Security Antivirus. How to remove? (Uninstall guide)

removal by Alice Woods - -   Also known as SecurityAntivirus | Type: Rogue Antispyware
12

Security Antivirus is a rogue security application from the same family as PC Live Guard malware. It’s one of many rogue anti-spyware programs that displays fake security alerts/pop-ups and false system security threats to scare you into thinking that your computer is infected. The main goal of this program is to trick you into purchasing the program that’s why it will prompt you to pay for the bogus software in order to remove the threats which don’t even exist. Most of the time, Security Antivirus rogue comes from fake online scanners, fake websites or misleading online ads. This virus can be also promoted using social engineering. One way or another, don’t install it and don’t pay for this totally useless program. Instead, please use the removal guide below to remove Security Antivirus.

Security Antivirus graphical user interface
[Figure 1. Security Antivirus graphical user interface]

Once installed, SecurityAntivirus will drop numerous files on your computer and later detect these files as serious computer threats. The fake files are: ANTIGEN.drv, ANTIGEN.exe, cid.dll, DBOLE.sys, ddv.dll, ddv.sys, energy.tmp, FS.drv, PE.exe, PE.sys, runddlkey.dll, std.exe, tjd.drv. The rogue program just imitates a system scan and reports false infections. Don’t worry about that and ignore false scan results. Furthermore, Security Antivirus will display many fake security alerts stating that your computer is infected or that there are otentially harmful programs on your PC. Some of the fake alerts displayed by this virus:

Potentially harmful programs have been detected in your system and need to be dealt with immediately. Click here to remove them using Security Antivirus.
Your PC may still be infected with dangerous viruses. Security Antivirus protection is needed to prevent data loss and avoid theft of your personal data and credit card details. Click here to activate protection.

Malicious applications, which may contain Trojans, were found on your computer and are to be removed immediately. Click here to remove these potentially harmful items using Security Antivirus.
No real-time malware, spyware and virus protection was found. Click here to activate.

Just like the false scan results these fake warnings were made to scare you. Last, but not least, Security Antivirus will hijack Internet Explorer and redirect search results to findgala.com. It may also block security related websites. Finally, it will modify Windows Hosts file and add the following lines in Hosts file:

74.125.45.100 4-open-davinci.com
74.125.45.100 securitysoftwarepayments.com
74.125.45.100 privatesecuredpayments.com
74.125.45.100 secure.privatesecuredpayments.com
74.125.45.100 getantivirusplusnow.com
74.125.45.100 secure-plus-payments.com
74.125.45.100 www.getantivirusplusnow.com
74.125.45.100 www.secure-plus-payments.com
74.125.45.100 www.getavplusnow.com
74.125.45.100 safebrowsing-cache.google.com
74.125.45.100 urs.microsoft.com
74.125.45.100 www.securesoftwarebill.com
74.125.45.100 secure.paysecuresystem.com
74.125.45.100 paysoftbillsolution.com
74.125.45.100 protected.maxisoftwaremart.com
95.211.99.110 www.google.com
95.211.99.110 google.com
95.211.99.110 www.google-analytics.com
95.211.99.110 www.bing.com
95.211.99.110 search.yahoo.com
95.211.99.110 www.search.yahoo.com

As you can see, Security Antivirus is a total scam. Please use the removal guide below to get rid of this infections as soon as possible. Also note that removal delay will probably make the situation more complicated because it is able to download and install additional malware onto your computer.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Security Antivirus you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Security Antivirus. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

More information about this program can be found in Reimage review.

Security Antivirus manual removal:

Kill processes:
SA345d.exe

Delete registry values:
HKEY_CURRENT_USERSoftware3

HKEY_CLASSES_ROOTSA345d.DocHostUIHandler

HKEY_USERS.DEFAULTSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=195&q={searchTerms}"

HKEY_CURRENT_USERSoftwareClassesSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=195&q={searchTerms}"

HKEY_CURRENT_USERSoftwareMicrosoftInternet Explorer "PRS" ="http://127.0.0.1:27777/?inj=%ORIGINAL%"

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "RunInvalidSignatures" = "1"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0User AgentPost Platform "App/7.00195"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "Security Antivirus"

Delete files:
72.mof

mozcrt19.dll

SA345d.exe

SAV.ico

sqlite3.dll

Adobe Reader Speed Launch.lnk

Adobe Reader Synchronizer.lnk

vd952342.bd

SAAKDUPV.cfg

Security Antivirus.lnk

cookies.sqlite

ANTIGEN.drv

ANTIGEN.exe

cid.dll

CLSV.drv

DBOLE.sys

ddv.dll

ddv.sys

energy.tmp

FS.drv

gid.drv

PE.drv

PE.exe

PE.sys

PE.tmp

runddlkey.dll

std.exe

tjd.drv

tjd.sys

c:\Program Files\Mozilla Firefox\searchplugins\search.xml

Delete directories:
C:Documents and SettingsAll UsersApplication Data345d567

C:Documents and SettingsAll UsersApplication Data345d567BackUp

C:Documents and SettingsAll UsersApplication Data345d567Quarantine Items

C:Documents and SettingsAll UsersApplication Data345d567SAVSys

%UserProfile%Application DataSecurity Antivirus

About the author

Alice Woods
Alice Woods - Likes to teach users about virus prevention

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

More information about the author


  • Guest

    I'm really scared whether or not this'll work, my computer is having a really hard time going on the internet, but I logged on guest instead of my user log in and the internet is ok for now….

  • Guest

    Hi,

    I am in a similar boat; I managed to download Spyware Doc but the virus won't let me open and run it…Don't know what to do…It keeps shutting the explorer but luckily I am ok with Safari.

    Anyone got any suggestions how to run Spyware Doc and override Security Antivirus?

    Thanks!

  • Faisal Abrar

    I have not tested Automatic Security Antivirus Removal . But I chose Manual Process and it works. You can use it.

  • Guest

    thank u
    thank u

    thank u

    thank u

  • Guest

    I can find those registry files when I looked them up manually? Does this mean they are already gone?

  • karchamberlin@comcast.net

    How do you get your money back from Security Anti virus if you were naive enough to fall for their scam like me??????