System Care Antivirus
Written by Tomas Meskauskas
Damage level: High
System Care Antivirus - how to remove?
System Care Antivirus is a fake antivirus program which strives to trick PC users into purchasing it's useless license key. It's a malicious software which imitates a legitimate security program and tries to force unsuspecting computer users into buying it. To achieve this deceptive goal System Care Antivirus performs fake computer security check-ups and pretends to detect various high risk malware and virus infections, moreover this rogue program generates various false security warning pop-ups. Most commonly this bogus program installs on user's operating system using found security vulnerabilities, after infiltration it will make certain registry modifications and will block execution of installed software, disable task manager and will hijack Internet browsers.
This fake security scanner originates from a family of rogue antivirus programs called Rogue:Win32/Winwebsec, previous it's variant was called AVASoft Antivirus Professional. PC users should understand that none of the information displayed by System Care Antivirus is real, all the indicated malware and virus infections are imaginary. If you see this program scanning your computer for security infections you can be sure that your PC is infiltrated with a fake antivirus software, the best way of treating it is it's removal from one's PC.
Screenshots of System Care Antivirus:
System Care Antivirus is being distributed using various exploit kits which are capable of detecting the security vulnerabilities of one's operating system or installed software and injecting it with malicious code. The main purpose of this rogue program is forcing computer user's into buying it's full version (99$) - notice that paying for this bogus software would equal to sending one's money to Cyber criminals, furthermore you would also give away your banking information which could easily be used for other rogue purposes. The best way of protecting one's PC from such fake antivirus software is using legitimate antivirus and anti-spyware software. If your computer is already infected with this rogue program you should use the provided removal guide and eliminate it from your PC.
Fake security warning messages generated by System Care Antivirus:
System Care Antivirus Firewall Alert
System Care Antivirus Firewall has blocked a program from accessing the Internet.
Internet Explorer Internet Browser is infected with worm SVCHOST.Stealth.Keyloger. This worm is trying to send your credit card details using Internet Explorer Internet Browser to connect to remote host.
System Care Antivirus Warning
Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss.
Click here to block unauthorised modification by removing threats (Recommended)
System Care Antivirus Warning
Your PC is still infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid the theft of your credit card details.
System Care Antivirus Warning
Intercepting programs that may compromise your privacy and harm your system have been detected on your PC.
Click here to remove them immediately with System Care Antivirus.
Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla FireFox, Outlook and other programs. Click here to remove it immediately with System Care Antivirus.
Application cannot be executed. The file cmd.exe infected.
Please activate your antivirus software.
System Care Antivirus removal:
System Care Antivirus shows fake security warning messages when users tries to access Internet using Internet Explorer, Google Chrome, Mozilla FireFox. To remove this rogue antivirus from your computer you will need to download recommended malware removal software. If your Internet browsers are blocked by "Warning! The site you are trying to visit may harm your computer! Your security setting level puts your computer at risk!" message please click on "Ignore warnings and visit that site in the current state (not recommended)" and continue with the download process.
If you can't run the remover, try to downloading alternate installer (It is renamed to iexplore.exe - most of fake antivirus programs doesn't block execution of files with this name)
Optional method to download the recommended anti-spyware program:
If you can't access your Internet browsers: Click Start then click Run. (Click Windows logo in Windows 7 and Windows Vista)
In Windows XP, When the Run dialog appears enter this text: www.pcrisk.com/download-spyware-remover and then press ENTER. In Windows 7 and Windows Vista you can type this line directly in the search field and then press ENTER.
After pressing enter, the File download dialog of recommended malware removal software will appear. Click Run and follow the on-screen instructions.
If you still were unable to download the recommended malware removal software - Before downloading, enter a retrieved license key in registration window of System Care Antivirus. Click "registration" button at the top of the main window of this fake antivirus software and enter this key:
Notice that entering this registration key will not remove System Care Antivirus - it will make the removal process less complicated. This fake antivirus software will stop generating fake security warning messages and will allow execution of installed software.
System Care Antivirus removal using Safe Mode with Networking:
1. Load your computer in Safe Mode with Networking: Click Start, click Shut down, click Restart, click OK. During your computer starting process press F8 key on your keyboard multiple times until you see Windows Advanced Option menu, then select Safe mode with networking from the list.
Video showing how to start Windows 7 in "Safe Mode with Networking":
Windows 8 users: Start Windows 8 is Safe Mode with Networking: Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click on Advanced startup options, in the opened "General PC Settings" window select Advanced startup. Click on "Restart now" button. Your computer will now restart into "Advanced Startup options menu". Click on the "Troubleshoot" button, then click on "Advanced options" button. In the advanced option screen click on "Startup settings". Click on the "Restart" button. Your PC will restart into Startup Settings screen. Press "5" to boot in Safe Mode with Networking.
Video showing how to start Windows 8 in "Safe Mode with Networking":
2. System Care Antivirus modifies system hosts file. It is used to resolve some canonical names of websites to ip addresses. When it is changed, the user may be redirected to malicious site still seeing good URL in address bar. It is very hard to find out if the site is genuine or not, when hosts file is modified. To fix this, please download Microsoft FixIt tool, that restores your hosts file to windows default. Run this tool when downloaded and follow the on-screen instructions. Download link below:
3. Download and install recommended malware removal software to completely remove this fake antivirus from your PC.
NOTE: Rogue antivirus programs can block the download of anti-spyware software, if you can't download it using the default location, try one of the alternative download locations below:
- Location 1 (The file is renamed to "iexplore.exe" because most of spyware doesn't block this file)
- Location 2
System Care Antivirus removal using a retrieved license (registration) key:
Here is a video showing how to get rid of System Care Antivirus:
1. Wait until System Care Antivirus rogue antivirus will finish it's fake security scan and click on the "Registration" button which is located at the top right corner of the main window.
2. In the opened window enter this retrieved registry key: AA39754E-715219CE This will trick System Care Antivirus into believing that you have already payed for it's full version. This step makes the removal process of this rogue antivirus program less complicated, after entering this registry key System Care Antivirus will allow execution of installed software (including Internet browsers) and you will be able to download anti-spyware software without various interruptions.
3. After entering this licence key System Care Antivirus will generate a couple of messages thanking you for registration and will imitate the removal process of previously detected malware and virus infections. Notice that after you enter the correct registration key System Care Antivirus will change it's user's interface color to while instead of red.
4. Notice that entering this registration key doesn't remove System Care Antivirus from your computer - it makes the removal process less complicated. To completely remove this rogue antivirus from your computer download and install recommended anti-spyware software.
Other tools, known to remove System Care Antivirus:
Optional methods which can be used to eliminate System Care Antivirus:
Remove System Care Antivirus using a new user account.
System Care Antivirus removal using System Restore.
System Care Antivirus removal using a Rescue Disk.
If you can't access Internet please follow these instructions.