Windows Virtual Security is a fake program hailing from the family of fakeVimes. This rogue virus is distributed through malicious websites that can install this virus on a computer without user permission and also without user consent. Windows Virtual Security`s target is to sell its license for full version which is a useless thing but it represents itself to be a powerful antivirus software.
Once the fake “Windows Virtual Security” malware has installed on a computer, it will add itself to system startup list. hence whenever the infected computer is rebooted, Windows VirtualSecurity will pop up, it will act like it is scanning the system for malwares. After a while, its bogus scanner will display a very scary system security report stating that Windows Virtual Security has found PC in danger. It has detected some harmful threats. Some annoying pop up messages will keep appearing on computer screen telling user about virus infections. This is the Windows Virtual Security`s first trick to convince user that his computer is virus infected and he is in need of a good antivirus software that can remove viruses from his PC. After this job, the malware will start offering to use the full version it because you are using its trial version as yet, the pro version will remove all the threats from your system. Please keep in your mind, Windows Virtual Security is a fake software, it makes false promises. It just trying to trick you into buying its upgrade. the actual problem with your computer is “Windows Virtual Security” program itself. It reports about viruses that do not exist in your PC. Thus it is recommended to take an immediate action to remove Windows Virtual Security malware as soon as possible.
How to Uninstall Windows Virtual Security virus manually:
To remove this virus manually, complete the following set of tasks. Do not forget to create a backup before getting started to the manual removal guide.
To prform manual removal steps, you may need to learn,
How to stop a process
How to delete registry entries
Stop Windows Virtual Security processes:
Protector.exe
Remove Windows Virtual Security Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
Delete Windows Virtual Security files:
%AppData%\Protector.exe
Auto Removal
To remove this virus Automatically, We suggest following tools:
Malware Bytes Anti-Malware (Download)
HitMan Pro Anti-Malware (Download)
