In this guide i will teach you how you different methods of remove fake anti virus software that on rare occations gets installed on your PC
First let's take a look at what a fake anti virus software is.
What is a rogue anti virus?
It's basicly a program that looks like a AV program which is programmed to make you think your computer has a lot of viruses thereby hoping to scare you to buy an insanely overpriced license for a program that does nothing what so ever. The scan result the program present you with is fake and the likelyhood of your computer having that many viruses at once without you even noticing is less than zero.
How did i get this program?
The most common ways of getting rogue anti virus software is through suspicious websites that prompts you to download something, or just outright installs it in the background or as a piggyback from another download bundled into the instal pack.
How do i get rid of it?
I will here show you two methods on how to get rid of them as sometimes one of the methods may not work while the other does, it's very uncommon for both these methods to fail
Method 1
First thing you need to do is boot your computer up in safe mode, this can be done by pressing f8 rapidly when your computer is starting, you will then be presented with a menu from which you will pick safe mode with networking
Next open your web browser and go to www.malwarebytes.org and download the program. When it's done install it and run it by picking quick scan from the menu. If it finds something click remove when the scan is done.
Reboot your computer and you should be good, just run malwarebytes once more just to be sure everything is gone.
Now if malwarebytes still haven't detected the rogue AV yet you will have to remove it manually which we will do in method number 2
Method 2
Like in the first method you will have to boot your computer in safe mode.
When your computer has started and you're logged in locate regedit
if you're running windows 8 open the "app menu", press the tile key and type regedit
If you're running windows 7 open your start menu and type regedit into the open text window
If you're on windows xp click start>RUN then type regedit.
WARNING: Do not mess around with values in regedit if you don't know what they're for. Editing certain values can cause severe damage to your computer or in worst case render it useless.
Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
Check for the value called Shell. If this is ANYTHING other than explorer.exe, right click it, pick edit and type in explorer.exe then OK.
Now we have prevented the fake AV from starting up when you boot your computer outside safe mode. Now we're going to remove the rest of it.
Usually these kinds of software hide in the appdata (Windows xp), Appdata/roaming(Windows 7-8) or in program files. It usually have the same name as the software and can also probably be located by opening the properties menu of the executable on your desktop.
When you find the folder mark it and delete it.
Normally malwarebytes should pick up on the software in 24-48 hours after it's detected and should be coded into their database, download malwarebytes, make sure the database version is up to date and run a scan.
Now i want to end this tutorial by telling youa few things
1) Under NO circumstances should you buy a license for these kinds of softwares, it will only give the criminals who released the software your credit card information.
2) In some poorly coded rogue anti virus softwares you can find the activation code in clear text by dragging the executable into a text editing program like notepad. This however is uncommon these days, but in a few instances it might actually work.
3) Very often you can find an activation code by doing a google search for that rogue AV's activation code.
4) These regedit values might also be edited by viruses http://www.symantec.com/connect/articles/most-common-registry-key-check-while-dealing-virus-issue
I would strongly urge you to refrain from tampering with them unless you know what they do. Personally i only know a handfull of them
Hope this guide was helpfull. If you have further questions. feel free to reply to this thread
I might edit in information i forgot to put in it
xit
First let's take a look at what a fake anti virus software is.
What is a rogue anti virus?
It's basicly a program that looks like a AV program which is programmed to make you think your computer has a lot of viruses thereby hoping to scare you to buy an insanely overpriced license for a program that does nothing what so ever. The scan result the program present you with is fake and the likelyhood of your computer having that many viruses at once without you even noticing is less than zero.
How did i get this program?
The most common ways of getting rogue anti virus software is through suspicious websites that prompts you to download something, or just outright installs it in the background or as a piggyback from another download bundled into the instal pack.
How do i get rid of it?
I will here show you two methods on how to get rid of them as sometimes one of the methods may not work while the other does, it's very uncommon for both these methods to fail
Method 1
First thing you need to do is boot your computer up in safe mode, this can be done by pressing f8 rapidly when your computer is starting, you will then be presented with a menu from which you will pick safe mode with networking
Next open your web browser and go to www.malwarebytes.org and download the program. When it's done install it and run it by picking quick scan from the menu. If it finds something click remove when the scan is done.
Reboot your computer and you should be good, just run malwarebytes once more just to be sure everything is gone.
Now if malwarebytes still haven't detected the rogue AV yet you will have to remove it manually which we will do in method number 2
Method 2
Like in the first method you will have to boot your computer in safe mode.
When your computer has started and you're logged in locate regedit
if you're running windows 8 open the "app menu", press the tile key and type regedit
If you're running windows 7 open your start menu and type regedit into the open text window
If you're on windows xp click start>RUN then type regedit.
WARNING: Do not mess around with values in regedit if you don't know what they're for. Editing certain values can cause severe damage to your computer or in worst case render it useless.
Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
Check for the value called Shell. If this is ANYTHING other than explorer.exe, right click it, pick edit and type in explorer.exe then OK.
Now we have prevented the fake AV from starting up when you boot your computer outside safe mode. Now we're going to remove the rest of it.
Usually these kinds of software hide in the appdata (Windows xp), Appdata/roaming(Windows 7-8) or in program files. It usually have the same name as the software and can also probably be located by opening the properties menu of the executable on your desktop.
When you find the folder mark it and delete it.
Normally malwarebytes should pick up on the software in 24-48 hours after it's detected and should be coded into their database, download malwarebytes, make sure the database version is up to date and run a scan.
Now i want to end this tutorial by telling youa few things
1) Under NO circumstances should you buy a license for these kinds of softwares, it will only give the criminals who released the software your credit card information.
2) In some poorly coded rogue anti virus softwares you can find the activation code in clear text by dragging the executable into a text editing program like notepad. This however is uncommon these days, but in a few instances it might actually work.
3) Very often you can find an activation code by doing a google search for that rogue AV's activation code.
4) These regedit values might also be edited by viruses http://www.symantec.com/connect/articles/most-common-registry-key-check-while-dealing-virus-issue
I would strongly urge you to refrain from tampering with them unless you know what they do. Personally i only know a handfull of them
Hope this guide was helpfull. If you have further questions. feel free to reply to this thread
I might edit in information i forgot to put in it
xit
Last edited:





