Severity scale  
  (72/100)

Windows Protection Unit. How to Remove? (Uninstall Guide)

removal by - -   Also known as Windows Protection Unit | Type: Rogue Antispyware
12

Windows Protection Unit is a rogue anti-spyware program with aim to scare you into thinking that your computer is infected and to make you buy useless security product. If your computer is infected with this rogue anti-spyware program, don't purchase it! It is a scam and has nothing to do with genuine antivirus software. Instead, remove Windows Protection Unit from your computer as soon as possible and do not allow it to download additional malware. The rogue anti-spyware program is usually promoted through the use of trojans, fake online anti-malware scanners and hacked websites. Once your computer is infected with either trojan downloaders or scareware, you will be flooded with fake security alerts and notifications from Windows task bar claiming that your computer is seriously infected and that you must use Windows Protection Unit in order to clean your computer.

When running,Windows Protection Unit will start a fake system scan and report many non-existent infections. The scan is fabricated from start untill end, these infections are all fake and don't actually exist. The truth is that this program is unable neither to detect nor to delete any kind of infections. To make things worse, Windows Protection Unit will constantly display pop-ups and security warnings very similar to those shown by Windows Security Center. These alerts will state that your computer is infected with malware, e.g. spyware, trojans or even viruses. All this undesirable behavior is done only to trick you into purchasing Windows Protection Unit.

Warning
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:\Windows\system32\dllcache\wmploc.dll
C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.

Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.

Error
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.

What is more, this rogue anti-spyware program hijacks Internet Explorer and redirects the users to malicious websites that promote Windows Protection Unit or other malware. In some cases, this virus modifies Windows HOST file and blocks certain websites in order to protect itself from being removed. As you can see, this program is harmful and must be removed upon detection. The removal guide below provides all information required to remove Windows Protection Unit from your computer. We strongly recommend you to use malware removal software given below.

The latest parasite names used by FakeVimes:
Windows Internet Guard, Windows Web Watchdog, Windows AntiBreach Patrol, Windows Antivirus Patrol, Windows Pro Defence Kit

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Windows Protection Unit. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Windows Protection Unit. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2012-04-15 13:25)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-04-15 13:25)
Hitman Pro
Webroot SecureAnywhere AntiVirus

Windows Protection Unit manual removal

Kill processes:
Inspector-[rnd].exe
Protector-[rnd].exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
Delete files:
%AppData%\Inspector-[rnd].exe
%AppData%\Protector-[rnd].exe

Information updated:

Comments on Windows Protection Unit

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)