Severity scale:  

Windows Virtual Angel. How to remove? (Uninstall guide)

removal by Julie Splinters - -   Also known as WindowsVirtualAngel | Type: Rogue Antispyware

Windows Virtual Angel is a totally harmful computer program that has the same objectives as all the rest of the rogue anti-spywares. It belongs to FakeVimes family of malwares and clearly uses the same features as its earlier versions. We highly recommend not to fall for Windows Virtual Angel and remove this threat once you find it on your computer. For that, run a full system scan with anti-malware program to make sure that all infected files are eliminated.


Being a fake security solution, Windows Virtual Angel penetrates into PC in a stealthy way, that means it uses security vulnerabilities to come inside and unnoticeably download all its files. The most interesting part of its infiltration is registry modification which helps for this virus launch as soon as user reboots his PC. In addition, Windows Virtual Angel tends to generate fabricated security scanners that report about invented threats and viruses on the targeted computer. Of course, we highly recommend to ignore such alerts because most of these 'viruses' are harmless system files. Here are some examples of Windows Virtual Angel alerts:

Attempt to modify registry key entries detected.
Registry entry analysis is recommended.

Potential malware detected
It is recommended to activate the protection and perform a
thorough system scan to remove the malware.

Firewall has blocked a program from accessing
the Internet

Windows XP USER API Clien: DLL
User32.dll is suspended to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Please click “Prevent attack” button to prevent all attacks and protect your PC.

After reporting about all these invented threats, Windows Virtual Angel offers you install a licensed its version as a tool capable to help you fix your computer. However, paying for it is the same as giving your money for scammers because it is useless just like unregistered Windows Virtual Angel version.


In order to stop those multiple obnoxious notifications that usually tell you about the extremely bad security condition on your PC, you should remove Windows Virtual Angel from the PC. Under no circumstances believe its alerts and scan reports and run a full system scan with reputable anti-spyware program to get rid of this dangerous malware for good. According to our security experts, running Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus or Reimage is the easiest way to fix your machine.If you are disabled from launching these programs, enter this this code: 0W000-000B0-00T00-E0020 to 'register' your virus first.

The latest parasite names used by FakeVimes:

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Windows Virtual Angel you agree to our privacy policy and agreement of use.
do it now!
Reimage (remover) Happiness
Reimage (remover) Happiness
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Windows Virtual Angel. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

More information about this program can be found in Reimage review.
Windows Virtual Angel snapshot
Windows Virtual Angel

Windows Virtual Angel manual removal:

Kill processes:

Delete registry values:

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "WarnOnHTTPSToHTTPRedirect" = 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegedit" = 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegistryTools" = 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableTaskMgr" = 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "Inspector"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "ID" = 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "net" = "2012-2-17_2"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "UID" = "rudbxijemb"

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options_avp32.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options_avpcc.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsashDisp.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsdivx.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmostat.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsplatin.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionstapinstall.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionszapsetup3001.exe

There are more similar entries, you should let spyware Doctor to identify them.

Delete files:

About the author

Julie Splinters - Malware removal specialist

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Julie Splinters
About the company Esolutions