SAntivirus Realtime Protection Lite is basically SegurazoThreat SummaryDistribution of the fake antivirusRemove SAntivirus Realtime Protection Lite (SEGURAZO)Step 1. Disable Network ConnectionStep 2. Set EnableLUA key value to 0Step 3. Use SAntivirus UninstallerStep 4. Clean Windows Registry from SAntivirus/Segurazo remainsStep 5. Force delete leftover files in the installation folder

The program causes extreme annoyance for computer users as it cannot be uninstalled like any regular program due to its trickeries to stay on the infected host. Besides, since it spreads alongside low-reputation programs such as miners or fake browsers, it slows down the computer system significantly. This guide explains how to uninstall SAntivirus manually, step-by-step. We can firmly state that this is unique and the most detailed guide for home users. Previously known as Segurazo Antivirus, the operators behind this unwanted software began its distribution campaign in 2019. However, in 2020 it has changed its name to SAntivirus Realtime Protection Lite. It is believed this was done due to a rising users’ dissatisfaction as well as low reputation of the software (there are hundreds of user-created topics questioning how to remove this fake antivirus from their computers on forums like Reddit). As mentioned earlier, users find it impossible to uninstall the program via Control Panel or Apps and Features. Moreover, some victims claim that it makes the whole SAntivirus removal process even harder. It is clear that the software tends to root deeply into the system to prevent its elimination. This definitely signals that the program should be trusted and must be removed from the system as soon as possible.

Threat Summary

Distribution of the fake antivirus

The most suspicious fact about SAntivirus (Segurazo) mainly spreads in software bundles and not via its official website. We have investigated users’ feedback online and have discovered that this program mainly spread via general software download websites, outdated and no longer supported software and old game downloads or ROMs. Some of the programs that users claim to be spreading Segurazo via their installers are:

NOX Player app;VirtualDub;various abandonware (outdated and old game downloads) and other sources.

It is also worth mentioning that users who have installed this fake antivirus often report founding versions of Chromium virus installed on their systems. Therefore, we strongly recommend you to check for it as well. Please share how you downloaded this program in the comments below. This will help others from getting caught in the same trap again.

Remove SAntivirus Realtime Protection Lite (SEGURAZO)

This guide explains how to remove SAntivirus Realtime Protection Lite yourself (without using any tools or software). Please understand that deleting this fake antivirus from your computer requires some time and patience, so if you rather delete it automatically, consider downloading RESTORO. Now, there are two essential things you need to know in order to complete the program’s removal successfully. First, you need to boot your PC in Safe Mode. If you do not want to boot your PC in Safe Mode, you must disable network connection first. We will explain how to do everything in this detailed tutorial.

Step 1. Disable Network Connection

Please disable network connection before you begin removing SAntivirus Realtime Protection Lite. Ideally, keep this tutorial opened in a separate window during the unwanted program removal procedure. We suggest disabling in via Windows Network and Sharing Center as explained below. An alternative way to disable Network Connection is to boot in Safe Mode. If you find that you still can’t delete some unwanted folders and files after disabling network connection, then try booting in SAFE MODE as explained here (includes guide to booting in normal mode as well) and then delete the residue of the unwanted program.

Step 2. Set EnableLUA key value to 0

Users have reported that temporarily disabling User Account Control via Windows Registry helped them to remove stubborn Segurazo folders that couldn’t been removed in a simple way. Please note that disabling UAC is a temporary measure and after performing SAntivirus removal, you should repeat these steps, reverting the EnableLUA value back to 1 (true) value.

Step 3. Use SAntivirus Uninstaller

Now that Network Connection is disabled, you can run SAntivirus Realtime Protection Lite Uninstaller. It will help to get rid of PART of files. However, we will explain how to perform a manual computer cleanup of Segurazo remains in Windows later. Here’s what you need to do: If any files will be left, we will delete them later via CMD.

Step 4. Clean Windows Registry from SAntivirus/Segurazo remains

In this part, we will clean Windows Registry from keys and values associated with SAntivirus Realtime Protection Lite (widely known as Segurazo). In order to remove SAntivirus Realtime Protection Lite remains from your computer’s registry, we will need to navigate through the registry by expanding folders in given order. Please be extremely careful and double-check what you’re deleting before doing so. Incorrect removal of keys can mess up your computer. In addition, consider backing up registry first. TIP #1. We strongly suggest dragging the required columns in the Registry (such as name) to expand them so that you can see the key/value names clearly. TIP #2. You can easily copy and paste given navigation route to the navigation bar in the Windows registry and press Enter to access specific folder faster. Or, you can expand each folder by hand. TIP #3. If you find that you cannot delete certain values in the registry, simply right-click the key and choose Permissions. Then tap on Administrator, and put a check on Read&Write. Then click Apply and OK. You can see an example below.

Now that you have read all three tips, you can start deleting unwanted values from Windows Registry to completely get rid of SAntivirus Realtime Protection Lite. The SAntivirus Realtime Protection Lite removal from Windows registry should now be complete. Next, we are going to delete any remaining values from the computer using Command Prompt. Then press Enter. You will need to delete the detected keys (on the left side of the Registry) or value on the right side. To find next value, click Edit>Find Next. You should delete the following components:

Step 5. Force delete leftover files in the installation folder

By now, you should have removed all remains of Santivirus (Segurazo). However, if you’d rather opt for automatic removal of it, or if you’d like to double-check your system and perform PC repair, we suggest downloading RESTORO for this matter. OUR GEEKS RECOMMEND Our team recommends a two-step rescue plan to remove ransomware and other remaining malware from your computer, plus repair caused virus damage to the system: GeeksAdvice.com editors select recommended products based on their effectiveness. We may earn a commission from affiliate links, at no additional cost to you. Learn more. Get INTEGO ANTIVIRUS for Windows to remove ransomware, Trojans, adware and other spyware and malware variants and protect your PC and network drives 24/7. This VB100-certified security software uses state-of-art technology to provide protection against ransomware, Zero-Day attacks and advanced threats, Intego Web Shield blocks dangerous websites, phishing attacks, malicious downloads and installation of potentially unwanted programs. Use INTEGO Antivirus to remove detected threats from your computer. Read full review here. RESTORO provides a free scan that helps to identify hardware, security and stability issues and presents a comprehensive report which can help you to locate and fix detected issues manually. It is a great PC repair software to use after you remove malware with professional antivirus. The full version of software will fix detected issues and repair virus damage caused to your Windows OS files automatically. RESTORO uses AVIRA scanning engine to detect existing spyware and malware. If any are found, the software will eliminate them. Read full review here.