Windows Guard Tools

Windows Guard Tools Description



Windows Guard Tools Screenshot 1Windows Guard Tools markets itself as a system scanner that can defend your PC against viruses and other types of harmful software, but the real intent behind Windows Guard Tools’s marketing is to make you pay money for fake security features. Just as Windows Guard Tools’s creators haven’t bothered to take the time to make Windows Guard Tools look like anything more than a minor tweak to identical variants of FakeVimes scamware, they’ve also been far too lazy to include actual threat detection or removal features in Windows Guard Tools. As a result, like most other types of rogue anti-malware scanners, Windows Guard Tools’s best efforts can only produce inaccurate warning messages and fake system scans. SpywareRemove.com malware experts recommend that you treat Windows Guard Tools as hostile software to be eradicated by a genuine anti-malware product, since Windows Guard Tools may also create security vulnerabilities on your PC by launching browser redirects or attacking security-related Windows programs.

The Contrivances by Which Windows Guard Tools Makes a Grab for Your Wallet


Windows Guard Tools is a recent variant of rogue anti-malware software from Win32/FakeVimes, a scamware classification that includes both older PC threats such as Volcano Security Suite, Windows Profound Security, VirusSecurity, Windows PRO Scanner, Windows Shielding Utility, Windows Virtual Angel, Windows Expert Series, Windows Premium Console, Windows Personal Doctor, Windows Control Series, Smart Security, Windows AntiHazard Helper, Personal Security Sentinel, Windows Malware Sleuth, Windows Software Keeper, Windows System Defender, Windows Health Keeper, Personal Internet Security 2011, Windows Telemetry Center, Windows Home Patron, Windows Enterprise Suite, Windows Basic Antivirus, Windows Defending Center, Windows Care Taker, Smart Virus Eliminator, Internet Security Essentials, Windows Protection Unit, Windows Privacy Counsel, Windows Antivirus Care, Windows Instant Scanner, Best Malware Protection, Windows Safety Module, Best Antivirus Software, Windows Safety Maintenance, Windows No-Risk Agent, Windows Secure Workshop, Smart Internet Protection 2011, Windows Secure Workstation, Windows Advanced Security Center, Windows Privacy Extension, Fast Antivirus 2009, Additional Guard, Windows Firewall Constructor, Windows Activity Debugger, Windows Safety Manager, Windows Active Guard, Windows Safety Series, Live PC Care, Windows PC Aid, Windows Pro Defence, Windows Virus Hunter, Windows Functionality Checker, Windows Antivirus Rampart, Windows Safety Toolkit, Windows High-End Protection, Windows Private Shield, Windows Interactive Security, Windows Software Saver, Windows Proactive Safety, Windows Privacy Module, PrivacyGuard PRO, Windows Turnkey Console, Windows Performance Catalyst, My Security Wall, Windows Custodian Utility, Windows AntiHazard Center, Windows First-Class Protector, CleanUp Antivirus, Windows Shield Tool, Windows Protection Maintenance, PC Live Guard, Windows ProSecure Scanner, Windows Pro Solutions, Windows Advanced Toolkit, Windows Ultimate Security Patch, Windows Antivirus Machine, Windows Antihazard Solution, Windows Debug Center, Windows Efficiency Accelerator, Windows Secure Web Patch, Windows Stability Guard, Windows Guard Solutions, Windows Security Suite, Antivirus Smart Protection, Windows Protection Master, Windows Trouble Taker, Windows Daily Adviser, Windows Antivirus Release, Windows ProSecurity Scanner, Windows Maintenance Guard, Windows Problems Stopper, Windows Pro Safety Release, Windows Pro Rescuer, Windows Performance Adviser, Windows Multi Control System, Windows Web Commander, Windows Maintenance Suite, Internet Security Suite, Enterprise Suite, Windows Abnormality Checker, Keep Center Keeper, Smart Internet Protection 2012, Extra Antivirus, Windows Internet Booster, My Security Engine, Windows Active Defender, Windows Virtual Security, Security Master AV, Windows Tools Patch, Windows Defence Counsel, Home Safety Essentials, Total Anti Malware Protection, Windows Enterprise Defender, Windows Managing System, Windows Pro Web Helper, Windows Pro Safety, Windows Custom Management, Windows Virtual Firewall, Windows Smart Warden, Home Malware Cleaner, Windows Premium Guard, Windows Safeguard Upgrade, Windows No-Risk Center, Windows Crucial Scanner, Windows Interactive Safety, Security Antivirus, Smart Engine, Windows Security Renewal, Anti-Malware Lab, Windows Guardian Angel, Windows Security System, Windows Smart Partner, Windows Ultimate Safeguard, Windows Sleek Performance, Windows Custom Safety, Windows Premium Defender, XP Smart Security, Windows Process Director, Windows Antivirus Patch, My Security Shield, Strong Malware Defender, Windows Advanced User Patch, Windows Proprietary Advisor, Windows Anti-Malware Patch, Windows Warding System, System Protection Tools, Windows Threats Destroyer, Windows Safety Checkpoint, Windows Web Combat, Windows Secure Surfer, Smart Anti-Malware Protection, Windows Risk Minimizer, Activate Ultimate Protection, Live Enterprise Suite, Windows Safety Wizard, Windows Be-on-Guard Edition and Virus Doctor. Windows Guard Tools and its brethren may be designed to work with Windows, but they’re anything but Microsoft-affiliated products, and Windows Guard Tools is unable to provide any of the many anti-malware and security features that Windows Guard Tools pretends to have.

As a cover for its weaknesses, Windows Guard Tools will launch with Windows and create spontaneous and inaccurate pop-up alerts coupled with faux system scans, both of which imply that your PC is being attacked by rootkits, keyloggers, identity theft and other types of serious PC threats.
Download SpyHunter Spyware Scanner
Even if you’re desperate to stop this flood of fake security information, SpywareRemove.com malware analysts don’t see any reason to spend money on Windows Guard Tools, which can be forced into silence only by deleting Windows Guard Tools with a legitimate anti-malware application. Before you attempt this, you may also want to attempt to circumvent Windows Guard Tools’s startup routine or fake Windows Guard Tools’s registration with the key ’0W000-000B0-00T00-E0020,’ which also registers many other members of FakeVimes.

What Windows Guard Tools Really is Protecting When It Blocks Your Software


Windows Guard Tools may also attempt to prevent you from using some types of applications or interfere with features and functions for the benefit of its criminal partners. These attacks are all common to Win32/FakeVimes-based PC threats, and SpywareRemove.com malware researchers have made particular note of them due to the potential security problems that they can pose if Windows Guard Tools isn’t deleted with appropriate software and appropriate alacrity:
  • Windows Guard Tools may redirect your browser to malicious websites (typically those that market rogue security programs like Windows Guard Tools itself).
  • Your browser searches may also be redirected to spam search engines and other sites, particularly if you’re attempting to search with Google.
  • Most damningly, Windows Guard Tools can also attempt to disable various anti-virus and security programs by altering their Registry entries. This can be resolved by booting Windows Guard Tools in a way that avoids its auto start routine and then using appropriate software to restore your Registry or reinstall the programs that were disabled.

In spite of the latter attack, SpywareRemove.com malware experts don’t recommend attempting to remove Windows Guard Tools without assistance from either a PC security expert or dedicated anti-malware programs, since many of Windows Guard Tools’s attacks will alter the Windows Registry and other Windows components (which can damage your OS if edited improperly).

Windows Guard Tools Automatic Detection Tool (Recommended)


Is your PC infected with Windows Guard Tools? To safely & quickly detect Windows Guard Tools, we highly recommend you run the malware scanner listed below.



Visual & GUI Characteristics


Windows Guard Tools Screenshot 2Windows Guard Tools Screenshot 3Windows Guard Tools Screenshot 4Windows Guard Tools Screenshot 5Windows Guard Tools Screenshot 6Windows Guard Tools Screenshot 7Windows Guard Tools Screenshot 8Windows Guard Tools Screenshot 9Windows Guard Tools Screenshot 10Windows Guard Tools Screenshot 11Windows Guard Tools Screenshot 12

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name Detection Count
    1 Windows Guard Tools.lnk 438
    2 %APPDATA%\ Protector-hdux.exe 12
    3 %APPDATA%\ Protector-scxq.exe 12
    4 %AppData%\Windows Guard Tools\ScanDisk_.exe N/A
    5 %AppData%\Microsoft\Internet Explorer\Quick Launch\Windows Guard Tools.lnk N/A
    6 %AppData%\Windows Guard Tools\Instructions.ini N/A
    7 %CommonAppData%\58ef5\SP98c.exe N/A
    8 %CommonAppData%\58ef5\SPT.ico N/A
    9 %CommonAppData%\SPUPCZPDET\SPABOIJT.cfg N/A
    10 %Desktop%\Windows Guard Tools.lnk N/A
    11 %Programs%\Windows Guard Tools.lnk N/A
    12 %StartMenu%\Windows Guard Tools.lnk N/A

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Activate Ultimate Protection “%CommonAppData%\58ef5\SP98c.exe” /s /dHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UninstallHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate ProtectionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\DisplayIcon [unknown dir]\[unknown file name].exe,0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\DisplayName Activate Ultimate ProtectionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\DisplayVersion 1.1.0.1010HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\InstallLocation [unknown dir]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\Publisher UIS Inc.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\UninstallString “[unknown dir]\[unknown file name].exe” /delHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandler\ Implements DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandler\ClsidHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFGHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\ConsoleTracingMask -65536HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\EnableConsoleTracing 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\EnableFileTracing 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\FileDirectory %windir%\tracingHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\FileTracingMask -65536HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\MaxFileSize 1048576HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAVHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\Debugger svchost.exe
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ Implements DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32\ [unknown dir]\[unknown file name].exeHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID\ [unknown file name].DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandler\Clsid\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
Posted: May 25, 2012 | By
Share:
Follow Me on Pinterest More More
Threat Level: 10/10
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Rate this article:
Detection Count: 96

2 Comments

  • cathy varney says:

    this window guard tools is on my Dell laptop..I ant it off..now! i cannot use my dell laptop because of this and i cannot remove it to save my life!!!!!

  • Victoria Kemp says:

    Never ever use windows security

Leave a Reply

What is 14 + 2 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)