Windows Defence Unit uninstall guide

Start spreading the news!

Windows Defence Unit is a malicious program which attacks many computers today. The way it gets into PCs is quite pushy, so you definitely need to be aware of how dangerous it is. The program doesn’t get into PCs legally. What it does is entering computers by means of fake Microsoft Security Essential Alerts. These fake MSE alerts prompt users into buying this rogue as a solution to remove all unreal threats supposedly revealed on your system.

Windows Defence Unit virus

After successful installation into PC the Windows Defence Unit immediately tries to make you think it is some legitimate program. So, it runs a fake scanning of your PC and then reports the large number of fake security threats, warnings and notifications about invented viruses. It then tells you that in order to have all these fake threats removed you need to purchase its full version, which is absolutely useless and good for nothing.

Download Combo Cleaner

As you see now, purchasing Windows Defence Unit is the total waste of your funds. We recommend you to immediately get rid of this scam by running a complete scan of your PC with a reliable security software as explained below. Please carefully follow these removal instructions. If you have any questions getting rid of this rogue please let us know.

Windows Defence Unit removal milestones:

  • In Windows Defence Unit click “?” Menu button and click “Register“:
  • Register Windows Defence Unit virus

  • Paste this product key – 0W000-000B0-00T00-E0022 exactly as shown in the image below, then click “Register“:
  • Windows Defence Unit product key

    Note! If this product key has been found to be invalid, try one of these keys as well:

    1. 0W000-000B0-00T00-E0001
    2. 0W000-000B0-00T00-E0002
    3. 0W000-000B0-00T00-E0003
    4. 0W000-000B0-00T00-E0021
  • Afer registration download GridinSoft Trojan Killer, install the program, scan your PC with it and remove all infections detected by clicking “Remove selections” button at the end of scan.
  • Download GridinSoft Trojan Killer
  • Restart your computer and repeat scan.

Video that explains how to activate Windows Defence Unit virus:

Associated files and registry entries information

Related files:

%AppData%\svc-[rnd].exe
%CommonAppData%\connector.swf
%Programs%\Windows Defence Unit.lnk
%Desktop%\Windows Defence Unit.lnk

Related registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PrSft %AppData%\svc-[rnd].exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\Debugger svchost.exe

Fake security alerts, notifications and warnings of Windows Defence Unit scam:

Firewall has blocked a program from accessing the Internet
C:\Program Files\Internet Explorer\iexplore.exe
is suspected to have infected your PC.
This type of virus intercepts entered data and transmits them
to a remote server.

Error
Trojan activity detected. System integrity at risk.
Full system scan is highly recommended.

Error
System data security is at risk!
To prevent potential PC errors, run a full system scan.