Avast Doesn't Block "Antivirus 2011"

Unfortunately, Avast has let the rootkit called “Antivirus 2011” into several computers I service. The executable shows up as av.exe but it is tied to a rootkit, so removing av.exe only temporarily stops the problem. It comes back when you reboot. I’m surprised that Avast didn’t catch it.

The best solution is to purge all temp files in the user folders and in the temp directories, as well as the prefetch directory, then run a good rootkit eliminator such as ComboFix in order to remove everything. It will take about an hour to remove files, scan, and rescan to be sure everything’s gone.

Hi davidkaye, welcome to the forum :slight_smile:

Unfortunately, every AV companies are playing catch up, so things will be missed…I have seen sites that spit out new versions of system tool type infections daily, and there are ones that are updated hourly…

The best you could do is submit the files, and if possible, the locations of where they came from.
I would think the rootkits would be most useful to avast, but all of the files would be good to send.

Scott