A: what it is and how to remove it
A-Fast Antivirus is a rogue anti-spyware program that uses misleading methods to scare users into thinking that their computers are infected with malware. This scareware is promoted through the use of Trojans and various malicious websites such as fake online scanners.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with A.
Do it yourself · free Remove A yourself 5 steps, about 15 minutes, no software needed.
Start the steps
A: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | A |
| Type | Rogue antivirus |
| Symptoms | An unknown program in Installed apps |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 4 more facts
| Evidence | One write-up by a security site; details still limited |
|---|---|
| Program | A |
| First seen | 26 April 2021 |
| Facts checked | 7 October 2026 |
From our report of Apr 2021 · not reviewed since
What A is
A-Fast Antivirus is a rogue anti-spyware program that uses misleading methods to scare users into thinking that their computers are infected with malware.
This scareware is promoted through the use of Trojans and various malicious websites such as fake online scanners. Once installed, A-Fast Antivirus will simulate a system scan and report numerous infections. Then it will prompt you to pay for a full version of the program to remove the infections which don't even exist.
Furthermore, AFast Antivirus will display fake security alerts and pop-ups from Windows taskbar stating that your computer is not protected or under attack from a remote computer. Some of those fake security alerts read:
The rogue program also blocks legitimate anti-malware programs and system tools such as task manager stating that it's infected. A-Fast Antivirus is a scam. Don't buy this bogus program. Removal guide for A-Fast Antivirus: When removing A-Fast Antivirus, reboot your computer into Safe Mode with Networking at first (Just reboot a machine and before Windows is launched start tapping F8 button.
You will see a table with this option). Then, login as the same user you were previously using in the normal Windows mode, download Spyware Doctor anti-spyware and save it on your desktop. Make sure you install it and update the program before performing a scan. Now you will have to choose performing a full system scan, the program will list and offer to remove all the detected malware.
If the A-Fast Antivirus still blocks legitimate anti-malware programs, please use of the the following serials to activate A-Fast Antivirus. Then you will be able to use an anti-malware program to remove the infection. B0B302F772 C197C46C46 B20C1467B7 041E4B235A 25CCCC7329 9926220EED A58EC19D33 C15F2FF276 F61E370D62 DDAD6A7A2C 9F8122FE00 3754DD9DA6 3DC52EA100 EE73BBFFA6 7E61C9C7DF EE34D2E8A7 AA61971AA1 9D2510E3E8
How to remove A
Nothing it reports is real.
These steps remove it and undo a payment if you made one.
Step 1: Do not pay, and undo a payment if you made one
A reports problems to sell a licence: the "threats" or "errors" it lists are invented or harmless leftovers. If you already paid, ask your card issuer to dispute the charge and cancel the subscription both in the seller's account and through your bank.
If you called a phone number it showed and let someone connect, treat the PC as remotely accessed and remove the remote tool. Uninstalling it from Windows 11 or Windows 10 does not cancel a subscription by itself.
Full procedure with screenshots: What to do after paying a scammer
Step 2: Uninstall A
Open Settings > Apps > Installed apps in Windows 11, or Settings > Apps > Apps & features in Windows 10. Sort the list by install date and find A, then choose Uninstall from the three-dot menu next to it (in Windows 10, click the entry and then Uninstall).
Remove anything else installed on the same day that you do not recognise, because such programs usually arrive together in one installer. If the uninstaller opens a browser page with an offer or a survey, close it: the program is removed either way.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Remove it from startup
Whatever A installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 4: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 5: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Protect your privacy - employ a VPN
There are several ways how to make your online time more private - you can access an incognito tab.
However, there is no secret that even in this mode, you are tracked for advertising purposes. There is a way to add an extra layer of protection and create a completely anonymous web browsing practice with the help of VPN. This software reroutes traffic through different servers, thus leaving your IP address and geolocation in disguise.
Besides, it is based on a strict no-log policy, meaning that no data will be recorded, leaked, and available for both first and third parties. The combination of a secure web browser and VPN will let you browse the Internet without a feeling of being spied or targeted by criminals.
No backups? No problem. Use a data recovery tool
If you wonder how data loss can occur, you should not look any further for answers - human errors, malware attacks, hardware failures, power cuts, natural disasters, or even simple negligence.
In some cases, lost files are extremely important, and many straight out panic when such an unfortunate course of events happen. Due to this, you should always ensure that you prepare proper data backups on a regular basis.
If you were caught by surprise and did not have any backups to restore your files from, not everything is lost. is one of the leading file recovery solutions you can find on the market - it is likely to restore even lost emails or data located on an external device.
Questions about A
Is A a virus?
Most programs that appear the way A did are not viruses in the strict sense. They are potentially unwanted programs:
- real software that arrives bundled with other downloads and then shows offers
- changes browser settings
- starts with Windows
Some are harmless, some are annoying and a few carry adware. What makes it worth removing is that you did not choose it.
Uninstall it from Installed apps and check the startup list and the browsers for anything added the same day. If it refuses to uninstall or returns after a restart, treat it as more serious and run a Microsoft Defender offline scan.
A will not uninstall. What can I do?
First restart the PC and try again, because the program may have been running and locked its own files. If the uninstaller is missing or fails, start Windows in Safe Mode, where most third-party programs do not start, and remove A from Installed apps there.
If it still refuses, delete its startup entry and its scheduled task, restart, and try once more. A program that actively prevents removal is behaving like malware, so finish with a Microsoft Defender offline scan. Avoid third-party uninstallers offered on search ads; several of them are unwanted programs themselves.
Why does A look so official?
Because copying the design costs nothing and makes people trust it. The program behind A in the list of installed apps borrows Windows colours, icons and wording, sometimes even the name of a well-known security brand. None of that gives it access to real security information.
A real alert can be checked in seconds: open Windows Security from the Start menu and look at Protection history. If nothing is listed there, the official-looking window is fake, and the program that draws it is what needs to be removed.
What if I paid A?
Contact your bank or card issuer the same day, explain that the payment went to a fake security program and ask for a chargeback. Keep screenshots of A in the list of installed apps, the payment receipt and any e-mails.
If you gave card details in the program, ask the bank to block and replace the card. Then uninstall the program and run a full scan in Windows Security. If you also called a number and let someone connect to your PC, uninstall the remote-access tool they used and change your passwords from another device.
Will the seller of A refund me if I ask?
Sometimes, but do not depend on it and do not let them steer the process. If you contact the seller, do it in writing and keep the replies. Never install software, share your screen or give banking details to get a refund.
The more reliable route is your card issuer or PayPal: a chargeback or dispute for a product sold with false claims. If the seller or anyone claiming to represent them calls you first about a refund, treat it as a scam and hang up.
I entered my card number in A. What should I do?
Call your card issuer using the number on the back of the card, report the purchase as fraud and ask for a new card. Ask them to block further charges from the same merchant. Watch your statements for small test charges, which often come before larger ones.
If you used a password on the order page or the same e-mail for the purchase, change that password and expect phishing e-mails that mention the purchase. Your bank can also tell you whether the merchant is linked to other fraud reports.
Should I reset my PC because of A?
Only if the signs point to deeper access. Reset when you see A in the list of installed apps again after removal, when Windows Security cannot start or update, when remote access tools you did not install keep appearing, or when you simply cannot trust the PC any more.
Otherwise, the plan in this guide plus an offline scan is enough. If you do reset, choose Remove everything and Cloud download for a fresh copy of Windows, restore only documents and photos, and reinstall programs from their official sites. Change important passwords from the clean system afterwards.
A has no uninstaller. How do I get rid of it?
Some scareware does not register an uninstaller, or its uninstaller only opens another sales page. In that case, end the program in Task Manager, then go to Task Manager > Startup apps, right-click its entry and choose Open file location to find its folder. Disable the startup entry, restart in Safe Mode and delete the folder.
Check Task Scheduler for tasks with the same name. Finally, run the Microsoft Defender offline scan, which removes remaining files that Microsoft knows about. Restart afterwards and check that nothing named after A starts again.
I let a technician connect to my PC because of A. Is it safe now?
Not until you check. While connected, the caller could install other programs, create a user account or look at saved passwords. Disconnect from the internet, uninstall the remote access program and anything else installed during the call, and run a full scan and the Microsoft Defender offline scan.
From another device, change your e-mail and banking passwords and turn on two-step verification. If the caller opened your online banking, call the bank today. A reset of Windows is the safest option if you cannot tell what was done.
Will Fortect remove A?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For A, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)