Windows Defence Master trojan – how to get rid of it?

Windows Defence Master stands for a malware that is of the FakeVimes rogue family. This is a bogus anti-spyware tool that has the only plan in mind – to make you spend your money for the totally useless services supposedly rendered by this scam. So, this is a real scam that should be immediately deleted. Following these recommendations will help you to get rid of Windows Defence Master off your system.

Windows Defence Master scam

Windows Defence Master gets into computers by means of all sorts of trojan horses. They may use all kinds of vulnerabilities inside of your browser. As a consequence, you might see some fake security alerts supposedly originating from Microsoft, telling you to download some program that will aid you in cleaning your system from malwares. In reality, as we’ve mentioned already, these are bogus alerts not associated at all to Microsoft company.

Download Combo Cleaner

Windows Defence Master, after successful illegal entry, initiates imitation of some system cleanup on your computer. Thus, it runs the fake scan of your system and reports the large number of fake infections supposedly available on your machine. This is done in order to make you purchase the so-called “ultimate protection” supposedly provided by Windows Defence Master, which is absolutely helpless for real malware removal. You must disregard all scary warnings and tricks of Windows Defence Master, don’t ever purchase its useless “license”. Refer to the removal guide provided in the rest of this article that will help you to delete this scareware from your PC for good.

Windows Defence Master removal milestones:

  • In Windows Defence Master click “?” Menu button and click “Register“:
  • Register Windows Defence Master virus

  • Paste this product key – 0W000-000B0-00T00-E0022 exactly as shown in the image below, then click “Register“:
  • Windows Defence Master product key

    Note! If this product key has been found to be invalid, try one of these keys as well:

    1. 0W000-000B0-00T00-E0001
    2. 0W000-000B0-00T00-E0002
    3. 0W000-000B0-00T00-E0003
    4. 0W000-000B0-00T00-E0021
  • Afer registration download GridinSoft Trojan Killer, install the program, scan your PC with it and remove all infections detected by clicking “Remove selections” button at the end of scan.
  • Download GridinSoft Trojan Killer
  • Restart your computer and repeat scan.

Video that explains how to activate Windows Defence Master virus:

Associated files and registry entries information

Related files:

%AppData%\svc-[rnd].exe
%CommonAppData%\connector.swf
%Programs%\Windows Defence Master.lnk
%Desktop%\Windows Defence Master.lnk

Related registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PrSft %AppData%\svc-[rnd].exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\Debugger svchost.exe

Fake security alerts, notifications and warnings of Windows Defence Master scam:

Firewall has blocked a program from accessing the Internet
C:\Program Files\Internet Explorer\iexplore.exe
is suspected to have infected your PC.
This type of virus intercepts entered data and transmits them
to a remote server.

Error
Trojan activity detected. System integrity at risk.
Full system scan is highly recommended.

Error
System data security is at risk!
To prevent potential PC errors, run a full system scan.