1 of 3
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • System crashes
  • Annoying Pop-up's
  • Slow Computer

Windows Antivirus Master

Windows Antivirus Master is no better than other bogus antivirus programs, because this piece of malware turns the system’s performance upside down and attempts to lure you into its deception. The rogue looks like a reliable antivirus application, which “scans” the system and displays various infections. However, this fraudulent program replaces Windows Safety Master and other malicious programs that are used to deceive computer users; hence, it is highly advisable to remove Windows Antivirus Master as soon as possible to avoid highly probable misunderstanding.

Computer users become victimized by this treacherous program due to their own irresponsibility. If you, for example, browse the Internet carelessly and ignore the fact that there are many compromised websites and infected files that circulate around the network, your PC could be easily infected by Windows Antivirus Master. It the beginning, it is likely that you will identify this application as an antivirus program, because it looks and operates like one. It produces pop-up balloons, scans the system and presents fictitious infection, which are not present in the system. Remove Windows Antivirus Master if you find it on the computer, because the rogue’s attempt to deceive you may be successful and you may start thinking that the system is being damaged by various threats.

Since Windows Antivirus Master comes from Rogue.FakeVimes family of computer infections, it will do everything the previous applications (such as Windows Ultimate Booster or Windows Efficiency Kit) were capable of. Just as it has been mentioned above, Windows Antivirus Master will spam you with fake system security notifications that should make you believe your computer is seriously infected with tons of malware, for example:

Keylogger actively detected. System information security is at risk. It is recommended to activate protection and run a full system scan.

Activate Windows Ultimate Booster to get ultimate protection against Identity Theft, Viruses, Malware and other threats!

However, the fake security pop-ups are only a small part of what Windows Antivirus Master does in order to push you into the corner. The rogue wants you to purchase the license for a program which cannot deliver what it promises. Users are usually forced into purchasing the program, because Windows Antivirus Master blocks their executable files and subsequently you can no longer load your Internet browser. Also, to protect itself from being removed, the rogue denies access to Windows Task Manager, Registry Editor, and it can even block Windows Explorer.

Nevertheless, despite the fact that it seems there is no way out of this situation, you should NEVER purchase the full version of Windows Antivirus Master, because this way you would give away your credit card information to cyber criminals, and that would definitely lead to a major cyber theft. The easiest way to remove Windows Antivirus Master infection symptoms is to activate it with these registration keys:


By doing this it will buy you some time and you will be able to acquire a licensed computer security application that would help you delete Windows Antivirus Master from your system. If you do not wish to use any activation keys or they simply do not work work you. Follow the instructions listed bellow that will help you to restore Windows Explorer and then access the Internet to download a antispyware software tool of your choice.

How to Remove Windows Antivirus Master

  1. Reboot the PC and tap F8 repeatedly once BIOS screen disappears.
  2. Use arrow keys to navigate and select Safe Mode with Command Prompt. Press Enter.
  3. When system loads, type cd.. after C:\Windows\system32 in the Command Prompt. Press Enter.
  4. When C:\Windows line shows up, enter \explorer.exe next to it and hit Enter.
  5. Windows Explorer will load. Open Start menu.
  6. Enter %appdata% into the Search box (or Run utility on Windows XP) and hit Enter.
  7. Delete guard-{4 random symbols}.exe file from Application Data directory.
  8. Restart the PC in Normal mode and open Start menu.
  9. Enter regedit into Search box (or Run utility for Windows XP) and press Enter.
  10. Go to HKEY_CURRENT_USER\Software\Microsoft\Windows NT\Current Version\Winlogon.
  11. Locate Shell on the right pane and right-click it.
  12. Click Modify and type %WinDir%\Explorer.exe for Value. Press OK.
  13. Access http://www.pchreat.com/download-sph and install SpyHunter to scan your PC.

The best way to remove Windows Antivirus Master is to use a reliable malware removal application. Processes, files and registry entries related to the infection are terminated, and the system is protected against further infections. After the removal, all that you need to do to keep the system protected is to update the antispyware application regularly so that it is ready to resist malware attacks anytime.

Download Spyware Removal Tool to Remove* Windows Antivirus Master
  • Quick & tested solution for Windows Antivirus Master removal.
  • 100% Free Scan for Windows

How to manually remove Windows Antivirus Master

Files associated with Windows Antivirus Master infection:

%AppData%\svc-[random file name].exe

Files associated with Windows Antivirus Master infection (Win7, Vista):

C:\Users\[Current User]\AppData\Roaming\svc-[random file name].exe

Windows Antivirus Master processes to kill:

%AppData%\svc-[random file name].exe

Remove Windows Antivirus Master registry entries:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%AppData%\svc-[random file name].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "GuardSoftware" = %AppData%\svc-[random file name].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableVirtualization" = 0

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.