Home > Threats > TrustedAntivirus

What is TrustedAntivirus

Posted on 30 November 2007 under Rogue Programs

1. What is TrustedAntivirus?

It is rogue PC security software, created on purpose to display fake computer system security alerts, thus confusing user into believing that the system is infected with some viruses, which usually are assumed. TrustedAntivirus is offered as computer cleaning and protection tool, but in order to remove found spyware/viruses user is repeatedly prompted to purchase licensed program version.

Regarding incompetent PC diagnostics function TrustedAntivirus is not able to scan computer properly and detect really dangerous and most recent threats. That is why the program is also defined as a scareware or fake anti-spyware software.

Additional objects: TrustedAntivirus toolbar will be installed along on your internet browser.

TrustedAntivirus security alert:

2. TrustedAntivirus screen shot:

TrustedAntivirus

3. How to remove TrustedAntivirus:

  1. Internet connection might be disabled or Internet browser might be blocked by TrustedAntivirus, so it won't be possible to download any files to infected computer. In this case please download all files required for TrustedAntivirus removal to another computer and then transfer them on the infected one using CD/DVD or USB flash drive.
  2. To remove TrustedAntivirus download Spyware Doctor and install the program (for the installation guide click here). Before installation, make sure all other programs and windows are closed.
  3. After the installation, computer scan should be started automatically. If so, please move to the next step. If not, click "Status" on the left side menu and press "Scan Now" button to run computer scanner as shown in the picture below:

  4. After the scan has been completed and scan results have been generated, press "Fix Checked" button to remove TrustedAntivirus.

  5. Restart the computer to complete TrustedAntivirus removal procedure.

4. TrustedAntivirus files:

gtb.dll, iefwbho.dll, pblock.dll, popupg.dll, sbiebho.dll
bm.exe, pgs.exe, ptask.exe, runbst.exe, ubstcw.exe, ugac.exe

5. Hijackthis entries:

O2 Entries:
O2 - BHO: IEFW Object - {6F87F145-DC2D-4766-AF03-3A3B96FFAD98} - C:\Program Files\TrustedAntivirus\Tools\sbiebho.dll
O2 - BHO: CIEIntegrator Object - {5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E} - C:\Program Files\TrustedAntivirus\Tools\pblock.dll
O2 - BHO: CIEIntegrator Object - {7A7F202E-AF91-4889-9DD5-2FE241085CC1} - C:\Program Files\TrustedAntivirus\Extra\popupg.dll
O2 - BHO: IEFW Object - {FAAD2038-C371-473D-86F1-5B11D39C3775} - C:\Program Files\TrustedAntivirus\Extra\iefwbho.dll
O3 Entries:
O3 - Toolbar: AntiVirus Toolbar - {03B121E9-6152-48b5-BB38-B642B21C62BD} - C:\Program Files\TrustedAntivirus\gtb.dll
O4 Entries:
O4 - HKLM\..\Run: [bm] "C:\Program Files\Common Files\TrustedAntivirus\bm.exe" dm=http://trustedantivirus.com ad=http://trustedantivirus.com sd=http://ykeeper.trustedantivirus.com
O4 - HKLM\..\Run: [ugac] "C:\PROGRA~1\COMMON~1\TRUSTE~1\ugac.exe" -start
O4 - HKLM\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\pgs.exe
O4 - HKLM\..\Run: [ptask] C:\Program Files\TrustedAntivirus\ptask.exe
O4 - HKLM\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\runbst.exe
O4 - HKLM\..\Run: [ubstcw] "C:\PROGRA~1\COMMON~1\TRUSTE~1\ubstcw.exe" -start
O4 - HKLM\..\RunOnce: [atf.exe] "C:\Program Files\TrustedAntivirus\runbst.exe" /empty