• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove Virus Protector (Uninstall instructions)

Myantispyware team February 20, 2010    

Virus Protector is a rogue antispyware program that installed through the use of trojans and uses false scan results and fake security alerts informing that your computer is infected in order to trick you into purchasing the full licensed version.

Once installed, the rogue will configure itself to run automatically when you logon to Windows and drop numerous files with random names on to your computer that are made to appear as infections, but are in reality harmless. These files, during the scan, Virus Protector will label as malware, trojans and viruses. Of course, the scan results are a fake. The malicious program is unable to find the infections, as will not protect you from possible infection in the future. Important, do not trust the scan results, simply ignore them.

In order to create the fully simulation that you computer is infected, Virus Protector will display various fake security warnings that stats:

Spyware Alert
Your computer is infected with spyware. It could damage your
critical files and expose your private data on the Internet. Click
here to register your copy of Virus Protector and remove
spyware threats from your PC.

Process is blocked!
Harmful memory infections detected.
Process [filename] was terminated.

Virus Protector
Internet attack
attempt detected

However, all of these alerts are fake and like false scan results should be ignored!

If you get infected with Virus Protector, please do not be fooled into buying it. Instead of doing so, follow the removal guide below in order to remove Virus Protector and any associated malware from your computer for free.

More screen shoots of Virus Protector



Symptoms in a HijackThis Log

F2 – REG:system.ini: Shell=C:\WINDOWS\system32\




.exe
O20 – AppInit_DLLs:

Spyware software are surreptitiously installed on user`s computer to collect information about computer’s configuration, user`s private information, user’s activity without his consent. Spyware may also change Windows settings, download and install other malicious programs without the user’s knowledge.

.dll

Use the following instructions to remove Virus Protector (Uninstall instructions)

Read the article: How to reboot computer in Safe mode and reboot your computer in the Safe mode with command prompt.

Once Windows loaded, command prompt (black window) opens. Type notepad and press Enter.

A notepad window opens. Type the following text into notepad:

[Version]
Signature="$Chicago$"
Provider=Myantispyware.com


[DefaultInstall]
AddReg=regsec

[regsec]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools,0x00000020,0
HKLM, Software\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell,0x00000020,"Explorer.exe"

Once finished, please checkup the text twice. You will see a screen similar to the one below.


Notepad

Save this as fix.inf to your Desktop (remember to select Save as file type: All files in Notepad). Close Notepad.

In the command prompt type Explorer.exe and Press Enter. Windows Explorer opens. Locate the fix.inf, click right button and select Install. Close Windows Explorer.

In the command prompt type shutdown -r and press Enter. Your computer will be rebooted.

Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.

MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.

As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu. You will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer for Virus Protector infection. This procedure can take some time, so please be patient.

When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below.
Note: list of infected items may be different than what is shown in the image below.


Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove Virus Protector. MalwareBytes Anti-malware will now remove all of associated Virus Protector files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Note 3: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

Virus Protector creates the following files and folders

The rogue uses random filenames to hide itself.

Virus Protector creates the following registry keys and values

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Virus Protector”

Malware removal Rogue Anti Spyware

 Previous Post

How to remove PC Defender (Uninstall instructions)

Next Post 

How to remove XP AntiSpyware 2010, XP Antivirus Pro 2010

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

123 Comments

  1. Barry
    ― March 14, 2010 - 9:48 am  Reply

    Patrick, that command helped – I seem to have gotten rid of the Virus Protector – but I have lost my desktop and start menu – I did run the TDSS Killer software that was recommended to Kris (I ran it through the command prompt) and I tried to run the Malwarbytes through the command prompt as well but I can’t get to my desktop/start menu in normal windows or when I open in safe mode – any other recommendations?

  2. vc
    ― March 15, 2010 - 4:36 am  Reply

    I remove the virus very easily
    I start the laptop in debuge mode, so virus could not run in this mode
    i have already malwarebyte installed(can installed if dont have it)
    then i run malwarebyte, and it clears the damn virus.

  3. Patrik
    ― March 15, 2010 - 11:18 am  Reply

    Barry, boot your computer in Normal mode. Once Windows loaded, press CTRl + ALT + DEL. Task manager opens. Click File, New task. Type explorer.exe and press Enter. You icons and taskbar should back. Try run Malwarebytes and perform a scan.

  4. carfixr44
    ― March 15, 2010 - 9:15 pm  Reply

    Patrick, your advice has been terrific. I have been battling this Virus Protector Beast for three days. Safe Mode with Command Prompt was the clue I needed. Renaming the scanner installation solved the next problem. This machine is almost back to normal, but I still have no taskbar or icons. Explorer.exe opens Windows Explorer, but no desktop.

  5. Patrik
    ― March 16, 2010 - 9:15 am  Reply

    Run Registry Editor and check HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell key. It should contains “Explorer.exe”

  6. Barry
    ― March 16, 2010 - 11:54 am  Reply

    If I press CTRL + ALT +DEL, I get a message indicating that the Task Manager has been restricted by Administrator. NOTE: When I did run the TDSSKiller, the result screen indicated that nothing was found or eliminated. Am I possibly dealing with a more serious trojan virus?
    Again, any assistance is appreciated. I do feel like I am making some progress.

  7. Patrik
    ― March 17, 2010 - 12:36 pm  Reply

    Barry, you have tried check “shell” value as i posted above ? If you need a help, please open a new topic in our Spyware removal forum.

  8. carfixr44
    ― March 17, 2010 - 10:01 pm  Reply

    I found that I was denied access to my entire user profile and was being switched to the default profile. The microsoft Security Essentials tool found another nasty trojan: win32/FakeMagic. That gave me back my user profile and my icons, but regedit still says it has been disabled by my administrator.

  9. Patrik
    ― March 19, 2010 - 7:32 am  Reply

    carfixr44, open a new topic in our Spyware removal forum. I will help you. Also you can scan your computer with Malwarebytes, it should fix your trouble.

  10. MikeM
    ― March 24, 2010 - 1:44 pm  Reply

    For those having issues with Malwarebytes not removing this, try SuperAntiSpyware. It worked on my dad’s pc as MWB didn’t find anything.

  11. meena
    ― March 25, 2010 - 10:30 am  Reply

    Hello. I downloaded this Virus Protector thing and now I cannot access any of my files, documents, etc. when I open my laptop. As soon as I open my laptop and after the welcome logo appears, this Virus Protector thing starts running and the background is black. I cannot right-click to close it and I cannot stop it since the window’s start logo won’t open. I really need help. It’s my new laptop and I need it for college. Any advice? Thanks.

  12. Patrik
    ― March 25, 2010 - 11:21 am  Reply

    meena, read the instructions above. You need use safe mode with networking to repair your computer.

  13. Ricky
    ― March 26, 2010 - 6:03 am  Reply

    I followed the above steps and seems like the Virus Protector is removed. Coz now when i start the PC there is nothing.
    Problem is i see only my Wallpaper and nothing else.

    Tried the CTRL + ALT + DEL… but it wont allow me the access.

    i downloaded the Malwarebytes in the Safe mode with network.

    “Run Registry Editor and check HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell key. It should contains “Explorer.exe””

    How to run Registry Editor when i have no access to anything??

    Please Help

    Using Windows XP

  14. Patrik
    ― March 26, 2010 - 7:35 am  Reply

    Ricky, run Malwarebytes Anti-malware in Safe mode.

  15. tt
    ― March 26, 2010 - 9:10 pm  Reply

    ok,i have the virus protector problem,i have followed all directions and nothing will work, i can not get to my task manager and can not get to my desktop what so ever…im not sure what to do…i have many pics of my sons firsts on this computer and im afraid i wont get to see them agian because of this virus….can someone help please!!!

  16. Patrik
    ― March 26, 2010 - 10:09 pm  Reply

    tt, probably your computer infected with a new version of the rogue. Ask for help in our Spyware removal forum.

  17. Nick
    ― March 27, 2010 - 3:18 am  Reply

    Very simple fix… Go into safe mode with command prompt and type the following:

    %systemroot%\system32\restore\rstrui.exe

    I tried all the other things and nothing worked. I did this and restored my computer to 3 days prior and it works perfectly!

    Hope this helps!!!!

  18. Ceon
    ― March 28, 2010 - 5:34 pm  Reply

    Thank u so much Nick!!!! I tried everything else also and had no success. Then I found your post and everything is back to normal. Once again thank you so much Nick, your a life saver.

  19. Jason
    ― March 28, 2010 - 10:11 pm  Reply

    I tried to run Windows in Safe mode, but I get BSOD. Help!!!!!

  20. Brian
    ― March 29, 2010 - 1:42 am  Reply

    I have followed the instructions to the point where I have copied MalwareBytes Setup to a Memory Stick but when I try to install it to the infected computer I get an error message, Error Code: 732(12007,0),and report to Anti-Malware support team.
    I pressed OK and MalwareBytes allowed me to run a full scan.
    After running MalwareBytes, VirusProtector was still active.
    Your help appreciated

  21. Brian
    ― March 29, 2010 - 4:59 am  Reply

    I have now followed the advice of (Comment by) Nick — March 27, 2010 and have got rid of Virus Protector

  22. Patrik
    ― March 29, 2010 - 6:14 am  Reply

    Jason, open a new topic in our Spyware removal forum.

  23. Patrik
    ― March 29, 2010 - 6:17 am  Reply

    Brian, looks like you can`t update Malwarebytes. Read the instructions and update it manually.

  24. davide
    ― March 29, 2010 - 5:26 pm  Reply

    Hi, I have a problem with virus protector, i tried everithing posted above and nothing,i going crazy

  25. Angelica
    ― March 30, 2010 - 12:28 am  Reply

    I tried the fixes but nothing seemed to work. Decided to do a good ol system restore and everything is fine! I went into safemode with command prompt, typed explorer.exe, located system restore (start menu>programs>accessories>system tools>system restore). Pcked a date about a week ago and all worked fine. Quickly updated my malwarebytes and avg and ran full scans. All is well! Hope this helps whoever can access explorer!

  26. Patrik
    ― March 30, 2010 - 5:02 am  Reply

    Davide, then open a topic in our Spyware removal forum.

  27. iamsam
    ― March 31, 2010 - 4:06 am  Reply

    It worked perfectly.
    1.Started the system in Safe mode with command prompt.
    2. I change directory to E(which is my DVD drive)where Malwarebytes is located.
    3. Then installed the Malwarebytes from my dvd drive.
    4. run scan then restart.
    5. problem solved.
    6. Thanks Patrick. You’re awesome dude!

  28. Vitaly
    ― March 31, 2010 - 11:27 pm  Reply

    Used safe mode with command prompt. Restored using method described by Nick above. Works fine now.

    But think about it, if they find a way to run it in Same mode with command prompt, plus if they screw/corrupt restore points (so booting from Windows original installation DVD would be useless) it would be PERFECT malware! Only way to get rid of it would be complete system re-installation or bootable media(Linux based?) with NTFS drivers and antimalware soft. Early versions of Virus Protector was allowing to boot into Safe Mode with networking. Now it is not possible. Also before user was able to access regedit from Safe Mode, not anymore (apparently disabled by group policies). So developers are working! Looking forward to see what new features will be implemented in VP;)

  29. JohnG
    ― March 31, 2010 - 11:38 pm  Reply

    Followed the instructions and the bastard beast disappeared. Thanks to the genius of Patrik.

  30. Ricardo Frustockl
    ― April 5, 2010 - 12:04 pm  Reply

    Thank you for your clear instructions and the writing of the FiX.inf file. That seemed to be the final missing fix on all the other sites about “remove virus protector”

    Thanks again!
    Ricardo Frustockl

« Previous 1 2 3 4 5 Next »

Leave a Reply to clara Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

remove android virus
How to remove virus from Android phone
adwcleaner
AdwCleaner – Review, How to use, Comments
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
browser redirect virus
How to remove Browser redirect virus [Chrome, Firefox, IE, Edge]
How to remove browser hijacker virus (Chrome, Firefox, IE, Edge)

Recent Guides

How to remove PC Defender (Uninstall instructions)
How to remove Antimalware Doctor (Uninstall instructions)
How to remove Security Central (Uninstall instructions)
How to remove Personal Anti Malware (Uninstall instructions)
How to remove Security Essentials 2010 (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.