How to remove ANG AntiVirus 09 (Removal Instructions)
Sunday, March 1st, 2009
Description:
ANG Antivirus 09 is a rogue anti-spyware program from the same developers as Antivirus 2010. This program displays false positive scan results to trick you into purchasing the software. ANG Antivirus 09 also displays fake security alerts from your Windows taskbar and from within Internet Explorer to attempt to trick you into thinking you are infected.
Due to the fact that this program is always running it will begin to slow down your computer. At this time we have not seen ANG AntiVirus 09 installed via Trojans, but that does not mean it wont be. It most likely will in the near future because Antivirus 2010 was Trojan installed as well. Please use the information below to remove this infection from your computer.
Threat Level: High
Manual Removal Instructions for ANG AntiVirus 09
End these processes if they exist:
Learn how to end processes
angpd.exe
rkgnd.exe
Delete these files if they exist:
Lean how to remove files
c:\Program Files\Common Files\System\mgnc
c:\Program Files\Common Files\System\mgnc\angpd.exe
c:\Program Files\Common Files\System\mgnc\angpd.xml
c:\Program Files\Common Files\System\mgnc\angpid.exe
c:\Program Files\Common Files\System\mgnc\mcdk.exe
c:\Program Files\Common Files\System\mgnc\rkgnd.exe
c:\Program Files\Common Files\System\mgnc\wsd.exe
Remove these Registry keys if they exist:
Learn how to remove Windows Registry entries
Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly. Please edit the Registry only if you know what you are doing.
HKEY_CURRENT_USER\Software\ANG AntiVirus 09
HKEY_CURRENT_USER\Software\Total Virus Protection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “UXPVP 1.0.7.0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “76112549345328287″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce “65438761234587528″

