Wednesday 23 November 2011

Remove AV Protection 2011 - Removal Guide

AV Protection is a rogue software from WinAVPro family who created Open Cloud Security, AV Security 2012 and many other rogue products in last few months. AV Protection 2011 installs itself silently in your computer and then bugs you for money. Forced Scans and fake infected reports are main weapons of AV Protection 2011. This software is usually bundled with Zero Access Rootkit. This rootkit actually protects AV Protection 2011 and any process which will try to scan it will get terminated automatically. This is why AV Protection 2011 removal is not that easy. Here is how this fake antivirus software makes its way inside your computer :

1. You download something from Internet thinking it as a useful utility. The download can be disguised to look like a real software.
2. Once you double click over the installer file, your computer will get infected with the rogue software.

AV Protection 2011 will make several copies of itself on your computer so that you can't get rid of it easily. The main goal of this software is dragging you into purchasing full version of AV Protection 2011. Since AV Protection 2011 is a fake software, It can't help you with anything. Buying a rogue software is same as throwing your money into drain. After buying rogue software, you'll get a key and after entering that key in rogue software, it will stop showing any infections!

Here is a screen shot of AV Protection 2011 doing a fake scan :


AV Protection 2011 will show you infection alerts like :

Security Warning
Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer.
Click here to clean your PC immediately.

Security Warning
There are critical system files on your computer that were modified by malicious software.
It may cause permanent data loss.
Click here to remove malicious software.

Don't care about any warnings shown while AV Protection 2011 is active on your computer. This software is generating all these fake alerts to motivate you to purchase full version of rogue software. This rogue software can't help you and removing this rogue software from your computer is the only way to restore your computer's normal functionality.

How To Remove AV Protection 2011

You can get rid of AV Protection 2011 can be removed easily If you follow right method. There are two ways to remove the rogue software from your computer :

A) Automatic Removal Method

As the name implies, you can remove AV Protection 2011 easily using a genuine anti-malware software. You just need to scan all files on your computer using a legitimate software and you can remove all the infections in like 10 minutes. Here is what you need to do :

1. Reboot your computer and press "F8" key on your keyboard repeateadly.
2. You'll see Windows Startup Menu, please select "Safe Mode With Networking" and press Enter.

3. When  your computer boots up, download Spyware Doctor by clicking the button below :


After downloading Spyware Doctor, install it in your computer and then update its virus database. After updating virus database, conduct a "Full Scan" of your computer. Spyware Doctor will automatically detect presence of AV Protection 2011 in your computer and once the scanning process is finished, click "Fix Checked" button to remove all threats from your computer.


B) Manual Removal Method

Manual Removal method is not recommended for most computer users as It can be really complicated to remove the rogue software manually. If you make any mistakes during removal or delete system files mistakenly, your computer may paralyze even further.

This is why we suggest that you follow manual removal steps with extreme caution. If you are unsure about which method is right for you, simply follow Automatic Removal method as there are no risks involved.


Follow these manual removal steps for AV Protection 2011 at your own risk :

1. First of all, reboot your computer in "Safe Mode with Networking" mode.
2. Now find and delete these files from your computer :

%AppData%\AV Protection 2011.lnk
%AppData%\ldr.ini
%AppData%\246DE\
%AppData%\246DE\ED59.46D
 %AppData%\<random>\
%StartMenu%\Programs\AV Protection 2011\
%StartMenu%\Programs\AV Protection 2011\AV Protection 2011.lnk
%ProgramFiles%\DED59\
%ProgramFiles%\DED59\lvvm.exe
%ProgramFiles%\LP\
%ProgramFiles%\LP\6AB2\
%ProgramFiles%\LP\6AB2\027.exe
%Temp%\dwme.exe
%System% \AV Protection 2011v121.exe

Please note that AV Protection 2011 may create different filename on your computer and we suggest that you don't remove any file based on your guesswork because It can be harmful for other program on your computer.

3. After removing infected files, now you need to remove compromised registry entries. Run registry editor by clicking on Start-->Run, type "regedit" and click OK button. Remove these registry entries :

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "<random>"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "<random>"

Please note that these removal methods are indicative and sometimes manual removal method may not work If a particular software changes its way of working. Automatic removal method is always an option for you If you are looking for complete removal of rogue software.

No comments:

Post a Comment