Monday, March 24, 2014

Remove Fake Antivirus 1.97Remove Fake Antivirus 1.97

Remove Fake Antivirus is used to remove the most popular fake antiviruses. What is fake antivirus? This is a type of virus/malwares which disguises itself to be an antivirus. It infects your computer when you accidentally click a link in a website which will download the malware into your computer and run automatically when your windows boot. It scan the infected computer and produces fake alert warnings. It convinces you that your computer is in danger and urge you to purchase a useless copy of the fake antivirus. These fake antiviruses must be removed immediately.

Remove Fake Antivirus 1.97 is used to remove:
  1. Security Cleaner Pro
  2. Sinergia Cleaner
  3. Titan Antivirus 2013
  4. Antivirus Security Pro
  5. Attentive Antivirus
  6. Antivirus System File
  7. iON Internet Security
  8. Smart Security
  9. PC Defender Plus
  10. Windows Proprietary Advisor
  11. Windows Smart Warden
  12. Home Malware Cleaner
  13. Strong Malware Defender
  14. AV Security 2012
  15. Data Recovery
  16. Wolfram Antivirus
  17. Security Protection
  18. Windows Antivirus 2011
  19. Mega Antivirus 2012
  20. AVG Antivirus 2011
  21. PC Security 2011
  22. ThinkPoint
  23. ThinkSmart
  24. Antivirus 8
  25. Security Tool
  26. My Security Shield
  27. Antivirus 7
  28. Antivirus GT
  29. Defense Center
  30. Protection Center
  31. Sysinternals Antivirus
  32. Security Master AV
  33. CleanUp Antivirus
  34. Security Toolbar
  35. Digital Protection
  36. XP Smart Security 2010
  37. Antivirus Suite
  38. Vista Security Tool 2010
  39. Total XP Security
  40. Security Central
  41. Security Antivirus
  42. Total PC Defender 2010
  43. Vista Antivirus Pro 2010
  44. Your PC Protector
  45. Vista Internet Security 2010
  46. XP Guardian
  47. Vista Guardian 2010
  48. Antivirus Soft
  49. XP Internet Security 2010
  50. Antivir 2010
  51. Live PC Care
  52. Malware Defense
  53. Internet Security 2010
  54. Desktop Defender 2010
  55. Antivirus Live
  56. Personal Security
  57. Cyber Security
  58. Alpha Antivirus
  59. Windows Enterprise Suite
  60. Security Center
  61. Control Center
  62. Braviax
  63. Windows Police Pro
  64. Antivirus Pro 2010
  65. PC Antispyware 2010
  66. FraudTool.MalwareProtector.d
  68. Green AV
  69. Windows Protection Suite
  70. Total Security 2009
  71. Windows System Suite
  72. Antivirus BEST
  73. System Security
  74. Personal Antivirus
  75. System Security 2009
  76. Malware Doctor
  77. Antivirus System Pro
  78. WinPC Defender
  79. Anti-Virus-1
  80. Spyware Guard 2008
  81. System Guard 2009
  82. Antivirus 2009
  83. Antivirus 2010
  84. Antivirus Pro 2009
  85. Antivirus 360
  86. MS Antispyware 2009
  87. IGuardPC or I Guard PC
  88. Additional Guard

(all of them are fake antivirus which are
viruses or trojans) and other fake antivirus from your computer.

Remove Fake Antivirus is used to remove
fake antivirus which are viruses or trojans.

Latest updated :
Link I Link II
md5: 37c37f0def2d42bcfa7507d0b445e080
Pad File 1: rfa.xml
Pad File 2: rfa.xml

Recent Posts


Diego Vazquez said...


eyeglass4u said...

great blog enjoied your blog nice work

andy said...

Thank You! Once my computer was attacked by these fake good guys - it was awful. I caught on
much too late. This fix is Hero material too me!

May The Highest one bless You fully.

( aka Andy, Andi, You there, geek, nerd, etc.)

Dawn Sunlight said...

Thanks !

someone said...

What about one called "Net Protector".

Olzen said...

Net Protector is not fake antivirus

Javier said...

Gentlemen ; I have tested and it seems to work well. I would like to launch on several computers using a script; has this tool any parameters such /start /noreboot in order to launch it via script?

Olzen said...

No. If you want, tell me what feature you want, then I make it for u.

Javier said...

Thanks for your quick reply.
Below goes what IMHO I consider mandatory command line switches to allow this precious tool being scripting-read:

/start - automatically start scanning&fixing
/noreboot - do not reboot after scanning

The below command line parameters would be desiderable but not mandatory:

/quiet - no progress and windows shown .
/log - dump final status to a file.
/verbose - additional info shown.

thanks very much for your hard work.

Olzen said...

Ok. I have added "/start" into the program. Thank for your valueable advice.

Shin said...

It didn't work well for Antivirus Pro 2010. I just let you know it and hope your improvement.

Olzen said...

Ok. I have fixed it. Thank for your information which make the program better.

tommahawk8771 said...

The antivirus system Pro wont even let me download this it keeps telling me its infected and closing it out

Olzen said...

follow the manual removal at

coloroutside said...

i have the file csrss.exe on my computer... ive tried everything. ive been on my laptop for 2 hours. how can i get rid of this.

ive used:
spyware doctor
microsoft windows malicious software removal tool

will your program get rid of csrss.exe?

Olzen said...

The below link is about the process csrss.exe

Mònica said...

gracias saque el cyber

Ken said...

Thank you for writing and offering this wonderful tool for free. It removed a nasty fake AV from my system and I've recommended others use it to fix their systems as well.

Santa Isabel said...

Remove fake anti virus won't run on my Vista OS. virus keep blocking. Please help us. Won't open task manager.

Olzen said...

RFA is just used to remove the 30 types of fake antiviruses only. It does not used to remove other viruses. You should use other good antivirus such as Kapersky to remove the virus.

Olzen said...

If task manager is disabled, please read this post:

Santa Isabel said...

Remove fake anti virus won't run on my Vista OS. tried to open it several times but won't open. Virus keep blocking. Please help us. Won't open task manager. Antivirus System Pro keep blocking all program. Won't open either process kill.

Santa Isabel said...

Task manager is not disable it just won't open because of this AntiVirus System Pro. Even the RFA won't open. Please help us. Thank You.

Olzen said...

You should use Rescue Disc to boot your computer. Use a clean computer to create rescue disc from any good antivirus and use it to boot your computer and remove the virus.

Olzen said...

There is other way to terminate the virus process: Boot your windows, When u see the welcome screen (or before seeing the welcome screen), press Ctrl+Alt+Del to open Task Manager and end the process sysguard.exe.

Olzen said...

u may need to terminate sysguard.exe a few time. After making sure the processes are terminated, u should run RFA or other antispyware / antivirus again and reboot your computer.

venky said...

The list you created is really useful, computer users should be aware of these virus removal are fake and they are trying to insert virus into system and make them to buy there product

Coolerman said...

Thanks a lot.

BA-Software said...

How to use yout PAD file? this is a useful program and i want list it on my software directory at: and

Ca you provide a direct link for your PAD file?

solomon said...

The list you created is really useful, computer users should be aware of these virus removal are fake and they are trying to insert virus into system and make them to buy there product

Olzen said...

Pad File:

Millaapopka said...

Thanks it worked

zlobtrojan said...

You are a life saver! Thank you!!!

Dong-Her said...

I used Remove Fake Antivirus 1.59 to remove antivirus live and it's working, however, I cannot use wireless network and it keep saying I should place ...2003 again. Is it possible I need system disk to recover damage file?

Olzen said...

May be u need to use other antivirus / virus removal tool like Kapersky Virus Remover to remove other virus in your computer. May be u can reinstall your wireless driver as nowsaday the virus is so brilliant that when we remove them, it may cause some damage to our computer too.

Santa Isabel said...

I can't open RFA 1.59 because of security tool prevent it. Task bar can open but can't find what image name should be remove. pls. help!

Santa Isabel said...

I Tried a-squared HiJackFree and also won't open, it was block by Security Tools. I open task bar but don't know what file should be remove. Please help us!!

Santa Isabel said...

There is no sysguard.exe on task manager, so I don't know which filr should stop process.

Olzen said...

Run windows in safe mode. (
Kill all processes except the system proceses in a-squared Hijackfree.
Then run RFA.

If a-squared Hijackfree is blocked, may be u can rename the hijackfree executable file to other name, such as 01923242.exe and run it.

Santa Isabel said...

Hi It's me again. I've tried the a-squared hijackfree on safe mode and I need to register right on the spot, but can't acces the internet on safe mode. I run RFA 1.59 and I run it several times, reboot it several times also on safe mode, but the security tool virus is still there. I've got internet acces on regular mode but on safe mode don't have.

Olzen said...

hijackfree don need to register. Try to download it at this link:

Make sure you don't kill the process a2HiJackFree.exe

Santa Isabel said...

Thank you for your help. I tried what you told me. I kill process except for asquared files. some file that I can kill process but some are can't and everytime some of this file has been kill, my computer turn to blue screen. I done this several times including highlight the file that I want to kill process at the same time still blue screen. I run the RFA 1.59 several times on the safe mode and still the security tools are still there. I run the RFA 1.59 on the regular mode and the virus are still there. Desperate eed your help again. Thank you.

Olzen said...

Please don't kill the following processes or will activate blue screen as they are windows system files:

c:\windows\system32\conhost.exe and a2hijackfree.exe

Make sure you run windows in safe mode.
Run RFA and don't reboot.
Run Kapersky Virus Removal Tool
(download at:
and then reboot your computer.

Weak said...

nice blog!

rrktrainer4063 said...

I burn a cd with the program copied along with an autorun.inf. I put both files in a folder and replace the exe as each new release comes out so I can burn them together. The autorun will run with all the ones I've had to remove so far, may pop behind the fake window. Open notepad and paste

Open=Remove Fake Antivirus.exe
Icon=Remove Fake Antivirus.exe

and save as autorun.inf. Burn both this and the exe to the root of the cd, no folders, and once the infected system is booted, put cd in drive and wait for the initial pop for the program, remember to look behind the fake window for it.

Hope this helps.

Robert said...

a very good side that you have. I've posted a link on my blog at so my readers can follow you. Keep up the good work on your blog.

marry said...

Blogs are so informative where we get lots of information on any topic. Nice job keep it up!!

Dissertation Abstract

寶寶瑋 said...

my PC was infected by fake antivirus, I am appreciated for your blohg and download, now the fake antivirus has been cleared, thank you very much, your are the best, thank you.

Austin from Taiwan

Santa Isabel said...

I have no chance to thank you and sorry for the delay. I just want to thank you for the effective solutions that you gave. Once again, THANK YOU VERY MUCH!

佩政 said...

I love readding, and thanks for your artical.

Rookie Blog said...

Fake antivirus is everywhere and some even auto install from malicious website. Clever hackers are good in enabling the auto download of the malicious software bypassing all security on computers

Technologik said...

Great tool, much easier than doing it the manual way. Thanks!!

pai said...

Did it real simple way. I only had WiFi Internet connection so couldn't download any antimalware etc. via "safe mode with networking".
My solution:
1. Startup in "safe mode"
2. Create new user account (as administrator)
3. Login as this new user
(no malware or any virus software is activated)
4. Download Malwarebytes free edition software
(other software will probably also work)
5. Ran Malwarebytes
6. Logoff -> Logon as original user
and ....... VOILA !

Olzen said...

"3. Login as this new user
(no malware or any virus software is activated)"
Some malwares will also activate itself no matter we login as new user or not as the malwares have modified registry setting so that every user (new user or old user) will run the malware in safe mode or normal mode.

Carmina said...


UtOpiK said...

Thanks for your help

trafiköküzü said...

if you are not able to run the software restart your computer in safe mode.. the run the software.. Also you can try to end fake av software task by hitting CTRL + Shift + ESC although Fake AV closes it too

Paul said...

There are many fake antivuruses, which are doing mess in your system. At first, check if anti-virus which you are going to install is popular and verified.

GPM said...

Your fake antivirus really works!, Ive post that file on my blog at

Thank You Olzen!

Omaya Sonali said...

Wonderful thing

amit said...

Got infected with ThinkPoint.....
Very-thankful to this post !!!!
This rogue doesn't disables CTRL+ALT+DEL ...
highly indebted...
thanks once again thanks for this invaluable guide..



Builditup said...

Thanks. This was very helpful. I cleaned up my daughter's computer and it's running excellent now. Thanks again. I'll post you on my file at

funtrickz said...

thanks it work.....

~Cyber~ said...

Very very very helpful THANK YOU!

I got the new fake one with the blue background and big red letters it took up quite a few hours but I finally got rid of antivirus program didn't block it but this info helped me gain access to the internet and my antivirus software (which it blocked).

Once I could do that scan it identified and removed it.. Thanks ever so much I just don't understand why people can be so cruel some of us on fixed incomes can't afford this nonsense.

SFriends said...

Thanks a lot for spending your valuable time on it.God bless you

Post a Comment