Home Malware Programs Rogue Anti-Virus Programs Win 7 Antivirus Pro

Win 7 Antivirus Pro

Posted: February 2, 2010

Win 7 Antivirus Pro is a copy of other rogue security applications and pretends to offer the user anti-virus, anti-spyware and similar protective features. However, Win 7 Antivirus Pro will only give you false positives and other bad information to persuade you into registering Win 7 Antivirus Pro for a hefty fee. In addition to fraud, Win 7 Antivirus Pro is also guilty of blocking legitimate applications and web browser hijacking attacks. Removing Win 7 Antivirus Pro is simply common sense once you're aware of Win 7 Antivirus Pro's true functions, but this should be done by dedicated anti-virus software, since deleting Win 7 Antivirus Pro 'by hand' is more likely to cause other problems.

Win 7 Antivirus Pro: Not So Pro at Protecting Your PC

Win 7 Antivirus Pro is one small arm of a large group of rogue anti-virus programs. This family of rogue anti-virus applications uses a naming scheme that consists of the operating system being infected, a semi-random descriptive word or two-word phrase and finally the optional additional of a recent year, such as 2010 or 2011. Thus, Win 7 Antivirus Pro, Win 7 Antivirus Pro 2010, Vista Antispyware 2010, Win 7 Internet Security 2011 and XP Internet Security are all examples of the same basic threat.

Desktop alerts will become frequent while Win 7 Antivirus Pro is active on your PC, since Win 7 Antivirus Pro will create these warnings without checking your system to see if they're true or not first! Most of these fake errors are just used to badger you into spending money on Win 7 Antivirus Pro, but some of them have a more sinister purpose. For instance, the below message:

Win 7 Antivirus Pro Firewall Alert
Win 7 Antivirus Pro has blocked a program from accessing the Internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.

This error and ones similar to it are used to stop applications from running and don't indicate any real Trojan infection. Win 7 Antivirus Pro will typically use this tactic to stop you from running anti-malware scanners or other security tools that could assist you in stopping or deleting Win 7 Antivirus Pro.

Be a Real Pro and Remove Win 7 Antivirus Pro

Win 7 Antivirus Pro is also known to:

  • Prevent the proper use of your web browser by changing it to use a malicious proxy server. This lets Win 7 Antivirus Pro hijack your web search results to stop you from going to security-oriented sites. Win 7 Antivirus Pro may also change your homepage or force you to go to malicious websites.
  • Win 7 Antivirus Pro will add startup entries into the Windows Registry, so the rogue anti-virus program will run whenever you start the computer. Win 7 Antivirus Pro may continue to run even when closed, since a background memory process doesn't necessarily leave any visual evidence of being active. You can see active memory processes in Task Manager if Win 7 Antivirus Pro hasn't blocked it.

The activation key '1147-175591-6550' has been known to work for many rogue anti-virus programs related to Win 7 Antivirus Pro, and may also work for Win 7 Antivirus Pro, as well. When trying to remove Win 7 Antivirus Pro, you should prevent Win 7 Antivirus Pro from running first. This usually involves a Safe Mode boot, although other options are available if Safe Mode is compromised.

As is typically the case, deleting Win 7 Antivirus Pro by removing the files yourself isn't the best solution, since you risk failure and potential system damage. Your PC will have the best chance of coming out of the scrap in perfect health if you use a good anti-malware program to scan your computer for threats and delete Win 7 Antivirus Pro.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\AppData\Local\av.exe
    2 %UserProfile%\AppData\Local\WRblt8464P

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command =/START -safe-modeHKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\commandHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center

Related Posts

Loading...