Monday, December 12, 2011

Get rid of Antivirii 2011 as another malware of Antivirus Clean 2011 family

Antivirii 2011 (Antivirii2011) is a malicious program of the same genera of rogues as Antivirus Clean 2011. Its interface has been updated as compared to the malware of its family preceding it. However, these have been moderate updates that did not alter core pattern of the software.
There was a long interruption between releases of the two deceptive security tools. The forerunner of the rogue under review was registered as a malicious applications at the mid of April 2011, while the next application of the same functionality was only observed in the wild closer to the middle of December of the same year.
Removal of Antivirii 2011, in spite of similarity of the two malicious programs, requires utterly different approach than that for other members of its strain. The tool available here is a free scanner that will remove Antivirii 2011, just like any other infection, including programs related to the adware in question.



Manual removal guide:
Delete infected files:
C:\WINDOWS\system32\antivirii.exe.exe
C:\WINDOWS\system32\[SET OF RANDOM CHARACTERS].exe
Delete infected registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Security"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe "Debugger"


Rename the remover to "explorer.exe" or try to install from Safe Mode if virus blocks download\installation

No comments: