Antivirii 2011

Keep the fake software Antivirii 2011 away from your PC. This rogue program can do the same harm as any other computer viruses.

Antivirii 2011 is a rogue security program that comes from NRB (Napalm Rogue Builder). This fake anti-virus software is hosted on various fraud web sites that will provide a quick online virus scan upon your visit. On an analysis conducted by precisesecurity.com, these web sites will open a browser window that mimics the looks of Windows Explorer. However, authors behind the attack have integrated a virus scanner to deceive users and convince them to download the trial version of Antivirii 2011.

Other than the copied Windows Explorer interface, Antivirii 2011 will also present a fake “Windows Security Alert” consisting of an identified number of infected files. Execution of this alert may install Antivirii 2011 and will bring severe disruption on the PC.

Once Antivirii 2011 is installed, it alters the registry to run itself every time Windows starts. So far, this single change is the only recorded harm it can cause on the infected PC.

Likely, this rogue security software will fabricate scary tactics like fake security alerts and system tray messages. Virus scan runs routinely on every Windows start-up. Detecting dozens of non-existing viruses, Trojans and worms attempts to aggravate victim’s concern over this shaped situation.

The only solution to this type of malware behavior is to scan the computer with an effective and genuine anti-malware product. Simple and free removal tool is what we can provide to help you delete Antivirii 2011.

Screen Shot Image:

Antivirii 2011 Scanner

Technical Details and Additional Information:

Antivirii 2011 Is Also Detected As:
TR/Dropper.Gen (AntiVir), SHeur4.JTW (AVG), Trojan.FakeAlert.CQI (BitDefender), Heur.Suspicious (Comodo), Trojan.Win32.FakeAV!IK (Emsisoft), Trojan.FakeAlert.CQI (F-Secure), Trojan.FakeAlert.CQI (GData), Trojan.Win32.FakeAV (Ikarus), Trojan-FakeAV.Win32.Antivirii.a (Kaspersky), Artemis!97B7917E777D (McAfee), W32/Adclicker.LLM.dropper (Norman), Mal/Generic-L (Sophos), Trj/CI.A (Panda)

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Malware Behavior
Fake anti-virus program Antivirii 2011 can be acquired by visiting maliciously created web sites or legitimate web sites that are compromised by a Trojan. When visiting these sites, it will display the following message:

Message from webpage
Windows Security has found possible virus threats on your computer and it will perform a quick scan.

Fake Message From Webpage

Next, the site will scan visitor’s computer using a graphical user interface similar to Windows Explorer.

Fake Windows Explorer

While Antivirii 2011 is running on the computer, it will display various fake security alerts including the following:

Your computer is in danger!
Antivirii 2011 has detected some serious threats to your computer!
These viruses need to be eliminated immediately! Please click this icon to remote threats.

Fake System Tray Alert

Your system is infected!
Your computer is compromised by hackers, adware, malware and worms!
Antivirii 2011 can remove this infection. Please click this icon to remove threats.

Fake Task Bar Warning

Antivirii 2011 – Malware Detected
Threats have been detected!
Warning! Some serious threats have been detected to your computer, that need to be removed instantly or they may cause critical damage to your computer!
Antivirii 2011 can remove these viruses easily, and prevent damage to your personal computer.
If you click “Remove viruses”, you can protect your computer from destruction, however, if you click “Continue unprotected”, your identity can be compromised and you may lose all your important files and experience system slowdown.

[cf]regis[/cf] [cf]files[/cf]

How to Remove Antivirii 2011

This guide requires a tool called Malwarebytes' Anti-Malware. It is a free tool designed to eradicate various computer infections. MBAM scanner is distributed for free.

Boot Windows in Safe Mode With Networking

1. First thing to do is to reboot the computer in Safe Mode with Networking to avoid Antivirii 2011 from loading at start-up. You may want to print this procedure as we have to restart the computer to complete the removal process.
- Restart the computer.
- Before Windows begins to load, press F8 on your keyboard.
- It will display an Advanced Boot Options menu. Please select Safe Mode with Networking.
- Windows will now start in Safe Mode.

Antivirii 2011 Removal Tool

2. Download removal software and save it on your Desktop or any location on your PC.
3. When finish downloading, double-click on the file to install the application.
4. Follow the prompts and install with default configuration.
5. Before the installation completes, you need to update the database.

6. Click Finish. Program will run automatically and you will be prompt to update the program before doing a scan. Please update.
7. When finished updating, the tool will run. Select Perform full scan on main screen to check your computer thoroughly.
8. When scanning is finished click on Show Results.
9. Make sure that all detected threats are checked, click on Remove Selected. This will delete all files and registry entries that belongs to Antivirii 2011.
10. Restart your computer.

Note: If Antivirii 2011 prevents mbam-setup.exe from downloading. Download the software from another computer. Renaming it to something like 'anything.exe' can help elude the malware.

Alternative Removal Method for Antivirii 2011

Option 1 : Use Windows System Restore to return Windows to previous state

If Antivirii 2011 enters the computer, there is a big chance that Windows files, registry entries and other essential components are also infected. System Restore can reinstate clean system files by restoring the configuration to an earlier date. The method also replaces compromised files with a clean version. If you have a saved restore point before Antivirii 2011 infiltrates the PC, we highly encourage you to execute this procedure if none of the above works. You may proceed with Windows System Restore, click here to see the full procedure.

Option 2 : Antivirii 2011 manual uninstall guide

IMPORTANT! Manual removal of Antivirii 2011 requires technical skills. Deleting system files and registry entries by mistake may result to total disability of Windows system. We advise you to perform a backup of registry before proceeding with this guide.

1. Kill any running process that belongs to Antivirii 2011.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for Antivirii 2011 files (refer to Technical Reference) and click End Process.

End Task

2. Delete all registry entries that belong to this malware.
- Press [Windows Key]+R on your keyboard.
- In the 'Open' dialog box, type regedit and press Enter. This will open registry editor.
- Find and delete registry entries as mentioned in Technical Reference section below.
- Close registry editor. Changes made will be save automatically.

Run Regedit

3. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.

4. Delete all files dropped by Antivirii 2011.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Technical Reference'. Make sure that you execute 'End Task' first before deleting the file. Otherwise, the system will not let you perform this action.

Technical Reference

Associated Files and Folders:Added Registry Entries: