Free App to Remove a Plethora of FAKE Antivirus Software

Oct. 22nd, 2009 By Karl L. Gechlik

I hate, I repeat, I HATE fake antivirus programs with a fury! You know exactly what I am talking about. These are pieces of software that advertise their ability to protect and fix your machine, yet once they are installed, they take over your machine, disable your antivirus and hold your computer as a virtual hostage.

Here is an example of one of these roguee programs. It is called Antivirus 2008 and there is another called Antivirus 2009 that looks identical to it but with the different year. If you have never seen anything like this… Then good for you! You are doing a great job at security (or you are using a Mac or Nix’ box!)

remove fake antivirus

I’ve found a great free app that helps remove fake antivirus applications. It’s aptly called Remove Fake Antivirus. Check out the list of applications that it detects and removes. Each of these links will take you to the author’s blogspot which will tell you more about the threat.

  1. Cyber Security
  2. Alpha Antivirus
  3. Braviax
  4. Windows Police Pro
  5. Antivirus Pro 2010
  6. PC Antispyware 2010
  7. FraudTool.MalwareProtector.d
  8. Winshield2009.com
  9. Green AV
  10. Windows Protection Suite
  11. Total Security 2009
  12. Windows System Suite
  13. Antivirus BEST
  14. System Security
  15. Personal Antivirus
  16. System Security 2009
  17. Malware Doctor
  18. Antivirus System Pro
  19. WinPC Defender
  20. Anti-Virus-1
  21. Spyware Guard 2008
  22. System Guard 2009
  23. Antivirus 2009
  24. Antivirus 2010
  25. Antivirus Pro 2009
  26. Antivirus 360 and
  27. MS Antispyware 2009

OK so I am assuming that you have one of these infections and you want to use Remove Fake Antivirus to fix your machine up. Let’s see how we can do that. First we start by downloading the application from here. That is a direct link because the download page is polluted with Google ads and confuses users as to what to download. The author’s site can be found here.

Run the application and you will first see its welcome screen listing the nastiness it can deal with and then you will see this screen:

Remove1

Go ahead and hit ‘Yes’ and it will start scanning  your local machine for the fake applications listed above.

You can go ahead and click Show details to get a closer look as to what is going on:remove fake antivirus

As it goes through each possible infection you will see it listed on the console. Don’t be alarmed, this does not mean that your PC has the infections.

remove3

Up until now my only solution was Malware Bytes demo version. But now it looks like Remove Fake Antivirus 1.35 is going to be my go-to program. It took 6 minutes to run the full scan. I had originally located this application while battling Antivirus 2009 yesterday. And it worked like a charm!

Once the application has completed you will see this screen:

fake antivirus removal

Click Yes and all the files that Remove Fake Antivirus could not remove because the files were in use will then be kicked to the curb. The author’s site also serves up suggestions for how to deal with and prevent these types of infections. Among them is to set the UAC prompts to the highest levels – I guess I should not have mine disabled, eh?

Remove Fake AntivirusDownload

For more information about fake antivirus software, read Ryan’s post “Detect Fake Antivirus software & Spyware Removal programs“. How do you deal with rouge or fake antivirus or spyware applications? Do you have policies that keep this type of stuff out of your corporate environments? What do you do or use? Please share with us in the comments so we can learn from each other!

(By) Karl Gechlik is a superhero of the IT industry. His days are spent monitoring and maintaining systems on Wall Street. He helps people with their technical issues for free over at AskTheAdmin.com.

Enjoyed the article? Subscribe to MakeUseOf to get daily updates on new cool websites and programs in your email for free. You'll also get free printable cheat sheets to your favorite programs

Your Email:

Add MakeUseOf to:



20 Comments Add Comment
2009-10-22 07:47:31
Altzan

Great Timing! I just got infected by Win Police Pro and I need to kill it. Gonna try this when I get home.

2009-10-22 09:53:49
John D
Subscribed to comments via email

I always found Malwarebytes to be 100% at removing such things, but it’s always good to have another option!

2009-10-22 10:28:16
Subscribed to comments via email

You should also note, removing them can destroy vital system files, so be careful when doing so.

2009-10-22 11:49:18

Fake Antivirus is really a headache. I am glad this tool can so easily take care of that.

2009-10-22 12:23:40
Hiqutipie

I know Symantec has a list of the Fake Software & Wikipedia has a partial list but where is the Full List posted for everyone and why haven’t servers removed them…

There are a ton of popups & advertisements that advise you to test your system with their software & that you can only repair the system by purchasing their software to fix all the problems they found…Its all false advertising & deceptive business practices which should be Flagged & Removed by Servers as well as made public…

The Power users know how to avoid dangerous software but the average public user will be at High Risk until the net does a better job of policing itself…MacAfee siteadvisor & WOT should be out in front of this topic…

2009-10-23 01:18:58
Subscribed to comments via email

Just one problem…http://twitpic.com/mkfgs

2009-10-23 08:35:54

Catester what program is issuing the warning? It is listing the application as a numeric executable – an application that is NOT on my system.

2009-10-29 03:14:46

It also tries to change your default search provider. I have Google blocking such changes, which is why I know the attempt was made. I did not allow the change so I can not say what provider it tries to switch you to.

(Comments wont nest below this level)
2009-10-23 06:19:25
Gregor

Thanks Karl,

exactly what i need when “that friend with constant computer problems” calls me explaining his antivirus is telling him he is infected. ;D

2009-10-23 11:56:55
Subscribed to comments via email

Karl, This is VIPRE Antivirus + Antispyware, version 3.`.2837. My defs are up to date.

I receive that message when I try to download the file from the site you linked to. I did not override the warning and download the program. Please contact me privately if you want more specifics; I’m happy to help.

2009-10-23 22:21:06
Subscribed to comments via email

Why we need another software when we are having AVs like KAV ?

2009-10-23 23:18:33
Altzan

I tried running this and got an error: So-and-so illegal operation, Ignore or Abort.
Can’t get it to work on either XP or 2000.

2009-10-23 23:57:46
Altzan

GREAT. I ran this, and now I am getting a BSOD every time I boot the computer… 0×0000001E win32k.sys
It’s totally unusable now.

2009-10-24 01:52:56
Subscribed to comments via email

LOL! Go linux! xD

(Comments wont nest below this level)
2009-10-23 23:44:17
Subscribed to comments via email

And why you would download fake antivirus? It’s just stupid. Really the people download software from banners?

2009-10-24 05:37:18
Subscribed to comments via email

See, I told you it would cause system damage. To repair it fully, you’ll need the disk. Then run sfc /scannow . To prevent this happening in the future, make sure you start it in safe mode.

2009-10-24 11:44:36
Altzan

Unfortunately, this laptop of mine doesn’t have a CD drive.

2009-11-13 15:26:11

you can download it from Microsoft’s website.

http://neosmart.net/blog/2008/windows-vista-recovery-disc-download/

(Comments wont nest below this level)
2009-11-21 00:13:42
1fastbullet

Great find.
My neighbor is the type that, if it’s free, it gets put on his machine. He keeps my rent paid for me, as I’m forever cleaning up the garbage he downloads.

One Question: has anyone attempted using this from an USB flash drive? Mwn, this would be great to use from one!!

Reply

You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.