Windows Custom Safety

Windows Custom Safety Description



Windows Custom Safety Screenshot 1The FakeVimes scamware train has shown no signs of slowing down with its latest offering to the masses, Windows Custom Safety. This rogue anti-malware scanner may pretend to keep phishing attacks, rootkits, spyware and other threats away from your hard drive, but SpywareRemove.com malware researchers have verified Windows Custom Safety’s inability to do any of the aforementioned defensive acts. Instead of giving your computer an increase in safety, Windows Custom Safety will institute a lock down against your PC’s real security software, redirect your browser to hostile sites and display fake explanations for these attacks that include the names of practically every PC threat imaginable – except itself. Once it’s identified, deleting Windows Custom Safety should occupy the top slot on your schedule, although you may also need to disable Windows Custom Safety with any of the methods below to access appropriate anti-malware programs.

How Windows Custom Safety Customizes Your Safety in Perverse Ways


Windows Custom Safety is marketed in the form of a multi-featured security and anti-malware product, but its software actually is focused on the opposite aim: of making your computer unsafe, feeding you false security information and blocking anything that could thwart these attacks. These are traits that Windows Custom Safety shares with other variants of FakeVimes such as Windows Safety Manager, Windows Guardian Angel, Windows Abnormality Checker, Windows Health Keeper, Windows Trouble Taker, Windows Performance Catalyst, Windows Guard Tools, Windows Ultimate Safeguard, Windows Software Saver, Windows Virtual Angel, VirusSecurity, Windows Functionality Checker, Windows Maintenance Suite, Windows Virus Hunter, Smart Internet Protection 2011, Windows AntiHazard Helper, XP Smart Security, Activate Ultimate Protection, Internet Security Suite, Windows Stability Guard, Windows Instant Scanner, Windows Secure Workstation, Windows Safety Wizard, Virus Doctor, Security Master AV, Windows Malware Sleuth, Windows Software Keeper, Windows Basic Antivirus, Windows Sleek Performance, System Protection Tools, Antivirus Smart Protection, Windows Secure Web Patch, Windows First-Class Protector, Smart Virus Eliminator, Windows Privacy Module, Windows Active Guard, Anti-Malware Lab, Windows Risk Minimizer, Windows Profound Security, Windows Smart Warden, Strong Malware Defender, Windows Antivirus Patch, Windows Pro Defence, Windows Ultimate Security Patch, Windows Interactive Safety, Windows Antivirus Rampart, Windows PC Aid, Windows Custom Management, Windows Web Combat, Home Safety Essentials, Security Antivirus, Windows Tools Patch, Windows Guard Solutions, Extra Antivirus, Windows Anti-Malware Patch, Windows Smart Partner, Windows Efficiency Accelerator, Windows Safety Series, Smart Internet Protection 2012, Windows Premium Console, Windows Antivirus Release, PC Live Guard, Windows Safety Toolkit, Windows High-End Protection, Windows Safety Checkpoint, Volcano Security Suite, Live PC Care, Windows Proprietary Advisor, Personal Internet Security 2011, Total Anti Malware Protection, Windows System Defender, Windows Performance Adviser, Windows Active Defender, Windows Premium Guard, Windows Daily Adviser, Windows Privacy Extension, Windows Virtual Firewall, Windows Safety Module, My Security Wall, Home Malware Cleaner, Windows Pro Rescuer, My Security Engine, Windows Telemetry Center, Windows Web Commander, Windows Activity Debugger, Windows Protection Maintenance, Windows Turnkey Console, Windows PRO Scanner, Windows Safeguard Upgrade, Windows Crucial Scanner, Keep Center Keeper, Windows Care Taker, Windows Safety Maintenance, Windows Shielding Utility, Windows ProSecure Scanner, Windows Maintenance Guard, Windows Antivirus Machine, Windows Defence Counsel, Windows Shield Tool, Windows Security System, Windows Secure Workshop, Internet Security Essentials, Windows Be-on-Guard Edition, Windows Pro Safety Release, Windows Private Shield, Windows Problems Stopper, Windows Defending Center, Windows Advanced User Patch, Windows Premium Defender, Windows Custodian Utility, Windows Protection Unit, Windows Pro Web Helper, Smart Anti-Malware Protection, Windows No-Risk Center, Windows Threats Destroyer, Windows No-Risk Agent, Windows Pro Safety, Windows Multi Control System, Windows Internet Booster, Windows Pro Solutions, Windows Interactive Security, Windows Enterprise Suite, Windows Protection Master, Windows Enterprise Defender, Personal Security Sentinel, Fast Antivirus 2009, Windows Personal Doctor, Windows Managing System, Windows Advanced Security Center, Windows Privacy Counsel, Windows Firewall Constructor, Windows Process Director, Windows Expert Series, Enterprise Suite, Windows Antivirus Care, Best Antivirus Software, Windows Antihazard Solution, Windows AntiHazard Center, Windows Secure Surfer, Windows Security Renewal, PrivacyGuard PRO, Best Malware Protection, Windows ProSecurity Scanner, Additional Guard, Smart Engine, Windows Home Patron, Smart Security, Windows Advanced Toolkit, Windows Virtual Security, Windows Control Series, Windows Security Suite, Windows Debug Center, Windows Warding System, Live Enterprise Suite, My Security Shield, Windows Proactive Safety and CleanUp Antivirus. While Windows Custom Safety launches with Windows and is easily identified, its attacks are not always as out-in-the-open, and SpywareRemove.com malware researchers have noted common Windows Custom Safety symptoms as shown below:
  • Search engine redirects to malicious sites.
  • Blocked PC security websites that are replaced by fraudulent error pages.
  • Pop-up alerts that warn you about the presence of attacks or harmful programs that actually aren’t present in the first place (such as identity theft or unrelated rootkits).
  • Fake system scans that Windows Custom Safety uses to continue its illusion of your PC being attacked by unrealistically large amounts of varied PC threats.
  • Anti-malware and security programs that Windows Custom Safety blocks with inaccurate warning messages – typically about supposed infections that have latched onto these programs.
    Download SpyHunter Spyware Scanner
    Blocked software can extend to basic Windows utilities like Task Manager.

Getting Windows Back to Normal without Windows Custom Safety’s Shifty Assistance


Windows Custom Safety, like all modern members of the FakeVimes family of rogue anti-malware programs, has been confirmed to make modifications to Windows file during its infection process. These changes may allow your PC to be continued to be attacked by browser redirects and other issues even after Windows Custom Safety is deleted, if you fail to remove all of Windows Custom Safety’s alterations. SpywareRemove.com malware researchers suggest using a reputable brand of anti-malware equipment to scan your complete PC for all traces of Windows Custom Safety and remove them in an automated fashion, since manual removal is hazardous for non-experts in PC security.

Since PC threats from Windows Custom Safety’s family may also be installed by other forms of hostile software, such as Trojan droppers, SpywareRemove.com malware research team also recommends that you use thorough system scanning features that can detect related PC threats, in addition to Windows Custom Safety. Updating your anti-malware software prior to trying to delete Windows Custom Safety is also encouraged since Windows Custom Safety is a recent derivative of its family.

Windows Custom Safety Automatic Detection Tool (Recommended)


Is your PC infected with Windows Custom Safety? To safely & quickly detect Windows Custom Safety, we highly recommend you run the malware scanner listed below.



Visual & GUI Characteristics


Windows Custom Safety Screenshot 2Windows Custom Safety Screenshot 3Windows Custom Safety Screenshot 4Windows Custom Safety Screenshot 5Windows Custom Safety Screenshot 6Windows Custom Safety Screenshot 7Windows Custom Safety Screenshot 8Windows Custom Safety Screenshot 9Windows Custom Safety Screenshot 10Windows Custom Safety Screenshot 11Windows Custom Safety Screenshot 12

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\"Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\"Debugger" = "svchost.exe"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Inspector = %AppData%\Protector-[RANDOM CHARACTERS].exe

Additional Information

  • The following messages's were detected:
    # Message
    1Error Keylogger activity detected. System information security is at risk. It is recommended to activate protection and run a full system scan.
    2Error Software without a digital signature detected. Your system files are at risk. We strongly advise you to activate your protection.
    3Warning Firewall has blocked a program from accessing the Internet. Windows Media Player Resources C:\Windows\system32\dllcache\wmploc.dll C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Posted: June 8, 2012 | By
Share:
Follow Me on Pinterest More More
Threat Level: 10/10
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
Rate this article:
Detection Count: 112

4 Comments

Leave a Reply

What is 15 + 13 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)