Rogue:JS/FakeAV
Rogue:JS/FakeAV is a detection for another variant of a group of Trojan that spreads fake antivirus programs. Flashing of Rogue:JS/FakeAV infection denotes that malicious HTML or JavaScript file is detected on the computer. This virus attempts to lure you into downloading a copy of a rogue program.
Damage Level: Medium
Systems Affected: Windows 9x/ME, 2000, XP, Windows Vista, Windows 7
Characteristics
Once Rogue:JS/FakeAV is executed on the machine, it will redirect your Internet browser to a fake online virus scanner web site. The site will execute a virus scan. Unsuspecting victim’s thinks that the scan is running locally because the virus will mimic Windows Explorer as its scanner interface.
After the scan, it will display an alert stating that your computer is in trouble. Next, it will try to convince you to run a more precise virus scan by downloading a trial version of rogue security product. Rogue:JS/FakeAV will display the following message:
Windows Antivirus 2012 has found critical process activity on your PC and will perform fast scan of system files!
Here is the screenshot image of this fake alert.

When you follow this prompt, it instantly download and install the rogue software that will make your PC inoperable until you purchase the paid version.
Distribution
Rogue:JS/FakeAV is mainly distributed as part of Trojan Downloader. It means that other Trojan who has gain access to your computer may have dropped this virus. File-sharing networks and spam email messages are also considered additional method for its propagation.
How to Remove Rogue:JS/FakeAV
1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Open your antivirus application and update the virus definitions. This method ensures that your antivirus program can detect even newer variants of Rogue:JS/FakeAV.
3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Select Safe Mode with Networking.
- System will boot Windows loading only necessary drivers and system files.
4. Open your antivirus program and run a full system scan. After the scan, delete all infected items. If unable, better place them in quarantine. Once the scan is complete, please proceed with the next step.
Online Virus Scanner:
Another way to remove Rogue:JS/FakeAV without the need to install additional antivirus application is to perform a thorough scan with free online virus scanner that can be found here or on websites of legitimate anti-virus and security provider.
5. Go to Online Virus Scanner list and run a virus scan. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.
6. After completing the necessary download, your system is now ready for online virus scanning.
7. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
8. Remove or delete all detected items.
9. When scanning is finished, you may now restart the computer in normal mode.
Automatic Removal of Rogue:JS/FakeAV
In order to completely remove the threat, it is best to download and run this tool. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.Alternative Removal Method for Rogue:JS/FakeAV
Option 1 : Use Windows System Restore to return Windows to previous state
If Rogue:JS/FakeAV enters the computer, there is a big chance that Windows files, registry entries and other essential components are also infected. System Restore can reinstate clean system files by restoring the configuration to an earlier date. The method also replaces compromised files with a clean version. If you have a saved restore point before Rogue:JS/FakeAV infiltrates the PC, we highly encourage you to execute this procedure if none of the above works. You may proceed with Windows System Restore, click here to see the full procedure.