Mar 20

Threat Description:

Av-2010.com is a hijacker site helping Antivirus Soft rogue security program spread through the Internet. It paralyzes your web surfing ability and redirects your browser to a bogus alert page that informs (or rather – misinforms) you about some problems Internet Explorer has allegedly encountered. That is a misleading message that encourages you to follow the further instructions and in the long run end up on Av-2010.com selling Antivirus Soft scam. The underlying essence of this hijacker lies inside Antivirus Soft malcode. This rogue antivirus solution incorporates its own Registry keys into the corresponding Windows directory thus disabling some essential computer functions. One of those is the victim’s capability of surfing the Internet, Av-2010.com hijacker being the outcome. You will not only appear to have browsing trouble, you will as well find it problematic to run any processes because the malware will state they are all infected and close them immediately. So you might want to use the services of a trusted automatic removal tool to get rid of Av-2010.com hijacker issue. Alternatively, you can try erasing the malware manually – just locate and delete the files and Registry keys listed below.

Determine if your system is infected with Av-2010.com hijacker and related threats:

Av-2010.com Screenshot:

Av-2010.com

How to remove this threat manually:

Av-2010.com manual uninstall procedure:

Get rid of the related corrupt files:

  • %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe
  • %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sftav.exe

Delete the associated registry entries:

  • HKEY_CURRENT_USER\Software\AvScan
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“

Please note that Av-2010.com manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Av-2010.com Removal Tool

Leave a Reply