Jan 09

Malware Analysis:

Super AV adds up to our category of rogue anti-spyware programs. This is by no means a typical antivirus program, although that’s exactly the impression you may get from the name. No, it’s something that just pretends to be benign but is in fact so malicious inside. Super AV usually uses drive-by downloads to penetrate into one’s computer. Basically, this means it’s really difficult to spot the moment it got inside. All it takes for this malware to intrude is just one click on some ad or other link when you’re online. After that, the program will be actively interfering with your computer usage, displaying fabricated scanners like the one shown on the image below, as well as loads of pop-ups that alert you in many different ways. The main idea of Super AV on this stage is to get you believing that your PC is at risk. It says you have worms (e.g. Worm.Reclog.A), trojan horses (like TrojanDownloader.Phexsol.B, Trojan.Hooblong.A), backdoors (Backdoor.Sajdela, Backdoor.Bigdipper.AB), exploits and other sample of badware. Among all the options and buttons on this utility’s interface, there’s one most prominent button reading ‘Register’ which is the most desired one by hackers for users to hit. They prompt you to buy the licensed copy of Super AV so as to handle all the supposedly detected infections. But even if you do pay the registration fee, it won’t do you or your computer any good. This will simply lead to the alleged elimination of the threats that never really were inside your system. Therefore it’s out of the question that Super AV should be removed as it is a virus that may harm your workstation.

Determine whether or not your computer is infected with Super AV scam:

Super AV Snapshot:

Super AV

How to remove Super AV manually:

To perform manual removal of this rogue, you should do the following:

Delete the corrupt files listed below:

  • %WINDOWS%\[random].exe

Remove the following associated registry entries:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Security” = “%Windows%\[random].exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe “Debugger” = “[random].exe”

Please note that manual removal of Super AV is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Super AV Removal Tool

Leave a Reply