Description of Antivirus Lab 2009 and consequences of its residing on your PC

Among the contemporary malware, Antivirus Lab 2009 or AntivirusLab 2009 is one of the most cunning.  Ads at blogs are not a novelty at all and not a novelty in malware promotion too. However, in contrast to others, it was Antivirus Lab 2009 that was a pioneer in using intermediate web-sites to attract (or rather to attack) users.  The trickery is pretty simple but works. The general workflow of this trapping looks like follows: posting of a comment consisting of web-site name that includes such names as Google or MSN at popular blogs. It is not forbidden to register such web-sites; you may also register web-site like or However, this would not be a proof of their reliability, don’t you find so? Moreover, it should be noted that such sites are rather malicious because rascals are widely applying the technique of malware propagation described here. Further on, from such seems to be fair web-sites users are redirected to on-line scan by Antivirus Lab 2009 with a title “XP Antivirus – Windows Internet Explorer”. If your OS is other than Windows XP, you may wonder that chrome of this on-line popup is different from your original chrome. There is nothing strange, such pop-ups is just a trickery and nothing but complex image. Clicking this image you are clicking hidden link that starts upload of malware trial and redirects you to purchase form of Antivirus Lab 2009 (AntivirusLab 2009).
Taking into account a number of victims, we are obliged to conclude this technique works well. However, most of users suffered were just infected with trail and decided not to buy the rogue.

Antivirus Lab 2009 Technical Details

  • Full name: Antivirus Lab 2009, AntivirusLab2009, AntivirusLab 2009
  • Type: Rogue anti-spyware
  • Origin: Russian Federation

Antivirus Lab 2009 Screenshots (click to enlarge):

Signs of being infected with Antivirus Lab 2009:

Antivirus Lab 2009 (AntivirusLab 2009) was installed if you visited its on-line scan page. Antivirus Lab 2009 might be installed in other way than from its fake scan-page. In this case, pay attention to system slowing down and disordering signs. It is likely that media players are disabled by the rogue. After its trial installation, Antivirus Lab 2009 usually installs icon at the system tray and generates other scan. This scan is other than on-line, though fake as well.

Manual Removal of Antivirus Lab 2009:

Please, be careful with manual removal of Antivirus Lab 2009 (AntivirusLab 2009). Follow the guidelines strictly, otherwise removal may fail and useful files deleted. Be aware that single Antivirus Lab 2009 is often  insufficient, as other related and unrelated malware may keep residing on your PC.

Remove Antivirus Lab 2009 files and dll’s:
AntiVirus Lab 2009 2.1.lnk

Unregister Antivirus Lab 2009 registry values:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVirusLab2009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A21C8D81-A9C7-46c6-A488-2A32FA0DAEB6}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AntiVirusLab2009″

