How to Remove Rogue Anti-Malware

How to Remove Rogue Anti-Malware Guide Updated for 2013 here

Rogue AntiMalware products are installed without user consent and display fake alerts in the windows task bar or inundate the user with popups stating that they are infected. These products are simply fakes and are only trying to obtain your credit card info.



Some Examples of these Rogue AntiMalware Products are:

Virus Heat

Malware Crush

Malware Alarm

Virus Protect

Virus Protect Pro

Dom Media Player

We currently use 3 applications for removing rogue anti-malware applications (they are below). Please note that ALL removal applications should be run in safe mode for best results.

  1. Spyware Doctor with AntiVirus (automatic fixing which is nice!)
  2. MalwareBytes’ rogue remover(free application).
  3. SmitFraudFix (free application)



SmitFraudFix instructions are below:

For best results you should run SmitFraudFix in SafeMode. Instructions can be found below:

Use:

 

    • Search:
      • Double-click SmitfraudFix.exe
      • Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt

 


 

    • Clean:
      • Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
      • Double-click SmitfraudFix.exe
      • Select 2 and hit Enter to delete infect files.
      • You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
      • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
      • A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt

 


 

    • Optional:
      • To restore Trusted and Restricted site zone, select 3 and hit Enter.
      • You will be prompted: Restore Trusted Zone ? answer Y (yes) and hit Enter to delete trusted zone.