Title: Windows Antivirus Care
Also known as: WindowsAntivirusCare

Remove Windows Antivirus Care
Removal instructions

 
Severity scale:Windows Antivirus Care severity is 67  (67 / 100)
 

Windows Antivirus Care is a rogue anti-spyware program that displays fake security warnings and claims to found a variety of infections to make you think that your computer is infected with trojans and viruses. Once installed, it will pretend to scan your PC and then report numerous spyware infections that can supposedly be removed only with their anti-spyware software. Of course, the scan results are false so you can sefely ignore them. Anyway, you should remove Windows Antivirus Care from your computer as soon as possible because removal delay may worsen the situation. The rogue program can download and install additional malware on your computer including keyloggers and rootkits. Please follow the removal instructions below to remove this fake anti spyware program from your computer using recommended automatic malware removal tool.

Windows Antivirus Care is promoted through the use of Trojans and other malware that usually comes from fake online virus scanners and hacked websites. When running, it will attempt to block legitimate anti-virus program on your computer. What is more, you will see many fake security alerts on your computer stating that you are infected with very dangerous malware. Some of them will state that your computer is infected with malware whereas others will claim that you are under attack from a remove computer. Just like the false scan results, these fake security warnings can be safely be ignored. Some of those fake security alerts read:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
Warning!
Location: c:\windows\system32\taskmgr.exe
Viruses: Backdoor.Win32.Rbot

As you can see, Windows Antivirus Care is nothing more but a scam. Don't buy it! If you have already purchased it then you should contact your credit card company and dispute the charges. Then follow the removal instructions below to get rid of Windows Antivirus Care using legitimate antimalware software.

The latest parasite names used by FakeVimes:
Windows Internet Guard, Windows Web Watchdog, Windows AntiBreach Patrol, Windows Antivirus Patrol, Windows Pro Defence Kit

Automatic Windows Antivirus Care removal:

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
By downloading any of provided Anti-spyware software to remove Windows Antivirus Care you agree with our Privacy Policy and Agreement of Use.
SpyHunter is recommended remover to uninstall Windows Antivirus Care. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

If you failed to remove Windows Antivirus Care using SpyHunter, submit question to our support team and provide as much details as possible.
dot
STOPzilla
download
manual required
We are testing STOPzilla's efficiency at removing Windows Antivirus Care (2012-04-19 09:55:36)
dot
Malwarebytes Anti Malware
download
manual required
We are testing Malwarebytes Anti Malware's efficiency at removing Windows Antivirus Care (2012-04-19 09:55:36)
dot
XoftSpySE Anti Spyware
download
manual required
We are testing XoftSpySE Anti Spyware's efficiency at removing Windows Antivirus Care (2012-04-19 09:55:36)
dot
Defender Pro Ultimate
download
manual required
We are testing Defender Pro Ultimate's efficiency at removing Windows Antivirus Care (2012-04-19 09:55:36)

what to do if you failed to remove the infection?
Virus Removal
Phone Support
Help Line to remove Windows Antivirus Care
Windows Antivirus Care snapshot:
Windows Antivirus Care snapshot

Windows Antivirus Care manual removal:

Kill processes:
%appdata%\Inspector-[rnd].exe
%AppData%\Protector-[rnd].exe
Delete registry values:
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Policies\\System "DisableRegedit" = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Policies\\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Policies\\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Run "Inspector"
HKEY_CURRENT_USER\\Software\Microsoft\\Windows\\CurrentVersion\\Settings "net" = "2012-3-11_2?
HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Settings "UID" = "origkboryd"
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\InternetExplorer\\Main\\FeatureControl\\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\atcon.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\bipcp.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\ecengine.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\infwin.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\msconfig
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\PavFnSvr.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sahagent.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\titaninxp.exe
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\wsbgate.exe
Unregister DLLs:
%AppData%\NPSWF32.dll

Delete files:
%appdata%\Inspector-[rnd].exe
%AppData%\Protector-[rnd].exe
%AppData%\NPSWF32.dll

Geolocation of Windows Antivirus Care:

This map reveals the prevalence of Windows Antivirus Care. Countries and regions that have been affected the most are: India and United States.

QR code for Windows Antivirus Care removal instructions:

Windows Antivirus Care qrcode
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than standard barcodes, including url links, geo coordinates, and text.

The reason we add QR code to the website is that parasites like Windows Antivirus Care are really hard to remove on infected computer. you can quicly scan the QR code with your mobile device and have manual removal instructions to uninstall Windows Antivirus Care right in your pocket.

Simply use the QR scanner and read removal instructions from mobile device.
Information added: 2012-04-19 09:55:36
Information updated: 2012-08-02 02:18:34

Additional resources:

Attention: If you know know a reputable website reated to security threats, please add a link here: add url

Post Comment:

Attention: Use this form only if you have additional information about Windows Antivirus Care parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Like us on Facebook
Latest spyware news:
Subscribe to spyware news
Please enter your e-mail address:
If you do not want to receive our spyware
newsletter please unsubscribe here
48646 Subscribers
Ask us
I failed to remove Windows Antivirus Care using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight against computer parasites on the Internet alone. If you have a website, we would be more than happy if you would like to cooperate and help us spread the information about latest threats. Remember, knowledge is the most powerful weapon. Help your visitors protect their computers!
add text box
rss feed
help other