AntiVirus System 2011 Virus Removal

AntiVirus System 2011 is a rouge anti-spyware program which can misguide a user by providing wrong information regarding the system security of his/her computer. AntiVirus System 2011 can gain access to a pc through Trojans, insecure websites and other malicious programs. Once installed in a computer, AntiVirus System 2011 will conduct fake scans of the machine and will come up with so-called “infections” which according to this software cannot be removed without the paid version of AntiVirus System 2011. In addition to this, the software will keep sending security alerts to the user giving him/her the impression that the system is at risk.

However, the truth is AntiVirus System 2011 itself is a virus which comes up with all these threats only to pursue a user to buy the commercial product. One of the major issues that you need to take under consideration is that AntiVirus System 2011 is capable of disabling your system security and can steal your confidential information once it gets access to your system.

Once running in a computer, AntiVirus System 2011 usually comes up with these alerts:

Security Center Alert
To help protect your computer, Security Center has blocked some features of this program.
Name: Screen.Grab.J.exe
Risk: High

System critical warning!
You have been infected by a proxy-relay trojan server

Antivirus detects viruses, worms, and Trojan horses. They
can (and do) destroy data, format your hard disk or can
destroy the BIOS. By destroying the BIOS many times you
end up buying a new motherboard or if the bios chip is removable then that chip would need replacing

AntiVirus System 2011

AntiVirus System 2011

» Download AntiVirus System 2011 Removal Software

Now if your computer gets infected by AntiVirus System 2011, you should consider taking necessary steps as soon as possible to delete it from the machine or else it can make your life quite difficult. There are some reliable virus removal guides/procedures available online that can assist you to get rid of AntiVirus System 2011.

Remove Proxy Setting so You Can Connect to the Internet Again.

Proxy Settings

 

How to Remove AntiVirus 2011 Manually

First you need to stop the following processes to delete AntiVirus 2011 from your machine:

AntiVirus_System_2011.exe
securityhelper.exe
securitymanager.exe
2010yo.exe

In order to stop the processes, at first you need to go to the file location and rename the file. Once that is done, restart the computer and go back to the file location again and then delete the file.

The next step is getting rid of the following files:

For Windows XP

C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ae0965a7157cd.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\alerfa.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\alerfa2.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\altedf.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\backd-efq.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\brdss.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\cocksucker.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\cosock.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\cowceb.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\cunifuc.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\d20mes.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\dc_3.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\dd10x10.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ddoll3342.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\destroyer.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\dffuck.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\dgxdro.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\fadz43.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\fe.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\format.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\g_dx234.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\gedx_ae09.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ggwwef9752.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\gpupz2a.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\hardwh.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\hhbboll_2.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\hiphop.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\htfad4.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\hvipws9.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\jdhellwo3.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\jkfuckfu.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\jofcdks.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\kn.a.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\kock.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\lols.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\lorsk.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ploper.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\poertd.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ppddfcfux.exxe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\protector2.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\pswwg3c.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\puzpup.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\qwedvor.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\r0life.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\rator.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\rtfme.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\safe.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\snowif.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\sycre.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\timem.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\w32-reno-c.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\w32rim_mem.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\warsddd_w.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\wefgetn_00.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\wined.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\winifi.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\wqefqw7e.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\wrcud12.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\wrfwe_di.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\_2.tmp
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\2010yo.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ae0965a7157cd.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\al3erfa3.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\[random].exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\ae0965a7157cd.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\winlogoff.exe
C:\Documents and Settings\YOUR USER NAME\ApplicationData\Local\Temp\wrfwe_di.exe
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\AntiVirus_System_2011.exe
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\IcoActivate.ico
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\IcoHelp.ico
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\IcoUninstall.ico
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\securityhelper.exe
C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\securitymanager.exe
C:\Documents and Settings\USER NAME\Application Data\ \Microsoft\Internet Explorer\Quick Launch\AntiVirus System 2011.lnk
C:\Documents and Settings\Desktop\AntiVirus System 2011.lnk
C:\Documents and Settings\Start Menu\Programs\AntiVirus System 2011\
C:\Documents and Settings\Start Menu\Programs\AntiVirus System 2011.lnk
C:\Documents and Settings\Start Menu\Programs\AntiVirus System 2011\Activate AntiVirus System 2011.lnk
C:\Documents and Settings\Start Menu\Programs\AntiVirus System 2011\AntiVirus System 2011.lnk
C:\Documents and Settings\Start Menu\Programs\AntiVirus System 2011\Help AntiVirus System 2011.lnk
C:\Documents and Settings\Start Menu\Programs\AntiVirus System 2011\How to Activate AntiVirus System 2011.lnk

For Windows Vista/Windows 7

C:\Users\YOUR USER NAME\AppData\Local\Temp\\ae0965a7157cd.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\alerfa.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\alerfa2.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\altedf.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\backd-efq.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\brdss.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\cocksucker.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\cosock.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\cowceb.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\cunifuc.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\d20mes.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\dc_3.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\dd10x10.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\ddoll3342.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\destroyer.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\dffuck.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\dgxdro.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\fadz43.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\fe.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\format.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\g_dx234.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\gedx_ae09.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\ggwwef9752.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\gpupz2a.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\hardwh.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\hhbboll_2.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\hiphop.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\htfad4.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\hvipws9.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\jdhellwo3.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\jkfuckfu.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\jofcdks.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\kn.a.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\kock.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\lols.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\lorsk.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\ploper.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\poertd.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\ppddfcfux.exxe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\protector2.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\pswwg3c.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\puzpup.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\qwedvor.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\r0life.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\rator.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\rtfme.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\safe.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\snowif.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\sycre.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\timem.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\w32-reno-c.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\w32rim_mem.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\warsddd_w.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\wefgetn_00.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\wined.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\winifi.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\wqefqw7e.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\wrcud12.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\wrfwe_di.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\_2.tmp
C:\Users\YOUR USER NAME\AppData\Local\Temp\\2010yo.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\ae0965a7157cd.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\al3erfa3.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\[random].exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\ae0965a7157cd.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\winlogoff.exe
C:\Users\YOUR USER NAME\AppData\Local\Temp\\wrfwe_di.exe
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\AntiVirus_System_2011.exe
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\IcoActivate.ico
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\IcoHelp.ico
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\IcoUninstall.ico
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\securityhelper.exe
C:\Users\YOUR USER NAME\AppData\AntiVirus System 2011\securitymanager.exe
C:\Users\YOUR USER NAME\AppData\Microsoft\Internet Explorer\Quick Launch\AntiVirus System 2011.lnk
C:\Users\Desktop\AntiVirus System 2011.lnk

Once you have successfully deleted these traces, AntiVirus System 2011 should no longer be running in your machine and now you should run a complete virus scan for the system using Spyware Doctor with Antivirus. This will let you know whether you have been able to remove all the traces of AntiVirus System 2011 successfully and also whether there is any other threat still available in the system.

AntiVirus System 2011 Registry Removal Procedures

It is important to make sure that you have deleted all the infected files from the registry too. These are the registry values that you might need to remove:

KEY_CURRENT_USER\Software\AntiVirus System 2011
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "2kowmeuswvw3"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AntiVirus System 2011"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Security Manager"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011
HKEY_CURRENT_USER\Software\AntiVirus System 2011
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | pbavwturwm4e = “%AppData%\AntiVirus System 2011\securityhelper.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | AntiVirus Studio 2010 = “”%AppData%\AntiVirus System 2011\AntiVirus_System_2011.exe” /STARTUP”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | Security Manager = “%AppData%\AntiVirus System 2011\securitycenter.exe”

Again we would like to emphasize on the fact that once you are done with the manual AntiVirus System 2011 removal procedure, you should run a COMPLETE virus scan of your pc with Spyware Doctor with Antivirus in order to make sure that the system is completely out of risk.

AntiVirus System 2011 Directories:

XP

  • C:\Documents and Settings\USER NAME\Application Data\ \AntiVirus System 2011\

Windows 7 / Windows Vista

  • C:\Users\Start Menu\Programs\AntiVirus System 2011\

Outside Resources:

http://answers.microsoft.com/en-us/windows/forum/windows_vista-security/anti-virus-system-2011-this-is-a-virus-on-my/1992ffac-5c74-4e98-b84b-3fe3d521e68d

http://www.bleepingcomputer.com/virus-removal/remove-antivirus-system-2011

Speak Your Mind

*

RemoveVirus.org cannot be held liable for any damages that may occur from using our community virus removal guides. Viruses cause damage and unless you know what you are doing you may loose your data. We strongly suggest you backup your data before you attempt to remove any virus. Each product or service is a trademark of their respective company. We do make a commission off of each product we recommend. This is how removevirus.org is able to keep writing our virus removal guides. All Free based antivirus scanners recommended on this site are limited. This means they may not be fully functional and limited in use. A free trial scan allows you to see if that security client can pick up the virus you are infected with.