Windows Guardian Angel


Call Toll Free in the US and Canada!


Title: Windows Guardian Angel
Type: Rogue Antispyware

Remove Windows Guardian Angel. Removal instructions

 
Also known as: WindowsGuardianAngel
Severity scale:  (80 / 100)

 

Windows Guardian Angel is a fake program that imitates a legitimate anti-spyware tool in order to earn money from computer users. The application infiltrates computer without any notification and it doesn’t need authorization of its user.

Windows Guardian Angel is installed with a help of Trojan viruses that spread on malicious websites promoting online scanners. The program invades the system using rough techniques. It quickly integrates there and blocks your reputable anti-spyware tools in order to make it difficult to be removed.

The application looks exactly like a legitimate anti-spyware removal software. It runs the scan on your machine and after it finishes. Windows Guardian Angel displays a list of infected files. In reality these scan results doesn’t reflect a real condition of your computer.

However, Windows Guardian Angel insists removing them and this, however, is possible only if you register its copy. Of course, you are asked to pay for this license and that is how the creators of Windows Guardian Angel gain money from the users of infected computers.

The program also modifies some keys in Windows Registry and hijacks your Internet Browser. It displays a bunch of various alerts which warn about spyware infections detected on your system. These notifications also claim that you need to purchase Windows Guardian Angel in order to fix the protection problems on your computer:

Torrent Alert
Recomended: Please use secure encrypted protocol for torrent links.
Torrent link detected!
Receiving this notification means that you have violated the copyright laws. Using Torrent for downloading movies and licensed software shall be prosecuted and you may be sued for cybercrime and breach of law under the SOPA legislation.
Please register your copy of the AV to activate anonymous data transfer protocol through the torrent link.

Warning! Identity theft attempt Detected
Hidden connection IP: xxxxxxxxx
Target: Your passwords for sites

Warning
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:\Windows\system32\dllcache\wmploc.dll
C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.

Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.

Error
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.

Ignore these messages just like the scan results and do not pay for activating this scam application. Instead you should get rid of Windows Guardian Angel itself with a reliable anti-spyware program, like . If you have already paid for this malicious program you can still try to contact your credit card company so that the charges would be canceled. Windows Guardian Angel is totally worthless software and you should not waste your money on it.

Automatic Windows Guardian Angel removal:

remover for Windows Guardian Angel

SpyHunter is recommended remover to uninstall Windows Guardian Angel.
You should confirm using free trial that it detects current version of parasite.

Note:
Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention,
please read manul removal instructions below.

If you failed to remove Windows Guardian Angel using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.

STOPzilla


We are testing STOPzilla’s efficiency at removing Windows Guardian Angel
(2012-03-20 07:24:53)

Malwarebytes Anti Malware

We are testing Malwarebytes Anti Malware’s efficiency at removing Windows Guardian Angel
(2012-03-20 07:24:53)

Spyware Doctor

We are testing Spyware Doctor’s efficiency at removing Windows Guardian Angel
(2012-03-20 07:24:53)

XoftSpySE Anti Spyware

Windows Guardian Angel manual removal:

Kill processes:
%appdata%\Inspector-[rnd].exe %AppData%\Protector-[rnd].exe

HELP:
how to kill malicious processes

Delete registry values:
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Policies\\System “DisableRegedit” = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Policies\\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Policies\\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Run “Inspector”
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Settings “net” = “2012-3-11_2?
HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Settings “UID” = “origkboryd”
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\InternetExplorer\\Main\\FeatureControl\\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\atcon.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\bipcp.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\ecengine.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\infwin.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\msconfig
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\PavFnSvr.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sahagent.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\titaninxp.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\wsbgate.exe

HELP:
how to unregister malicious DLLs

Delete files:
%AppData%\NPSWF32.dll %AppData%\Protector-3 characters.exe %AppData%\result.db %CommonStartMenu%\Programs\Windows Managing System.lnk %Desktop%\Windows Managing System.lnk

HELP:
how to remove harmful files
Information added: 2012-03-20 07:24:53
Information updated: 2012-03-20 07:24:53