Threat Database Malware Avc2011.exe

Avc2011.exe

By Domesticus in Malware

Avc2011.exe is a file that you will only find on your computer if it is infected with the rogue anti-virus application Antivirus Clean 2011. Avc2011.exe is the malware program itself; it is Antivirus Clean 2011's executable file. Therefore, Avc2011.exe is responsible for some of the worst, most disruptive symptoms of an infection of Antivirus Clean 2011.

Where You will Find Avc2011.exe on an Infected PC?

Avc2011.exe will be located in the Program Files folder, where Avc2011.exe will be organized with the other files for Antivirus Clean 2011, in order to make it appear that Antivirus Clean 2011 is a real program. Avc2011.exe is dropped in this particular location by the Trojan that installs Antivirus Clean 2011.

The malware will also make changes to the Registry that reference Avc2011.exe. One of these changes is made in order to tell Windows to run Avc2011.exe every time the system starts up, by pointing to the location of Avc2011.exe in the Program Files folder. The Registry key is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AntivirusClean" = 'C:\Program Files\Antivirus Clean 2011\avc2011.exe'.

While Antivirus Clean 2011 is running, there will be an entry in the Registry that says HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache "avc2011.exe". There has been a lot of confusion about what is going on with this Registry key; so in order to clear things up, it is important to understand that this Registry key is not created by Antivirus Clean 2011 or avc2011.exe. HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache is where Windows keeps a record of the programs that are currently running, in real time. So, Windows (or to be more technical, Explorer) creates this Registry key and records the value of "avc2011.exe" within it. The malware does not, in itself, create this change to the Registry, and this particular change is harmless.

One of the problems with Antivirus Clean 2011 is that Antivirus Clean 201 runs when Windows starts, and then Antivirus Clean 2011 prevents you from removing Antivirus Clean 2011's files, including avc2011.exe. Therefore, you probably will not be able to remove avc2011.exe when Windows is running in its normal mode. However, with proper anti-virus software or experienced technical support, you can get rid of avc2011.exe and Avc2011.exe's negative effects on your PC.

File System Details

Avc2011.exe may create the following file(s):
# File Name Detections
1. %Program Files%\Antivirus Clean 2011\avsetup.exe
2. %Program Files%\Antivirus Clean 2011\avservice.exe
3. %Program Files%\Antivirus Clean 2011\avc2011.exe

Trending

Most Viewed

Loading...