AVSystemCare

AVSystemCare Description



AVSystemCare is a fake security program designed to lure you into purchasing its rogue full version. AVSystemCare is designed to issue fake security warnings to make you believe that your computer is infected with spyware. These messages may look similar to the ones issued from Windows Security center. Although AVSystemCare may seem a legitimate program, it only seeks to swindle you out your money and is a rogue program. AVSystemCare may be installed through various security loopholes or with the help of malicious Trojans.
Download SpyHunter Spyware Scanner

Aliases


Potentially harmful program WinFixer.IB [AVG]Downloader.Win32.WinFixer.z [VBA32]Not-A-Virus.Downloader.Win32.WinFixer.z [eWido]not-a-virus:Downloader.Win32.WinFixer.z [Kaspersky]Win32:Winfixer-F [Avast]Generic Malware [Panda]AdWare.Winfixer [Ikarus]RogueAntiSpyware.AVSystemCare [PCTools]Win-Trojan/Xema.variant [AhnLab-V3]High Risk Worm [Prevx]

More aliases (22)


AVSystemCare Automatic Detection Tool (Recommended)


Is your PC infected with AVSystemCare? To safely & quickly detect AVSystemCare, we highly recommend you run the malware scanner listed below.




Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name Detection Count
    1 %ProgramFiles%\AVSystemCare 703
    2 RTasks.exe 703
    3 aviupd.exe 665
    4 pgs.exe 614
    5 UGaChk.dll 438
    6 IEFWBHO.dll 403
    7 AVSystemCare.lnk 183
    8 Uninstall AVSystemCare.lnk 117
    9 %AllUsersProfile%\Start Menu\Programs\AVSystemCare 87
    10 %CommonProgramFiles%\AVSystemCare 73

    More files

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}AVSystemCare
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {D961C9CA-59B3-46DD-9CEE-47714CFE2831}{C4514FE1-54AA-42f0-B212-BA8065206F8F}{55B49019-E69E-47FD-A67F-F28D83E5B695}

Additional Information

  • The following cookies were detected:
    avsystemcare
Posted: April 20, 2007 | By
Share:
Follow Me on Pinterest More More
Threat Level: 10/10
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Rate this article:
Detection Count: 30

5 Comments

  • bob says:

    I am fighting with my bank now on my visa account.. I got sucked into this avsystem & when i tried to call them they never answer their phone. i have a charge on my visa account for this avsystem ..but when i tried to download it my computer crashed.i told my bank that it is a dishonest company and was not paying for this charge. they said they would get back to me.

  • alpha82 says:

    Im sick of this AVSystemCare.com scam. How can I find out who this site is run by and have them arrested? I cant use my control panel i cant delete temporary internet files i cant use windows media player and I cant run a new windows XP CD. Tried to delete app.exe and as soon as i delete it it reappears magically right back into my c drive.

  • Bill says:

    AVSystemCare is also using the file WINTAVSNET.EXE… look for it!

  • ghostrider01 says:

    ravi,

    You should use reliable antivirus or antispyware program to get rid of this virus.

  • ravi says:

    romnov.exe virus how can be remove in my pc

Leave a Reply

What is 9 + 9 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)