Remove Windows Antivirus Patch. Removal instructions
Windows Antivirus Patch is a rogue anti-spyware program that is promoted through the use of hacked websites and fake web pop-ups claiming that your computer is infected with spyware and trojans. Very often this fake anti-spyware program is installed on the system without users’s knowledge or permission. However, sometimes, users install such rogueware manually but they think that this software is legitimate. Once Windows Antivirus Patch is installed it will perform a quick system scan and state that your computer is infected with spyware, Trojans and other viruses. It will then prompt you to pay for a full version of the program to remove the infections; otherwise your personal information can be stolen and your files can be deleted. Of course, those infections are all fake and do not exist on your computer, so don’t purchase it. Instead, please follow the removal instructions below to remove Windows Antivirus Patch from your computer as soon as possible.
While running, the rogue program will display numerous fake security alerts and notifications on your computer claiming that your are infected. Windows Antivirus Patch will state that your computer is under attack from a remote computer or that there are many infected files on the system. It may also state that you will lose all your sensitive information and important files if you won’t purchase the program and remove malware from your PC. These alerts, like the fake scan results, are designed to scare you into thinking that your computer has been compromised. Just like the scan results, these fake alerts are all fake and the only real infection is Windows Antivirus Patch itself.
Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Error
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.
If your computer is infected with Windows Antivirus Patch, remove it from the system as soon as possible. If you have already purchased it, then contact your credit card company and dispute the charges. Last, but not least, please use the removal instructions below to remove Windows Antivirus Patch and related malware from your computer either manually or with an automatic removal tool.
Windows Antivirus Patch snapshot:
Automatic Windows Antivirus Patch removal:
(2012-04-16 07:24:24)
(2012-04-16 07:24:24)
(2012-04-16 07:24:24)
Windows Antivirus Patch manual removal:
Kill processes:
Inspector-[rnd].exe Protector-[rnd].exe
how to kill malicious processes
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
how to remove registry entries
Delete files:
%AppData%\Inspector-[rnd].exe %AppData%\Protector-[rnd].exe
how to remove harmful files
Information updated: 2012-04-16 07:27:18