Windows Active Guard  

Windows Active Guard. How to remove? (Uninstall guide)

by ,   Also known as WindowsActiveGuard | Type: Malware

Windows Active Guard is a rogue anti-spyware that really looks like its forerunners from FakeVimes family. Just like its predecessors, this program tries only to steal the money from its victims and doesn't even try to help user find viruses on his computer. If you have also been receiving various security alerts from Windows Active Guard, keep in mind that they are misleading and should never be trusted. This rogue seeks only to make its victims concerned about their computers and then creates a need of its licensed version. We highly recommend NOT to believe Windows Active Guard malware and remove this threat without any delay using a reputable anti-spyware version.


Windows Active Guard may get into your PC with a help of trojan horse what is really hard to notice or intercept. Trojan hores not only downloads the trial its version on the computer, but also sets the malware start as soon as PC is rebooted. This is done by changing some system parameters and adding Registry keys of its own. So, every time PC starts, Windows Active Guard starts showing itself through fake system scanners and alerts popping up without any break. All these messages report that your PC is dangerously infected with malware and that you need to remove them. Of course, these Windows Active Guard mesaages look really convincing and may trick many internet users. Mostly, they look something like that:

Firewall has blocked a program from accessing the Internet
Internet Explorer
C:\program files\internet explorer\iexpolre.exe
C:\program files\internet explorer\iexpolre.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Please click “Prevent attack” button to prevent all attacks and protect your PC.

Warning! Virus Detected
Threat Detected: Trojan-Downloader.Win32.Agent
Security Risk:
Infected File: regedit.exe
Description: Programs classified as Trojan download and install new versions of malicious programs, including Trojans and AdWare, on victim computers.
Please click “remove All” button to erase all infected files and protect your PC

Be sure that Windows Active Guard scanners will always detect the same threats and viruses. No wonder why – this rogue anti-spyware aims to frighten its victims and make them believe they should really pay the money for its license. However, we highly recommend to ignore every alert got from Windows Active Guard because most of them report legitimate files found on the system. Be sure that every scanner you get is also fabricated and should be ignored if you don't want to end up purchasing the FAKE licensed version.

HOW TO REMOVE Windows Active Guard? 

In order to stop all this campaign, we recommend to remove Windows Active Guard malware from your computer. Otherwise it may hijack your web browser and do other unwanted stuff on your PC. Manual removal is really dangerous because you may make various damage for your computer's system parameters, so we recommend running a full system scan with SpyHunter or STOPzilla anti-malware programs that will authomatically remove this threat for you. In case you are blocked, enter this code into its registration section: 0W000-000B0-00T00-E0020.

The latest parasite names used by FakeVimes:
Windows Internet Guard, Windows Web Watchdog, Windows AntiBreach Patrol, Windows Antivirus Patrol, Windows Pro Defence Kit

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
SpyHunter - remover Happiness
Compatible with Microsoft Windows
What to do if failed? If you failed to remove infection using Webroot SecureAnywhere AntiVirus SpyHunter, read here how to submit a support ticket or submit a question to our support team and provide as much details as possible.
SpyHunter is recommended to uninstall Windows Active Guard. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of SpyHunter malware removal tool.

More information about this program can be found in SpyHunter review.

If you decided to select another anti-spyware, uninstall SpyHunter from your computer.
more than 40.000.000 downloads!
Webroot SecureAnywhere AntiVirus is recommended remover to uninstall Windows Active Guard. You should confirm using free trial that it detects current version of parasite.
Not using OS X? Download a remover for Windows.
Alternate Software
We are testing STOPzilla's efficiency (2012-08-02 03:31)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-08-02 03:31)
XoftSpySE Anti Spyware
We are testing XoftSpySE Anti Spyware's efficiency (2012-08-02 03:31)
Defender Pro Ultimate
Windows Active Guard screenshot
Windows Active Guard snapshot

Windows Active Guard manual removal

Kill processes:
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
There are more similar entries, you should let spyware Doctor to identify them.
Delete files:

Removal guides in other languages

Information updated:

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name


(All fields are required)
Like us on Facebook