It came to my attention today that there is a fake AVG Anti-virus (avg.exe) floating around on the internet. AVG can now add itself to the list of anti-virus programs which are a victim of their own success as malware writers now consider it widespread enough to be worthy of imitation.
How to tell Fake AVG Anti-virus (avg.exe) from the real AVG Anti-virus
If we look at the two screenshots below you can see that there are a few differences between the fake and the genuine AVG Anti-virus.


You don’t have to look too closely to see the following differences:
1) The colour scheme on the fake AVG is light blue whereas with the real AVG the colour scheme is much darker.
2) With the fake AVG Anti-Virus here’s no “File Components History Tools Help” menu bar.
3) The menu on the left hand side of the program is laid out differently.
4) The information at the bottom of the left hand side menu is laid out differently.
5) If you open task manager there will be a process running called avg.exe – this is the fake anti-virus program. With the genuine version of AVG Anti-virus there is no program or process called avg.exe (see screenshot below from Windows XP Task Manager).

Fake AVG Anti-virus (avg.exe) Malware Removal
If you have determined that the Fake AVG Anti-virus (avg.exe) is installed on your computer then you need to remove it as soon as possible. According to some reports the Fake AVG Anti-virus is also bundled with spyware which will track the websites visited. As avg.exe appears to block downloads from anti-virus sites and prevents the installation of anti-virus and anti-malware programs here’s the steps I used to remove the infection and the changes it made to the computer.
1) On another computer download MalwareBytes Anti-Malware from Filehippo and copy it to a USB memory stick.
2) Reboot your computer into Safe Mode. To do this, turn your computer off and then back on and start tapping the F8 key on your keyboard. Eventually you will be brought to a menu similar to the one below:

Use the arrow keys on your keyboard, select Safe Mode and press Enter on your keyboard.
Windows will now boot into safe mode and prompt you to login. Login with your usual username and password.
3) Install MalwareBytes Anti-Malware from the USB stick.
4) Run the program using the “Perform Full Scan” setting – this will remove SOME of the files and registry entries created by avg.exe.
5) Re-start the computer normally and login with your usual username and password.
6) Run MalwareBytes Anti-Malware again. Use the “Perform Full Scan” setting again – this will remove any remaining files and registry entries.
7) Perform a Full System Scan or Whole Computer Scan with your anti-virus program. If you don’t have any anti-virus installed then you can download AVG Free Edition from Filehippo.com
Once you have scanned your computer in Safe and Normal Mode followed by a full scan with your anti-virus then the AVG Fake Anti-Virus (avg.exe) should of been completely removed from your system.
More technical details regarding Fake AVG Anti-virus (avg.exe) can be found at Bleeping Computer by clicking the link below:
Remove AVG Anti-virus 2011 (avg.exe)
If you have followed this guide successfully then “Share the knowledge” using one of the links below and feel free to comment below.