Remove Antivir. Description and removal instructions

 
Title: Antivir

Type: Spyware
Severity scale:Antivir severity is 72  (72 / 100)
 
Antivir is a misleading anti-spyware application that reports false or exaggerated system security threats and infections to make you think that your computer is infected with malware. Once installed, it will simulate system scans and display a list of infections, but won't let you to remove those supposed infections unless you pay for a full version of the program. As you can see, the main goal of this misleading application is to trick you into purchasing the program. This is nothing more but a scam. Do not pay for it and uninstall Antivir from your computer as soon as possible.

Antivir graphical user interface
[Figure 1. Antivir graphical user interface]

Antivir is promoted through the use of Trojans that come mostly from fake online anti-malware scanners. Of course, the scammers use other misleading methods to promote their bogus product. Social engineering is very popular distribution method too. You shouldn't accept invitations or open links received from unknown people. When installed, Trojans download rogue application and displays fake security alerts. Those fake security alerts or notifications will state that your computer is infected, for example: "Warning! Identity theft attempt detected". Other fake notification states:


Trojan:W32/Inject Activity Detected
Trojan:W32/Inject is a large family of malware that secretly makes changes to the Windows Registry. Variants in the family make also makes changes to other running processes.


Antivir - fake alert
[Figure 2. Antivir - fake alert]

To make things worse, Antivir will hijack Internet Explorer and display "Warning! Visiting this site may harm your computer!" message [Figure 3].

Antivir - fake Internet Explorer warning
[Figure 3. Antivir - fake Internet Explorer warning]

Further more, Antivir may block legitimate anti-spyware software and block security related websites. There shouldn't be any doubts about this bogus application - it must be removed upon detection. Most importantly, do not purchase Antivir. Otherwise, you will simply lose your money. If your computer is infected with this malware, please use the removal guide below to remove Antivir manually for free. Also make sure to scan your PC with a legitimate anti-spyware application to remove the remains or additionally installed malware.


Related files: Antivir.exe, UpdateCheck.dll, Antivir.lnk, uninstall.lnk

Antivir properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

Automatic Antivir removal:

remover for Antivir

Antivir manual removal:

Kill processes:
antivir.exe
Delete registry values:
HKEY_CURRENT_USER\Software\EVAACD
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AV"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"
Unregister DLLs:
UpdateCheck.dll

Delete files:
antivir.exe UpdateCheck.dll Antivir.lnk Uninstall.lnk
Delete directories:
C:\Program Files\AV
C:\Program Files\Common Files\Uninstall
C:\Program Files\Common Files\Uninstall\AV
C:\Documents and Settings\All Users\Start Menu\AV

Other programs to remove Antivir:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 27/11/09
Information updated: 28/07/10

Additional resources related to Antivir:

Attention: If you know or you have a website or page about Antivir removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Antivir parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by . 2010-07-28 17:07:39
OK as soon as windows starts ctrl alt and delete right away and you will see a prosess it's just random letters you will know what im talking about when you see it end it. must be the first thing you do when windows load the run spy ware remover

2. by . 2010-07-19 19:07:59
Need some help from anyone I am trying everything recommended. But as soon as any process starts a window pops up and says Application cannot be executed. The file is infected. Do you want to activate your anrivirus software now. Someone please help.

3. by . 2010-07-19 15:07:33
Someone Help Me. I Can't Download It Because It's Not Letting Me On My Internet!

4. by . 2010-07-18 23:07:05
I was able to get into the task manager by opening it just as Windows booted however I could not find any of the above files on my computer. Any Ideas???

5. by . 2010-07-17 01:07:31
this antivir won't let me open task manager - anyone know what i can do about it?

6. by . 2010-07-14 14:07:35
it wont let me on internet and i dont know how to remove it:"(

7. by . 2010-04-05 10:04:02
This keeps on popping up on my laptop it took me 1 hour to figure out how to remove it>

8. by . 2010-03-08 21:03:10
Antivir said I had 442 threats. The day before Macfee said I had zero. I hate the Internet...

9. by . 2010-03-08 21:03:51
Got Antivir pop ups on my computer like crazy yesterday.I tried to google in on a PC, and I only got websites that told me to get a free download. I went to a non-infected Mac and googled it, and found this site. Thank you!

10. by . 2010-03-04 12:03:32
I can't believe so many have gotten the same scam. If I hadn't kept
searching for info on Antivir I would have purchased the damn thing. Window
Defender searched and found no infections in my computer. Thank God I
have my iPhone which enabled me to search for some kind of resolution.

11. by . 2010-03-03 09:03:18
I just got scammed by this antivir 2010. I could not access anything on my computer and I did not want it to crash so I bought it. Yes I can access everything now but should I still remove antivir. They also got me for $20.00 more than I agreed to.

12. by . 2010-03-02 17:03:51
Windows Defender was able to remove Antivir automatically in less than 5 mins. I highly recommend this program because it's free and it worked quickly for me.

13. by . 2010-03-02 14:03:06
I couldnt even go to google, had to search it on my kindle.

14. by . 2010-02-28 23:02:43
2 last person posted a commented Avira and Antivir are 2 totaly differnent programs 1 is spyware/scam other is not don't get them mixed up

15. by . 2010-02-27 23:02:28
Wow, such bullshit. Is this place sponsored by a competitor or by the malware makers?
I am not a huge Avira fan, but they are certainly a legitimate and fairly decent antivirus company.

16. by . 2010-02-24 16:02:58
So glad looked at this..............nearly bought it as it was doing my head in so much!! Got Spyware Doc and everything is now fine!!! Yay!!!!!!!!

17. by . 2010-02-18 17:02:15
I worked great for me. Found 8 infections

18. by . 2010-02-14 12:02:15
I knew something was wrong when it said that everyhting normal was a trojan. Stupid piece of work. It just didn't seem right that they forced you to buy their scam.

19. by . 2010-02-13 15:02:16
Thank you so much for this advice! I saw this and thought it to be a scam. However it really did hijack my browser. I installed Spyware doctor and it got rid of the little bugger. Thank goodness!

20. by . 2010-02-08 08:02:06
Thanks for the advise - Windows Defender got rid of it.

See more comments about Antivir >>>
Related news:
Similar parasites:
Related articles:
Related discussions: