Windows Defence Counsel
Written by Tomas Meskauskas on
What is Windows Defence Counsel and how to remove it?
Windows Defence Counsel is a fake antivirus program which uses generated security scans and warning pop-ups to scare PC users into believing that their computers are infected with spyware. When installed on your computer this malicious software will start imitating a security program and will pretend to initiate a security check-up. This fake security scan will end up in generation of a long list of supposedly detected malware, most of them will be indicated to be high and critical risk.
To make this detection list appear more real Windows Defence Counsel will constantly interrupt your work by showing fake security warning pop-ups which states that your computer is being attacked by viruses and every time you will try to launch any of your programs a false firewall alert will be displayed. If you click "Remove All" or "Prevent Attack" buttons in Windows Defence Counsel you will be asked to activate "ultimate protection" (purchase a licence for this program) in order to remove the detected malware. You shouldn't buy this program, it's rogue and it uses misleading strategy to scare you into believing that your PC is infected. In fact none of the spyware and other infections that are detected by Windows Defence Counsel actually exists on your computer, this bogus software comes from a family of rogues called "FakeVimes". It's predecessors were called Windows Guard Tools, Windows Safety Maintenance, Windows Multi Control System. You shouldn't trust Windows Defence Counsel, it's created by Cyber criminals and is promoted using various malicious methods.

Most commonly Windows Defence Counsel is spread using misleading websites which displays fake security warning messages and offers false anonymous torrent connections. False online security warning messages are commonly followed by imaginary security scans which provides generated malware detection lists. Don't trust any of such online messages which states that your computer is infected by viruses, most commonly such method are used to spread fake antivirus programs such as Windows Defence Counsel. Other known distribution methods includes fake Microsoft Security Essentials warning messages. To prevent such fake antivirus programs from entering your computer you should always use a legitimate antivirus and antispyware programs and avoid following the guidance of mentioned fake online security pop-ups. If you have noticed a program which a similar user interface as the one in the screenshot you can be sure that you are dealing with a fake antivirus software which should be eliminated from your PC. Windows Defence Counsel is an empty program which uses generated warning messages and security scans to scare you into buying it's licence key, use this removal guide and eliminate it from your PC.
Windows Defence Counsel generates such fake warning messages:
"Warning! Virus Detected Threat detected: FTP Server Infected file: C:\Windows\System32\dllcache\wmploc.dll"
"Warning! Identity theft attempt Detected Hidden connection IP: 58.82.12.124 Target: Your passwords for sites"
"Error Key-logger activity detected. System information security is at risk. It is recommended to activate protection and run a full system scan"
Windows Defence Counsel removal:
Before downloading the remover for Windows Defence Counsel click a question mark icon at the top of the main window of this program, choose "Activate Now" and enter this registration code: 0W000-000B0-00T00-E0020 This will enable blocked Windows functions and will make the further removal process much easier, after entering the activation code continue to downloading the spyware remover.
remover for Windows Defence Counsel
If you can't download or run spyware remover try running registry fix (link below). It enables execution of programs. download registryfix.reg file, double click it, click YES and then OK.
Manual Windows Defence Counsel removal instructions:
Step 1
Start your computer in safe mode. Click Start, then click Shut down. Select Restart and click OK. During your computer starting process press F8 key on your keyboard multiple times until Windows Advanced Options menu shows up, then select Safe mode with networking from the list and press ENTER.

Step 2
Now we need to remove proxy settings. Windows Defence Counsel adds a proxy to your Internet connection settings to show various errors when you try to access Internet. To do this, open Internet explorer, click Tools and select Internet Options. Then select the "Connections" tab.

In the "Connections" tab, click LAN settings, if a "Use a proxy server for your LAN" is checked, uncheck it and press OK. In some cases Windows Defence Counsel could hide this setting from you, and ywillou see that proxy setting is disabled, while actually it could be enabled, but not shown up in these settings. If a "Use a proxy server for your LAN" is unchecked, It is recommended to check it, then un-check it and then click OK.

Step 3
Download HijackThis and save it on your desktop. Some malicious programs are able to block HijackThis so when you click the download link, in the Save dialog rename HijackThis.exe to iexplore.exe and only then click the Save button. After saving the file on your desktop, double click it. In the main HijackThis window click “Do a system scan only” button. Select these entries (place a tick at the left of the entry):
O4 - HKCU\..\Run: [Inspector] %AppData%\Protector.exe (Protector.exe file may have 3 or more random characters at the end of it's file name like ProtectionGQY.exe)
After selecting required entries, click "Fix Checked" and these entries will be removed. After this procedure you can close HijackThis and proceed to the next removal step.
Step 4
Download a legitimate anti-spyware software to fully remove Windows Defence Counsel from your computer. We recommend using Spyware Doctor 2012 version
Step 5
After removing Windows Defence Counsel, you will need to reset your Hosts file. Don't skip this step, this malware modifies your Hosts files, and you will encounter browser redirect problems if malicious entries will not be removed from hosts file.
Hosts file is used to resolve some canonical names of websites to IP addresses. When it is changed, the user may be redirected to malicious site still seeing good URL in address bar. It is very hard to find out if the site is genuine or not, when hosts file is modified. To fix this, please download Microsoft Fix It tool, that restores your hosts file to Windows default. Run this tool when downloaded and follow the on-screen instructions. Download link below:
Finish
After doing all these steps your computer should be clean. Windows Defence Counsel will be removed.
Other tools known to remove Windows Defence Counsel:
Some malicious software modifies browser settings and disables downloads of spyware and virus removing software. If you have problems downloading anti-spyware software with Internet Explorer, try downloading with Chrome, FireFox, Opera, etc.
If you can't access Internet:
Load your computer in safe mode. Click Start, click Shut down, click Restart, click OK. During your computer starting process press F8 key on your keyboard multiple times until you see Windows Advanced Option menu, then select Safe mode with networking from the list.
Start Task manager. Press ctrl+alt+del (or ctrl+shift+esc) and end task the processes of rogue program. ( if after this procedure you can't access any programs press ctrl+alt+del, click File, select New Task, and type explorer.exe then press OK.
Open Internet explorer, click Tools and select Internet Options. Select Connections, then click LAN settings, if a Use a proxy server for your LAN is checked, un-check it and press OK.
After this procedure you should be able to access Internet. Now you can download anti-spyware software from our "Top spyware removers" section and run a full scan. Download, install and don't forget to update your selected anti-spyware program. Then run a full system scan.
Manual Windows Defence Counsel removal:
If you were unable to remove Windows Defence Counsel using the steps above, you can use this manual removal instruction. Use it at your own risk. If you don't have strong computer knowledge you could harm your operating system. Be careful and use it only if you are an experienced computer user. (Instructions on how to end processes, remove registry entries...)
End these Windows Defence Counsel processes:
random.exe
Protector.exe (Protector.exe file may have 3 or more random characters at the end of it's file name like ProtectionGQY.exe)
Remove these Windows Defence Counsel registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net
Delete these Windows Defence Counsel files:
%StartMenu%\Programs\Windows Defence Counsel.lnk
%AppData%\Protector.exe (NOTE: this file may have various symbols at the end of it's name. Look for the similar file name pattern and remove it)
%AppData%\result.db
%Desktop%\Windows Defence Counsel.lnk
Other tips, that might help remove Windows Defence Counsel
- If you can't download anti-spyware software: Click on the download link, when the save dialog opens change the file name (example: when downloading mbam-setup.exe rename it to iexplore.exe).
- If you have installed anti-spyware program but you can't run it do the following steps:
- Click Run, type %ProgramFiles% and press Enter. Open folder of your anti-spyware program, search for executable file and rename it. (example: Open Malwarebytes’ Anti-Malware folder, right-click on the main executable file (mbam.exe) then click rename. Rename the mbam.exe file to iexplore.exe, winlogon.exe firefox.exe or other known executable file.
- If you can't access your anti-spyware software, try creating a new user account:
Click Start -> Settings -> Control panel.
Click User Accounts and create a new account.
Reboot your computer and log in using a newly created user account.
After this procedure you should be able to access your anti-spyware programs. Update and run a full system scan.

