Home Malware Programs Rogue Anti-Virus Programs SFX Fake AV

SFX Fake AV

Posted: April 13, 2012

Threat Metric

Ranking: 6,908
Threat Level: 2/10
Infected PCs: 5,485
First Seen: April 13, 2012
Last Seen: October 10, 2023
OS(es) Affected: Windows

SFX Fake AV Screenshot 1SFX Fake AV is a combination of ransomware Trojan and rogue anti-virus program that locks down your PC and requests that you purchase a registered version of its 'AV' software, supposedly as a consequence of your computer being used to commit illegal file-trafficking activities. However, SFX Fake AV isn't affiliated with any type of legal agency and its software registration offer doesn't have any purpose except to steal money and financial information from its victims. In an innovative fashion for a ransomware Trojan, SFX Fake AV also displays some characteristics that are common to its family members such as creating fake pop-up alerts about nonexistent PC threats on your computer. Although removing SFX Fake AV may be difficult due to its tendency to block other applications that could assist with its deletion, SpywareRemove.com malware experts note that it's both possible and desirable to delete SFX Fake AV with suitable anti-malware products, which will restore your computer back to good health.

SFX Fake AV – a Downloading-Aficionado's Worst Fears Come True

Most ransomware Trojans that SpywareRemove.com malware researchers have analyzed use threats about catching their victims engaged in commonly-committed online crimes, such as downloading illegal files, to lend believability to their scam, and SFX Fake AV is simply one of the latest variants in this philosophy. Some of its predecessors' choice of threat targets torrent-users specifically, and its warnings of potential lawsuits even include mention of the much-reported SOPA legislation. Other types of pop-up alerts may also be on display, such as fake system scans and fake detections of a 'Porn-Tool' program that's infecting Windows system components. SpywareRemove.com malware experts encourage you to ignore all pop-up alerts, warnings and other messages from SFX Fake AV, which has no legal ground to stand on, nor legitimate AV software to provide in its registration process.

SFX Fake AV's presence is also problematic in that SFX Fake AV attempts to prevent you from using security and diagnostic programs that could help to detect or delete SFX Fake AV. Applications that fall victim to these attacks include Process Explorer, a Windows utility that tracks which files and directories are used by any given program, as well various web browsers. This issue causes SpywareRemove.com malware researchers to recommend disabling SFX Fake AV before you try to remove SFX Fake AV, and also classifies SFX Fake AV as a significant security threat.

How to Take SFX Fake AV Out and Get Back to Your (Hopefully Legal) Downloading Experience

SFX Fake AV is still a very recently identified PC threat, and you may need to update your anti-malware software before it can find or remove SFX Fake AV from your computer, particularly given that SFX Fake AV has already been observed to exist in multiple variants. Since SFX Fake AV uses system changes that block other applications, it's not recommended that you remove SFX Fake AV without any help from software that can also reverse its settings alterations. Above all else, SpywareRemove.com malware research team warns against trying to buy SFX Fake AV's related AV scamware, since this will waste your money and expose your financial information to criminal abuse.

If you need to disable SFX Fake AV to scan your PC with appropriate anti-malware programs or use a web browser to download such scanners, several different methods can be used to bypass the startup routine for SFX Fake AV. Some of the most common solutions that SpywareRemove.com malware analysts have found helpful include:

  • Booting your OS from a removable drive (such as a USB device).
  • Rebooting in Safe Mode, which is available on all versions of Windows.
  • Booting your OS from a network-shared drive.


SFX Fake AV Screenshot 2

Technical Details

Additional Information

The following URL's were detected:
everyday-news-channel.com
Loading...