AVGFree i thot i had gotten rid of it until i restarted my PC. THank goodness this works.

    And i thot this was some Halloween virus that explodes on Halloween itself. *phew*.

    I HATE MALWARES!!!!!!!!!

  17. Bunchy
    ― November 2, 2009 - 7:47 pm  Reply

    Thanks a lot… followed the steps, seems to work perfectly. Rebooted twice so far without a problem.

  18. Brandon
    ― November 6, 2009 - 5:37 pm  Reply

    Thanks for the advice; I’ve got a friend having problems with the AntiVirus System Pro program. Soon, that’ll be fixed. 🙂

  19. mit
    ― November 9, 2009 - 3:11 pm  Reply

    Help needed with winguard2009.
    I followed steps of anonymous and renamed iehelper.dll. rebooted. My explorer doesn’t open. How do I make it to work again? I connot run system recovery….it doesn’t open the screen to run the restore operation. Pl help fast

  20. Patrik
    ― November 10, 2009 - 6:22 am  Reply

    mit, please ask for help in our Spyware removal forum.

  21. Tito
    ― November 14, 2009 - 3:46 am  Reply

    I was going nuts with the antivirus systems pro, I took my laptop to a repair shop, and not even the dude there was able to help me. So I desided to give spybot a chance and it worked for me, I’m free of this crazy bug and my laptop is back to normal. Some of you may want to give it a try…hey you never know.

  22. Brian
    ― November 16, 2009 - 9:33 pm  Reply

    Hey,

    Removed the antivirus software but now can not find my preferred wireless network (it’s a secured network) but other computers in my house can find it … I am worried I have deleted a certain file?

    It’s weird, because it sees other networks that are in the area and secured, but can’t find my network.. any advice?

  23. Zoyia
    ― November 16, 2009 - 10:55 pm  Reply

    Hi, i ran both OMT and MBAM in safe mode becasue it wouldn’t let me run them in regular mode…. but the virus/ trojan is still here, any ideas?

  24. Patrik
    ― November 17, 2009 - 11:12 am  Reply

    Zoyia, looks like your computer is infected with a new variant of the rogue. Ask for help in our Spyware removal forum.

  25. David
    ― November 21, 2009 - 3:09 pm  Reply

    I’ve done everything stated, but for some reason it won’t let me use the internet. I can go to any website as Admin in Safe Mode, but when I log in just as my typical user i get no internet. I use ‘ipconfig/release, /renew’ and i DO have an ipaddress, but it never connects to the internet. PLZ help.

  26. Patrik
    ― November 21, 2009 - 11:43 pm  Reply

    David, you have tried to ping any site ?
    Start->Run,
    Type cmd
    type ping google.com
    If is works, then check proxy setting of browser.
    Also you can ask for help in our Spyware removal forum.

  27. joseph
    ― November 23, 2009 - 4:47 am  Reply

    i did everything it told me to do
    but it cant find the iehelper.dll
    and the computer works fine
    until when i restart
    everything is back there
    and if i do it again
    it deltes everything and it states that it cant find iehelper.dll
    please help me
    i need my laptop

  28. Patrik
    ― November 24, 2009 - 12:02 am  Reply

    joseph, please follow these steps.

  29. Sherry Garrett
    ― November 24, 2009 - 10:49 pm  Reply

    I have not installed this monster but a warning bar keeps popping up on my websites and covering info I need off the sites. If I click on it it comes up and wants me to purchase. How do I get rid of it?

  30. Patrik
    ― November 24, 2009 - 10:59 pm  Reply

    Sherry, please read my previous comment. Make a HijackThis log, open a new topic in our Spyware removal forum and post HijackThis log into it.

« Previous 1 2 3 Next »

Leave a Reply to jim Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

remove chrome extension
How to remove Chrome extensions installed by enterprise policy
Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide
Malwarebytes won’t install, run or update – How to fix it
How to reset Mozilla Firefox (Updated Apr. 2018)

Recent Guides

Remove XP Deluxe Protector (Uninstall instructions)
How to remove WinBlueSoft (Uninstall instructions)
How to remove Presto Tuneup (Uninstall instructions)
How to use TrendMicro online virus scanner (Trend Micro HouseCall)
How to remove Fast Antivirus 2009 (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.