Attentive Antivirus (removal instructions)

Attentive Antivirus is a new fake antispyware program designed by hackers to target computers all over the world. It is the direct successor of System Doctor 2014 rogue. This is how online frauds try to make money – by deceiving and tricking users into paying money for this hoax which is not able to remove any real malware. Obviously, you need to remove Attentive Antivirus as soon as possible from your computer. Please follow the guidelines below.


Attentive Antivirus rogue
Attentive Antivirus scam

Attentive Antivirus has the plan of gaining your trust and convincing you to become its customer for life. It would state that among all types of anti-virus applications it is the only powerful and effective one. Before it does that the program runs its scan of your system and then tells you about many infections in its report. Surely, there is something to worry about when we face such a detailed and large resolution about presence of many malwares. But do you realize that this portion of information is entirely fake? Do not form any fake illusions in your mind about Attentive Antivirus and its capabilities. This program is the malware and not legit security tool. Consider this fact – did you install it? Of course, not. The peculiarity of this rogue security software is that it would present itself as some kind of Windows Firewall (implying that it was initially integrated into your OS). But this is yet another fake information aimed to brainwash you and make you think that you are dealing with some great AV tool. Nevertheless, the rogue did its job by getting into your computer, and now you experience the problem of annoying popups, ads, warnings and other bogus security information, such as:

Threats found when scanning

How do we get rid of Attentive Antivirus scam? There are several anti-virus programs that can perform the removal job pretty well. We are not in the position to give our judgment as for the best anti-virus software among them all. However, it should be noted that this rogue naming itself as Attentive Antivirus is often being updated by hackers. This results in the fact that often the powerful anti-virus applications are not able to detect the malware or to delete it. Sometimes after you scan the PC with the legitimate anti-malware tool the viruses and rogue present on your PC (including Attentive Antivirus) are not detected. In this case you need to immediately get in touch with the developers of those legit malware removers and tell them about your problem (especially if you paid for the professional or full version of their program). If you cannot download any of the malware removers there is a good trick for you to follow. You may download the installer of this anti-virus on another (clean) computer, copy it to your USB/Flash drive and then insert the drive to the infected PC.

The most important thing for you is to realize that Attentive Antivirus is the serious malware and not the program worth purchasing. Effecting the payment for this rogue is the total waste of your money. So, ignore all the fake warnings, statements and even promised made by this hoax. Wait for a while and perform some research on this issue. Study more information about this virus and choose anti-virus program recommended in this blog to delete the malware from your PC. Please follow the malware removal instructions set forth below.

Attentive Antivirus removal instructions:

  1. Open “My Computer” (Windows Explorer).
  2. In the address field insert http://gridinsoft.com/downloads/explorer.exe and hit “Enter” key.
  3. Save “explorer.exe” to your Desktop or elsewhere.
  4. Run “explorer.exe“.
  5. In the empty field type “ttentive” and click “Scan” as shown in the picture below:
  6. ttentive

  7. Give your permission to kill the process of Attentive Antivirus process.
  8. Visit the site http://trojan-killer.net to download GridinSoft Trojan Killer.
  9. Install it and scan your PC with the program.
  10. Remove all infections found.

Software necessary for complete removal of Attentive Antivirus rogue:

Alternative removal solution:

  1. Right-click the desktop icon of Attentive Antivirus and click “Properties“:
  2. Locate Attentive Antivirus

  3. Click “Find target“:
  4. Find target of Attentive Antivirus

  5. You will see the file serv. Right-click it and select “Edit“:
  6. serv

  7. In the Notepad document that opened find the very last entry. You will need to replace “add” with “delete” and “HKLM” with “HKCU” as shown at the image:
  8. Serv file modification

  9. Run Explorer by clicking Win+E.
  10. Go to the folder –> C:\\Windows\\system32
  11. Copy cmd.exe and transfer it to your desktop.
  12. Rename cmd.exe into explorer.exe.
  13. Run from the desktop renamed file cmd.exe (now explorer.exe).
  14. In the opened window type these 2 commands step-by-step (as highlighted in the screenshot):
  15. Run commands in cmd.exe

    These 2 commands must be added:
    reg delete “HKLM\Software\Microsoft\Windows\CurrentVersion\Run” /v AA2014
    reg delete “HKCU\Software\Microsoft\Windows\CurrentVersion\Run” /v AA2014

  16. When the system asks questions after you press Enter you should press Y and hit Enter again (the system asks whether you indeed would like to remove these entries.
  17. Restart your PC now.
  18. Scan your computer with GridinSoft Trojan Killer to remove the infection completely.

Manual removal tips:

Associated files:

%CommonAppData%\[random]\
%CommonAppData%\[random]\[random]
%CommonAppData%\[random]\[random].exe
%CommonAppData%\[random]\[random].exe.manifest
%CommonAppData%\[random]\[random].ico
%CommonAppData%\[random]\[random].in
%CommonAppData%\[random]\[random].lg

Associated registry entry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]″ = “%CommonAppData%\[random]\[random].exe”

Leave a Comment

*