• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Antivirus Scan virus (Uninstall instructions)

Myantispyware team December 18, 2010    

Antivirus Scan is a malicious program from the same family of malware as Antivirus Action and Antivirus IS. The software pretends to be a legitimate antivirus but, in reality, it is a totally scam. Antivirus Scan will hijack browsers, block legitimate Windows applications, display various fake security alerts and detect numerous false infections in order to trick you into purchasing its full version. Remember, the program is unable to detect and remove any infections, so do not pay for the bogus software, simply ignore all that it will display you.

Like other fake security software, Antivirus Scan is distributed with the help of trojans or other malicious software. Moreover, the authors of of the fake program may also distribute it on social networks (Twitter, My Space, Facebook, etc) and spam emails. Please be careful when opening attachments and downloading files or otherwise you can end up with a rogue program on your computer. Remember that the rogue is a highly dangerous application and you need remove Antivirus Scan as soon as possible!

During installation, the rogue will be configured to start automatically when Windows loads. Once Antivirus Scan is started, it will imitate a system scan and detect a lot of various infections that will not be fixed unless you first purchase the program. Important to know, all of these reported infections are fake and don’t actually exist on your computer! So you can safely ignore the scan results that Antivirus Scan gives you.

While Antivirus Scan is running, it will flood your computer with warnings and fake security alerts. Some of the alerts:

Windows Security alert
Windows reports that computer is infected. Antivirus software
helps to protect your computer against viruses and other
security threats. Click here for the scan your computer. Your
system might be at risk now.

INFILTRATION ALERT
Your computer is being attacked by a Internet
Virus. It could be a password stealing attack, a
trojan – dropper or similar.

Moreover, Antivirus Scan will hijack Internet Explorer so that it will randomly show a warning page which states:

Internet Explorer Warning – visiting this web site may harm your computer!
Most likely causes:
The website contains exploits that can launch a malicious code on your computer
Suspicious network activity detected
There might be an active spyware running on your computer

Of course, like false scan results above, all of these alerts are just a fake. All of them are created in order to convince you that you must purchase the full version of Antivirus Scan and, thus, fix the entire system. So, you can safely ignore the fake warnings and alerts.

As you can see, all Antivirus Scan does is fake and you should stay away from the malicious application! If your PC has been infected with the rogue, then ignore all it gives you and follow the removal instructions below in order to remove Antivirus Scan and any associated malware from your computer for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\Run: [{RANDOM}] %Temp%\{RANDOM}\{RANDOM}.exe

Automatic removal instructions for Antivirus Scan

Step 1. Reboot your computer in Safe mode with networking

Restart your computer.

After hearing your computer beep once during startup, start pressing the F8 key on your keyboard. On a computer that is configured for booting to multiple operating systems, you can press the F8 key when the Boot Menu appears.

Instead of Windows loading as normal, Windows Advanced Options menu appears similar to the one below.

safe-mode-how-to
Windows Advanced Options menu

When the Windows Advanced Options menu appears, select Safe mode with networking and then press ENTER.

Step 2. Reset Internet Explorer Proxy options

Run Internet Explorer, Click Tools -> Internet Options as as shown in the screen below.


Internet Explorer – Tools menu

You will see window similar to the one below.


Internet Explorer – Internet options

Select Connections Tab and click to Lan Settings button. You will see an image similar as shown below.


Internet Explorer – Lan settings

Uncheck “Use a proxy server” box. Click OK to close Lan Settings and Click OK to close Internet Explorer settings.

Step 3. Stop Antivirus Scan from running

Download HijackThis from here. Run it and click Scan button. Look for lines that looks like:

O4 – HKCU\..\Run: [{RANDOM}] {PATH}\Temp\{RANDOM}.exe

Example:

O4 – HKLM\..\Run: [audpdogk] c:\docume~1\user\locals~1\temp\akotrowvc\bcgcihiagnz.exe
O4 – HKCU\..\Run: [audpdogk] C:\Users\User\AppData\Local\akotrowvc\bcgcihiagnz.exe

Note: list of infected items may be different. If you unsure, then check it in Google. Skip this step, if you does not find any malicious lines.

Place a checkmark against each of them. Once you have selected all entries, close all running programs then click once on the “fix checked” button. Close HijackThis.

Step 4. Remove Antivirus Scan associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

Antivirus Scan remover
Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove Antivirus Scan. MalwareBytes Anti-malware will now remove all of associated Antivirus Scan files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Antivirus Scan removal notes

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Note 3: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

Antivirus Scan creates the following files and folders

%Temp%\{RANDOM}\
%Temp%\{RANDOM}\{RANDOM}.exe

Antivirus Scan creates the following registry keys and values

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter | “Enabled” = “0”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | “ProxyOverride” = “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | “ProxyServer” = “http=127.0.0.1:30215”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings | “ProxyEnable” = “1”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | {RANDOM}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | {RANDOM}

Malware removal Rogue Anti Spyware

 Previous Post

How to remove Defragmenter virus

Next Post 

How to remove Disk Repair virus

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

96 Comments

  1. Tony
    ― January 6, 2011 - 8:03 am  Reply

    Omg I love u guyss I couldn’t get my essay printed out cus it was affected. I was freaking out but thanks to you guys I was able to get an A on it thanks. Ur a lifesavor

  2. Jemand
    ― January 7, 2011 - 8:07 pm  Reply

    You saved my baby!!! Thank you sooo much.. This is fucking awesome!! 🙂

  3. Patrik
    ― January 8, 2011 - 8:15 am  Reply

    Peter, you can leave Malwarebytes. Its a good malware and spyware remover.

  4. Patrik
    ― January 8, 2011 - 8:18 am  Reply

    joane, if you unsure, then best way is start a new topic in our Spyware removal forum. I will help you.

  5. Patrik
    ― January 8, 2011 - 8:20 am  Reply

    kirstin, then ask for help in our Spyware removal forum. Link in my previous comment.

  6. Patrik (Myantispyware admin)
    ― January 8, 2011 - 8:23 am  Reply

    Linda, you need to reset proxy settings of Internet Explorer. Repeat the step 2 above.

  7. brijesh
    ― January 8, 2011 - 10:19 am  Reply

    thanks a lot…bro…..thank u very much…..

  8. Rav
    ― January 8, 2011 - 2:39 pm  Reply

    This worked of course, but the goddamned McAfee Antivirus didnt even find or stop the antivirus scan virus, thats what pissed me off. Im going to ask for my money back!

  9. Saurabh
    ― January 9, 2011 - 4:11 pm  Reply

    Thanks a lot for this blog… I was able to fix my computer by following the steps…

  10. ottoman
    ― January 9, 2011 - 11:46 pm  Reply

    Men thank you so much!
    no problems at all after following this post!
    for real just awesome!

  11. j
    ― January 10, 2011 - 2:01 am  Reply

    Thank you so much….this worked fantastic

  12. Bob Rivera
    ― January 10, 2011 - 4:11 pm  Reply

    Spot on. Thanks a billion!

  13. Bradley
    ― January 10, 2011 - 7:33 pm  Reply

    This worked for me and was very easy, but now my problem is, IE will not connect when i reestablish the proxy. Is there anything I can do to return those settings to normal, and have IE bring up internet?

  14. Mandy
    ― January 10, 2011 - 9:07 pm  Reply

    Help!!
    The Antivirus scan does not let me download the HiJack program and just closes it automatically! What can I do?? Thank you.

  15. Diamond
    ― January 10, 2011 - 10:43 pm  Reply

    It said i couldn’t install HijackThis is safe mode, so I went back to normal mode. Every time I uncheck “use a proxy sever” and try to download HijackThis, the malware puts it back to the proxy server, so I can’t access any web pages. I’ve been trying for over an hour. Please help!

  16. Patrik (Myantispyware admin)
    ― January 11, 2011 - 3:42 am  Reply

    Bradley, repeat the step 2 above.

  17. thomas
    ― January 12, 2011 - 2:59 pm  Reply

    way to rock guys

  18. Koi
    ― January 12, 2011 - 7:03 pm  Reply

    Hi I need to download malwareBytes but my Internet has been switch to emergency mode which I can’t click on tools to set the proxy help please

  19. shane
    ― January 13, 2011 - 11:30 am  Reply

    I found the file to delete with hijack this, but malware bytes wont find any infected objects. I downloaded the mbam-rules.exe update to my external hard drive, put it on my laptop and ran it. It still says its outdated and wont find any infected files. what should i do??

  20. Raina
    ― January 14, 2011 - 1:54 pm  Reply

    I am trying to fix this, but I can’t get my laptop into safe mode. F8 doesn’t work and I tried to go to run..misconfig…but the virus won’t let me go any farther.

  21. Selin
    ― January 14, 2011 - 5:02 pm  Reply

    It was amazing!!!! Briallint!!! Thank youuuuuu

  22. Nick
    ― January 14, 2011 - 7:01 pm  Reply

    I think I love you? No not really, but thank you so very much xD I keep coming back to this website-and it always helps!

  23. Sonia
    ― January 14, 2011 - 7:39 pm  Reply

    Thanks so much. This helped me heaps. I hate antivirus scan == well thanks once again! You’re the best!!

  24. hkump
    ― January 14, 2011 - 7:58 pm  Reply

    thank you soooooo much!!! i was trying to fix my computer for 6 hours and found this and got it fixed in 20 min!! thank you soo much i soo appreciate it!!!!

  25. Patrik (Myantispyware admin)
    ― January 14, 2011 - 10:41 pm  Reply

    Koi, what is your version of Windows ?

  26. Patrik (Myantispyware admin)
    ― January 14, 2011 - 10:43 pm  Reply

    shane, try update Malwarebytes once again and perform a fresh scan.

  27. Patrik (Myantispyware admin)
    ― January 14, 2011 - 10:51 pm  Reply

    Raina, try the following:
    Run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Click Advanced button to open Proxy settings. Copy and paste the following text into “Do not use proxy server for addresses beginning with:”

    go.trendmicro.com;www.myantispyware.com;www.malwarebytes.org;

    Click OK to save Proxy settings, then Click OK to close Lan Settings and Click OK to close Internet Explorer settings.

    Download HijackThis from here. Once Save dialog opens, you need first to rename hijackthis.exe to iexplore.exe

    Further click Save button to save it to desktop. If you are using the Firefox, then you need right click to the above link to open a Save dialog.

    Run HijackThis. Click Scan button. Select entries that looks like:

    R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:{RANDOM}
    O4 – HKCU\..\Run: [{RANDOM}] {PATH}\Temp\{RANDOM}.exe

    Example:

    R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:49512
    O4 – HKLM\..\Run: [audpdogk] c:\docume~1\user\locals~1\temp\akotrowvc\bcgcihiagnz.exe
    O4 – HKCU\..\Run: [audpdogk] C:\Users\User\AppData\Local\akotrowvc\bcgcihiagnz.exe

    Place a checkmark against each of them. Once you have selected all entries, close all running programs then click once on the “fix checked” button. Close HijackThis.
    Reboot your computer.
    Go to step 4 above.

  28. Koi
    ― January 15, 2011 - 8:50 am  Reply

    windows vista, shortly after I got antivirus scan, when I click the Internet it first ask me for permission to enter in isafemode.exe but Internet is blocked like u said. But after a few hours when I click on the Internet it’s in the safety mode and I couldn’t enter address

  29. Lele
    ― January 15, 2011 - 4:29 pm  Reply

    I was doing great until I got to the end of step 2; didn’t know whether to stay in safe mode or not!?! What do I do???

  30. Lele
    ― January 15, 2011 - 5:12 pm  Reply

    Everything’s AOK!!! Went back to step 2 and stayed in safe mode….. and everything worked this time!!! It removed the Antivirus Scan Virus!!!! Yayyyyyyy…. malwarebytes Anti-malware is awesome….. thanks guys!!!!!

« Previous 1 2 3 4 Next »

Leave a Reply to Nancy Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
How to reset Mozilla Firefox (Updated Apr. 2018)
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
ads by adware
How to remove Adware from Windows 10 (Virus removal guide)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]

Recent Guides

How to remove Defragmenter virus
How to remove HDD Tools virus
How to remove Smart HDD virus
How to remove Security Shield and SecurityShield
How to remove HDD Rescue (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.