
By Jim
Updated on Tuesday, June 15th, 2010
Sysinternals Antivirus might sound like a very legitimate application. That’s quite true as Microsoft owns the Sysinternals brand and it is actually a site that provides tools for administering and monitoring Windows computers. Among other things, they also have a few anti-malware tools available though none of them are named Sysinternals Antivirus.
So while you think you can trust this rogue anti-spyware app, don’t! Like many others, it will merely offer up scans of fake viruses that won’t harm your computer at the least. It does this so it can extort you for money by saying that it can remove these malware in exchange for an ‘upgrade’ to the software. Don’t send your money to them!
It’s better to just remove this bad piece of software and get a true antivirus application instead. One of the reasons why you need to remove this is that it introduces security holes in your computer, making you vulnerable to actual malware. They can then steal your information, credit card details and any other data in your system that can be useful to them.
You can remove this program easily and painlessly though. Just follow our instructions below to be in the clear of this nasty infection.
- Download Spyware Doctor and save to your Desktop (if you cannot download then bookmark this page and skip to Step 3 to restore your internet)
- Rename the file iexplorer.exe
- Restart your Computer in Safe Mode with Networking (keep tapping F8 while your system boots up)
- Launch Internet Explorer, click on Tools and then Internet Options.
- Click on the Connections tab and select LAN Options
- Uncheck the box Use a Proxy Server For Your LAN and click OK
- Launch iexplorer.exe (Spyware Doctor)
- Update Malware Definitions and click Start Scan
- Click the Fix Checked button and remove Sysinternals Antivirus
Remove Sysinternals Antivirus In Minutes With an Automatic Removal Tool.
Simply Click “Start Download Now!” to Begin!

Symptoms Of Infection
- Your computer is acting slow. Sysinternals Antivirus slows down your system significantly. This includes starting up, shutting down, playing games, and surfing the web.
- You are getting pestered with pop ups. Sysinternals Antivirus infects your registry and uses it to launch annoying pop up ads out of nowhere.
- Searches are redirected or your homepage and desktop are settings are changed. This is a symptom of a very serious Sysinternals Antivirus infection.
Dangers Of Infection
Viruses like Sysinternals Antivirus will infect your registry and other important system files. If the infection is not treated it can cause a complete collapse of your system.
![]()
Some Sysinternals Antivirus infections contain spyware and keyloggers which can be used to record sensitive data like passwords, credit card, bank account, and social security numbers. The longer you allow the infection to fester, the greater the chance of identity fraud.
How To Remove Infection Manually
Uninstall Sysinternals Antivirus Processes
svchost.exe
Sysinternals Antivirus.exe
dbsinit.exe
ccsmn.exe
ccsrr.exe
Delete Sysinternals Antivirus Files
c:\Program Files\alggui.exe
c:\Program Files\extra1.dat
c:\Program Files\extra2.dat
c:\Program Files\nuar.old
c:\Program Files\skynet.dat
c:\Program Files\svchost.exe
c:\Program Files\wp3.dat
c:\Program Files\wp4.dat
c:\Program Files\scdata
c:\Program Files\scdata\dbsinit.exe
c:\Program Files\scdata\wispex.html
c:\Program Files\scdata\images
c:\Program Files\scdata\images\i1.gif
c:\Program Files\scdata\images\i2.gif
c:\Program Files\scdata\images\i3.gif
c:\Program Files\scdata\images\j1.gif
c:\Program Files\scdata\images\j2.gif
c:\Program Files\scdata\images\j3.gif
c:\Program Files\scdata\images\jj1.gif
c:\Program Files\scdata\images\jj2.gif
c:\Program Files\scdata\images\jj3.gif
c:\Program Files\scdata\images\l1.gif
c:\Program Files\scdata\images\l2.gif
c:\Program Files\scdata\images\l3.gif
c:\Program Files\scdata\images\pix.gif
c:\Program Files\scdata\images\t1.gif
c:\Program Files\scdata\images\t2.gif
c:\Program Files\scdata\images\Thumbs.db
c:\Program Files\scdata\images\up1.gif
c:\Program Files\scdata\images\up2.gif
c:\Program Files\scdata\images\w1.gif
c:\Program Files\scdata\images\w11.gif
c:\Program Files\scdata\images\w2.gif
c:\Program Files\scdata\images\w3.jpg
c:\Program Files\scdata\images\word.doc
c:\Program Files\scdata\images\wt1.gif
c:\Program Files\scdata\images\wt2.gif
c:\Program Files\scdata\images\wt3.gif
c:\Program Files\Sysinternals Antivirus
c:\Program Files\Sysinternals Antivirus\Sysinternals Antivirus.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.acf
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.ltd
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.lti
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.acb
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.aci
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.mt
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\lleod150
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmharun.log
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmrun.log
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk
Remove Sysinternals Antivirus Registry Files
HKCR\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}
HKLM\SYSTEM\CurrentControlSet\Services\AdbUpd
HKEY_CURRENT_USER\Software\Sysinternals Antivirus
HKEY_CLASSES_ROOT\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “novavapp”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “novavappr”
Popular Search Terms
Remove Sysinternals Antivirus
Delete Sysinternals Antivirus
Uninstall Sysinternals Antivirus
How to get rid of Sysinternals Antivirus
How to remove Sysinternals Antivirus
Sysinternals Antivirus removal
Remove SysinternalsAntivirus
SysinternalsAntivirus removal
Sysinternals-Antivirus
Warning! If Spyware Doctor is blocked by the virus then run your system in safe mode and try again. To do this reboot your system and tap F8 repeatedly as your computer starts up. Then run Spyware Doctor as normal. If this doesn’t work try renaming the Spyware Doctor EXE file.
Posted under Fake Antispyware | No Comments
