How to remove Windows Active Defender

Home » Rogue Anti-Spyware » Windows Active Defender Repair and protect your computer easily. Download Windows Active Defender removal tool

Windows Active Defender description

Windows ActiveDefender is another malicious program which spreads with the help of trojan. It comes to the system via its flaws. WindowsActiveDefender is designed to pilfer money from unwary users, so it gains to trick users into thinking their PC is severely compromised.

Once installed it starts to imitate computer scans and displays numerous fake security alerts:

Warning!
Application cannot be executed. The file notepad.exe is infected.
Please activate your antivirus software.

Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.

Error
Potential malware detected.
It is recommended to activate protection and perform a thorough system scan to remove the malware.

Do not fall for this scam but use decent anti-spyware application and get rid of Windows ActiveDefender as soon as possible. Malware is not able to provide any actual computer security service, so it is needed to be cleaned with reputable security tool.

How to get rid of Windows Active Defender

This infection can be removed using Spyware Doctor.

Download does not start? Try a mirror download here

Spyware Doctor is widely valued as one of the best AntiSpyware programs available to protect you from Windows Active Defender and the latest internet security threats. If your computer is infected with Windows Active Defender we strongly recommend automatic spyware scanner.

How to manually remove Windows Active Defender

To get rid of spyware such as Windows Active Defender you need to remove processes, search and delete registry keys, DLL and other Windows Active Defender related files from your computer.

Take Note: The manual process of removing spyware from your computer is difficult and puts you at risk of damaging your computer. We advise using our automatic Windows Active Defender remover.

  1. Uninstall Windows Active Defender from Control Panel
    Start > Settings > Control Panel > Add/Remove Programs. Double click to uninstall.
  2. End these Windows Active Defender processes:
    Protector-.exe
    To stop processes press Ctrl + Alt + Del or click Start > Run > type "taskmgr". Select malicious process in the list and click "End Process" button.
  3. Unregister Windows Active Defender DLL files:
    NPSWF32.dll
    To unregister DLL click Start > Run > type "regsvr32 /u PATH_TO_FILE/FILE.dll"
  4. Delete Windows Active Defender registry entries: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-6-8_7"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "dyitduggwx"
    HKEY_CURRENT_USER\Software\ASProtect
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe

    To open registry editor click Start > Run > type "regedit".
    Warning! Manual registry entries editing may cause damage to your system.
    Download Uniblue RegistryBooster 2010 to scan for registry errors.
  5. Search and delete these Windows Active Defender related files:
    %AppData%\NPSWF32.dll
    %AppData%\Protector-.exe
    %AppData%\Protector-.exe
    %AppData%\result.db
    %AppData%\1st$0l3th1s.cnf

Tags

, , ,

Similar Threats

Leave a Reply