Description: Antivirus Action is a fake security client and a direct clone of Antivirus IS, Security Suite, Antivir Solution Pro, AV Security Suite, AntiSpyware Soft, Antivirus Suite. Like most fake programs this rogue attempts to trick the user into making a purchase of the program by showing FALSE scan results. The program will also constatntly nag the user about purchaing the client and it's very common to have messages that come up about your computer being hacked into and even porn pop ups. These are all tricks used to push the user into making a purchase.
Antivirus Action
» Download Antivirus Action Removal Software
Once infected with Antivirus Action you may be blocked from viewing other websites and blocked from running and installing many programs.
Antivirus Action Removal Guide
Step 1. Watch this proxy removal guide on how to remove the proxy settings from your web broweser. You may also want to read the manual guide to see how to do this manually if you are using Firefox. Please note that some users may not be able to complete this step untill they fully stop the Antivirus Action running processes. It may also work better in safe mode with networking.
Remove Proxy Setting so You Can Connect to the Internet Again.
Antivirus Soft Removal Video ( NOT Antivirus Action but it's basically the SAME EXACT THREAT. This should work for you. Just substitute out the correct names and files)
Antivirus Action Manual Removal Procedures
The first step you must take in order to remove Antivirus Action is to stop the following process:
XP USERS
- C:\Documents and Settings\\%Your User Name%\Local Settings\Application Data\[random characters]\[random characters]agnz.exe
Vista / Windows 7 Users
- C:\Users\%Your User Name%\AppData\Local\[random characters]\[random characters]agnz.exe
Top Stop this process you can either browse to the file location and re-name the file like we did in the video above, or you can download our process killer tool under SOFTWARE tab above. Be sure to download the one already re-named explorer.exe
We also want to point out that your Internet Explorer and or Chrome will not be able to connect to the internet in many cases. You need to remove the proxy setting first. View the video above on how to do this.
The next step in Antivirus Action removal is to delete the following file:
Windows XP:
- %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters]agnz.exe
Windows Vista/7:
- %User%\AppData\Local\[random characters ]\[random characters]agnz.exe
You may not have the agnz.exe at the end. However it still have the random characters and is in the same folder paths as above chances are it's the threat you want to remove.
Once the above steps have been completed, Antivirus Action is mostly gone from your computer. Even if in most cases this step would ensure that no other malicious software are present on the disk it is still recommended to scan the entire PC using genuine security software such as Spyware Doctor with Antivirus.
Antivirus Action Registry Removal Procedures
Removing files and folders alone is not sufficient to completely remove Antivirus Action. The following keys and settings should also be removed from the Windows registry to complete Antivirus Action removal. Please note that the below refferences are for educational purposes only. Normal computer users should use Antivirus software to remove infected registry items:
- KEY_CURRENT_USERSoftwareAntivirus Action
- HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun “Antivirus Action”
- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallAntivirus Action
- HKEY_CURRENT_USERSoftware[random characters]
- HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerPhishingFilter "Enabled" = "0"
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "ProxyOverride" = ""
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "ProxyServer" = "http=127.0.0.1:33921"
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "ProxyEnable" = "1"
- HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "[random characters] gnz.exe"
- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun "[random characters]agnz.exe"
You should now run a full security scan to ensure no other threats are installed on your computer.
Antivirus Action Directories:
- Vista and Windows 7 Users: %User%\AppData\Local\[random characters ]\
- XP Users: %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\
Outside Resources:
https://community.mcafee.com/message/154576
http://www.pctechguide.com/virus-removal/remove-antivirus-action
Speak Your Mind