• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Antivir (Uninstall instructions)

Myantispyware team November 27, 2009    

Antivir_scan_completeAntivir is is not a legitimate security application. The program is a rogue antispyware program that spreads mostly with the help of fake online malware scanners. It will report that your computer is infected and you must install Antivir to clean your PC. That online scanner is scam and could not possibly detect malware, trojans and viruses on your computer.

When Antivir is downloaded and installed, it will be configured to run each time when you login to Windows. Once started, it will start a scan of your computer and list a lot of infections to scare you into thinking that your computer is infected. All of these infections are fake and cannot harm your computer. The rogue uses the false scan results as method to trick you into purchase so-called “full” version of the software.

Antivir blocks the ability to run some programs. The following warning will be shown when you try to run the Notepad:

Antivir Resident Shield: Virus Detected
Warning! Active virus detected

While Antivir is running your computer will display nag screens, warnings and fake security alerts from your Windows taskbar. It will state that trojan activity detected or identity theft attempt detected. Some of the alerts:

Internet Shield: Identity theft attampt detected
Warning! Identity theft attempt detected

Trojan:W32/Inject Activity Detected
Trojan:W32/Inject is a large family of malware that secretly
makes changes to the Windows Registry. Variants in the
family make also makes changes to other running processes.

Adobe Acrobat and Adobe Flash Errors Found
A vulnerability in Adobe Acrobat, Adobe Reader, and
Adobe Flash can result in remote code execution or virus
downloading.

What is more, the program will hijack Internet Explorer and randomly shows a “Warning! Visiting this site may harm your computer!” warning page.

However, all of these warnings are fake and supposed to scare you into thinking your computer is in danger. You should ignore all of them! If you find that your system is infected with this malware, then most importantly, do not purchase it. Use the removal guide below to remove Antivir from your computer for free.

More screen shoots of Antivir



Symptoms in a HijackThis Log

O2 – BHO: &UpdateCheck.dll – {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} – C:\WINDOWS\system32\UpdateCheck.dll
O4 – HKCU\..\Run: [AV] C:\Program Files\AV\Antivir.exe

Use the following instructions to remove Antivir (Uninstall instructions)

1. Remove core components of Antivir

Download Avenger from here and unzip to your desktop.

Run Avenger, copy, then paste the following text in Input script Box:

Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Folders to delete:
%ProgramFiles%\AV


Files to delete:
%WinDir%\system32\UpdateCheck.dll

You will be asked Are you sure you want to execute the current script?. Click Yes. You will now be asked “First step completed — The Avenger has been successfully set up to run on next boot. Reboot now?”. Click Yes.

Your PC will now be rebooted.

2. Remove Antivir associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for Antivir infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

Antivir_remover
Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected for start Antivir removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Antivir creates the following files and folders

C:\Program Files\AV
C:\Program Files\Common Files\Uninstall
C:\Program Files\Common Files\Uninstall\AV
C:\Documents and Settings\All Users\Start Menu\AV
C:\Documents and Settings\All Users\Start Menu\AV\Antivir.lnk
C:\Documents and Settings\All Users\Start Menu\AV\Uninstall.lnk
C:\Program Files\AV\antivir.exe
C:\Program Files\Common Files\Uninstall\AV\Uninstall.lnk
%UserProfile%\Desktop\Antivir.lnk
C:\WINDOWS\system32\UpdateCheck.dll

Antivir creates the following registry keys and values

HKEY_CURRENT_USER\Software\EVAACD
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AV”

Rogue Anti Spyware Tutorials - HowTo

 Previous Post

How to remove REAnti (Uninstall instructions)

Next Post 

How to remove RESpyWare (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

48 Comments

  1. Cecilia
    ― November 28, 2009 - 12:18 pm  Reply

    Thank you so much for this infomation!! Finally I got this crap of my computer! It drove me nuts trying to uninstall it.

  2. Marcellus
    ― November 30, 2009 - 12:00 pm  Reply

    Cecilia , how did you unstall it, it drives my crazy too

  3. Patrik
    ― November 30, 2009 - 11:08 pm  Reply

    Marcellus, if instruction above does not help you, then ask for help in our Spyware removal forum.

  4. george
    ― December 2, 2009 - 11:33 am  Reply

    Thank you so much for the help. Kids downloaded a game and got this crap on my computer. This process worked perfectly. Norton didn’t even catch it with a deep scan. I’ll be purchasing this.

  5. Cherie
    ― December 2, 2009 - 3:02 pm  Reply

    God bless u i was so worried that this crap would destroy my computer. Thank you so very very much!

  6. Jeannie
    ― December 3, 2009 - 9:28 pm  Reply

    Thank you; it worked like a charm and did not take long at all.

  7. sonia
    ― December 3, 2009 - 10:55 pm  Reply

    hello there i just wanted to say that i tried soooo hard to delete antivir from my pc i went through the way it says on top of this page but i cant delete it i would like to know why please because antivir is now officially the most annoying…. thank you.
    please help!

  8. Patrik
    ― December 4, 2009 - 10:56 am  Reply

    sonia, if the instruction above does not help you, then ask for help in our Spyware removal forum.

  9. Marcellus
    ― December 5, 2009 - 2:49 am  Reply

    It worked thanks Patrik

  10. Jay M.
    ― December 5, 2009 - 3:40 am  Reply

    this antivir pop ups kept driving crazy i spend two day doing some research on how to remove this crap finally i came across with this post. unsure if i should follow this instruction i went ahead and tried it.. correct me if I’m wrong but it seem to me by noticing this post that this is like a new virus that just came up?..thank you so much for your help.

  11. Patrik
    ― December 5, 2009 - 11:00 pm  Reply

    Jay, what is a new virus ? Both apps that i suggest to use are legitimate security tools.

  12. Cameron
    ― December 7, 2009 - 3:28 am  Reply

    Thank you so much, I had that piece of shit Antivir on my laptop and it was so annoying…This antimalware removed it for FREE! Seriously, thank you!

  13. Sherry
    ― December 7, 2009 - 4:55 pm  Reply

    Why is it this AntiVir is able to get passed ENOD, Norton and most importantly, Windows Security? What the hell is going on with that? I was able to uninstall it. I am sure Windows is aware this bunch of thieves are using a symbol that is identical to their Security icon in the upper left hand corner. Microsoft needs to get on the ball and prepare a security update against this type of stuff.

  14. Matt
    ― December 8, 2009 - 2:45 am  Reply

    Wonderful, took no time at all, cleaned up computer for mom and sister. Thank you!

  15. Matt J
    ― December 11, 2009 - 2:15 pm  Reply

    Nasty bit of Malware this ‘antivi’. One of my employees has it, I’ve tried everything BUT malwarebytes at this point including the manual fix. Unfortunately, some of the program files for it are

  16. Surajit
    ― December 12, 2009 - 12:51 am  Reply

    Thanx…It is Very much helpful….

  17. Bailey
    ― December 14, 2009 - 4:06 am  Reply

    Looks Like AVG And The Threat Windows Look Like Microsoft Security Essentials!

  18. Robert Strobel
    ― December 14, 2009 - 5:41 pm  Reply

    The antivir will not let me get on-line. How can I download avenger to my desktop so I can uninstall?

  19. Patrik
    ― December 15, 2009 - 7:58 am  Reply

    Robert, try download Avenger in the Safe mode with networking. Also you can download it to another computer, then move Avenger to infected PC using CD disk or flash drive.

  20. Suda
    ― December 30, 2009 - 11:26 am  Reply

    OMG tnk u so much..it was giving me a headache… Tnx alot!!!

  21. Gian Oneto
    ― January 2, 2010 - 11:15 pm  Reply

    I am so happy I got rid of this nasty antivir. Thank you so much. You are of great help since it is also very easy and straight forward.

  22. grax
    ― January 14, 2010 - 11:45 pm  Reply

    it work thhanks

  23. Sean
    ― January 16, 2010 - 3:26 am  Reply

    I know I am only reiterating what most of the other users have said, but these instructions worked perfectly! I am amazed. Holy $#!+

  24. jame
    ― January 30, 2010 - 3:42 pm  Reply

    I have personal security on my laptop..
    is this the same as the thing on here..
    like happening.
    cause i want to get rid of it 😐

  25. Patrik
    ― January 31, 2010 - 3:28 am  Reply

    Jame, try the steps.

  26. Arrick Moore
    ― February 10, 2010 - 11:28 am  Reply

    You dont have to go into safemode to remove this…. You can open Windows Updates and browse to it from there, this AV doesnt block the Update Explorer window.

  27. Arrick Moore
    ― February 10, 2010 - 11:30 am  Reply

    To clariify my last post, you can get to the avenger site by opening up the Windows Update window, then browse from it to the site in question to download the removal tools.

  28. Adam
    ― February 13, 2010 - 11:21 am  Reply

    I downloaded the MalwareBytes Anti-malware and whenever I try to open it it says: Run time error ‘0’. What does that mean?

  29. Patrik
    ― February 14, 2010 - 10:01 am  Reply

    Adam, click Start, Run, type cmd and press Enter.
    Command console opens.
    Type
    regsvr32 "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll"
    Press Enter.
    Type
    regsvr32 "C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll"
    Press Enter.
    Type
    regsvr32 "C:\Program Files\Malwarebytes' Anti-Malware\vbalsgrid6.ocx"
    Press Enter.
    Try run Malwarebytes once again.
    Note: Malwarebytes should be installed into C:\Program Files\Malwarebytes’ Anti-Malware

  30. Cathy
    ― February 14, 2010 - 5:35 pm  Reply

    I followed the steps and copied the script into avenger. I rebooted my PC and the script failed. I believe it stated that the folders didn’t exist.

1 2 Next »

Leave a Reply Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
This setting is enforced by your administrator (Removal guide)
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide
ads by adware
How to remove Adware from Windows 10 (Virus removal guide)
How to reset Google Chrome settings to default

Recent Guides

How to remove REAnti (Uninstall instructions)
How to remove KeepCop (Uninstall instructions)
How to remove Eco AntiVirus 2010 (Uninstall instructions)
How to remove Additional Guard (Uninstall instructions)
How to remove Koobface worm (Removal guide)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.