Omega AntiVir

Seeing an instance of Omega AntiVir scanner on your computer symbolizes that you are infected either with a Trojan Zlob or Trojan Downloader. Creating these Trojans will spread potentially unwanted program and install it on computer without user’s intervention. Lately, Omega AntiVir rogue program was seen to be actively distributing by these Trojan. Once inside the computer, it will employ deceiving tactics of getting user’s attention, either by an automatic virus scanning that will give fabricated results or excessive alert messages that advise computer users to get the registered version to be able to keep the computer safe.

Since a Trojan is responsible for installing Omega AntiVir, it will make changes to system and registry so that users will not be able to remove them with ease. It will disable various Windows functions such as Registry Editor, Task Manager, and Folder Options. To uninstall Omega AntiVir from computer, you must use an Omega AntiVir removal tool or a known and reputable anti-malware program. This will remove all associated files and entries hidden on various folders of your hard drive.

Screen Shot Image:

Omega AntiVir image

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

View More

Characteristics (Analysis)
Omega AntiViris a rogue program. Unlike Trojans and viruses, rogues do not reproduce once it enters the system. They usually propagate by means of another infection. Once inside the computer, it generates some changes to Internet browser and registry. Rogue program process an attempts to call itself on every Windows boot-up. A more sophisticated rogue programs can halt security application by ending relevant process.

Added Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Omega AntiVir" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Omega AntiVir
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\SetupPack.DocHostUIHandler
Associated Files and Folders:
C:\Documents and Settings\All Users\Application Data\OAV
C:\Documents and Settings\All Users\Application Data\OAV\oav.cfg
C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Omega AntiVir.lnk
C:\Documents and Settings\User\Application Data\Omega AntiVir
C:\Documents and Settings\User\Application Data\Omega AntiVir\cookies.sqlite
C:\Documents and Settings\User\Desktop\Omega AntiVir.lnk
C:\Documents and Settings\All Users\Application Data\52f53
C:\Documents and Settings\All Users\Application Data\52f53\mozcrt19.dll
C:\Documents and Settings\All Users\Application Data\52f53\OM83b.exe
C:\Documents and Settings\All Users\Application Data\52f53\OMEGA-AV.ico
C:\Documents and Settings\All Users\Application Data\52f53\sqlite3.dll
C:\Documents and Settings\User\Start Menu\Omega AntiVir.lnk
C:\Documents and Settings\User\Start Menu\Programs\Omega AntiVir.lnk 

How to Remove Omega AntiVir

1. Kill any running process that belongs to Omega AntiVir.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for the following files and click End Task.
OM83b.exe

2. Delete all registry entries that belong to this malware.
- Press [Windows Key]+R on your keyboard.
- In the 'Open' dialog box, type regedit. This will open registry editor.
- Find and delete the following:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Omega AntiVir"
- Close registry editor. Changes made will be save automatically.

3. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please Update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.

4. Delete all files dropped by Omega AntiVir.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Associated Files and Folders.'

Automatic Removal of Omega AntiVir

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.