1 of 3
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Can't be uninstalled via Control Panel
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • System crashes
  • Annoying Pop-up's
  • Slow Computer

Windows Defence Unit

Are you seeing various warnings that your system is infected with malicious software? If it is exactly so, it is very probable that your computer is infected with a rogue application better known as Windows Defence Unit. It is an application that belongs to FakeVimes family of infections; thus, you should not expect anything beneficial from it. It is known that this program seeks to scare computer users and thus easily extort money from them. Actually, you should not trust any word of Windows Defence Unit because it is simulated security software. It might appear on all the computers with Windows operating system, which is why we recommend that you keep your antimalware tool enabled. Do you already have Windows Defence Unit on your system? You should better get rid of it as soon as possible.

As the main purpose of this application is to make you believe that your computer is infected, it is not surprising that Windows Defence Unit is going to perform a scan and then provide you with a list of malicious software that has supposedly entered your system. Do not be scared; these threats do not exist onto your computer; however, it is still possible that you have other infections like Trojan on your PC. As you might have already understood, you should not believe any promises of Windows Defence Unit because it is not going to do anything good for you.

What is more, you should not buy the license that costs $99.9 because you will not only lose your money, but also reveal your credit card details. It means that the possibility that all your money will be stolen is rather high. Thus, if you have already paid money, we recommend that you call your credit card issuer and ask to cancel the payment. However, your credit card information might be already known for cyber criminals; thus, you should be very careful.

The removal of Windows Defence Unit is not very easy because it does not allow accessing Task Manager, Registry Editor, Internet and other essential tools. Thus, you should enter 0W000-000B0-00T00-E0022 or 0W000-000B0-00T00-E0021 and all the annoying symptoms will be gone. Then, you will have an opportunity to erase the program itself. For this matter, SpyHunter antimalware suite is the most suitable.

Windows Defence Unit removal

  1. Reboot your computer and start tapping F8 straightaway after BIOS screen is gone.
  2. Select Safe Mode with Command Prompt using arrow keys and press Enter.
  3. Type cd.. alongside C:\Windows\system32 and press Enter.
  4. Enter explorer.exe near C:\Windows . Tap Enter.
  5. Click the Start button after Windows loads up and select Search/RUN.
  6. Enter %appdata%.
  7. Locate svc-[random file name].exe and right-click on it. Select Delete.
  8. Restart your computer in a normal mode.
  9. Click the Start button again, select Search/RUN and enter regedit.
  10. Move to HKEY_CURRECT_USER\Software\Microsoft\Windows NT\Current Version\Winlogon .
  11. Locate shell and right-click on it, then select Modify.
  12. Type in %WinDir%\Explorer.exe as Value and then click OK.
  13. Launch your browser and visit http://www.pcthreat.com/download-sph .
  14. Download the recommended tool, install it, and scan your computer to remove Windows Defence Unit.
Download Spyware Removal Tool to Remove* Windows Defence Unit
  • Quick & tested solution for Windows Defence Unit removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows Defence Unit

Files associated with Windows Defence Unit infection:

svc-weem.exe
%AppData%\data.sec
%AppData%\svc-[random file name].exe

Windows Defence Unit processes to kill:

svc-weem.exe
%AppData%\svc-[random file name].exe

Remove Windows Defence Unit registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd
HKEY_CURRENT_USER\Software\Microsoft\Windows\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd "ImagePath" = "123123.sys"
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.