Windows Premium Defender virus – how to uninstall manually

Windows Premium Defender seems to be an efficient protection tool because of its name and interface but the hidden truth is different from this reality. “Windows Premium Defender” is a fake program which is created by hackers to earn some extra bucks by selling useless softwares online. This piece of software is classified as rogue virus. It use malicious tactics to trick people into paying for hackers not for defending your PC. Let me explain how this rubbish thing works.

There are many websites owned by malware creators. They use downloader trojans to drop the virus into a computer through those websites. Mostly these sites are shareware program distributors or free online virus scanners. Once Windows Premium Defender virus has been installed on your PC, it will start its malicious activities immediately. It will set itself for auto startup so whenever you logon to your windows, this program will start automatically. Now it will act like if its scanning your system for malwares. There is a notable thing that the virus is installed on your computer very secretly under hidden mode. This process dose not ask the user for permission because it is done by Trojans so you wont get to know when this malware is being downloaded to your PC. After getting into your PC, it will pop up, The interface and appearance of Windows Premium Defender is just like a real anti-virus software so many users fall for this program and they think it is really scanning their PC. After a while, it will display some popup windows stating some scary reports about your PC. like:

Warning! Virus Detected
Threat Detected: Trojan-Downloader.Win32.Agent
Security Risk:
Infected File: regedit.exe
Description: Programs classified as Trojan download and install new versions of malicious programs, including Trojans and AdWare, on victim computers.
Recommended:
Please click “remove All” button to erase all infected files and protect your PC

The message above is copied from the fake Windows Premium Defender alert. Please do not worry about such creepy messages. The target of Windows PremiumDefender is to ask you to click that nasty PREVENT ATTACKS button, when you go through this, you,ll be asked to pay the registration fee. Do not register this software because it is a scamware and fake program that can not defend your computer. It is good to remove this bug as soon as possible.

How to uninstall Windows Premium Defender virus manually:

To remove this virus manually, complete the following set of tasks. Do not forget to create a backup before getting started to the manual removal guide.
To prform manual removal steps, you may need to learn,
How to stop a process
How to delete registry entries

Stop Windows Premium Defender processes:
Protector.exe

Remove Windows Premium Defender Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe

Delete Windows Premium Defender files:
%AppData%\Protector.exe

Auto Removal

To remove this virus Automatically, We suggest following tools:


Malware Bytes Anti-Malware (Download)


HitMan Pro Anti-Malware (Download)