Windows Protection Unit


Call Toll Free in the US and Canada!


Title: Windows Protection Unit
Type: Rogue Antispyware


Remove Windows Protection Unit. Removal instructions

 
Also known as: Windows Protection Unit
Severity scale:  (72 / 100)

 

Windows Protection Unit is a rogue anti-spyware program with aim to scare you into thinking that your computer is infected and to make you buy useless security product. If your computer is infected with this rogue anti-spyware program, don’t purchase it! It is a scam and has nothing to do with genuine antivirus software. Instead, remove Windows Protection Unit from your computer as soon as possible and do not allow it to download additional malware. The rogue anti-spyware program is usually promoted through the use of trojans, fake online anti-malware scanners and hacked websites. Once your computer is infected with either trojan downloaders or scareware, you will be flooded with fake security alerts and notifications from Windows task bar claiming that your computer is seriously infected and that you must use Windows Protection Unit in order to clean your computer. 

When running,Windows Protection Unit will start a fake system scan and report many non-existent infections. The scan is fabricated from start untill end, these infections are all fake and don’t actually exist. The truth is that this program is unable neither to detect nor to delete any kind of infections. To make things worse, Windows Protection Unit will constantly display pop-ups and security warnings very similar to those shown by Windows Security Center. These alerts will state that your computer is infected with malware, e.g. spyware, trojans or even viruses. All this undesirable behavior is done only to trick you into purchasing Windows Protection Unit. 

Warning
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:\Windows\system32\dllcache\wmploc.dll
C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.

Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.

Error
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.

What is more, this rogue anti-spyware program hijacks Internet Explorer and redirects the users to malicious websites that promote Windows Protection Unit or other malware. In some cases, this virus modifies Windows HOST file and blocks certain websites in order to protect itself from being removed. As you can see, this program is harmful and must be removed upon detection. The removal guide below provides all information required to remove Windows Protection Unit from your computer. We strongly recommend you to use malware removal software given below.

Automatic Windows Protection Unit removal:

remover for Windows Protection Unit

Spyware Doctor is recommended remover to uninstall Windows Protection Unit.
You should confirm using free trial that it detects current version of parasite.

Note:
Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention,
please read manul removal instructions below.

If you failed to remove Windows Protection Unit using Spyware Doctor please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.

SpyHunter

We are testing SpyHunter’s efficiency at removing Windows Protection Unit
(2012-04-15 13:25:46)

STOPzilla

We are testing STOPzilla’s efficiency at removing Windows Protection Unit
(2012-04-15 13:25:46)

Malwarebytes Anti Malware

We are testing Malwarebytes Anti Malware’s efficiency at removing Windows Protection Unit
(2012-04-15 13:25:46)

XoftSpySE Anti Spyware

Windows Protection Unit manual removal:


Kill processes:
Inspector-[rnd].exe Protector-[rnd].exe

HELP:
how to kill malicious processes

Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe

HELP:
how to remove registry entries

Delete files:
%AppData%\Inspector-[rnd].exe %AppData%\Protector-[rnd].exe

HELP:
how to remove harmful files
Information added: 2012-04-15 13:25:46
Information updated: 2012-04-15 13:25:46