CP Antivirus 2100

CP Antivirus 2100 is a must-removed application that was categorized as another rogue security program currently propagated through the Internet by means of a Trojan. This Trojans are known for their capabilities to take advantage of system vulnerability to be able to penetrate a system. Once it was executed in a computer, it will locate a remote server and download the unregistered version of CP Antivirus 2100. At the same time, it will be installed and configured to run automatically on the computer. Once loaded, it will start a virus scan and generate fake results in order to deceive the victims and force them to get the CP Antivirus 2100 registration key, which will cost too expensive for a useless program.

Presence of CP Antivirus 2100 virus will disable certain functions of the compromised unit. Installed application will be prevented from running and will state that the .exe file is infected. A recommendation to fix this will be displayed but a registered version of CP Antivirus 2100 must be obtained first. This malicious software was also designed to be installed without a components for automatic removal. The only way to get rid of this rogue one is to use an effected and legitimate anti-malware solution. Below is a simple guide and tool to remove CP Antivirus 2100 together with all the files and registry entries it has concealed on the victims PC.

Alias: Computer Antivirus 2100

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

CP Antivirus 2100 Removal Procedures

Manual Removal:
1. Press Ctrl+Alt+Del on keyboard to stop process associated to “CP Antivirus 2100″. When Windows Task Manager opens, go to Processes Tab and find and end the following process:
(random characters).exe

2. You need to update your installed antivirus application to have the latest database.
3. Thoroughly scan the computer and any detected threats must be removed. If removal is prohibited, it is best to quarantine the infected item. Manually locating and deleting of malicious files should also be performed. Please see files below that are related to CP Antivirus 2100 Virus.
4. Registry entries created by CP Antivirus 2100 must also be remove from the Windows system. Please refer below for entries associated to the rogue program. [how to edit registry]
5. Exit registry editor.
6. Get rid of CP Antivirus 2100 start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
(random characters).exe

7. Click Apply and restart Windows.

CP Antivirus 2100 Removal Tool:
In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

Using Portable SuperAntiSpyware:
To thoroughly remove the virus, it is best to do a separate scan of another security program so that other infected files not detected by anti-virus application can be remove as well. Click here to download and run SAS Portable Scanner.

Scan with Norton Power Eraser:
A free removal tool from Norton Antivirus was developed to remove unfamiliar threats without using the traditional AV signatures. Download the tool from this location and start scanning the computer for viruses.

Technical Details and Additional Information:

Malicious Files Added by CP Antivirus 2100:
%UserProfile%\Desktop\CP Antivirus 2100.lnk
%UserProfile%\Start Menu\Programs\CP Antivirus 2100\CP Antivirus 2100.lnk
%AppData%\Microsoft\[random].exe

CP Antivirus 2100 Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘.exe’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = ”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = ’127.0.0.1:33554′

What to do next...