Severity scale  
  (72/100)

Antivir. How to Remove? (Uninstall Guide)

removal by - -   | Type: Rogue Antispyware
Antivir is a misleading anti-spyware application that reports false or exaggerated system security threats and infections to make you think that your computer is infected with malware. Once installed, it will simulate system scans and display a list of infections, but won't let you to remove those supposed infections unless you pay for a full version of the program. As you can see, the main goal of this misleading application is to trick you into purchasing the program. This is nothing more but a scam. Do not pay for it and uninstall Antivir from your computer as soon as possible.

Antivir graphical user interface
[Figure 1. Antivir graphical user interface]

Antivir is promoted through the use of Trojans that come mostly from fake online anti-malware scanners. Of course, the scammers use other misleading methods to promote their bogus product. Social engineering is very popular distribution method too. You shouldn't accept invitations or open links received from unknown people. When installed, Trojans download rogue application and displays fake security alerts. Those fake security alerts or notifications will state that your computer is infected, for example: "Warning! Identity theft attempt detected". Other fake notification states:


Trojan:W32/Inject Activity Detected
Trojan:W32/Inject is a large family of malware that secretly makes changes to the Windows Registry. Variants in the family make also makes changes to other running processes.


Antivir - fake alert
[Figure 2. Antivir - fake alert]

To make things worse, Antivir will hijack Internet Explorer and display "Warning! Visiting this site may harm your computer!" message [Figure 3].

Antivir - fake Internet Explorer warning
[Figure 3. Antivir - fake Internet Explorer warning]

Further more, Antivir may block legitimate anti-spyware software and block security related websites. There shouldn't be any doubts about this bogus application - it must be removed upon detection. Most importantly, do not purchase Antivir. Otherwise, you will simply lose your money. If your computer is infected with this malware, please use the removal guide below to remove Antivir manually for free. Also make sure to scan your PC with a legitimate anti-spyware application to remove the remains or additionally installed malware. Related files: Antivir.lnk, uninstall.lnk

Antivir properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Antivir. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended remover to uninstall Antivir. You should confirm using free trial that it detects current version of parasite.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
STOPzilla
Tested and Confirmed! STOPzilla removes Antivir (2009-11-27 01:28:41)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes Antivir (2009-11-27 01:28:41)
SpyHunter
We are testing SpyHunter's efficiency (2012-06-05 08:22)
STOPzilla
Tested and Confirmed! STOPzilla removes Antivir (2009-11-27 01:28:41)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes Antivir (2009-11-27 01:28:41)
Webroot SecureAnywhere AntiVirus

Antivir manual removal

Kill processes:
antivir.exe
Delete registry values:
HKEY_CURRENT_USER\Software\EVAACD
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AV"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"
Unregister DLLs:
UpdateCheck.dll

Delete files:
antivir.exe
UpdateCheck.dll
Antivir.lnk
Uninstall.lnk

Delete directories:
C:\Program Files\AV
C:\Program Files\Common Files\Uninstall
C:\Program Files\Common Files\Uninstall\AV
C:\Documents and Settings\All Users\Start Menu\AV

Geolocation of Antivir

Map reveals the prevalence of Antivir. Countries and regions that have been affected the most are: Germany, Austria, Madagascar, Switzerland and Cameroon.

Information updated:

Comments on Antivir

0
0
juneberry
Spyhunter doesnt work and I feel some of the paid and widely marketed anti virus/spyware soft wares could be the source of this extremely harmful virus. Try spybot and malwarebytes. if both cannot remove this virus, then you might need some big help.
0
0
cybersloth
That is a FAKE antivir.

this is just another name for this type of infection:
Antivirus 2010/2011
XP anti spyware
windows Av
Whateva... I have even seen a fake AVG

Antivir by Avira is one of the Top free AV solutions available and has an Umbrella logo.

What i would like to know is what the heck people are clicking on to get this junk on their PCs in the first place, just think, if you had a mac this would not have happened, however basic tasks might be just that little bit more anoying.

remember all the fake AV and fake PC tuneup SW will want you to pay, and will seem fantastic in their diagnosis.
0
0
<Guest>
i used safe mode in windows XP and system restore, this should solve teh problem
0
0
<Guest>
I can't use the internet on the computer that is infected with this antivira software how do i get rid of it on a different computer ?
0
0
<Guest>
Used System Restore twice to get rid of this horrible malware, but now System Restore won't let me go back to a previous date and create a new restore point.
0
0
<Guest>
Thanks a lot for this, I was pretty worried and was about to buy the program when I noticed they were spelling everything incorrectly.
I just used system restore and I can browse the web again, but I still need to delete the program completely.
0
0
<Guest>
Same poster, just used windows defender and it's working fine.
0
0
<Guest>
every one it changes your LAN settings in IE choose autodetect and uncheck everything else
0
0
<Guest>
I now can't go on the internet so I used a friends computer to look it up. What do I do?
0
0
<Guest>
My first ever infection. what a nightmare!
On Vista press f8 on startup, choose safe mode, then system restore - worked a treat.
Thanks for this website andmy old apple laptop!
More comments »

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)