Remove AntiVermins. Description and removal instructions

 
Title: AntiVermins

Type: Trojans
Severity scale:AntiVermins severity is 60  (60 / 100)
 
AntiVermins is a trojan that displays an icon in the system tray. This icon shows a message saying that the compromised computer is infected with dangerous viruses and asks the user to download and install a removal program, which actually is AntiVermins, the same named corrupt illegally distributed spyware remover. Once the user clicks on that message, the trojan opens a web site distributing AntiVermins. It may also attempt to download the application without asking for user permission. The trojan is able to change the Internet Explorer default home page, redirect the web browser to malicious web sites, download and install other parasites. AntiVermins automatically runs on every Windows startup.

AntiVermins, AntiVerminser and AntiVermeans Removal Guide


Related files: antivermins.exe, cvnzie.dll, hjpprpu.dll, kuhmk.dll, ownyhr.dll, cthkpcv.dll, vwfps.dll

AntiVermins properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic AntiVermins removal:

remover for AntiVermins

AntiVermins manual removal:

Kill processes:
antivermins.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivermins
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\antivermins.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{3C767C6B-602D-4B9B-829D-A3DC5B2D89DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{4FBBDFD6-2CA9-4BBA-93E4-AADF75321BCA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{FE288882-F661-4522-88F3-20CFB7866FA4}
HKEY_CLASSES_ROOT\Typelib\{6B112EBD-0C90-4AC4-A969-F36797F00006}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C767C6B-602D-4B9B-829D-A3DC5B2D89DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4FBBDFD6-2CA9-4BBA-93E4-AADF75321BCA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE288882-F661-4522-88F3-20CFB7866FA4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0A1949AB-8B12-4A6F-9B5D-12D4115CCCEA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1724E437-1FCE-4D21-95E2-6E2452C25628}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1ECABCEE-5F00-449B-BBE3-9C35E160E832}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D652EC7-AF61-487A-B82A-0C4A6A9FF3C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{500B879D-86C3-4C45-943F-3FC3BF793B38}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{50FE5318-DC2A-440A-AC94-B9041819EE48}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{59DAA331-B3F9-408E-81DF-ADE79D129600}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B768BE7-942B-4838-89BF-40AB729A62AB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C0B132E-86CB-4B3B-9CAF-CB7F57A60C81}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{78E2412E-3C9A-4EE8-AD97-3ABD95EC49D3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{85524659-53E5-40AF-835B-2F0B8745DF0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A9D1422-D311-4673-8579-61FCDB76BD0D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B6CDDF17-9F1A-47CA-8E3D-FF6BD1B05D3F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D6BD48FC-DD6F-4242-90B0-6CBE4AD43362}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D7D22218-EBF0-454C-B948-11BB8FC3118B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{ECA8F1E3-C03F-47E6-842D-7B2BCF0445CA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6B112EBD-0C90-4AC4-A969-F36797F00006}
HKEY_LOCAL_MACHINE\SOFTWARE\AntiVermins
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVermins
Unregister DLLs:
cthkpcv.dll, cvnzie.dll, hjpprpu.dll, kuhmk.dll, ownyhr.dll, vwfps.dll

Delete files:
antivermins.exe, cthkpcv.dll, cvnzie.dll, hjpprpu.dll, kuhmk.dll, ownyhr.dll, vwfps.dll
Delete directories:
C:\Program Files\AntiVermins
Misc:
Exact file location:
antivermins.exe - C:\Program Files\AntiVermins
cthkpcv.dll, cvnzie.dll, hjpprpu.dll, kuhmk.dll, ownyhr.dll, vwfps.dll - C:\WINDOWS\System, C:\WINDOWS\System32 or C:\WINNT\System32


Domain Name: ANTIVERMINS.COM (85.255.119.66)
Registrant:
AntivirSoft LTD
AntivirSoft LTD (info@antivermins.com)
Ukraine, 73000, Hersonskya obl., g.Herson, ul. Kuybusheva, 15
Herson
Hersonskya oblast,73000
UA
Tel. +380.3100240

AVOID THIS DOMAIN AND THIS IP! Better block them in your Hosts file.

Other programs to remove AntiVermins:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 22/12/06
Information updated: 05/05/07

Additional resources related to AntiVermins:

Attention: If you know or you have a website or page about AntiVermins removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about AntiVermins parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Guest. 2007-05-05 00:05:55
MANUAL removal is free, i.e. all the instructions, even the Removal Guide.

AUTOMATIC removal is paid.

Nobody's lying.

2. by Guest. 2007-05-03 23:05:43
This site says it's free to remove the anti-vermins spyware, but when you install it, it then askes for $$$ to remove the malware.
Why must these companies lie to sell their software?


Related news:
Similar parasites:
Related discussions: