Antivirus System Pro

Antivirus System Pro is another rogue antivirus application that will made public together with its sister program called Antivir System Pro. Antivirus System Pro disguises as an antivirus application. It will show spoof virus scan result on computer, followed by a display of exaggerated results displaying a number of threats found. This is a technique used to convince computer owners from buying the registered version of the program which according to some are worthless. What do we expect from a fake security program?

Since Antivirus System Pro conquers a computer with the help of a Trojan, expect a modification on your system files with scattered hidden files. Antivirus System Pro also creates its own entry on the registry so that it will run simultaneous with Windows. When running, it will block an access to Internet and prevent an access to security related websites. It will make your antivirus program to stop responding by ending security-related process. Removing this rogue application may be difficult if done manually. This is why we offer an Antivirus System Pro removal tool and procedure on this page to serve as your guidance.

Screen Shot Image:

Antivirus System Pro image1

Antivirus System Pro Image2

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista

Antivirus System Pro Removal Procedures

Antivirus System Pro REMOVAL TOOL:
In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected computer.

MANUAL REMOVAL PROCEDURE:
1. Press Ctrl+Alt+Del on keyboard to stop process associated to “Antivirus System Pro”. When Windows Task Manager opens, go to Processes Tab and find and end the following process:
sysguard.exe

2. You need to update your installed antivirus application to have the latest database.

3. Thoroughly scan the system and any detected threats must be removed. If removal is prohibited, it is best to quarantine the infected item. Manually locating and deleting of malicious files should also be performed. Please see files below that are related to Antivirus System Pro Virus.

4. Registry entries created by Antivirus System Pro must also be removed from the Windows system. Please refer below for entries associated to the rogue program.
- For Windows 2000/XP: Go to Start > Run, type “regedit” on dialog box then press Enter on keyboard.
- For Windows Vista/7: Go to Start > Search Program and Files, type “regedit” and press Enter.

5. Exit registry editor.

6. Get rid of Antivirus System Pro start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
sysguard.exe

7. Click Apply and restart Windows.

Technical Details and Additional Information:

Malicious Files Added by Antivirus System Pro
c:\WINDOWS\sysguard.exe
c:\WINDOWS\system32\iehelper.dll
C:\Documents and Settings\[4 random characters]sysguard.exe

Antivirus System Pro Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “system tool”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random characters]”
HKEY_CURRENT_USER\Software\AvScan
HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}