AntivirusLive: what it is and how to remove it
Antivirus Live is a rogue antivirus tool that displays fake threats to trick users into purchasing fake protection. First reported in 2021, it blocks legitimate security software and hijacks browser settings.
Facts checked October 5, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If sysguard.exe returns after removal, a full scan can find the entry that brings it back.
Do it yourself · free Remove AntivirusLive yourself 5 steps, about 15 minutes, no software needed.
Start the steps
AntivirusLive: summary
| Distribution | Social engineering campaigns, Trojans |
|---|---|
| Name | AntivirusLive |
| Type | Malware, rogue anti-spyware |
| Detection names | No Microsoft detection name is known |
| Domain registered | 27 June 2026 (Sav.com, LLC - 36), paid until 27 June 2027 |
| Damage | Not recorded in the old report |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 5 more facts
| Symptoms | An unknown process in Task Manager |
|---|---|
| Files and processes | sysguard.exe |
| Evidence | One write-up by a security site; details still limited |
| First seen | 6 April 2021 |
| Facts checked | 5 October 2026 |
AntivirusLive in 2026: what we found
We opened antivirus.live in a clean desktop Chrome browser on 4 October 2026 and clicked nothing. This is one visit from one location: ad pages often behave differently on a second visit, in another country, on a phone or after a click, and many hide from automated browsers, so a quiet result is not proof that the page is clean.
antivirus.live · desktop Chrome · 4 October 2026
- Notification requestNone on this one visit.
- Pop-ups and new tabsNone on this one visit.
- Where it ledIt stayed on
antivirus.live. - Ad networksNone found in the page.
- Page title"Redirecting..."
Quiet on one visit The page made no request and sent us nowhere on this visit. That does not clear it: adware often shows nothing at first and sits quietly for a long time. What it showed you earlier may still be in your browser, so check the permissions below.
Is AntivirusLive a real security program?
- File:
sysguard.exe
AntivirusLive: what changed since our report
April 2021
Our first report
We described AntivirusLive on 6 April 2021 and updated the report on 4 May 2021.
June 2026
The domain is registered again
The current registration of
antivirus.livedates from 27 June 2026, after our first report: the address may now belong to someone else.October 2026
Our new check
We opened the address again in a clean browser; the results are above.
From our report of Apr 2021 · not reviewed since
More from our earlier report on AntivirusLive
- If you noticed that your Windows system was damaged, fix it with an automatic solution
- Windows Security Alert Windows reports that the computer is infected.
- Antivirus software helps to protect your computer against viruses and other security threats.
- Your system might be at risk now.
- Infiltration alert Your computer is being attacked by an Internet Virus.
- It could be a password-stealing attack, a trojan-dropper, or similar.
How to remove AntivirusLive
Nothing it reports is real.
These steps remove it and undo a payment if you made one.
Step 1: Do not pay, and undo a payment if you made one
AntivirusLive reports problems to sell a licence: the "threats" or "errors" it lists are invented or harmless leftovers. If you already paid, ask your card issuer to dispute the charge and cancel the subscription both in the seller's account and through your bank.
If you called a phone number it showed and let someone connect, treat the PC as remotely accessed and remove the remote tool. Uninstalling it from Windows 11 or Windows 10 does not cancel a subscription by itself.
Full procedure with screenshots: What to do after paying a scammer
Step 2: Uninstall programs you did not mean to install
Open Settings > Apps > Installed apps in Windows 11, or Settings > Apps > Apps & features in Windows 10, and sort the list by install date. Look at what appeared around the day the problem started and uninstall every program you do not recognise or did not choose.
Free converters, PDF and video tools, "system optimizers" and unknown browsers are the usual carriers of AntivirusLive. If a name is unclear, search for it before you remove it, so you do not uninstall a driver or a Windows component.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Remove it from startup
Whatever AntivirusLive installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 4: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 5: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Manual removal using Safe Mode
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.

- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.
- Go to Advanced options.

- Select Startup Settings.

- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.

Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.

- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.

- Go back to the process, right-click and pick End Task.

- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.

- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.

- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
Access your website securely from any location
When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.
If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.
Recover files after data-affecting malware attacks
While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.
More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.
Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.
From our report of Apr 2021 · outdated details corrected in October 2026
Antivirus Live - a fake anti-malware app that should be eliminated as soon as possible
Antivirus Live is a rogue security application, a fake malware removal tool that enters a computer with the help of Trojans and other malicious software.
It is from the same family as Antivirus System PRO and Spyware Protect 2009. Once installed, AntivirusLive will display fake security alerts and notifications about serious computer security threats or infections.
The rogue application will also block almost all programs, especially anti-virus, to protect itself from being deleted. You will see the "Application can not be executed" warning when you launch applications. Antivirus Live enables proxy servers for LAN and blocks security-related and antivirus software websites.
Malicious program will state that your computer is badly infected with Trojans, worms, spyware, and other malware. Then it will ask you to pay for a full version of the program to remove the infections which do not even exist.
The main goal of rogue antivirus app is to trick you into purchasing the program. In order to achieve its goals, the misleading application will simulate a system scan and report false scan results. In other words, this is nothing more but a scam. Do not purchase it!
What is more, this bogus security tool will impersonate Windows Security Center and state that Windows did not find any anti-virus software on your computer and that Windows is not updated. Obviously, the rogue program will suggest you to activate the app in order to protect your computer.
And that's, by the way, the main difference between legitimate Security and fake ones. The legitimate one does not promote any particular anti-virus software. When this fake anti-spyware application is running, you will also see many fake security alerts. Some of them will state:
After all the malicious files are gone, you should also clean your browsers and fix damaged system files. Since this process might take a while and be a bit complicated for regular computer users, we advise performing these steps automatically with .

From our report of Apr 2021 · not reviewed since
Malware infection can be not noticed initially
Antivirus Live is promoted through Trojans' use that comes from fake online scanners and other misleading websites.
It is also distributed using social engineering. This means that users are presented with fake claims online, only to be taken advantage of.
For example, a pop-up ad might say that your computer is infected (and look similar to how Microsoft error alerts look like) or that your software is out of date and needs to be updated urgently. All these are tricks that make users install malware without realizing it.
Therefore, in order to avoid being tricked, follow these tips provided by security experts:
- Install a robust anti-malware and always keep it updated;
- Never postpone Windows updates and install security patches for all software;
- Install ad-block to avoid malicious ads and scripts;
- Do not believe claims that something is missing from your system, or that it is infected with a virus.
- Use strong passwords for all your accounts and never repeat them.
From our report of Apr 2021 · outdated details corrected in October 2026
Remove Antivirus Live by using legitimate security tool
As you can see, Antivirus Live is a totally useless and even dangerous application.
Before you can remove this infection, you have to end all processes associated with malware. Otherwise, you won't be able to run any anti-spyware/virus software.
Now terminate malicious processes. It should be sysguard.exe, for example, wmcqsysguard.exe.
Do not reboot your computer after using Process Explorer and terminating all related processes. Now you should be able to download an automatic Antivirus Live removal tool or another anti-spyware application.
Most importantly, do not purchase this malicious app. If you have already done that, please contact your credit card company and dispute the charges.
- Click on the Tools menu and then select Internet Options.
- In the Internet Options window, click on the Connections tab. Then click on the LAN settings button.
- Now you will see the Local Area Network (LAN) settings window. Uncheck the checkbox labeled Use a proxy server for your LAN under the Proxy Server section and press OK.
Questions about AntivirusLive
What is Antivirus Live?
Antivirus Live is a fake antivirus program, or rogue security application. Published in 2021, it was classified as a malware that enters systems through Trojans.
The domain antivirus.live was registered on 2026-06-27 by Sav.com, LLC. It belongs to the same malicious family as Antivirus System PRO and Spyware Protect 2009, all designed to deceive users into purchasing fake protection.
How does Antivirus Live infect my computer?
According to the 2021 guide, Antivirus Live is distributed via Trojans and other malicious software, as well as fake online scanners and misleading websites using social engineering. Users are presented with false claims that their computer is infected or that software needs urgent updates. These tricks make users install malware without realizing it.
What does Antivirus Live do?
The 2021 report states that once installed, Antivirus Live displays fake security alerts about serious computer threats that don't exist. It blocks almost all programs, especially legitimate antivirus software.
It hijacks Internet Explorer, changes LAN Settings, enables proxy servers, and blocks security websites. It will state your computer is damaged to trick you into purchasing the program.
Are the Antivirus Live warnings real?
No, all warnings are fraudulent. The 2021 guide confirms Antivirus Live simulates a system scan and reports false scan results. These alerts impersonate Windows Security Center.
The rogue app will claim Windows is not updated and has no antivirus, then urge you to activate the app. Legitimate Windows tools don't promote specific antivirus products like this.
What should I do if I see Antivirus Live alerts?
Do not follow the instructions in the alerts. Do not pay for the program or purchase any products it recommends.
The 2021 guide emphasizes this is a scam designed to trick you into giving cybercriminals money. Instead, end all malware processes and use legitimate antivirus software to remove the infection from your system.
How do I remove Antivirus Live?
First, disable the proxy server for LAN in Internet Explorer or use Firefox or Opera instead. End all processes related to the malware (usually files like wmcqsysguard.exe).
Do not reboot after terminating processes. Then download a legitimate anti-spyware application to scan and remove Antivirus Live completely. Use Microsoft Defender for thorough scanning.
What if my internet is blocked?
Antivirus Live blocks security websites and antivirus downloads. Try switching browsers or using Safe Mode with Networking. If that fails, use another device to download antivirus software and transfer it via USB.
Boot into Safe Mode to run the antivirus tool without the malware interfering. Complete removal may require offline scanning.
How can I prevent Antivirus Live?
The 2021 guide recommends installing robust anti-malware and keeping it updated, never postponing Windows updates, installing ad-blockers, and not believing claims that your system is infected. Do not interact with unsolicited pop-up warnings or alerts claiming your software is out of date. Use strong, unique passwords for all accounts to prevent credential theft.
Will Fortect remove AntivirusLive?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For AntivirusLive, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize, remove and avoid malware (read October 5, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 5, 2026)
- Microsoft Learn: How Microsoft names malware (read October 5, 2026)