It looks as though that Virus Doctor (or Virusdoctor) is an older rogue antivirus application, but since it seems related to the search I was seeing lot’s of last night about rootscan.info I thought I would devote an article to the removal instructions for virus doctor. Since it may be related to Windows PC Defender, you may see an article on that coming up this evening. But, first to the matter at hand: How to carry out a virus doctor removal.
First of VIrus Doctor is a rogue antivirus application that claims to find problems on your system and then it claims to be able to fix them if and only if you pay for the software. It usually finds its way on your system through a popup ad that claims your system is infected and then closing the popup redirects you to another web page with an animation of a scan of your pc claiming that it’s finding problems.
You may see messages such as this:
Malicious applications which can contain trojans found on your PC need to be immediately removed. Click here to remove these potentially harmful items immediately with Virus Doctor.
An unauthorized program has been prevented from accessing your PC.#Port:433 from 18.104.22.168
It should be possible to remove virus doctor by downloading malwarebytes antimalware, updating it to the latest version and running a full scan of the system. (You can find a link to malwarebytes antimalware on my virus removal toolkit page.
You may want to try running malwarebytes antimalware in safe mode if the first attempt is unsuccessful. I would try this before a manual removal.
If you need to do a manual removal you can use the following information to help:
The following sites should be blocked (using the hosts file):
You may make use of Task manager to kill of the following processes:
The following dll files will need to be unregistered:
And the following files and their folders should be removed:
%UserProf%Application DataMicrosoftInternet ExplorerQuick LaunchVirus Doctor.lnk
%UserProf%Application DataVirus Doctorsettings.ini
%UserProf%Application DataVirus Doctoruill.ini
%UserProf%Start MenuProgramsVirus Doctor.lnk
%UserProf%Start MenuVirus Doctor.lnk
%Docs%All UsersApplication Data[RANDOM]LanguagesVDDe.lng
%Docs%All UsersApplication Data[RANDOM]LanguagesVDFr.lng
%Docs%All UsersApplication Data[RANDOM]LanguagesVDIt.lng
%Docs%All UsersApplication Data[RANDOM]System Data ConfigurationDBInfo.ver
%Docs%All UsersApplication Data[RANDOM]System Data Configurationvd[RANDOM].bd
%Docs%All UsersApplication Data[RANDOM]unins000.dat
%Docs%All UsersApplication DataSystem Data Configurationconfig.cfg
%Docs%All UsersApplication DataSystem Data ConfigurationDB.ini
Some of the above may be created using random strings so be suspicious of files or folders that don’t seem to be naturally named.
Even after a manual removal, I suggest running a tool such as malwarebytes antimalware for a more thorough cleaning. Update and run it again after it cleans out the things it finds. (I like to run such utilities until it comes clean.)
Virus Doctor may be relate to the newer rogue Windows Additional Guard.
Related PostsRelated Posts
- How to Remove AntiKeep | AntiKeep Removal Guide AntiKeep is a rogue antivirus application from the same family as ReAnti and AntiAdd which we've written about in the last few days. Like many of these rogue application they will try to trick you into consenting to install it, or install without your permission. They will claim that there......
- How to Remove PC Live Guard | PC Live Guard Removal Guide PC Live Guard is a Rogue antivirus application that typically installs on a system through aggressive advertising and fake scan sites. You will see things that pop up appearing to be a scan of your computer, but it's really just an ad pushing this product. Once the software is on......
- How to Remove Additional Guard | Additional Guard Removal Guide Additional Guard is a rogue antivirus application and like many of these it can either be installed with or without the users permission. Even without a person actually wanting it, but simply visiting the wrong web page users may find this program on their system. Once on their system this......
- How to Build a Garage While many homes already have basic garages built into them, this isn't always the case, and some families find themselves seeking free plans, garage plans and the like. Some newer properties, and properties built by architects rather than home-building companies often do not come with the same garage space that......
- How to Remove Antivirus 2009, Spyware Guard 2008 and Other Malware My wife, kids, and I spent this past Christmas at my parents' house. It wasn't long after we arrived before I gravitated to their computer to check my email, read the news, check the stock market, etc. Much to my dismay, I found a barrage of malware, spyware, and......
- How Can Marketplace Samurai Aid Your Organization Increase? On the web marketplace is often a extremely competitive marketplace currently where surviving for any online company just isn't quick. Today a number of web sites are launched each and every now and then either to promote items or services of companies. Right way of marketing is critical for your......
- How to Remove Windows System Defender | Removal Guide
- Remove Total Security 2009 | TotalSecurity 2009 Removal
- How to Remove Windows Smart Security (Removal Guide)
- How to Remove Windows PC Defender | Windows PC Defender Removal
- How to Remove Windows Enterprise Defender (Removal Guide)