How to remove fake Antivirus (avt.exe)

1 Star2 Stars3 Stars4 Stars5 Stars (82 votes, average: 5.00 out of 5)
loadingLoading...

Antivirus (avt.exe) is introduced all at once as a trojan that is normally downloaded by PC user from certain fake online page, being promoted and installed through various fake alert trojans that advertise it on user’s desktop. By the way, its is not a pure trojan, since users get fake antispyware instead of true one while trojan rather means something completely unrelated to the described content. avt.exe is a new rogue application (clone of Defense Center, Protection Center, Data Protection, Digital Protection, Your Protection, Dr. Guard and User Protection).


One of the peculiarities of “Antivirus” is that as soon as it starts the trojan would scan PC to check the availability of already installed well-known antispyware and antivirus programs (AVG, Avira, McAfree, F-secure, Trojan Killer, Nod32, Loaris, etc). As soon as they are revealed avt.exe will attempt to uninstall them under the pretext that they may conflict with it by showing the following message:
Antivirus
Uncertified {antivirus name} antivirus software detected on your computer. You need to remove {antivirus name} software for correct operation of the Antivirus. Attention: If you don`t remove {antivirus name} software, the performance of your computer will dramatically degrade. Press “OK” to remove the {antivirus name}

The further behavior of the virus is similar to other well-spread trojans: Antivirus (avt.exe) starts “scanning” the PC to check whether there are any infections on it. As soon as the scan is completed avt.exe will indicate that there are hundreds of infections on computer. However, “Antivirus” will not let you remove them before you purchase the program. Please be advises that this recommendation is far beyond the actual state of your PC. All the infections it claims to reveal are fake and are not actually present on your system.
We therefore urge you not to install and purchase Antivirus (avt.exe) under any circumstances! Gridinsoft Trojan Killer can help you get rid of Antivirus (avt.exe).
As you see, the trojan avt.exe is not a lonely walker in the empty space. Similar to other trojans and rogue software, it has multiple links to other rogues. That’s why complex malware removal is the best way to get rid of rogue avt.exe . In addition, if you remove “Antivirus” automatically by using Gridinsoft Trojan Killer you get life-time protection from malware aggression.

Please be advised that GridinSoft LLC and Trojan-Killer.com IS NOT associated, affiliated, consorted, or connected with the publishers or creators of Antivirus (avt.exe) .


Antivirus (avt.exe) automatical remover:

  1. Download the last version of Trojan Killer to clear (not infected) computer and install it
  2. Update the virus database
  3. Copy whole folder “c:\Program Files\GridinSoft Trojan Killer” to your memory stick
  4. Rename “trojankiller.exe” to “iexplore.exe”
  5. Move memory stick to infected PC and run iexplore.exe from “Trojan Killer” folder

Antivirus (avt.exe) manual removal guide:

Delete Antivirus (avt.exe) files:

%documents and settings%\all users\application data\fiosejgfse.dll
%temp%\mswinsck.exe
%temp%\wscsvc32.exe
%appdata%\microsoft\internet explorer\quick launch\Antivirus.lnk
%desktop%\Antivirus support.lnk
%desktop%\Antivirus.lnk
%commonprograms%\AnVi\about.lnk
%commonprograms%\AnVi\activate.lnk
%commonprograms%\AnVi\buy.lnk
%commonprograms%\AnVi\Antivirus support.lnk
%commonprograms%\AnVi\Antivirus.lnk
%commonprograms%\AnVi\scan.lnk
%commonprograms%\AnVi\settings.lnk
%commonprograms%\AnVi\update.lnk
%programfiles\AnVi\about.ico
%programfiles\AnVi\activate.ico
%programfiles\AnVi\buy.ico
%programfiles\AnVi\avt.db
%programfiles\AnVi\avtext.dll
%programfiles\AnVi\avthook.dll
%programfiles\AnVi\avt.exe
%programfiles\AnVi\help.ico
%programfiles\AnVi\scan.ico
%programfiles\AnVi\settings.ico
%programfiles\AnVi\splash.mp3
%programfiles\AnVi\uninstall.exe
%programfiles\AnVi\update.ico
%programfiles\AnVi\virus.mp3

Delete Antivirus (avt.exe) registry entries:

hkcr\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
hkcu\Software\Microsoft\Windows\CurrentVersion\Run “Antivirus”
hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved “{5E2121EE-0300-11D4-8D3B-444553540000}”

3 thoughts on “How to remove fake Antivirus (avt.exe)

  1. Их полно сейчас! Достали уже эти псевдо-антивирусы!

Leave a Comment

*