Windows Active Guard virus removal tool

Windows Active Guard is a relatively new rogue-type infection that can easily attack many PCs today, and your workstation is surely not an exception. There are many similar malwares like this one, all of them share the same GUI and are extremely dangerous for your computer. Hurry up to remove this serious threat from your PC quickly and effectively.


Windows Active Guard is known to perform many evil deeds on your system. First, it modifies your PC and makes sure this application is launched automatically together with every system startup. This means that as soon as you switch your computer on you would first see Windows Active Guard hoax on your machine. The malware begins to scan your PC automatically each time you switch your computer on. However, all such scanning is being just imitated. There aren’t such threats as the hoax reports to your about. By the way, this infection is the only threat on your machine, and this is the one that you should remove from your system at once, without hesitation.

Apart of the fact that Windows Active Guard is a virus it is also quite dangerous for your wallet, by the way. What we mean by that is that this hoax wants to make you pay money for its fake and useless licensed version, which is not able to remove real threats. When serious infections do attack your machine Windows Active Guard will not render the desired level of protection for your computer. So, do not waste money buying it. Remove this hoax from your computer as soon as possible. Follow the removal guide you see below.

Windows Active Guard automatic remover:

Windows Active Guard manual remover:

Delete Windows Active Guard files:
Protector-[rnd].exe in %AppData% folder
Delete Windows Active Guard registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

