Red Cross Antivirus: what it is and how to remove it

Red Cross Antivirus is a rogue antivirus program that reports false system security threats to make you think that your computer is infected with severe malware. Recently, this rogue program is being distributed through the use of the fake Microsoft Security Essentials Alert Trojan.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If Red Cross Antivirus keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Red Cross Antivirus yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Red Cross Antivirus: screenshot
Red Cross Antivirus as our 2021 report showed it.

Red Cross Antivirus: summary

DistributionFake online virus scanners, software bundles, deceptive ads
DamageMoney loss, real malware infections
nameRed Cross Antivirus
TypeFake security software, rogue antispyware
PurposeDeceive users into thinking their computers are infected with malware to sell its paid version
Detection namesNo Microsoft detection name is known
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 6 more facts
NameRed Cross Antivirus
SymptomsAn unknown program in Installed apps
EvidenceOne write-up by a security site; details still limited
ProgramRed Cross Antivirus
First seen30 April 2021
Facts checked6 October 2026

Is Red Cross Antivirus a real security program?

From our report of Apr 2021 · not reviewed since

Red Cross Antivirus –

Red Cross Antivirus is a rogue antivirus program that reports false system security threats to make you think that your computer is infected with severe malware.

Recently, this rogue program is being distributed through the use of the fake Microsoft Security Essentials Alert Trojan.

Red Cross Antivirus is a typical rogue program, just like Peak Protection 2010, Pest Detector 4.1, Major Defense Kit, or AntiSpy Safeguard.

Don't worry, the scan results are false. You can safely ignore them. This also applies to fake warnings and pop-ups shown by the fake security tool.

Some of those fake alerts will state that your computer is under attack from a remote computer and that the RedCrossAntivirus has blocked a remote login attempt to your computer. Please don't purchase this bogus program. Instead, remove it either manually or automatically.

While Red Cross Antivirus is running, it will also block legitimate programs and security-related websites, including 2-spyware.com. It will probably block Task Manager and Registry Editor too. Also, note that you shouldn't use system restore to remove this virus.

Of course, it might be an option, but usually, rogue programs infect system restore points as well. If you find that your computer is infected with Red Cross Antivirus malware, please uninstall it from the system upon detection. If you have already purchased the rogue program, then please contact your credit card company and dispute the charges.

We strongly recommend using an automatic removal tool to remove the rogue program and any related malware from the computer. Proper, time-proven security software will protect your computer from such threats and hazardous malware. Once the rogue antispyware removal is completed, run system diagnostics with appropriate software to repair system-related issues.

Red Cross Antivirus: screenshot
Red Cross Antivirus in our 2021 report.

From our report of Apr 2021 · not reviewed since

More from our earlier report on Red Cross Antivirus

  • Scan the computer with proper security software to remove this parasite
  • With PC tune-up tools like the app, you can restore any damages caused by cyber infections

How to remove Red Cross Antivirus

Nothing it reports is real.

These steps remove it and undo a payment if you made one.

  1. Step 1: Do not pay, and undo a payment if you made one

    Red Cross Antivirus reports problems to sell a licence: the "threats" or "errors" it lists are invented or harmless leftovers. If you already paid, ask your card issuer to dispute the charge and cancel the subscription both in the seller's account and through your bank.

    If you called a phone number it showed and let someone connect, treat the PC as remotely accessed and remove the remote tool. Uninstalling it from Windows 11 or Windows 10 does not cancel a subscription by itself.

    Full procedure with screenshots: What to do after paying a scammer

  2. Step 2: Uninstall Red Cross Antivirus

    Open Settings > Apps > Installed apps in Windows 11, or Settings > Apps > Apps & features in Windows 10.

    Sort the list by install date and find Red Cross Antivirus, then choose Uninstall from the three-dot menu next to it (in Windows 10, click the entry and then Uninstall).

    Remove anything else installed on the same day that you do not recognise, because such programs usually arrive together in one installer. If the uninstaller opens a browser page with an offer or a survey, close it: the program is removed either way.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  3. Step 3: Remove it from startup

    Whatever Red Cross Antivirus installed usually starts with Windows.

    Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  4. Step 4: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  5. Step 5: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.

If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.

Recover files after data-affecting malware attacks

While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.

More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.

Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.

Questions about Red Cross Antivirus

What is Red Cross Antivirus and why is it on my PC?

Red Cross Antivirus is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.

Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need Red Cross Antivirus, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.

How do I stop programs like Red Cross Antivirus from being installed again?

Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.

Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped Red Cross Antivirus before it reached the app list.

I entered my card number in Red Cross Antivirus. What should I do?

Call your card issuer using the number on the back of the card, report the purchase as fraud and ask for a new card. Ask them to block further charges from the same merchant. Watch your statements for small test charges, which often come before larger ones.

If you used a password on the order page or the same e-mail for the purchase, change that password and expect phishing e-mails that mention the purchase. Your bank can also tell you whether the merchant is linked to other fraud reports.

Will the seller of Red Cross Antivirus refund me if I ask?

Sometimes, but do not depend on it and do not let them steer the process. If you contact the seller, do it in writing and keep the replies. Never install software, share your screen or give banking details to get a refund.

The more reliable route is your card issuer or PayPal: a chargeback or dispute for a product sold with false claims. If the seller or anyone claiming to represent them calls you first about a refund, treat it as a scam and hang up.

How do I know Red Cross Antivirus is fake?

Three things give it away. It appears as red Cross Antivirus in the list of installed apps, a window from a program rather than from Windows Security. It pushes you to act quickly by calling, paying or downloading.

And the threats it reports never show up when you run a scan in the real Windows Security app. Microsoft does not put phone numbers in warnings or charge for removing threats through pop-ups. Close the window, do not call, and follow the steps to find and uninstall the program behind it.

Should I reset my PC because of Red Cross Antivirus?

Only if the signs point to deeper access. Reset when you see red Cross Antivirus in the list of installed apps again after removal, when Windows Security cannot start or update, when remote access tools you did not install keep appearing, or when you simply cannot trust the PC any more.

Otherwise, the plan in this guide plus an offline scan is enough. If you do reset, choose Remove everything and Cloud download for a fresh copy of Windows, restore only documents and photos, and reinstall programs from their official sites. Change important passwords from the clean system afterwards.

What if I paid Red Cross Antivirus?

Contact your bank or card issuer the same day, explain that the payment went to a fake security program and ask for a chargeback. Keep screenshots of red Cross Antivirus in the list of installed apps, the payment receipt and any e-mails.

If you gave card details in the program, ask the bank to block and replace the card. Then uninstall the program and run a full scan in Windows Security. If you also called a number and let someone connect to your PC, uninstall the remote-access tool they used and change your passwords from another device.

What is Red Cross Antivirus?

Red Cross Antivirus is fake security software, sometimes called a rogue antivirus or scareware. The program, Red Cross Antivirus, shows invented or exaggerated problems to make you pay for a licence, and some versions send you to phone "support".

It does not protect the PC, and the threats it lists are not a reason to pay. Fake security programs usually arrive through fake virus warnings on websites, extra offers in free installers or ads for faster PCs. Uninstall it and use the free protection built into Windows instead.

Do I need to buy antivirus after removing Red Cross Antivirus?

No. Windows 11 and Windows 10 include Microsoft Defender in Windows Security, which provides real-time protection, scheduled scans, the offline scan and protection against unwanted apps at no cost. Keep it switched on and updated, and turn on Reputation-based protection under App & browser control.

If you prefer a third-party product, buy it from the vendor's own site after reading independent test results, never from a pop-up or a phone call. The lesson of Red Cross Antivirus is that security offers which arrive unasked are the ones to avoid.

Will Fortect remove Red Cross Antivirus?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Red Cross Antivirus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove "Unauthorized Access Detected" virus

“Unauthorised Access Detected” scam strikes again “Unauthorised Access Detected” virus operates as a tech support scam which scares users with fake claims that their computers might have been disabledRogue Anti-SpywareHigh riskJulie Splinters ·

Remove Systemcare-antivirus.org

Systemcare-antivirus.org is a fraudulent website that should always be avoided. You may run into it with and even without your knowledge because it has been promoted with a help ofRogue Anti-SpywareHigh riskUgnius Kiguolis ·

Remove Windows Antivirus 2008

Windows Antivirus 2008 – a fake security tool showing false-positive scan results Windows Antivirus 2008 is a corrupt security tool that is promoted as useful anti-spyware software. It manipulates the nameRogue Anti-SpywareMedium riskLucia Danes ·

Remove Personal Security

Personal Security - a fake anti-malware tool that will scam you out of your money Personal Security is a misleading anti-spyware application that displays fake security alerts/pop-ups and reports falseRogue Anti-SpywareMedium riskUgnius Kiguolis ·

Questions and experiences: Red Cross Antivirus

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year