Windows Multi Control System looks like a genuine antivirus application but it is a fake scanner just after your money. Its user interface looks like a genuine Windows software and this is why so many people believe that this product is coming from Microsoft and hence pay for the software without a second thought. However, the truth is something else and this shady software wants to push you into purchasing its full version.
Windows Multi Control System scans your computer like a genuine antivirus software and reports numerous non-existent infections on your computer. Now If you are too cautious about your computer’s security, you’ll start looking for a software to get rid of all the problems. At the same time, Windows Multi Control System will try to convince you that It is best software to solve all your computer problems. You’ll believe its words and pay for the software. Once you pay for it, the software will stop showing its fake reports and your money is gone. This is how this scam works and there are literally hundreds of such fake software all around the web. Such products get inside in your computer via fake downloads, fake flash scanners and other illegitimate methods. As you are reading this guide, you are certainly a victim of this threat and we suggest that you don’t worry as this software can’t harm your computer in anyway. We installed this software purposely in our research lab to see how it works and it took less than 5 minutes to remove Windows Multi Control System virus. Here is a screenshot of the rogue software doing a bogus scan and reporting non-existent infections :
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.
Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Like its scan results, above security alerts are a trick to convince you that your computer is really in serious danger and your personal information is at stake. We suggest that you don’t purchase the software at any cost and If you’ve already done that, contact your credit card company and chargeback the amount. To remove Windows Multi Control System, you can use the removal guide below.
How To Remove Windows Multi Control System
Windows Multi Control System blocks several legitimate applications in your computer. This action of the rogue software ensures that you can’t remove the rogue software so easily. We did a complete research on this software and here is how you can remove Windows Multi Control system in less than 5 minutes without risking any data on your computer. Removal methods below are fully tested and works like a charm.
A) Automatic Removal Method – The Most Easiest Method to remove the Rogue
1. Run Internet Explorer and download an application called Process Explorer and save it as “explorer.exe” on your desktop. Process Explorer is a free utility from Microsoft which will help you terminating Windows Multi Control System temporarily.
2. After downloading, double click over “explorer.exe” file and run it. This action will launch a window and you’ll see all running processes in your computer. You need to right click over a process named “protector-.exe” and select “End Process Tree”. Click “Yes” on the next dialog box. This command will terminate the rogue application so that you can clean the computer easily without any interference.
3. Now Download Spy Hunter and conduct a full scan of your computer to remove this infection completely from your computer. It will take less than 5 minutes and you can see the exact process in this view to learn how we removed it :
Manual removal is only useful for computer techies. If you believe that you can find the infected files on your computer manually, you can opt for this removal method. At the same time, keep in mind that deleing wrong files on your computer can have serious impact on your computer’s health. If you are unsure about how to following manual steps, please seek expert’s advice or follow automatic removal method.
If you are confident about your skills, follow these steps to remove Windows Multi Control System :
1. Correct Startup Registry Entry of Rogue Software
Run Registry editor by clicking on Start—>Run, type “regedit” and click OK button. If you’re able to launch Registry Editor, you need to correct these registry entries. In case you are not able to access registry editor, we suggest that you try to do the removal in Safe Mode with Networking Mode. (Learn How To Edit Registry)
You need to remove these registry entries so that virus can’t load its malicious files at startup :
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “ConsentPromptBehaviorAdmin” = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “ConsentPromptBehaviorUser” = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “EnableLUA” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-5-23_3″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “uksccxyoyf”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe
Keep in mind that deleting a wrong registry entry can have serious impact on your computer’s health. Ask for expert’s advice If you don’t know what you are doing.
2. Remove Windows Multi Control System Executable files
After removing malicious registry entry, please remove the malicious files associated with this rogue. Find these files and delete them. (Learn How To Search and Delete Files)
%AppData%\Protector-<random 3 chars>.exe
%AppData%\Protector-<random 4 chars>.exe
After removing above files, you also need to remove its icon from the desktop manually. Please note that executable file of this rogue software always start with name “protector” and then 3 or 4 random characters. You need to spot this process using Process Explorer as suggested in Automatic Removal method. If manual removal method fails, you can always try your hands on automatic removal method. Automatic Removal will take care of this rogue software as well as many other viruses which might be hiding in your computer since a long time.