• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Antivir (Uninstall instructions)

Myantispyware team November 27, 2009    

Antivir_scan_completeAntivir is is not a legitimate security application. The program is a rogue antispyware program that spreads mostly with the help of fake online malware scanners. It will report that your computer is infected and you must install Antivir to clean your PC. That online scanner is scam and could not possibly detect malware, trojans and viruses on your computer.

When Antivir is downloaded and installed, it will be configured to run each time when you login to Windows. Once started, it will start a scan of your computer and list a lot of infections to scare you into thinking that your computer is infected. All of these infections are fake and cannot harm your computer. The rogue uses the false scan results as method to trick you into purchase so-called “full” version of the software.

Antivir blocks the ability to run some programs. The following warning will be shown when you try to run the Notepad:

Antivir Resident Shield: Virus Detected
Warning! Active virus detected

While Antivir is running your computer will display nag screens, warnings and fake security alerts from your Windows taskbar. It will state that trojan activity detected or identity theft attempt detected. Some of the alerts:

Internet Shield: Identity theft attampt detected
Warning! Identity theft attempt detected

Trojan:W32/Inject Activity Detected
Trojan:W32/Inject is a large family of malware that secretly
makes changes to the Windows Registry. Variants in the
family make also makes changes to other running processes.

Adobe Acrobat and Adobe Flash Errors Found
A vulnerability in Adobe Acrobat, Adobe Reader, and
Adobe Flash can result in remote code execution or virus
downloading.

What is more, the program will hijack Internet Explorer and randomly shows a “Warning! Visiting this site may harm your computer!” warning page.

However, all of these warnings are fake and supposed to scare you into thinking your computer is in danger. You should ignore all of them! If you find that your system is infected with this malware, then most importantly, do not purchase it. Use the removal guide below to remove Antivir from your computer for free.

More screen shoots of Antivir



Symptoms in a HijackThis Log

O2 – BHO: &UpdateCheck.dll – {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\UpdateCheck.dll
O4 – HKCU\..\Run: [AV] C:\Program Files\AV\Antivir.exe

Use the following instructions to remove Antivir (Uninstall instructions)

1. Remove core components of Antivir

Download Avenger from here and unzip to your desktop.

Run Avenger, copy, then paste the following text in Input script Box:

Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Folders to delete:
%ProgramFiles%\AV


Files to delete:
%WinDir%\system32\UpdateCheck.dll

You will be asked Are you sure you want to execute the current script?. Click Yes. You will now be asked “First step completed — The Avenger has been successfully set up to run on next boot. Reboot now?”. Click Yes.

Your PC will now be rebooted.

2. Remove Antivir associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for Antivir infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

Antivir_remover
Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected for start Antivir removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Antivir creates the following files and folders

C:\Program Files\AV
C:\Program Files\Common Files\Uninstall
C:\Program Files\Common Files\Uninstall\AV
C:\Documents and Settings\All Users\Start Menu\AV
C:\Documents and Settings\All Users\Start Menu\AV\Antivir.lnk
C:\Documents and Settings\All Users\Start Menu\AV\Uninstall.lnk
C:\Program Files\AV\antivir.exe
C:\Program Files\Common Files\Uninstall\AV\Uninstall.lnk
%UserProfile%\Desktop\Antivir.lnk
C:\WINDOWS\system32\UpdateCheck.dll

Antivir creates the following registry keys and values

HKEY_CURRENT_USER\Software\EVAACD
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AV”

Rogue Anti Spyware Tutorials - HowTo

 Previous Post

How to remove REAnti (Uninstall instructions)

Next Post 

How to remove RESpyWare (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

48 Comments

  1. Patrik
    ― February 15, 2010 - 6:52 am  Reply

    Cathy, ask for help in our Spyware removal forum.

  2. Sarah
    ― February 15, 2010 - 4:21 pm  Reply

    Finally managed to get rid of Antivir thanks to the info on this site. Many thanks indeed! 😀

  3. Jonathan
    ― February 16, 2010 - 3:46 pm  Reply

    This program, “MalwareBytes,” worked to remove the “Security Antivirus” malware from my XP computer. Thank you! Jonathan Prather 2/16/2010

  4. emma
    ― February 17, 2010 - 1:21 pm  Reply

    I have this on my daughters laptop, it appears it has stopped me connecting from the internet. Is there a way to get rid of this virus without connecting to the internet? Please help its driving me crazy!!!!!!!!!!!

  5. Patrik
    ― February 17, 2010 - 11:43 pm  Reply

    Emma, download all suggested applications to another PC, then move them to the infected computer using a flash or cd disk.

  6. Sean
    ― February 18, 2010 - 5:34 am  Reply

    Brilliant!!! Thank you thank you thank you

  7. chandan
    ― February 20, 2010 - 5:23 am  Reply

    This program, “MalwareBytes,” worked to remove the “Security Antivirus” malware from my XP computer. Thank you!

  8. kate
    ― February 27, 2010 - 9:15 am  Reply

    my son downloaded this to his laptop, now the problem is, even in safemode, I can’t get it removed 🙁 please help …

  9. Patrik
    ― February 28, 2010 - 12:30 am  Reply

    kate, if the steps above does not help you, then ask for help in our Spyware removal forum.

  10. Takk
    ― February 28, 2010 - 3:03 pm  Reply

    Thanks, this seemed to work well. I used the list of files and just deleted them from a live Linux distro. Seemed to do the job.

  11. AlyM
    ― March 2, 2010 - 5:36 am  Reply

    Brilliant instructions! Easy to follow, links to the software required and screenshots so you know that what you see is correct.
    Certainly did the trick for me and excluding the download time probably only took 20 minutes to complete. NICE ONE!

  12. Nichole
    ― March 3, 2010 - 10:59 am  Reply

    It worked! The instructions were very easy to follow and I am so thankful! Thank you so much!

  13. Greg Bohrer
    ― March 6, 2010 - 11:12 am  Reply

    Thanks for your help. The AntVir was awful and was unable to delete the program without your help

  14. Jim
    ― March 9, 2010 - 9:08 am  Reply

    Excellent! I wasted 2 hours and 30bucks on XoftSpySE before finding this solution. Worked great. Keep the kids on supervised sites!

  15. jhro
    ― July 4, 2010 - 12:18 am  Reply

    it did not work?? the anvir code will not allow advenger to run it says teh file is infected and prevents me from carrying out th einstructions above?/ can you help

  16. Patrik
    ― July 4, 2010 - 9:42 am  Reply

    jhro, this is false alert. Avenger is legitimate small malware removal tool.

  17. RJ
    ― July 15, 2010 - 11:56 am  Reply

    jhro is right. It doesn’t just tell you not to open it, it won’t let you open it! How do i fix this please?!

  18. Patrik
    ― July 16, 2010 - 9:19 am  Reply

    RJ, please begin a new topic in our Spyware removal forum. I will help you.

« Previous 1 2

Leave a Reply to Nichole Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

How to reset Google Chrome settings to default
adwcleaner
AdwCleaner – Review, How to use, Comments
ads by adware
How to remove Adware from Windows 10 (Virus removal guide)
search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024
Files encrypted by ransomware become useless
How To Recover Encrypted Files (Ransomware file recovery)

Recent Guides

How to remove REAnti (Uninstall instructions)
How to remove KeepCop (Uninstall instructions)
How to remove Eco AntiVirus 2010 (Uninstall instructions)
How to remove Additional Guard (Uninstall instructions)
How to remove Koobface worm (Removal guide)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.