Windows Pro Defence is one of those rogue anti-spywares that come inside the system through its backdoors. This is done with a help of trojan horses used to download malware files to the target PC without any user's permission asked. As soon as it gets there, this scam is set to start every time you reboot your PC and starts displaying its misleading alerts and scanners without any delay. Windows Pro Defence seems to be particularly aggressive rogue because it has also been found to block legitimate antivirus software installed on one’s computer. Be sure you remove Windows Pro Defence in order to avoid this or other unwanted activities.
As soon as Windows Pro Defence is downloaded, it starts reporting about numerous infections 'found' on the system. However, these threats are not there for real because they either are invented or harmless system files. This brainwashing technique is common for rogue anti-spywares hailing from FakeVimes family and used for the only reason – to make users buy its licensed version. However, we do NOT recommend paying for Windows Pro Defence license because it is useless just like its trialware.
As we have already mentioned, Windows Pro Defence runs its startup scanners and displays popup notifications every time you reboot your PC. In most of the cases it claims:
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
By reporting all these errors and warnings, Windows Pro Defence tries to make you believe you should rely on it and pay for its license. However, paying for it is the same as sharing your money with scammers because situation on your computer remains the same. We highly recommend to remove this dangerous malware from your computer instead of paying for its licensed version. Use a reputable anti-spyware programs, such as Reimage"] or PlumbytesWebroot SecureAnywhere AntiVirus to forget this malware for good.
Windows Pro Defence manual removal
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
There are more similar entries, you should let spyware Doctor to identify them.
Comments on Windows Pro Defence
Post a comment
Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.