Step 1: Stop unwanted process running in background.
Click Start then Run and type taskmgr.exe
Click on Process tab in Task Manager and locate the following Image name(s).
AV2010.exe
svchost.exe
wingamma.exe
Highlight the Image name and click End Process to Stop.
Close Task Manager.
Step 2:- Delete the suspicious file(s) or folder(s) from the computer
Click on Start and Run, type
C:\Program Files\AV2010 c:\Program Files\AV2010\AV2010.exe c:\Program Files\AV2010\svchost.exe
C:\WINDOWS\system32\IEDefender.dll
c:\WINDOWS\system32\wingamma.exe c:\Documents and Settings\All Users\Desktop\AV2010.lnk c:\Documents and Settings\All Users\Start Menu\Programs\AV2010
c:\Documents and Settings\All Users\Start Menu\Programs\AV2010\AV2010.lnk c:\Documents and Settings\All Users\Start Menu\Programs\AV2010\Uninstall.lnk
Locate the following folder and Delete
c:\Program Files\AV2010
c:\Documents and Settings\All Users\Start Menu\Programs\AV2010
close the Window.
Step 3:- Uninstall the Suspicious program from the computer.
Click on Start and Run, type appwiz.cpl, press Enter.
Locate Antivirus 2010 in Add and Remove Program.
Click on Remove (Uninstall) button.
Close Add or Remove program.
Restart the computer.
Step 4:- Manual Removal of suspicious entries from Registry.
CAUTION: Changing the Registry incorrectly could cause your comuter to stop working. Please make sure to create backup of registry or create system point before proceeding.
Click Start, Click run and type regedit.
Create a registry backup.
Note: Some of these Registry keys and values may be random.
Locate the following registry keys, right click and Delete
HKEY_CURRENT_USER\Software\AV2010
HKEY_CLASSES_ROOT\AppID\{3C40236D-990B-443C-90E8-B1C07BCD4A68}
HKEY_CLASSES_ROOT\AppID\IEDefender.DLL
HKEY_CLASSES_ROOT\CLSID\{FC8A493F-D236-4653-9A03-2BF4FD94F643}
HKEY_CLASSES_ROOT\IEDefender.IEDefenderBHO
HKEY_CLASSES_ROOT\IEDefender.IEDefenderBHO.1
HKEY_CLASSES_ROOT\Interface\{7BC7565C-5062-43CE-8797-DC2C271140A9}
HKEY_CLASSES_ROOT\TypeLib\{705FD64B-2B7B-4856-9337-44CA1DA86849}
HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC8A493F-D236-4653-9A03-2BF4FD94F643}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 'Windows Gamma Display'
Restart the computer.