Antivirus GT

Antivirus GT or sometimes called as AntivirusGT is a fake anti-malware program that will disguise as anti-virus and anti-spyware for Windows operating system. It originated from the same group who spearheaded the spread of Antivirus 7. This type of software is being distributed through the Internet using different channels. A malicious web site pretending to be an online virus scanner can download Antivirus GT automatically on visitors computer via drive-by-download method. File-sharing networks, instant messaging programs and spam email messages can also contribute to the propagation of this unwanted application. With this mentioned, make sure that all cautions when clicking on link, opening email attachments and installing executable files are being taken with cautious.

If Antivirus GT is installed, a modification will be made to the system registry and make it start automatically with Windows operating system. A virus scan is performed and displays a very fast scan results detecting dozens of threats. Fake warning alerts will continuously pop-up on the screen stating that computer is infected. One sample alert will have this message:

AntivirusGT Resident Shield: Virus Detected
Warning! Active virus detected!
Threat Detected: Trojan.Injector.BZ
Infected File: C:\Windows\System32\rundll32.exe

It will prompt user to get rid of these viruses by getting the full version of Antivirus GT. Following this advise will just scam users and no protection or virus removal will be made. After all, this rogue program has no capability to perform as an antivirus program because it is lack of necessary application and database to do so. The only way to remove Antivirus GT is by using an updated version of anti-malware and anti-virus application.

Antivirus GT Screen Shot:

Antivirus GT Sreen Shot Image

Alias: AntivirusGT, AV GT

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Antivirus GT Removal Procedures

Manual Removal:
1. Stop Antivirus GT process by pressing Ctrl+Alt+Del. Windows Task Manager will open. Look for the following process:
antivirus GT.exe
avgt.exe

2. Update your installed anti-virus program.
3. Run a full system scan and clean/delete all detected infected file(s). A manual removal of virus-related files should also be performed.
4. Edit Windows registry and delete Antivirus GT entries.
5. Exit registry editor.
6. Remove Antivirus GT start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. System Configuration Utility will open. Go to Startup tab and uncheck the following Start-up item(s):
antivirus GT.exe
avgt.exe

7. Click Apply and restart Windows.

Antivirus GT Removal Tool:
In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

Technical Details and Additional Information:

While Antivirus GT still resides on the system, a continuous pop-up alert messages will be displayed to scare computer users and hope that they will be able to purchase the licensed version. Some of this alerts may contain these statement:

Resident Shield: New virus detected
Warning! New virus detected
Please click “Remove All” button to heal all infected files and protect your PC

Internet Shield: Identity theft attempt detected
112.58.55.78
Warning! Identity theft attempt detected
Please click “Prevent attack” button to heal all infected files and protect your PC

Security advisor: Important updates available
Attention! New important updates available
Always install latest updates to enhance your computer security and performance

Malicious Files Added by Antivirus GT:
c:\Documents and Settings\All Users\Start Menu\AVGT
c:\Documents and Settings\All Users\Start Menu\AVG\Antivirus GT.lnk
c:\Documents and Settings\All Users\Start Menu\AVG\Uninstall.lnk
c:\Program Files\AVGT
c:\Program Files\AVGT\Antivirus GT.exe
c:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb
c:\WINDOWS\system32\UpdateExplorer.dll
%UserProfile%\Desktop\Antivirus GT.lnk

Antivirus GT Registry Entries:
HKEY_CURRENT_USER\Software\EVA246
HKEY_CLASSES_ROOT\CLSID\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2BFE352-A303-4EA8-88FE-CE35361D7E8B}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AVGT”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “WinNT-EVI 12.03.2010″