Windows Smart Warden Virus – Removal Guide

Windows Smart Warden is definitely a bogus security program designed to steal money from unsuspecting consumers. This software is actually a virus which pretends like a security software but It can’t protect your computer from any threats. Now, Are you wondering about the purpose of this software in your computer? Let us tell you the truth that this software is only after your money and uses misleading marketing tactics. Its main purpose is scaring consumers and then motivating them into buying full version of Windows Smart Warden.

Windows Smart Warden virus enters in a disguised manner into your computer and starts doing its fake scans without asking. This virus spreads via Trojans as well as fake online scanners.  Once installed, It will launch itself at startup and won’t let you run any software in your computer. It will close down your antivirus software and won’t let you do anything unless you buy full version of this useless software.

It will show bogus alerts in System Tray like :

Windows Smart Warden Warning
Your computer is infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid theft of your credit card details. Click here to activate protection.

Error
Potential malware detected.
It is recommended to activate protection and perform a thorough system scan to remove the malware.

Above alerts are false and generated by Windows Smart Warden to scare you about your computer’s security. It wants you to believe that your computer is seriously compromised and Windows Smart Warden is the only software which can help you. We suggest that you don’t purchase this software at any cost as It can’t help you.  Even If you’ve already paid for the software in good faith, contact your credit card company and contest the charge.  You’ll surely get your money back. Here is a screenshot of the rogue software doing a fake scan (You can view more images below) :

How To Remove Windows Smart Warden

Windows Smart Warden can be removed easily provided you follow the right method. If you are not a computer geek, It can be really hard for you to remove this dangerous software from your computer. We have analyzed this infection on our machines and suggest these removal methods to get rid of the rogue software :

A) Automatic Removal

Automatic Removal is the best and most effective way to remove the rogue software without harming anything on your computer. You don’t need to mess up with anything as everything will be done a professional software called Spy Hunter. We’ve did this ourselves and you can see it in the video below. Here is what you need to do :

1. Run Internet Explorer and download Process Explorer and save it as “explorer.exe” on your computer. Process Explorer is a free utility from Microsoft which will help you in closing Windows Smart Warden.

2. After downloading, double click over “explorer.exe” and run it.  Now see the active processes list See the current processes list and right click with mouse over a process named “protector-upp.exe” and select “End Process Tree”. Click “Yes” on the next dialog box.  This command will close Windows Smart Warden and now It won’t intercept with removal process.

3. Don’t restart your computer yet! Now Download Spy Hunter and conduct a full scan of your computer to remove this infection completely from your computer. It will take less than 5 minutes.

This video shows how we removed Windows Smart Warden using Spy Hunter :

Watch the video above and see how we removed this bogus software so easily. Automatic Removal method is guaranteed to work all the time and Spy Hunter will also reveal lots of other threats which might be hiding in your computer since a long time without your knowledge. Always make sure to use a genuine Spyware Remover software on your computer to safeguard your computer from cyber criminals.  Spy Hunter is not a free software but it can save you from thousands of headaches for a very small price.

B) Manual Removal

Manual Removal is another method to remove Windows Smart Warden. We don’t recommend this method because It is only meant for computer experts and a small mistake can be fatal. If you delete a wrong file or mess up computer’s registry, things can turn more worse for you. Manual Removal method do work but only If you know what you’re doing. If you’re confident, follow these steps at your own risk :

1. Correct Startup Registry Entry of Rogue Software

Run Registry editor by clicking on Start—>Run, type “regedit” and click OK button. Now you need to remove this registry entries so that malware can’t load at startup. (Learn How To Edit Registry)

You need to correct some registry entries while remove others. Don’t mess up with registry editor If you are not sure how to do that.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe

2. Remove Windows Smart Warden files from your computer

After correcting the registry, please remove files associated with this rogue. Find these files and delete them. (Learn How To Search and Delete Files)

%appdata%\npswf32.dll
%appdata%\protector-[3 random letters].exe

If you correctly delete the executable file of this rogue software, It will not be able to launch itself. Still you need to use a genuine spyware scanner to scan your computer for its traces to make sure that everything is on the track. It would be much better If you start with automatic removal method instead to save your time and bypass all the manual removal steps. If you’re looking for any help, feel free to email us at webmaster at fixrogues.com and we’ll get back to you.

Be Sociable, Share!

Leave a Comment


NOTE - You can use these HTML tags and attributes:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Web Analytics