How to remove Windows Antivirus Machine
Windows Antivirus Machine description
Windows Antivirus Machine is a counterfeit application which pretends to be a legitimate computer protection tool. The parasite spreads via trojan. Trojan comes to user’s computer through the system’s vulnerabilities. Malware gains to force you into purchasing supposedly real protection software.
Once installed, Windows Antivirus Machine starts fake computer scans and floods user’s desktop with various security threats and fraudulent alerts. For example:
Error
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.
Error
Trojan activity detected. System data security is at risk.
It is recommended to activate protection and run a full system scan.
Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
All the alerts are fake and fraudulent. Do not believe any information it shows you. Malware is designed to trick user into believing their computer has many infections and various viruses. You will be offered to purchase its registered version. Do not buy it in any circumstances. It can cause you serious trouble and more viruses onto your computer. Windows Antivirus Machine also has an ability to hijack your browser to deceptive web pages that advertises fake tool. Ignore all the threats and use a malware remover to delete this bogus system as soon as possible.
How to get rid of Windows Antivirus Machine
This infection can be removed using Spyware Doctor.
Spyware Doctor is widely valued as one of the best AntiSpyware programs available to protect you from Windows Antivirus Machine and the latest internet security threats. If your computer is infected with Windows Antivirus Machine we strongly recommend automatic spyware scanner.
How to manually remove Windows Antivirus Machine
To get rid of spyware such as Windows Antivirus Machine you need to remove processes, search and delete registry keys, DLL and other Windows Antivirus Machine related files from your computer.
Take Note: The manual process of removing spyware from your computer is difficult and puts you at risk of damaging your computer. We advise using our automatic Windows Antivirus Machine remover.
- Uninstall Windows Antivirus Machine from Control Panel
Start > Settings > Control Panel > Add/Remove Programs. Double click to uninstall. - End these Windows Antivirus Machine processes:
Protector-.exe
To stop processes press Ctrl + Alt + Del or click Start > Run > type "taskmgr". Select malicious process in the list and click "End Process" button. -
Unregister Windows Antivirus Machine DLL files:
NPSWF32.dll
To unregister DLL click Start > Run > type "regsvr32 /u PATH_TO_FILE/FILE.dll" -
Delete Windows Antivirus Machine registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-8-1_7"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "mccrhntyql"
HKEY_CURRENT_USER\Software\ASProtect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe
To open registry editor click Start > Run > type "regedit".
Warning! Manual registry entries editing may cause damage to your system.
Download Uniblue RegistryBooster 2010 to scan for registry errors. -
Search and delete these Windows Antivirus Machine related files:
%AppData%\NPSWF32.dll
%AppData%\Protector-.exe
%AppData%\Protector-.exe
%AppData%\result.db
%AppData%\1st$0l3th1s.cnf


