Green AV: what it is and how to remove it
Green AV is a rogue security application that reports false or exaggerated system security threats to make you think that your computer is seriously infected. The rogue program then asks to purchase a registered version of Green AV to remove threats that don not really exist.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with Green AV.
Do it yourself · free Remove Green AV yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Green AV: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | Green AV |
| Type | Rogue antivirus |
| Symptoms | An unknown program in Installed apps |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 4 more facts
| Evidence | One write-up by a security site; details still limited |
|---|---|
| Program | Green AV |
| First seen | 26 April 2021 |
| Facts checked | 7 October 2026 |
From our report of Apr 2021 · not reviewed since
What Green AV is
Green AV is a rogue security application that reports false or exaggerated system security threats to make you think that your computer is seriously infected.
The rogue program then asks to purchase a registered version of Green AV to remove threats that don not really exist. This misleading application is just another variant of Green Antivirus 2009 malware. Do not purchase it! Uninstall Green AV from the system as soon as possible.
Green AV is usually promoted through the use of Trojans, fake online anti-malware scanners and other misleading websites. The rogue program is promoted on green-av-pro.com and green-av.com. Please stay away from these websites. It uses Microsoft Windows XP graphical user interface elements, logos, icons to make it look more reliable and reputable.
Once installed, the rogue program will display fake security alerts claiming that your PC is under attack or that is seriously infected. These fake security alerts look like those legitimate from Widows Security Center. This parasite may also impersonate Windows Security Center and report that anti-virus protection is disabled.
You will see the following fake security notification: "Your PC is not protected Security center reports that 'Green AV' is inactive. Antivirus software helps to protect your computer against viruses and other security threats. You system might be at risk now."
While running, GreenAV will ostensibly scan the system and display a variety of infections that can't be removed unless you purchase the program. The scan results are false; do not purchase Green Antivirus because it won't help you. Instead, you should remove this infection form your PC immediately because it will likely download additional malware onto your computer.
What is more, it will block antivirus programs and hijack Internet browsers. As result, you will be redirected to various untreated and misleading websites that are full of advertisements or promote rogue security programs. If you find that your computer is infected with this parasite, please use the removal guide to get rid of GreenAV manually for free.
How to remove Green AV
Nothing it reports is real.
These steps remove it and undo a payment if you made one.
Step 1: Do not pay, and undo a payment if you made one
Nothing that Green AV says it found needs fixing by Green AV. Close its windows and do not enter card details.
If you bought it, contact your bank or card issuer about a dispute and cancel any renewal, keeping the receipt e-mail as evidence. Uninstalling it from Windows 11 or Windows 10 removes the program but leaves the subscription running.
Full procedure with screenshots: What to do after paying a scammer
Step 2: Uninstall Green AV
Green AV is removed like any other program, from the list of installed apps. In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.
Select Green AV, click Uninstall and follow the uninstaller to the end. Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 4: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after Green AV, its publisher or created on the day the problem started.Delete those folders, and check
C:\Program FilesandC:\Program Files (x86)too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 5: Scan the PC, then run the offline scan
A scan finds the parts of Green AV that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
Questions about Green AV
Is Green AV a virus?
Most programs that appear the way Green AV did are not viruses in the strict sense. They are potentially unwanted programs:
- real software that arrives bundled with other downloads and then shows offers
- changes browser settings
- starts with Windows
Some are harmless, some are annoying and a few carry adware. What makes it worth removing is that you did not choose it.
Uninstall it from Installed apps and check the startup list and the browsers for anything added the same day. If it refuses to uninstall or returns after a restart, treat it as more serious and run a Microsoft Defender offline scan.
How do I stop programs like Green AV from being installed again?
Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.
Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped Green AV before it reached the app list.
Do I need to reinstall Windows to get rid of Green AV?
Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see green AV in the list of installed apps again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.
Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.
I called the number from Green AV. What now?
End the call and do not let them reconnect. If they installed a remote-access tool, disconnect the PC from the internet and uninstall that tool from Installed apps. Change passwords for e-mail, banking and anything you typed during the call, using another device.
If you paid, contact the bank today for a chargeback. Report the number to the authorities in your country. The program behind green AV in the list of installed apps still needs removing: follow the plan in this guide, then run a full scan in Windows Security.
Green AV will not uninstall. What can I do?
Close it in Task Manager first, then uninstall it from Settings > Apps > Installed apps (in Windows 10, Apps & features). If it blocks this or restarts itself, start Windows in Safe Mode, where third-party programs do not start automatically, and uninstall from there.
Afterwards run a Microsoft Defender offline scan and delete any leftover folder named after Green AV in C:\Program Files or %AppData%. If nothing works, Windows can be reset while keeping your personal files, which removes the program together with any settings it changed.
Someone called offering a refund for Green AV. Is it genuine?
Almost certainly not. Refund calls are a well-known second stage of scareware and tech support scams. The caller says you are owed money, asks you to install a remote access program to "process" it, then opens your online banking, makes it look as if too much was refunded and asks you to send the difference back.
Hang up. Real refunds go back to the card or PayPal account you paid with, through your bank or the payment provider, and never need remote access or a gift card.
How do I know Green AV is fake?
Three things give it away. It appears as green AV in the list of installed apps, a window from a program rather than from Windows Security. It pushes you to act quickly by calling, paying or downloading.
And the threats it reports never show up when you run a scan in the real Windows Security app. Microsoft does not put phone numbers in warnings or charge for removing threats through pop-ups. Close the window, do not call, and follow the steps to find and uninstall the program behind it.
Is my card safe after buying Green AV?
Treat it as exposed. The order page belongs to the seller of Green AV, and you cannot know how the number is stored or shared. Ask your bank for a replacement card, which is usually free, and dispute the original charge as a misrepresented product.
Until the new card arrives, check your account daily for small or foreign transactions. If the bank offers alerts for every card payment, turn them on. Keep the receipt and screenshots, because they support the dispute.
Is Windows Security enough to protect me from programs like Green AV?
For most home users, yes, especially with Potentially unwanted app blocking turned on in Windows Security > App & browser control > Reputation-based protection settings. That setting blocks many scareware installers before they run.
No security tool stops every scam, though, because programs like Green AV are usually installed by the user after a frightening message. The habit that helps most is simple: ignore any website or pop-up that claims to have scanned your PC, and never call a number shown in a warning.
Will Fortect remove Green AV?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Green AV, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)