By George Norman
Added on 08 Feb 2010(105 Views)



classification: Rogue AntiSpyware Programs
SafePcAv, a rogue from the Winisoft family of rogues, is usually distributed by malicious software, like Trojans. These Trojans manage to compromise the user’s computer because they hide under the guise of a codec or Flash update. When the user visits a certain webpage and attempts to view a video, he is informed that a codec/Flash update is needed to play the video. He is then invited to download the phony codec/Flash update, thus compromising his computer. Once the Trojan makes its way onto the user’s computer, it downloads and installs SafePcAv without the user’s consent. It also creates a bunch of files that are harmless – these files will be later flagged as malware by SafePcAv.
Once SafePcAv has been installed, it will automatically run at startup. Each time the user boots up his computer, SafePcAv shows up and performs a fake system scan. The scan detects the files created by the Trojan as malware.

The SafePcAv rogue will also bombard the user with popups and fake security alerts. Like this one:
Spyware Alert!
Your computer is infected with spyware. It could damage your critical files or expose your private data on the Internet. Click here to register your copy of SafePcAv and remove spyware threats from your PC.”


The rogue will also display a fake Security Center window, hijack the browser, and more. The goal here is to scare the user into thinking his computer is infected. Once the user is nice and scared, SafePcAv offers to remove the infection – but only if said user will purchase a SafePcAv license. Since the infection is phony and the SafePcAv program is a fake security software application, you would only be wasting your money by paying for a license.

Automatic removal guide
Step 1. If you have a printer, make sure to print out this tutorial. If you do not have a printer, save this tutorial, go out to a copy center and print it out there. If you do not have a printer and do not want to go out, then use the pen and paper method: grab a pen and a piece of paper and write down the instruction presented in the steps below. In the process of eliminating SafePcAv from your machine you will need to shut down the browser. And since this will also shut down the tutorial, you need to know what you should do next.

Step 2. You will have to install Malwarebytes’ Anti-Malware. In this regard you need to download the software’s setup executable. Just click this link and save the .exe file on your computer (preferably on your desktop).

Step 3. Double click the Malwarebytes’ Anti-Malware setup executable. It should be on the desktop under the name mbam-setup. This will launch the installation process. If you already know how to install a piece of software, proceed to step 4. If you do not know how to do this, we’ll walk you though it all:



- The Select Setup Language window should have popped up. By default, the language in which the software will be installed is set to English, but you can change this. The software provides support for 30+ languages. After selecting the language of your choice, click OK. It would be best to just leave it set to English though.



- The Malwarebytes’ Anti-Malware Setup Wizard will now popup. Just click Next.



- You will be presented with the License Agreement. Click I accept the agreement and then click Next. If you do not accept the agreement you will not be able to continue.



- Keep clicking Next until you get to the Ready to install window. Now click Install. After the installation process completes click Finish. Do not uncheck the boxes next to Update Malwarebytes’ Anti-Malware or Launch Malwarebytes’ Anti-Malware.















Step 4. The Malwarebytes’ Anti-Malware application will launch automatically. The Perform quick scan option should be checked by default – if it isn’t then check it and then click Scan. You are well advised to close all running apps before clicking scan. This will ensure the scan for SafePcAv will complete swiftly.



Malwarebytes’ Anti-Malware will start scanning your files for signs of SafePcAv. This may take a while, so be patient. It all depends on how powerful your computer is and how many files Malwarebytes’ Anti-Malware has to scan.



When the scan for SafePcAv is complete you will be presented with a notification box. Click OK to close the notification box and go to the main Scanner screen. Click Show Results and you will be presented with a list of all the infected files Malwarebytes’ Anti-Malware has detected.





Step 5. Click Remove Selected and Malwarebytes’ Anti-Malware will remove all the infected files it has detected. It may be necessary to restart your computer in order to remove some of these files. After Malwarebytes’ Anti-Malware is done removing all the infected files, it will open Notepad and present the scan log to you. You can review the log at your leisure – save it If you want.



Step 6. Close Malwarebytes’ Anti-Malware and you’re done. No traces of SafePcAv should be left on your computer.

Manual removal guide

Stop and remove the processes:

SafePcAv.exe
uninstall.exe
%Program Files%/SafePcAv Software/SafePcAv/SafePcAv.exe
%Program Files%/SafePcAv Software/SafePcAv/uninstall.exe


Access the Windows Registry Editor and delete the following registry keys:

HKEY_CURRENT_USER/Software/SafePcAv
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/SafePcAv
HKEY_LOCAL_MACHINE/SOFTWARE/SafePcAv
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/system "EnableLUA" = "0"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run "SafePcAv"


Locate and delete the following files:

c:/Documents and Settings/All Users/Desktop/SafePcAv.lnk
c:/Documents and Settings/All Users/Start Menu/Programs/SafePcAv
c:/Documents and Settings/All Users/Start Menu/Programs/SafePcAv/1 SafePcAv.lnk
c:/Documents and Settings/All Users/Start Menu/Programs/SafePcAv/2 Homepage.lnk
c:/Documents and Settings/All Users/Start Menu/Programs/SafePcAv/3 Uninstall.lnk
c:/Program Files/SafePcAv Software
c:/Program Files/SafePcAv Software/SafePcAv
c:/Program Files/SafePcAv Software/SafePcAv/main_config.xml
c:/Program Files/SafePcAv Software/SafePcAv/SafePcAv.exe
c:/Program Files/SafePcAv Software/SafePcAv/uninstall.exe




Don't forget to:

Tags:

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Removal Guide Articles
How To Remove XP Micro Antivirus
If you did not manually install XP Micro Antivirus and ...
19 Feb 2010
How To Remove Software Antivirus
Software Antivirus, unlike what the name may suggest, is not ...
19 Feb 2010
How To Remove WiniFighter
The irony here is that the name WiniFighter would lead ...
19 Feb 2010
How To Remove PC Security 2009
PC Security 2009, a rogue antispyware program, is usually distributed ...
19 Feb 2010
How To Remove Security Essentials 2010
The people with malicious intent that put out the ...
18 Feb 2010
How To Remove Personal Anti Malware
Personal Anti Malware, a rogue security software application, is usually ...
18 Feb 2010
Recommended Tools

Top Downloads