Home Malware Programs Rogue Anti-Virus Programs AVT.exe

AVT.exe

Posted: August 3, 2010

AVT.exe is a rogue security program which spreads via the Internet by using Trojans and fake online security websites. AVT.exe is installed on victim computers without the user's approval. It will secretly enter the system before modifying settings and registry entries to have itself run whenever Windows is operating. Once active, computer users may experience constant security alert pop-ups advertising AVT.exe. AVT.exe runs its own virus scan which detects false threats on the computer to mislead users into getting the licensed version of this useless program. AVT.exe poses a huge security threat to PC safety and should be terminated immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %commonprograms%\AnVi\about.lnk
    2 %commonprograms%\AnVi\activate.lnk
    3 %commonprograms%\AnVi\Antivirus support.lnk
    4 %commonprograms%\AnVi\Antivirus.lnk
    5 %commonprograms%\AnVi\buy.lnk
    6 %commonprograms%\AnVi\scan.lnk
    7 %commonprograms%\AnVi\settings.lnk
    8 %commonprograms%\AnVi\update.lnk
    9 %desktop%\Antivirus.lnk
    10 %programfiles\AnVi\about.ico
    11 %programfiles\AnVi\activate.ico
    12 %programfiles\AnVi\avt.db
    13 %programfiles\AnVi\avt.exe
    14 %programfiles\AnVi\avtext.dll
    15 %programfiles\AnVi\avthook.dll
    16 %programfiles\AnVi\buy.ico
    17 %programfiles\AnVi\help.ico
    18 %programfiles\AnVi\scan.ico
    19 %programfiles\AnVi\settings.ico
    20 %programfiles\AnVi\splash.mp3
    21 %programfiles\AnVi\uninstall.exe
    22 %programfiles\AnVi\update.ico
    23 %programfiles\AnVi\virus.mp3
    24 avt.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}hkcu\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus"hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5E2121EE-0300-11D4-8D3B-444553540000}"HKEY..\..\..\..{RegistryKeys}hkcr\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}

Additional Information on AVT.exe

  • The following messages's were detected:
    # Message
    1 Uncertified {antivirus name} antivirus software detected on your computer. You need to remove
    {antivirus name} software for correct operation of the Antivirus.
    Attention: If you don't remove {antivirus name} software, the performance of your computer will
    dramatically degrade.
    Press "OK" to remove the {antivirus name}
Loading...