The EarthAV virus is an impressive attempt at trying to scam you into buying a fake antivirus program. Designed by a group of hackers (thought to be in China), this infection is spreading through 100′s of computers around the World, trying to steal money from people. This virus is what’s known as a “rogue antivirus” threat, as it’s designed to look like a legitimate antivirus program… the only problem is that it will just install itself on your PC and try to steal your data. Here’s how to remove it…
What Is The Earth AV Virus?
EarthAV is part of a growing number of “fake antivirus” programs that are designed to try and extort money from you in various ways. There are two parts to this virus – the fake application which tries to get you to buy the “upgrade”, and the back-end which attempts to steal your personal details. This virus is continually trying to steal your personal details, making it essential that you’re able to remove it in the most complete way possible.
How To Remove Earth AV From Your PC
Step 1 – Download & Install XoftSpySE
XoftSpySE is a powerful spyware & malware removal tool which you can download here. You need to install it on your PC and then let it scan your system. If you don’t have access to the Internet (because Earth AV blocked it) then you should download this tool on another PC and then transfer the installation file via CD or USB pen.
Using this tool is very simple. You need to select the type of scan you want to perform and then press “Scan” to get the tool to do the task. This will send XoftSpy through your system and it will identify all the infected files, removing them for you. This automated tool is the best way to remove the infection because it gets 95% of it.
Step 2 – Clean Out The Registry
XoftSpy is very effective at removing the actual infection from your PC, it does not finish the job properly… and ends up leaving a series of settings on your PC. These are kept in the ‘registry’ database and can actually allow the infection back onto your PC. In order to fully protect yourself, it is recommended that you download a registry cleaner and then use it to remove any of the infected ‘Earth AV’ registry keys that can still cause problems. This tool is automated and is very easy to use.
What This Removal Process Does:
Kills Processes
- eav.exe
- msdl.exe
- vec.exe
You should open up the “Task Manager” by clicking CTRL + ALT + DEL and then click on the “Processes” tab. This will then display a list of running processes, where you should then be able to find the listed files above. Click on each one and then click on the “End Process” button to stop the program from running. You can see an example of how that works below:
- c:\Documents and Settings\All Users\Application Data\eav
- c:\Documents and Settings\All Users\Application Data\eav\Base.dat
- c:\Documents and Settings\All Users\Application Data\eav\msdl.exe
- c:\Documents and Settings\All Users\Application Data\eav\msll.exe
- c:\Documents and Settings\All Users\Application Data\eav\vec.exe
- c:\Documents and Settings\All Users\Application Data\Microsoft\Machine
- c:\Documents and Settings\All Users\Application Data\Microsoft\Machine\WStech.dll
- c:\Documents and Settings\All Users\Start Menu\Programs\ Earth AV
- c:\Documents and Settings\All Users\Desktop\ Earth AV .lnk
- %APPDATA%\mozilla\firefox\profiles\\gsl.dll
- These files are what Earth AV will use to help it run. In order to ensure that this virus has been removed from your system in its entirety, you need to remove all these files from your computer. To do this, you need to open up “My Computer” and then locate the directories in question. After you’ve found one, remove it by pressing SHIFT + DELETE on your keyboard (this permanently removes it instead of sending it to your recycle bin).
Recomended – Clean The Registry (Highly Recommended)
In order to prevent Earth AV coming back on your PC, you need to remove all the registry entries it has entered. This important, because many people leave these intact and end up having the problem come back again. Registry entries store the settings and options for the program, and by using a registry cleaner, you can remove them all and get your computer fit and healthy again. This is highly recommended






