6/25/2012

Windows Pro Defence - a corrupt anti-virus tool.

Windows Pro Defence is a corrupt anti-virus tool that breaks into your private cyber life like a bolt out of blue. It infiltrates invisibly and does not wait for your approval. It is a big surprise for everyone who sees its shortcut on a computer. The cyber frauds will apply different tricks to wind unwary Internet surfers round and rob them off. This is why go on reading this entry to know how not to be caught and if it has already happened how to clean your PC.


This application seems to have no barriers while entering some particular workstation. It is often not detected by available security applications that are decent. The hoax, however, imitates the features of these legit AV tools. For example, it immediately runs many fake system scans of your computer and reports various kinds of infections. The rogue gets started automatically with every system startup, and then it begins implementing its malicious plots on your workstation. Be careful lest you do not trust these deceitful statements you get from Windows Pro Defence malware. Do not pay any money for its so-called licensed version. It is not able to protect your PC. It will not become your anti-virus shield. So, why do you still loiter? Don’t you understand by now that this application is worth immediate removal?

While running, Windows Pro Defence will also show fake security warnings from your Windows taskbar that are worded to make you think that your data is at risk or that you are under attack from a remote computer. Examples of some alerts you may see are:

Eliminate this plague using GridinSoft Trojan Killer. The milestones below will show you how exactly to get rid of this junkware using our recommended software. Make sure to contact if we can be of any assistance.

Windows Pro Defence virus remover:

malware removal tool

Delete Windows Pro Defence files:
%AppData%\NPSWF32.dll
%AppData%\Protector-[rnd].exe
%AppData%\result.db
Delete Windows Pro Defence registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

No comments:

Post a Comment