Severity scale  

Windows Antibreaking System. How to Remove? (Uninstall Guide)

removal by - -   Also known as WindowsAntibreakingSystem | Type: Rogue Antispyware

Windows Antibreaking System is a rogue anti-spyware program that uses fake alerts and false scan results to convince you that your computer is infected with viruses. It is installed mostly through the use of trojans and hacked websites but it may also come from fake online virus scanners. It's not a legitimate anti-spyware program, so you should remove Windows Antibreaking System if your computer is already infected. Uninstalling this rogue security program will ensure that your compuetr won't get infected with additional malware.

Once installed, Windows Antibreaking System will automatically scan your computer each time you log on to Windows. The scan is super fast and makes no sense what so ever because it doesn't scan the system. It only mimics genuine anti-spyware programs. Obviously, the scan results are false as well so you can sefely ignore them. The program drops several files on your computer and then identifies those files as malicious that can dmage the machine or steal your personal information. Also, Windows Antibreaking System will constantly display fake security alerts claiming that your computer is under attack from a remote server. These fake alerts are very annoying andshow up like every minute or two. You might not be able to do even a regular tasks with your computer.

Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.

Without a doubt, such behavior will also affect computer performance. Windows Antibreaking System will dramatically slow down your computer. Furthermore, Windows Antibreaking System will hijack your Internet browser and redirect you to various malicious websites. It should be obvious that Windows Antibreaking System is a scam and must be removed from the system as soon as possible. Please use the removal guide below to remove this infection from your computer using recommended anti-spyware applications. If you have already paid for this rogue anti-spyware program then contact your credit card company and dispute the charges.

The latest parasite names used by FakeVimes:
Windows Internet Guard, Windows Web Watchdog, Windows AntiBreach Patrol, Windows Antivirus Patrol, Windows Pro Defence Kit

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Reimage - remover Happiness
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Windows Antibreaking System. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Windows Antibreaking System. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
We are testing Plumbytes's efficiency (2012-04-11 03:14)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-04-11 03:14)
Hitman Pro
Webroot SecureAnywhere AntiVirus
Windows Antibreaking System screenshot
Windows Antibreaking System snapshot

Windows Antibreaking System manual removal

Kill processes:
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
Delete files:

Information updated:

Comments on Windows Antibreaking System

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name


(All fields are required)