Remove Sysinternals Antivirus
Like many other rogue programs Sysinternals Antivirus is a rogue security program. The rogue program tells users that by purchasing and installing Sysinternals Antivirus they will be able to delete viruses off their computer, but the problem is the rogue program is not a valid program so it will never locate any viruses. This rogue program is a master of disguise because it mimics real security software, so look carefully at what you are seeing. Chances are all of those annoying popups and fake security warnings are the result of your system being infected with Sysinternals Antivirus.
Automatic Sysinternals Antivirus removal:

Sysinternals Antivirus Remover
Warning! If the automatic remover is blocked by the spyware, then boot into Windows Safe Mode and try again. Learn how to boot into Safe Mode here.
Manual Sysinternals Antivirus removal:
Kill processes: Alggui.exe, ccsmn.exe, ccsrr.exe, dbsinit.exe, Sysinternals Antivirus.exe
(Learn how to kill processes)
Unregister DLLs:
C:\Program Files\adc_w32.dll
(Learn how to unregister DLLs)
Delete registry keys:
HKEY_CURRENT_USER\Software\Sysinternals Antivirus
HKEY_CLASSES_ROOT\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavapp"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "novavappr"
(Learn how to delete registry keys)
Delete files:
C:\Program Files\adc_w32.dll
C:\Program Files\alggui.exe
C:\Program Files\extra1.dat
C:\Program Files\extra2.dat
C:\Program Files\nuar.old
C:\Program Files\skynet.dat
C:\Program Files\svchost.exe
C:\Program Files\wp3.dat
C:\Program Files\wp4.dat
C:\Program Files\scdata\dbsinit.exe
C:\Program Files\scdata\wispex.html
C:\Program Files\scdata\images\i1.gif
C:\Program Files\scdata\images\i2.gif
C:\Program Files\scdata\images\i3.gif
C:\Program Files\scdata\images\j1.gif
C:\Program Files\scdata\images\j2.gif
C:\Program Files\scdata\images\j3.gif
C:\Program Files\scdata\images\jj1.gif
C:\Program Files\scdata\images\jj2.gif
C:\Program Files\scdata\images\jj3.gif
C:\Program Files\scdata\images\l1.gif
C:\Program Files\scdata\images\l2.gif
C:\Program Files\scdata\images\l3.gif
C:\Program Files\scdata\images\pix.gif
C:\Program Files\scdata\images\t1.gif
C:\Program Files\scdata\images\t2.gif
C:\Program Files\scdata\images\Thumbs.db
C:\Program Files\scdata\images\up1.gif
C:\Program Files\scdata\images\up2.gif
C:\Program Files\scdata\images\w1.gif
C:\Program Files\scdata\images\w11.gif
C:\Program Files\scdata\images\w2.gif
C:\Program Files\scdata\images\w3.jpg
C:\Program Files\scdata\images\word.doc
C:\Program Files\scdata\images\wt1.gif
C:\Program Files\scdata\images\wt2.gif
C:\Program Files\scdata\images\wt3.gif
C:\Program Files\Sysinternals Antivirus\Sysinternals Antivirus.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.acf
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.ltd
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.lti
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.acb
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.aci
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.mt
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\lleod150
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmharun.log
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmrun.log
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk
(Learn how to delete files)
Delete folders:
C:\Program Files\scdata
C:\Program Files\Sysinternals Antivirus
%UserProfile%\Start Menu\Programs\Sysinternals Antivirus
Once you have removed Sysinternals Antivirus from your computer using either the automatic or manual method, make sure to block it and other malicious software using a HOSTS file. Please note that with the automatic method, your computer should be protected from future spyware threats since you now have a spyware blocker program installed. We recommend downloading the HOSTS file from here, which contains a complete, up-to-date list of malicious websites especially if you used the manual method.
If this article has helped you, please take this time to share it with Digg using the Digg button (see Digg share button to the left) or retweet it using Twitter (see retweet button to the left). You may also want to follow us on Twitter to keep up-to-date with the latest spyware prevention tips and spyware threats. If you'd rather follow us from your Facebook account, please join our Facebook fan page.
Installed this product several times, going thru’ all the recommended steps but Sysinternals Antivirus is still present.