Windows Antivirus Rampart is a program that pretends to be a legitimate security software –such as an antivirus – but in reality, it is a totally scam. It reports false infections, displays various fake security alerts, hijacks an Internet browser as a method to force you to believe that your computer is infected. Windows Antivirus Rampart is designed with one purpose – to scare you into thinking that your computer is in danger, and in order to make it safe again, you need to buy the full version of this program. If your computer is infected with this malware, then most importantly, do not purchase it! Uninstall the rogue from your computer as soon as possible. Use the removal guide below to remove Windows Antivirus Rampart manually from your computer for free.
Remove Windows antivirus rampart Processes

  1. Click on Start and then go for the option ‘Run’.
  2. Type tskmgr and press enter.
  3. This command will cause the Windows task manager to open.
  4. You can also open the Windows task manager directly by pressing the short cut keys ALT, CTRL and DEL all at a time.
  5. Find the ‘processes’ tab and click on it, and then find the Windows antivirus rampart processes.
  6. All the processes are listed under the column name called ‘image name’.
  7. Right click the processes and then select the option Delete.
  8. The Windows antivirus rampart processes are which must be deleted to stop the dangerous rouge from working are:

Protector-[random 3 chars].exe

Protector-[random 4 chars].exe

Remove Windows antivirus rampartRegistry key values

  1. Open Run using the start menu.
  2. Type regedit in it and press enter.
  3. Select the left pane of the windows registry editor and click on Edit.
  4. Now further click on Find and then enter the Windows antivirus rampartregistry values in it one by one.
  5. Right click on the shown registry values and then press Delete.

The Windows antivirus rampartregistry values that must be removed from the computer are:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\

Inspector = %AppData%\Protector-[random].exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\

Debugger = svchost.exe

HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\

Debugger = svchost.exe

Remove Windows antivirus rampartother files

  1. Open Run.
  2. Type cmd and press Ok.
  3. Enter the name of the Windows antivirus rampart file along with the directory name.
  4. If you do not know the directory where the files are located you can use the dir command.
  5. When the required file is shown write down “regsvr32 /u SampleName.exe” and change SampleName.exe with the following Windows custom safety name:

%AppData%\Protector-[random 3 chars].exe

%AppData%\Protector-[random 4 chars].exe

%AppData%\result.db

 

How to remove Windows Antivirus Rampart?

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>