How to Remove almost any Fake Antivirus Rogue Software from your computer

A Fake Antivirus (FakeAV) is any software that scares computer users with fake alert messages that their computer is infected. A Fake Antivirus program is also known as Rogue Antivirus, ScareWare or Ransomware and upon installed on your computer, it claims that malicious threats are found on your computer and you must buy the full version of the program to clean them. 

Fake Antivirus programs gets in your computer when you download and install free software from unknown internet websites. Please ignore all fake warning messages and DO NOT give any money to purchase the full version of them.

If you want to remove a Fake Antivirus program from your computer, proceed with the steps bellow:

bfbvsw42_thumb

How to remove (almost) any Fake Antivirus (FakeAV) software from your computer.

Step 1: Start your computer in “Safe Mode with Networking”

To do this,

1. Shut down your computer.

2. Start up your computer (Power On) and as your computer is booting up, press the "F8" key before the Windows logo appears.

3. Using your keyboard arrows, select the "Safe Mode with Networking" option and press "Enter".

safe-mode-with-networking_thumb1_thu[2]

Step 2. Terminate and clean malicious running processes and programs.

1. Download and save "RogueKiller" utility on your computer'* (e.g. your Desktop)

Notice*: Download version x86 or X64 according to your operating system's version. To find your operating system's version, "Right Click" on your computer icon, choose "Properties" and look at "System Type" section.

saa_thumb2_thumb_thumb_thumb_thumb1_

2. Double Click to run RogueKiller.

3. Let the prescan to complete (terminate malicious processes) and then press on "Scan" button to perform a full scan.

zus2b3u0

3. When the full scan is completed, press the "Delete" button to remove all malicious items found.

k12w4woi

Step 3. Prevent malicious programs from running at Windows Startup.

1. Download and run CCleaner.

2. At “CCleaner” main window, choose "Tools" on the left pane.

ccleaner-tools

3a. In "Tools" section, choose "Startup".

ccleaner-startup

3b. Choose the "Windows” tab and then select and delete all malicious programs running on Windows startup: *

Examples of malicious startup entries (CCleaner):

  • Yes  |  HKCU:RunOnce  |  C:\Program Files\Attentive Antivirus virus\X7gngpng.exe.”
  • Yes    |  HKCU:Run    | 4646.tmp   |   C:\TEMP\4646.tmp.exe”
  • Yes    |  HKCU:Run    | C:\ProgramData\Xgpsns33\Xgpsns33.exe

 

Additional Information*: Commonly Fake Antivirus folders/files are located (executed) at (from) the following locations on your computer:

Windows All:

  1. C:\Program Files\<Fake_Antivirus_Random_Name_Folder>\
  2. C:\Temp\
  3. C:\Windows\Temp\

Windows 8,7,Vista:

  1. C:\ProgramData\
  2. %AppData%C:\Users\<Your_USERNAME>\AppData\Roaming

Windows XP:

  1. C:\Documents and Settings\<Your_USERNAME>\Application Data\
  2. C:\Documents and Settings\All Users\Application Data\

 

Tip: Before deleting the malicious Startup entries, open Windows Explorer to find and delete manually the malicious folders and files from your computer. (e.g. RandomFolderName, RandomFileName.exe).

(sample screenshot1)

e24jjxfb_thumb1_thumb_thumb

(sample screenshot2)

sj40ebye

 

5. Close “CCleaner” & proceed to the next step.

 

Step 4: Clean Adware & Unwanted Browser Toolbars.

1. Download and save “AdwCleaner” utility to your desktop.

download-adwcleaner-home_thumb1_thum

2. Close all open programs and Double Click to open ”AdwCleaner” from your desktop.

3. Press “Scan”.

adwcleaner-scan_thumb1_thumb_thumb_t

4. When the scan is completed, press “Clean” to remove all the unwanted malicious entries.

adwcleaner-clean_thumb1_thumb_thumb_[2]

4. Press “OK” at “AdwCleaner – Information” and press “OK” again to restart your computer.

adwcleaner-information

5. When your computer restarts, close "AdwCleaner" information (readme) window and continue to the next step.

 

Step 5. Remove potentially unwanted programs (PUPs) with Junkware Removal Tool.

1. Download and run JRT – Junkware Removal Tool.

ooiklzrb_thumb3

2. Press any key to start scanning your computer with “JRT – Junkware Removal Tool”.

rbqt5vao_thumb1

3. Be patient until JRT scans and cleans your system.

e3folbue_thumb

4. Close JRT log file and and then reboot your computer.

nt3i1nap_thumb

 

Step 6. Clean your computer from remaining malicious threats.

Download and install one of the most reliable FREE anti malware programs today to clean your computer from remaining malicious threats. If you want to stay constantly protected from malware threats, existing and future ones, we recommend that you install Malwarebytes Anti-Malware PRO:

Malwarebytes™ Protection
Removes Spyware, Adware & Malware.
Start Your Free Download Now!

1. Run "Malwarebytes Anti-Malware" and allow the program to update to it's latest version and malicious database if needed.

2. When the "Malwarebytes Anti-Malware" main window appears on your screen, choose the "Perform quick scan" option and then press the "Scan" button and let the program scan your system for threats.

ahefjplu_thumb2_thumb_thumb_thumb

3. When the scanning is completed, press “OK” to close the information message and then press the "Show results" button to view and remove the malicious threats found.

juygdz2u_thumb2_thumb_thumb_thumb.

4. At the "Show Results" window check – using your mouse's left button- all the infected objects and then choose the "Remove Selected" option and let the program remove the selected threats.

54j5pumd_thumb2_thumb_thumb_thumb

5. When the removal of infected objects process is complete, "Restart your system to remove all active threats properly".

kh15degq_thumb2_thumb_thumb_thumb

6. Continue to the next step.

Step 6. Restart your computer & perform a full scan with your original antivirus program.

If this article was useful for you, please consider supporting us by making a donation. Even $1 can a make a huge difference for us in our effort to continue to help others while keeping this site free: