Fake Microsoft Warning Virus Scam Removal (April 2017 Update)

Keep in mind, SpyHunter’s malware & virus scanner is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.


This page aims to help you remove the Fake Microsoft Warning Virus Scam. Our removal instructions work for Chrome, Firefox and Internet Explorer, as well as every version of Windows.

Browser hijackers aren’t the most pleasant of programs to deal with and its latest representative called Fake Microsoft Warning Virus Scam is by far no exception. Once you’ve been infected by a browser hijacker, it’s very difficult to remain ignorant of that fact. Programs like these are actually very keen on making themselves noticed, so we’re guessing that you came to conclude that your PC had indeed been invaded when your Chrome, Firefox, Edge, Opera or other popular browser suddenly started behaving very oddly. We mean the change in its homepage, as well as the replacement of the old default search engine with a new one, which on top of all else also tends to initiate seemingly random and uncalled-for page redirects to various sponsored websites. In addition to the above, browser hijackers also tend to integrate ad-generating components within the users’ browsers, which results in a constant, never ending flow of popups, banners, box messages, in-text links and various other online ads. How do you make this advertising nightmare go away and how do you finally restore your previous browser settings? We will show you how to do that in our professional removal guide, which you can find below on this page. But do read through the following few paragraphs first, in order to gain a better perspective of Fake Microsoft Warning Virus Scam and what it’s up to.

Why browser hijackers behave the way that they do

The generation of the numerous ads may come across as random and many users find themselves wondering what their point is. Well, it’s really quiet simple. There are the products vendors and the service providers who would like to offer their products and services to the public, which is generally always done by means of online ads. hence, the more ads users are exposed to, the more likely they will be to purchase what those ads are promoting. You need to first find out about what you’re buying, if you’re going to buy, right? So, the same obvious principle applies here. One the other hand, we have the browser hijacker developers, who are just as invested in the ad generating process as the vendors. Why? Because they profit based on the number of times you or any other affected user clicks on the said ads. In fact, they earn revenue in accordance with remuneration systems like the Pay Per Click scheme, which foresees a small amount of money for each and every click.

However, this drive to gain as many clicks as possible leads to the developers often resorting to various techniques that don’t gain much approval among both regular users and cyber security experts. For one, in their pursuit of higher revenue, browser hijackers like Fake Microsoft Warning Virus Scam bombard you with ads, making it nearly impossible to dodge them, therefore, you inevitably end up clicking on this banner or that popup. Not to mention the deceitful tactics, where ‘Close’ and ‘X’ options don’t actually terminate and ad, but just redirect you to wherever that ad was set to send you. But there’s a more important and less obvious tactic that these programs use and it involves watching your online browsing patterns and taking them into account when generating their ads for each specific user separately. They can watch your latest search requests, or the pages that you spend the most time on. Even those you bookmark or favorite can tell the hijacker what it is you might be looking for in a product or a service.

Then, based on this data, the hijacker can start showing you ads that are relevant to your browsing habits and, therefore, to your interests. But aside from this being a blatant privacy violation, programs like Fake Microsoft Warning Virus Scam also have the capacity of exposing users to computer viruses and various harmful online threats. Unfortunately, though browser hijackers are not themselves malicious or in any way considered viruses, their many ads could risk getting your infected with something of the rank of a Trojan horse or ransomware, because hackers increasingly often rely on online ads to have their malware distributed to the end users. With this in mind, we strongly advise our readers to try and abstain from clicking on any online ads, no matter how trustworthy they may appear. It would be far easier and safer to simply remove the program generating the majority of them, so as to minimize the risk of a chance encounter with a real virus.

SUMMARY:

Name Fake Microsoft Warning
Type Browser Hijacker
Danger Level Medium (nowhere near threats like Ransomware, but still a security risk)
Symptoms  An change in your browser’s default homepage and search engine, as well as frequent page redirects.
Distribution Method Program bundles, as well as other hijackers and spam emails are the primary sources.
Detection Tool We generally recommend SpyHunter or a similar anti-malware program that is updated daily.

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you’ll need to purchase the full version. More information about SpyHunter and steps to uninstall.

Fake Microsoft Warning Virus Scam Removal

If you are a Windows user, continue with the guide below.

If you are a Mac user, please use our How to remove Ads on Mac guide.

If you are an Android user, please use our Android Malware Removal guide.


Step1

Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).

Step2

WARNING! READ CAREFULLY BEFORE PROCEEDING!

We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. If you want a fast safe solution, we recommend SpyHunter. 

>> Click to Download Spyhunter. If you don't want this software, continue with the guide below.

Keep in mind, SpyHunter’s malware & virus scanner is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab (the “Details” Tab on Win 8 and 10). Try to determine which processes are dangerous. 

malware-start-taskbar

Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at: https://howtoremove.guide/online-virus-scanner/




Scan Results


Virus Scanner Result
ClamAV
AVG AV
Maldet

After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections. 

Step3

Hold together the Start Key and R. Type appwiz.cpl –> OK.

appwiz

You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:

msconfig_opt

Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.

Step4

Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

  1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
  2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
  3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.

DNS

Step5

  • After you complete this step, the threat will be gone from your browsers. Finish the next step as well or it may reappear on a system reboot.

Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).

browser-hijacker-taskbar-properties

Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512  Remove Fake Microsoft Warning Virus Scam from Internet Explorer:

Open IE, click  IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove Fake Microsoft Warning Virus Scam from Firefox:

Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

pic 6

Find the adware/malware —> Remove.
chrome-logo-transparent-backgroundRemove Fake Microsoft Warning Virus Scam from Chrome:

Close Chrome. Navigate to:

 C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.

Step6

WARNING!
To remove parasite, you may have to meddle with system files and registries. Making a mistake and deleting the wrong thing may damage your system.
Avoid this by using SpyHunter - a professional Parasite removal tool.

Keep in mind, SpyHunter’s malware & virus scanner is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!