Remove Windows Protection Booster (Uninstall Guide)

Following this tutorial will help you to remove Windows Protection Booster virus from your computer. It is not very easy to uninstall this malicious program regularly, i.e. through the Control Panel of your system. You will simply not find it there. Furthermore, this rogue will also block your Desktop completely, without really giving you a chance to get rid of it. Nevertheless, we know a working solution that will assist you in removal of this annoying scam on your system.

Windows Protection Booster virus

Windows Protection Booster is fake anti-virus that comes from a well-spread FakeVimes rogue family. It poses as some reliable application able to detect and remove all contemporary computer threats. We have analyzed this program and now are ready to claim that there is a big difference between what Windows Protection Booster promises to do and the things it really does. It imitates system scanners and always comes up with shocking scan results, stating that your PC is horribly infected.

Even if your computer system is absolutely clean it will ‘detect’ tons of insecure objects (obviously fake and invented threats). The malware attempts you to trick in such way. You are recommended by this hoax to activate the paid version of it (so-called “ultimate protection”) allegedly able to clean all spotted issues. This is the typical tactic of virus developers, because it has the potential to bring them money. So, do not take the scan results seriously. Probably there are no problems with your PC except for Windows Protection Booster infection. Never buy its useless commercial version if you do not want to get a protection against viruses that will never work. You definitely need to get rid of this pest once and for all. The removal details can be found below.


Software necessary for Windows Protection Booster virus removal:

Windows Protection Booster removal steps:

  • In Windows Protection Booster click “?” Menu button anc click “Register”:
  • Register FakeVimes virus

  • Paste this product key – 0W000-000B0-00T00-E0022 exactly as shown at the image below, then click “Register“:
  • FakeVimes reg key

    Note! If this product key has been found to be invalid, try one of these keys as well:

    1. 0W000-000B0-00T00-E0001
    2. 0W000-000B0-00T00-E0002
    3. 0W000-000B0-00T00-E0003
    4. 0W000-000B0-00T00-E0021
  • Afer registration download Plumbytes Anti-Malware without any restrictions on the part of the rogue, scan your PC with Plumbytes Anti-Malware and remove all infections detected by clicking “Apply” button at the end of scan.
  • Restart your computer and repeat scan.

Windows Protection Booster similar removal video at YouTube:

Beware of ways how Windows Protection Booster is spread today:

Windows Protection Booster uses various vulnerabilities of browsers like Internet Explorer, Google Chrome, Mozilla Firefox, Opera and many others for the interference into your computer. For example, you might get the following scary alert, supposedly coming from Microsoft Antivirus:

Microsoft Antivirus fake alert
Microsoft Antivirus has found critical process activity on your PC

Microsoft Antivirus has found critical process activity on your PC. You will need to clean your computer to prevent the system breakage.

If you actually click the “OK” button as shown at the image you will have another fake alert, not associated at all to Microsoft Security Essential Alert, but yet claiming to be such:

Microsoft Security Essentials fake alert
Fake MSE Alert

Microsoft Security Essentials Alert
Potential threat details
Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. You need to clean your computer immediately to prevent the system crash.
Detected items:
– Trojan-PSW.Win32.launch
– HackTool:Win32/Welevate.A
– Adware.Win32.Fraud

Associated files and registry entries:

Related files:

%AppData%\svc-[rnd].exe
%CommonAppData%\connector.swf
%Programs%\Windows Protection Booster.lnk
%Desktop%\Windows Protection Booster.lnk

Related registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\PrSft %AppData%\svc-[rnd].exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\Debugger svchost.exe

Fake security alerts, notifications and warnings of Windows Protection Booster scam:

Firewall has blocked a program from accessing the Internet
C:\Program Files\Internet Explorer\iexplore.exe
is suspected to have infected your PC.
This type of virus intercepts entered data and transmits them
to a remote server.

Error
Trojan activity detected. System integrity at risk.
Full system scan is highly recommended.

Error
System data security is at risk!
To prevent potential PC errors, run a full system scan.