Antivir. How to remove?
(Uninstall guide)

Antivir | Type: Rogue Antispyware
Severity scale:  
Antivir is a misleading anti-spyware application that reports false or exaggerated system security threats and infections to make you think that your computer is infected with malware. Once installed, it will simulate system scans and display a list of infections, but won't let you to remove those supposed infections unless you pay for a full version of the program. As you can see, the main goal of this misleading application is to trick you into purchasing the program. This is nothing more but a scam. Do not pay for it and uninstall Antivir from your computer as soon as possible.

Antivir graphical user interface
[Figure 1. Antivir graphical user interface]

Antivir is promoted through the use of Trojans that come mostly from fake online anti-malware scanners. Of course, the scammers use other misleading methods to promote their bogus product. Social engineering is very popular distribution method too. You shouldn't accept invitations or open links received from unknown people. When installed, Trojans download rogue application and displays fake security alerts. Those fake security alerts or notifications will state that your computer is infected, for example: "Warning! Identity theft attempt detected". Other fake notification states:

Trojan:W32/Inject Activity Detected
Trojan:W32/Inject is a large family of malware that secretly makes changes to the Windows Registry. Variants in the family make also makes changes to other running processes.

Antivir - fake alert
[Figure 2. Antivir - fake alert]

To make things worse, Antivir will hijack Internet Explorer and display "Warning! Visiting this site may harm your computer!" message [Figure 3].

Antivir - fake Internet Explorer warning
[Figure 3. Antivir - fake Internet Explorer warning]

Further more, Antivir may block legitimate anti-spyware software and block security related websites. There shouldn't be any doubts about this bogus application - it must be removed upon detection. Most importantly, do not purchase Antivir. Otherwise, you will simply lose your money. If your computer is infected with this malware, please use the removal guide below to remove Antivir manually for free. Also make sure to scan your PC with a legitimate anti-spyware application to remove the remains or additionally installed malware. Related files: Antivir.exe, Antivir.lnk, uninstall.lnk

Antivir properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

Automatic Antivir removal:

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
By downloading any of provided Anti-spyware software to remove Antivir you agree with our Privacy Policy and Agreement of Use.
remover for Antivir
Compatible with OS X
Webroot SecureAnywhere AntiVirus is recommended remover to uninstall Antivir. You should confirm using free trial that it detects current version of parasite.
Not using OS X? Download a remover for Windows.
Do it now!
remover for Antivir Happiness
Compatible with Microsoft Microsoft Windows logo
SpyHunter is recommended remover to uninstall Antivir. You should confirm using free trial that it detects current version of parasite.
more than 40.000.000 downloads!
What to do if you failed to remove the infection?
If you failed to remove Antivir using Webroot SecureAnywhere AntiVirus SpyHunter, read here how to submit a support ticket or submit a question to our support team and provide as much details as possible.
Alternate Software
Tested and Confirmed! STOPzilla removes Antivir (2009-11-27 01:28:41)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes Antivir (2009-11-27 01:28:41)
XoftSpySE Anti Spyware
We are testing XoftSpySE Anti Spyware's efficiency at removing Antivir (2012-06-05 11:00:10)
Zemana Antimalware
Tested and Confirmed! STOPzilla removes Antivir (2009-11-27 01:28:41)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes Antivir (2009-11-27 01:28:41)
Virus Removal Phone Support
Help Line to remove Antivir

Antivir manual removal

Kill processes:
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AV"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"
Unregister DLLs:

Delete files:

Delete directories:
C:\Program Files\AV
C:\Program Files\Common Files\Uninstall
C:\Program Files\Common Files\Uninstall\AV
C:\Documents and Settings\All Users\Start Menu\AV

Geolocation of Antivir

Map reveals the prevalence of Antivir. Countries and regions that have been affected the most are: Germany, Austria, Madagascar, Switzerland and Cameroon.

Information added: 11/27/09 01:28; information updated: 06/05/12 08:22

Additional resources

Attention: If you know know a reputable website reated to security threats, please add a link here: add url

Comments on Antivir

Spyhunter doesnt work and I feel some of the paid and widely marketed anti virus/spyware soft wares could be the source of this extremely harmful virus. Try spybot and malwarebytes. if both cannot remove this virus, then you might need some big help.
That is a FAKE antivir.

this is just another name for this type of infection:
Antivirus 2010/2011
XP anti spyware
windows Av
Whateva... I have even seen a fake AVG

Antivir by Avira is one of the Top free AV solutions available and has an Umbrella logo.

What i would like to know is what the heck people are clicking on to get this junk on their PCs in the first place, just think, if you had a mac this would not have happened, however basic tasks might be just that little bit more anoying.

remember all the fake AV and fake PC tuneup SW will want you to pay, and will seem fantastic in their diagnosis.
i used safe mode in windows XP and system restore, this should solve teh problem
I can't use the internet on the computer that is infected with this antivira software how do i get rid of it on a different computer ?
Used System Restore twice to get rid of this horrible malware, but now System Restore won't let me go back to a previous date and create a new restore point.
Thanks a lot for this, I was pretty worried and was about to buy the program when I noticed they were spelling everything incorrectly.
I just used system restore and I can browse the web again, but I still need to delete the program completely.
Same poster, just used windows defender and it's working fine.
every one it changes your LAN settings in IE choose autodetect and uncheck everything else
I now can't go on the internet so I used a friends computer to look it up. What do I do?
My first ever infection. what a nightmare!
On Vista press f8 on startup, choose safe mode, then system restore - worked a treat.
Thanks for this website andmy old apple laptop!
More comments »

Post a comment

Attention: Use this form only if you have additional information about Antivir parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name


(All fields are required)
Like us on Facebook
Recent Malware
Read on mobile
Press Mentions
I failed to remove Antivir using SpyHunter.


add text box
rss feed
help other
Spreading the knowledge: It is very hard to fight against computer parasites on the Internet alone. If you have a website, we would be more than happy if you would like to cooperate and help us spread the information about latest threats. Remember, knowledge is the most powerful weapon. Help your visitors protect their computers!