"Best Antivirus Software", otherwise known as Best AV Software, has been concocted by hackers headquartered in Eastern Europe countries (Russian Federation is considered, at least for the purpose of this brief review, an Eastern European state).
The program is exported through the worldwide web of no or very uncertain borders into the US, Western Europe, Canada, other English speaking countries.
One may find one's browser loading a page that very promptly reports hundreds of viruses detected on the PC. A user is thus scared into loading and installing the misleading and dangerous counterfeit. To make things worse, the fake online scanner is registered with different IPs, some of which might apply exploit based loading to inject the disastrous adware bypassing user's consent formality.
Eventually, the adware demands a payment when it goes to extermination of the threats it has found. Fortunately, you can calm it down by entering one of the above registration numbers into its registration box.
U2FD-S2LA-H4KA-UEPB
U2FD-S2LA-H4KA-UEKZ
Those activation codes do not remove Best Antivirus Software. The ultimate way to get rid of Best Antivirus Software parasite is explained in the guide below.

Best Antivirus Software - how to remove?
Removal of Best Antivirus Software will for sure enhance computer system performance. If you are still unsatisfied, your PC got more viruses to deal with applying free security solutions – for example, one of those available here. Troubleshooting in case of encountering difficulties to get rid of Best Antivirus Software malware is available with Tutorials.
You can try to use one of the absolutely free programs. Please check our collection of Free Malware Removers.
Best Antivirus Software Removal Manual
Use the following serial code (activation number) to register and uninstall Best Antivirus Software. Note that removal using "Add\Uninstall Programs" Windows feature not able to remove related trojans and parasites
U2FD-S2LA-H4KA-UEPB
Incomplete or incorrect extermination of files and registry values constituting the infection, e.g. deletion of harmless files and registry entries instead of those specified below due to mistyping, is quite possible. Furthermore, resent observations on fake security tools have shown that this kind of malware might strike back, i.e. make harm to computer system in response to attempt of deleting its components.
If you are a Windows user, secure your computer system before proceeding to the adware extermination by means of system and registry backup prior to launching deletion of the adware components.
4 easy steps to remove fake antivirus:
Step1. System Backup
- Windows XP Here
- Windows Vista Here
- Windows 7 Here
Step2. Killing Best Antivirus Software Processes (in Windows)
You must kill Best Antivirus Software processes:
sld.exe kernel32.exe BAa76.exe ScanDisk_.exe
How to kill prcesses.
Once system and registry backup is complete, make sure the infection you want to get rid of is not currently running any processes; otherwise kill its processes in the Task Manager.
Step3. Exposure and Detection and Deletion of Best Antivirus Software Files
Once the targeted infection is idle, you need to find its relevant entries. Some of them might be hidden as the malware often attributes such value to its files in order to reduce the risk of their deletion.
%AppData%\Microsoft\Internet Explorer\Quick Launch\Best Antivirus Software.lnk %AppData%\Best Antivirus Software\ %AppData%\Best Antivirus Software\cookies.sqlite %AppData%\Best Antivirus Software\Instructions.ini %AppData%\Best Antivirus Software\ScanDisk_.exe %CommonAppData%\79b35\ %CommonAppData%\79b35\12.mof %CommonAppData%\79b35\BAa76.exe %CommonAppData%\79b35\BAS.ico %CommonAppData%\79b35\mozcrt19.dll %CommonAppData%\79b35\sqlite3.dll %CommonAppData%\79b35\BackUp %CommonAppData%\79b35\BackUp\Adobe Reader Speed Launch.lnk %CommonAppData%\79b35\BackUp\Adobe Reader Synchronizer.lnk %CommonAppData%\79b35\Quarantine Items\ %CommonAppData%\79b35\BABHBFWS\ %CommonAppData%\79b35\BABHBFWS\BAOHS.cfg %CommonAppData%\79b35\BASSys\ %UserProfile%\Desktop\Best Antivirus Software.lnk %UserProfile%\Recent\dudl.tmp %UserProfile%\Recent\energy.sys %UserProfile%\Recent\energy.tmp %UserProfile%\Recent\exec.tmp %UserProfile%\Recent\kernel32.dll %UserProfile%\Recent\kernel32.exe %UserProfile%\Recent\pal.dll %UserProfile%\Recent\ppal.drv %UserProfile%\Recent\ppal.sys %UserProfile%\Recent\SICKBOY.dll %UserProfile%\Recent\SICKBOY.sys %UserProfile%\Recent\sld.exe %UserProfile%\Recent\sld.sys %UserProfile%\Recent\SM.sys %UserProfile%\Recent\snl2w.sys %UserProfile%\Recent\tjd.dll %StartMenu%\Best Antivirus Software.lnk %StartMenu%\Programs\Best Antivirus Software.lnk
*This malicious software creates the folders and files with random names, most likely you will not find in their files and folders with names such as in the example above, but they will look something like this.
How to Expose and Detect Files

Step4. Delete Best Antivirus Software System Registry Values
Edit System Registry deleting the following entries:
HKEY_CURRENT_USER\Software\3 HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF} HKEY_CLASSES_ROOT\TAA.DocHostUIHandler HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}" HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}" HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "IIL" = 0 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "ltHI" = 0 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "ltTST" HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%" HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = 1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "UID" = "7" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "Mod/4.00007" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "DisallowRun" = 1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "0" = "msseces.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "1" = "MSASCui.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "2" = "ekrn.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "3" = "egui.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "4" = "avgnt.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "5" = "avcenter.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "6" = "avscan.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "7" = "avgfrw.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "8" = "avgui.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "9" = "avgtray.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "10" = "avgscanx.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "11" = "avgcfgex.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "12" = "avgemc.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "13" = "avgchsvx.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "14" = "avgcmgr.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "15" = "avgwdsvc.exe" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Best Antivirus Software" HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe

Disclaimer
