Added on 18 Nov 2009(92 Views)
classification: Rogue Anti-Virus Program
ndromeda Antivirus claims to be an award-wining security software solution that will keep your system safe and protected. But the simple truth of the matter is that Andromeda Antivirus will do no such thing. It will not detect malware if your computer has already been compromised, it will not remove said malware, and will definitely not protect your computer from future malware infections (if your computer is clean). Andromeda Antivirus has no security software capabilities because it is a rogue.
As a rogue it only cares about one thing and one thing only: your hard earned money. To be more precise, it only cares about making you waste your hard earned money. In this regard Andromeda Antivirus will use various scare tactics to convince you that your system is infected. These scare tactics include annoying popups, fake security alerts and phony system scans (that detect numerous fake infections). Then it asks the user to purchase an Andromeda Antivirus license to make things all better again.
That is nothing but a scam. By scaring you into thinking your computer is infected, the guys behind Andromeda Antivirus push you to purchase a license for a fake security software solution that claims it can remove the aforementioned infection. You would in fact be paying for a fake software application that claims to remove a phony infection. Don’t waste your money like that!
Automatic removal guide
Step 1. If you have a printer, make sure to print out this tutorial. If you do not have a printer, save this tutorial, go out to a copy center and print it out there. If you do not have a printer and do not want to go out, then use the pen and paper method: grab a pen and a piece of paper and write down the instruction presented in the steps below. In the process of eliminating Andromeda Antivirus from your machine you will need to shut down the browser. And since this will also shut down the tutorial, you need to know what you should do next.
Step 2. You will have to install Malwarebytes’ Anti-Malware. In this regard you need to download the software’s setup executable. Just click this link and save the .exe file on your computer (preferably on your desktop).
Step 3. Double click the Malwarebytes’ Anti-Malware setup executable. It should be on the desktop under the name mbam-setup. This will launch the installation process. If you already know how to install a piece of software, proceed to step 4. If you do not know how to do this, we’ll walk you though it all:

- The Select Setup Language window should have popped up. By default, the language in which the software will be installed is set to English, but you can change this. The software provides support for 30+ languages. After selecting the language of your choice, click OK. It would be best to just leave it set to English though.

- The Malwarebytes’ Anti-Malware Setup Wizard will now popup. Just click Next.

- You will be presented with the License Agreement. Click I accept the agreement and then click Next. If you do not accept the agreement you will not be able to continue.

- Keep clicking Next until you get to the Ready to install window. Now click Install. After the installation process completes click Finish. Do not uncheck the boxes next to Update Malwarebytes’ Anti-Malware or Launch Malwarebytes’ Anti-Malware.







Step 4. The Malwarebytes’ Anti-Malware application will launch automatically. The Perform quick scan option should be checked by default – if it isn’t then check it and then click Scan. You are well advised to close all running apps before clicking scan. This will ensure the scan for Andromeda Antivirus will complete swiftly.

Malwarebytes’ Anti-Malware will start scanning your files for signs of Andromeda Antivirus. This may take a while, so be patient. It all depends on how powerful your computer is and how many files Malwarebytes’ Anti-Malware has to scan.

When the scan for Andromeda Antivirus is complete you will be presented with a notification box. Click OK to close the notification box and go to the main Scanner screen. Click Show Results and you will be presented with a list of all the infected files Malwarebytes’ Anti-Malware has detected.


Step 5. Click Remove Selected and Malwarebytes’ Anti-Malware will remove all the infected files it has detected. It may be necessary to restart your computer in order to remove some of these files. After Malwarebytes’ Anti-Malware is done removing all the infected files, it will open Notepad and present the scan log to you. You can review the log at your leisure – save it If you want.

Step 6. Close Malwarebytes’ Anti-Malware and you’re done. No traces of Andromeda Antivirus should be left on your computer.
Manual removal guide
Stop and remove the processes:
Access the Windows Registry Editor and delete the following registry keys:
Locate and delete the following files:
Disable the following DLL libraries:
Don't forget to:
Tags:
Link to this article:
Add comment:
ndromeda Antivirus claims to be an award-wining security software solution that will keep your system safe and protected. But the simple truth of the matter is that Andromeda Antivirus will do no such thing. It will not detect malware if your computer has already been compromised, it will not remove said malware, and will definitely not protect your computer from future malware infections (if your computer is clean). Andromeda Antivirus has no security software capabilities because it is a rogue.

As a rogue it only cares about one thing and one thing only: your hard earned money. To be more precise, it only cares about making you waste your hard earned money. In this regard Andromeda Antivirus will use various scare tactics to convince you that your system is infected. These scare tactics include annoying popups, fake security alerts and phony system scans (that detect numerous fake infections). Then it asks the user to purchase an Andromeda Antivirus license to make things all better again.
That is nothing but a scam. By scaring you into thinking your computer is infected, the guys behind Andromeda Antivirus push you to purchase a license for a fake security software solution that claims it can remove the aforementioned infection. You would in fact be paying for a fake software application that claims to remove a phony infection. Don’t waste your money like that!
Automatic removal guide
Step 1. If you have a printer, make sure to print out this tutorial. If you do not have a printer, save this tutorial, go out to a copy center and print it out there. If you do not have a printer and do not want to go out, then use the pen and paper method: grab a pen and a piece of paper and write down the instruction presented in the steps below. In the process of eliminating Andromeda Antivirus from your machine you will need to shut down the browser. And since this will also shut down the tutorial, you need to know what you should do next.
Step 2. You will have to install Malwarebytes’ Anti-Malware. In this regard you need to download the software’s setup executable. Just click this link and save the .exe file on your computer (preferably on your desktop).
Step 3. Double click the Malwarebytes’ Anti-Malware setup executable. It should be on the desktop under the name mbam-setup. This will launch the installation process. If you already know how to install a piece of software, proceed to step 4. If you do not know how to do this, we’ll walk you though it all:

- The Select Setup Language window should have popped up. By default, the language in which the software will be installed is set to English, but you can change this. The software provides support for 30+ languages. After selecting the language of your choice, click OK. It would be best to just leave it set to English though.

- The Malwarebytes’ Anti-Malware Setup Wizard will now popup. Just click Next.

- You will be presented with the License Agreement. Click I accept the agreement and then click Next. If you do not accept the agreement you will not be able to continue.

- Keep clicking Next until you get to the Ready to install window. Now click Install. After the installation process completes click Finish. Do not uncheck the boxes next to Update Malwarebytes’ Anti-Malware or Launch Malwarebytes’ Anti-Malware.







Step 4. The Malwarebytes’ Anti-Malware application will launch automatically. The Perform quick scan option should be checked by default – if it isn’t then check it and then click Scan. You are well advised to close all running apps before clicking scan. This will ensure the scan for Andromeda Antivirus will complete swiftly.

Malwarebytes’ Anti-Malware will start scanning your files for signs of Andromeda Antivirus. This may take a while, so be patient. It all depends on how powerful your computer is and how many files Malwarebytes’ Anti-Malware has to scan.

When the scan for Andromeda Antivirus is complete you will be presented with a notification box. Click OK to close the notification box and go to the main Scanner screen. Click Show Results and you will be presented with a list of all the infected files Malwarebytes’ Anti-Malware has detected.


Step 5. Click Remove Selected and Malwarebytes’ Anti-Malware will remove all the infected files it has detected. It may be necessary to restart your computer in order to remove some of these files. After Malwarebytes’ Anti-Malware is done removing all the infected files, it will open Notepad and present the scan log to you. You can review the log at your leisure – save it If you want.

Step 6. Close Malwarebytes’ Anti-Malware and you’re done. No traces of Andromeda Antivirus should be left on your computer.
Manual removal guide
Stop and remove the processes:
AndromedaAntiVirus.exe
bprint.exe
vclipsrv.exe
bprint.exe
vclipsrv.exe
Access the Windows Registry Editor and delete the following registry keys:
HKEY_CURRENT_USER/Software/Antivirus
HKEY_LOCAL_MACHINE/SOFTWARE/Antivirus
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run/”Antivirus” = “%ProgramFiles%/AndromedaAntiVirus/Antvrs.exe”
HKEY_CLASSES_ROOT/*/shell/AV
HKEY_CLASSES_ROOT/Folder/shell/AV
HKEY_LOCAL_MACHINE/SOFTWARE/AndromedaAv
HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Enum/Root/LEGACY_ANDROMEDAAVDRV
HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/AndromedaAvDrv
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_ANDROMEDAAVDRV
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/AndromedaAvDrv
HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/AndromedaAVService
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/AndromedaAVService
HKEY_LOCAL_MACHINE/SOFTWARE/Antivirus
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run/”Antivirus” = “%ProgramFiles%/AndromedaAntiVirus/Antvrs.exe”
HKEY_CLASSES_ROOT/*/shell/AV
HKEY_CLASSES_ROOT/Folder/shell/AV
HKEY_LOCAL_MACHINE/SOFTWARE/AndromedaAv
HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Enum/Root/LEGACY_ANDROMEDAAVDRV
HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/AndromedaAvDrv
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_ANDROMEDAAVDRV
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/AndromedaAvDrv
HKEY_LOCAL_MACHINE/SYSTEM/ControlSet001/Services/AndromedaAVService
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/AndromedaAVService
Locate and delete the following files:
%ProgramFiles%/AndromedaAv/av.exe
%ProgramFiles%/AndromedaAv/DataBases/avd.avp
%ProgramFiles%/AndromedaAv/DataBases/avhd.avp
%ProgramFiles%/AndromedaAv/DataBases/avhd1.avp
%ProgramFiles%/AndromedaAv/DataBases/avm.avp
%ProgramFiles%/AndromedaAv/DataBases/av_nav_hd.avp
%ProgramFiles%/AndromedaAv/DataBases/av_nav_m.avp
%ProgramFiles%/AndromedaAv/Logs/08-2008_AndromedaAvLog.log
%System%/dllcache/crasctrs.dll
%System%/dllcache/tnetlogon.dll
%System%/drivers/winav.sys
%System%/andrav_inet.dll
%System%/AndromedaAv.exe
%System%/bpsnppagn.dll
%System%/hir50_qcx.dll
%System%/rqcap.dll
%System%/settings
%System%/thunk.dll
%System%/vCleanUp.exe
%ProgramFiles%/AndromedaAv/DataBases/avd.avp
%ProgramFiles%/AndromedaAv/DataBases/avhd.avp
%ProgramFiles%/AndromedaAv/DataBases/avhd1.avp
%ProgramFiles%/AndromedaAv/DataBases/avm.avp
%ProgramFiles%/AndromedaAv/DataBases/av_nav_hd.avp
%ProgramFiles%/AndromedaAv/DataBases/av_nav_m.avp
%ProgramFiles%/AndromedaAv/Logs/08-2008_AndromedaAvLog.log
%System%/dllcache/crasctrs.dll
%System%/dllcache/tnetlogon.dll
%System%/drivers/winav.sys
%System%/andrav_inet.dll
%System%/AndromedaAv.exe
%System%/bpsnppagn.dll
%System%/hir50_qcx.dll
%System%/rqcap.dll
%System%/settings
%System%/thunk.dll
%System%/vCleanUp.exe
Disable the following DLL libraries:
hinetres.dll
rpthreadVC.dll
thunk.dll
cpifmgr.dll
tmswdat10.dll
rpthreadVC.dll
thunk.dll
cpifmgr.dll
tmswdat10.dll
Don't forget to:
Tags:
Link to this article:
Add comment:
Removal Guide Articles
How To Remove XP Micro Antivirus
If you did not manually install XP Micro Antivirus and ...
19 Feb 2010
How To Remove Software Antivirus
Software Antivirus, unlike what the name may suggest, is not ...
Software Antivirus, unlike what the name may suggest, is not ...
19 Feb 2010
How To Remove PC Security 2009
PC Security 2009, a rogue antispyware program, is usually distributed ...
19 Feb 2010
How To Remove Security Essentials 2010
The people with malicious intent that put out the ...
18 Feb 2010
How To Remove Personal Anti Malware
Personal Anti Malware, a rogue security software application, is usually ...
18 Feb 2010
Recommended Tools
Registry Booster 2011 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2011
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2011
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



