Profantivir.com is a new scam domain promoting rogue program. Profantivir.com pushes one of the most dangerous known scareware applications- AV Security Suite. This fake program enters your system without your notification and does activity inside. What is more, Profantivir.com has enough bad power to turn your computer into a playground for hackers and do not allow you to browser normally. You may use the following instructions to get rid of Profantivir.com off your computer as early as possible.



This step-by-step guide can help you completely remove Profantivir.com. If you  have any problem during the remove process, please contact Tee Support agent 24/7 online for more detailed  instructions.







If you are not an advanced computer user, you had better back up the registry before remove Profantivir.com manually. Otherwise you might delete some other important values so that your computer is not able to work.



Profantivir.com Manual Removal Guides:



The files to be deleted are listed below:



%Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string].exe



%Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]tssd.exe



The registry entries that need to be removed are as follows:



HKEY_CURRENT_USER\Software\AvSuite



HKEY_LOCAL_MACHINE\Software\AvSuite



HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” =”1″



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = ““



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“



HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“

Bookmark and Share