Severity scale  
  (72/100)

AV Security Essentials. How to Remove? (Uninstall Guide)

removal by - -   Also known as AVSecurityEssentials | Type: Rogue Antispyware
12

AV Security Essentials is a rogue anti-spyware program that displays fake security alerts and reports false malware infections to make you believe your computer is infected with spyware and similar stuff. The rogue program is a clone of Smart Anti-Malware Protection scareware and it is promoted mostly through the use of Trojans and fake online virus scanners. Scammers may also promote their bogus software on popular social networks and instant messengers. Once installed, AV Security Essentials will run a fake system scan and display a list of non-existent malware infections. The scan results are completely false, so you may safely ignore them. The rogue program may detect legitimate programs and files as infections as well. For example, AV Security Essentials may claim that Internet Explorer (iexplore.exe) is infected by notorious Blaster worm. This is not true. That's why you shouldn't follow on screen instructions. Instead, please use the removal instructions below to remove AV Security Essentials from your computer safely.

When running, AV Security Essentials will display numerous fake and very annoying security alerts claiming that your computer is compromised or infected and that you should activate AV Security Essentials to ensure full system protection against the latest malware threats. This fake program will blocks legit antivirus and anti-spyware programs to protect itself from being removed. It may block those programs in Safe Mode too. It will claim that your anti-virus or any other program actually is infected. If you find that your computer is infected with AV Security Essentials, please follow the removal instructions below. And of course, don't purchase it. This is nothing more but a scam. However, if you have already bought it then you should contact your credit card company and dispute the charges as soon as possible. To make the removal procedure easier, you can activate this rogue application using this fake registration code U2FD-S2LA-H4KA-UEPB. This doesn't remove AV Security Essentials, but entering the fake registration key disables rogue's self defence mechanisms.

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall AV Security Essentials. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall AV Security Essentials. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2012-02-06 01:58)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-02-06 01:58)
Hitman Pro
Webroot SecureAnywhere AntiVirus

AV Security Essentials manual removal

Kill processes:
[random].exe
AV9c5_8046.exe
scandsk211d_8046.exe
ASa76.exe
eb.exe
runddlkey.exe
Delete registry values:
HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
Default = Implements DocHostUIHandler
LocalServer32 = %AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe
ProgID = AS9c5_8046.DocHostUIHandler
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\
Debugger = svchost.exe
Unregister DLLs:
mozcrt19.dll

Delete files:
%AllUsersProfile%\Application Data\5c678c\
%AllUsersProfile%\Application Data\5c678c\sqlite3.dll
%AllUsersProfile%\Application Data\5c678c\ASPSys\
%AllUsersProfile%\Application Data\5c678c\BackUp\
%AllUsersProfile%\Application Data\5c678c\Quarantine Items\
%AllUsersProfile%\Application Data\5c678c\582.mof
%AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe
%AllUsersProfile%\Application Data\5c678c\ASP.ico
%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll
%AllUsersProfile%\Application Data\ASLNP\
%AllUsersProfile%\Application Data\ASLNP\ASUUDJRRJXP.cfg
%AppData%\AV Security Essentials\
%AppData%\AV Security Essentials\cookies.sqlite
%AppData%\Microsoft\Internet Explorer\Quick Launch\AV Security Essentials.lnk
%UserProfile%\Desktop\AV Security Essentials.lnk
%Temp%\scandsk211d_8046.exe
%UserProfile%\Start Menu\AV Security Essentials.lnk
%UserProfile%\Start Menu\Programs\AV Security Essentials.lnk

Geolocation of AV Security Essentials

Map reveals the prevalence of AV Security Essentials. Countries and regions that have been affected the most are: United States.

Information updated:

Comments on AV Security Essentials

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)