• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

My AntiSpyware

Free antispyware software, Online Scanners, Instructions on how to remove spyware and malware.

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools
Home › Rogue Anti Spyware › Tutorials - HowTo › How to remove Security Antivirus (Removal guide)

How to remove Security Antivirus (Removal guide)

Myantispyware team February 10, 2010     3 Comments    

Security Antivirus is a new rogue security program, also known as rogue antispyware application. The rogue from the same family of malware as Live PC Care. Security Antivirus is installed through the use of trojans that come from fake online malware scanners.

When the trojan is installed, it will download and install Security Antivirus onto your computer and register it in the Windows registry to run automatically when Windows loads. The same trojan will also drop several files with random names in %UserProfile%\Recent folder (ANTIGEN.drv, ANTIGEN.exe, cid.dll, CLSV.drv, DBOLE.sys, ddv.dll, ddv.sys, energy.tmp, FS.drv, PE.exe, PE.sys, runddlkey.dll, std.exe, tjd.drv). All of these files can`t harm your computer, but Security Antivirus will label them as serious computer infections.

Once running, the rogue will simulate a system scan and report above files as dangerous infections that will not be removed unless you first purchase it. Of course, the scan results is fake, because Security Antivirus is unable to detect or remove any infections. So you can safely ignore all that the program displays you.

What is more, while Security Antivirus is running, it will flood your computer with warnings, fake security alert and notifications from Windows task bar. Some of the alerts:

System alert!
malicious applications, which may contains Trojans, were found
on your computer and are to be removed immediately. Click
here to remove these potentially harmful items using Security Antivirus.

System alert!
Potentially harmful programs have been detected in your
system and need to be dealt with immediately. Click here to
remove them using Security Antivirus.

System alert!
Security Antivirus has detected potentially harmful software in
your system. It is strongly recommended that you register
Security Antivirus to remove all found threats immediately.

However, all of these alerts and warnings are fake and like scan false results should be ignored!

Last but not least, Security Antivirus may block Task Manager and legitimate antivirus and antispyware programs (Kaspersky Antivirus, DrWeb, AdAware, McAfee, Norton AV, etc). Also the rogue will add several lines into HOSTS file so that when you open Google, Yahoo or Bing, you will be redirected to a malicious website.

As you can see, Security Antivirus is a scam which designed with one purpose to scare you into purchasing so-called “full” version of the program. Most important do not purchase it! Please follow the guidelines below to remove Security Antivirus and any associated malware from your computer for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\Run: [Security Antivirus] “C:\Documents and Settings\All Users\Application Data\27a1f\SAc9a.exe” /s /d

More screen shoots of Security Antivirus



Use the following instructions to remove Security Antivirus (Uninstall instructions)

Step 1. Remove Security Antivirus and any associated malware.

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for Security Antivirus infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.


Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected for start Security Antivirus removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Step 2. Reset HOSTS file

Run Malwarebytes Anti-malware. Open Tools tab. Under FileASSASSIN label click to Run Tool button. In the open window navigate to C->Windows->System32->Drivers->etc and select HOSTS file. Click Open button. Click YES to confirm. Close Malwarebytes Anti-malware.

Click Start, Run. Type notepad and press Enter. Notepad opens. Copy all the text below into Notepad.

127.0.0.1 localhost

Save this as HOSTS to your C->Windows->System32->Drivers->etc. (Remember to select Save as file type: All files in Notepad). Close Notepad.

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Security Antivirus creates the following files and folders

%UserProfile%\Application Data\Security Antivirus
C:\Documents and Settings\All Users\Application Data\SAVSys
C:\Documents and Settings\All Users\Application Data\27a1f\SAc9a.exe
%UserProfile%\Desktop\Security Antivirus.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Antivirus.lnk
%UserProfile%\Start Menu\Security Antivirus.lnk
%UserProfile%\Start Menu\Programs\Security Antivirus.lnk

Security Antivirus creates the following registry keys and values

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Security Antivirus

Rogue Anti Spyware Tutorials - HowTo

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

3 Comments

  1. karen kearney
    ― February 15, 2010 - 6:16 pm  Reply

    Tried your advice to rid computer of Security Antivirus but it keeps reappearing everytime i reboot after running Malwarebytes.
    Any suggestions???

  2. Patrik
    ― February 16, 2010 - 7:40 am  Reply

    Karen, probably your PC also infected with a trojan that reinstalls it. Ask for help in our Spyware removal forum.

  3. belal
    ― February 25, 2010 - 11:44 am  Reply

    thanks

Leave a Reply Cancel reply




New Guides

Samsung Mobile Promo Draw Scam Email
The Samsung Mobile Promo Draw Scam: Don’t Let Greed Blind You – Learn How to Avoid It!
Shaelan Xosha Factory Outlet Scam
Shaelan Factory Outlet: Reviews, Legitimacy, and Unveiling the Scam
Blowpush.com Click Allow Scam
Blowpush.com Virus Removal Guide
Joelact.com website
Joelact.com Review: Is Joelact a Legitimate Store or a Scam?
June Cash 2023 rewardsgiantusa
June Cash 2023 (Junecash2023.com) Review: Can You Really Earn $750 Quickly?

Follow Us

Search

Useful Guides

adwcleaner
AdwCleaner – Review, How to use, Comments
How to reset Google Chrome settings to default
remove android virus
How to remove virus from Android phone
How to reset Mozilla Firefox (Updated Apr. 2018)
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]

Recent Posts

How to remove SecurePcAv (Uninstall instructions)
How to remove Advanced Defender (Uninstall instructions)
How to remove Paladin Antivirus (Uninstall instructions)
How to remove SafePcAv (Uninstall instructions)
How to remove Your PC Protector (Uninstall instructions)

MYANTISPYWARE.COM

  • About Us
  • Contact Us
  • Privacy Policy

NEED A HELP ?

If you're seeing unwanted pop-ups or ads in your web-browser, you might have an adware installed on your computer. Use the following guide to stop pop-up ads and remove malicious software. Or ask for help here.

Links

  • Downloads
  • Instructions
  • Questions and Answers
  • Free Malware Removal Tools
Copyright © 2004 - 2023 MASW - Myantispyware.com.