AnVi Adware Removal Instructions
The Emsisoft malware research team has discoverd a new outbreak of the AnVi (Antivirus) adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.AnVi.
AnVi (Antivirus) is a rogue security program. This is a new variant from Defense Center, Protection Center, Data Protection, Digital Protection, Your Protection, User Protection, Dr. Guard , and PaladinAntivirus. This rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.
Create new files:
- %ProgramFiles%\AnVi\about.ico
- %ProgramFiles%\AnVi\help.ico
- %ProgramFiles%\AnVi\buy.ico
- %ProgramFiles%\AnVi\avtext.dll
- %ProgramFiles%\AnVi\avt.db
- %ProgramFiles%\AnVi\settings.ico
- %ProgramFiles%\AnVi\avt.exe
- %ProgramFiles%\AnVi\update.ico
- %ProgramFiles%\AnVi\activate.ico
- %ProgramFiles%\AnVi\scan.ico
- %ProgramFiles%\AnVi\avthook.dll
- %ProgramFiles%\AnVi\Uninstall.exe
- %UserProfile%\Desktop\Antivirus.lnk
- %UserProfile%\Desktop\Antivirus Support.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Scan.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Settings.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Antivirus.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Antivirus Support.lnk
- %UserProfile%\Start Menu\Programs\AnVi\About.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Update.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Activate.lnk
- %UserProfile%\Start Menu\Programs\AnVi\Buy.lnk
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\AnVi
- HKEY_LOCAL_MACHINE\software\Classes\*\ShellEx\ContextMenuHandlers\SimpleShlExt
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32
- HKEY_LOCAL_MACHINE\software\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “Antivirus”
Screenshots:
How to remove the infection of AnVi/Antivirus (Adware.Win32.AnVi)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.






















