Windows Guard Tools
Windows Guard Tools Description
The Contrivances by Which Windows Guard Tools Makes a Grab for Your Wallet
Windows Guard Tools is a recent variant of rogue anti-malware software from Win32/FakeVimes, a scamware classification that includes both older PC threats such as Volcano Security Suite, Windows Profound Security, VirusSecurity, Windows PRO Scanner, Windows Shielding Utility, Windows Virtual Angel, Windows Expert Series, Windows Premium Console, Windows Personal Doctor, Windows Control Series, Smart Security, Windows AntiHazard Helper, Personal Security Sentinel, Windows Malware Sleuth, Windows Software Keeper, Windows System Defender, Windows Health Keeper, Personal Internet Security 2011, Windows Telemetry Center, Windows Home Patron, Windows Enterprise Suite, Windows Basic Antivirus, Windows Defending Center, Windows Care Taker, Smart Virus Eliminator, Internet Security Essentials, Windows Protection Unit, Windows Privacy Counsel, Windows Antivirus Care, Windows Instant Scanner, Best Malware Protection, Windows Safety Module, Best Antivirus Software, Windows Safety Maintenance, Windows No-Risk Agent, Windows Secure Workshop, Smart Internet Protection 2011, Windows Secure Workstation, Windows Advanced Security Center, Windows Privacy Extension, Fast Antivirus 2009, Additional Guard, Windows Firewall Constructor, Windows Activity Debugger, Windows Safety Manager, Windows Active Guard, Windows Safety Series, Live PC Care, Windows PC Aid, Windows Pro Defence, Windows Virus Hunter, Windows Functionality Checker, Windows Antivirus Rampart, Windows Safety Toolkit, Windows High-End Protection, Windows Private Shield, Windows Interactive Security, Windows Software Saver, Windows Proactive Safety, Windows Privacy Module, PrivacyGuard PRO, Windows Turnkey Console, Windows Performance Catalyst, My Security Wall, Windows Custodian Utility, Windows AntiHazard Center, Windows First-Class Protector, CleanUp Antivirus, Windows Shield Tool, Windows Protection Maintenance, PC Live Guard, Windows ProSecure Scanner, Windows Pro Solutions, Windows Advanced Toolkit, Windows Ultimate Security Patch, Windows Antivirus Machine, Windows Antihazard Solution, Windows Debug Center, Windows Efficiency Accelerator, Windows Secure Web Patch, Windows Stability Guard, Windows Guard Solutions, Windows Security Suite, Antivirus Smart Protection, Windows Protection Master, Windows Trouble Taker, Windows Daily Adviser, Windows Antivirus Release, Windows ProSecurity Scanner, Windows Maintenance Guard, Windows Problems Stopper, Windows Pro Safety Release, Windows Pro Rescuer, Windows Performance Adviser, Windows Multi Control System, Windows Web Commander, Windows Maintenance Suite, Internet Security Suite, Enterprise Suite, Windows Abnormality Checker, Keep Center Keeper, Smart Internet Protection 2012, Extra Antivirus, Windows Internet Booster, My Security Engine, Windows Active Defender, Windows Virtual Security, Security Master AV, Windows Tools Patch, Windows Defence Counsel, Home Safety Essentials, Total Anti Malware Protection, Windows Enterprise Defender, Windows Managing System, Windows Pro Web Helper, Windows Pro Safety, Windows Custom Management, Windows Virtual Firewall, Windows Smart Warden, Home Malware Cleaner, Windows Premium Guard, Windows Safeguard Upgrade, Windows No-Risk Center, Windows Crucial Scanner, Windows Interactive Safety, Security Antivirus, Smart Engine, Windows Security Renewal, Anti-Malware Lab, Windows Guardian Angel, Windows Security System, Windows Smart Partner, Windows Ultimate Safeguard, Windows Sleek Performance, Windows Custom Safety, Windows Premium Defender, XP Smart Security, Windows Process Director, Windows Antivirus Patch, My Security Shield, Strong Malware Defender, Windows Advanced User Patch, Windows Proprietary Advisor, Windows Anti-Malware Patch, Windows Warding System, System Protection Tools, Windows Threats Destroyer, Windows Safety Checkpoint, Windows Web Combat, Windows Secure Surfer, Smart Anti-Malware Protection, Windows Risk Minimizer, Activate Ultimate Protection, Live Enterprise Suite, Windows Safety Wizard, Windows Be-on-Guard Edition and Virus Doctor. Windows Guard Tools and its brethren may be designed to work with Windows, but they’re anything but Microsoft-affiliated products, and Windows Guard Tools is unable to provide any of the many anti-malware and security features that Windows Guard Tools pretends to have.
As a cover for its weaknesses, Windows Guard Tools will launch with Windows and create spontaneous and inaccurate pop-up alerts coupled with faux system scans, both of which imply that your PC is being attacked by rootkits, keyloggers, identity theft and other types of serious PC threats. Even if you’re desperate to stop this flood of fake security information, SpywareRemove.com malware analysts don’t see any reason to spend money on Windows Guard Tools, which can be forced into silence only by deleting Windows Guard Tools with a legitimate anti-malware application. Before you attempt this, you may also want to attempt to circumvent Windows Guard Tools’s startup routine or fake Windows Guard Tools’s registration with the key ’0W000-000B0-00T00-E0020,’ which also registers many other members of FakeVimes.
What Windows Guard Tools Really is Protecting When It Blocks Your Software
Windows Guard Tools may also attempt to prevent you from using some types of applications or interfere with features and functions for the benefit of its criminal partners. These attacks are all common to Win32/FakeVimes-based PC threats, and SpywareRemove.com malware researchers have made particular note of them due to the potential security problems that they can pose if Windows Guard Tools isn’t deleted with appropriate software and appropriate alacrity:
- Windows Guard Tools may redirect your browser to malicious websites (typically those that market rogue security programs like Windows Guard Tools itself).
- Your browser searches may also be redirected to spam search engines and other sites, particularly if you’re attempting to search with Google.
- Most damningly, Windows Guard Tools can also attempt to disable various anti-virus and security programs by altering their Registry entries. This can be resolved by booting Windows Guard Tools in a way that avoids its auto start routine and then using appropriate software to restore your Registry or reinstall the programs that were disabled.
In spite of the latter attack, SpywareRemove.com malware experts don’t recommend attempting to remove Windows Guard Tools without assistance from either a PC security expert or dedicated anti-malware programs, since many of Windows Guard Tools’s attacks will alter the Windows Registry and other Windows components (which can damage your OS if edited improperly).
Windows Guard Tools Automatic Detection Tool (Recommended)
Is your PC infected with Windows Guard Tools? To safely & quickly detect Windows Guard Tools, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Windows Guard Tools
What happens if Windows Guard Tools does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 Windows Guard Tools.lnk 438 2 %APPDATA%\ Protector-hdux.exe 12 3 %APPDATA%\ Protector-scxq.exe 12 4 %AppData%\Windows Guard Tools\ScanDisk_.exe N/A 5 %AppData%\Microsoft\Internet Explorer\Quick Launch\Windows Guard Tools.lnk N/A 6 %AppData%\Windows Guard Tools\Instructions.ini N/A 7 %CommonAppData%\58ef5\SP98c.exe N/A 8 %CommonAppData%\58ef5\SPT.ico N/A 9 %CommonAppData%\SPUPCZPDET\SPABOIJT.cfg N/A 10 %Desktop%\Windows Guard Tools.lnk N/A 11 %Programs%\Windows Guard Tools.lnk N/A 12 %StartMenu%\Windows Guard Tools.lnk N/A
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Activate Ultimate Protection “%CommonAppData%\58ef5\SP98c.exe” /s /dHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UninstallHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate ProtectionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\DisplayIcon [unknown dir]\[unknown file name].exe,0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\DisplayName Activate Ultimate ProtectionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\DisplayVersion 1.1.0.1010HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\InstallLocation [unknown dir]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\Publisher UIS Inc.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Activate Ultimate Protection\UninstallString “[unknown dir]\[unknown file name].exe” /delHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandler\ Implements DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandler\ClsidHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFGHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\ConsoleTracingMask -65536HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\EnableConsoleTracing 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\EnableFileTracing 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\FileDirectory %windir%\tracingHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\FileTracingMask -65536HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\MaxFileSize 1048576HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAVHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\Debugger svchost.exe - The following CLSID's were detected:
HKEY..\..\{CLSID Path} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ Implements DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32\ [unknown dir]\[unknown file name].exeHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID\ [unknown file name].DocHostUIHandlerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dumped_.DocHostUIHandler\Clsid\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
Posted: May 25, 2012 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 96


More

this window guard tools is on my Dell laptop..I ant it off..now! i cannot use my dell laptop because of this and i cannot remove it to save my life!!!!!
Never ever use windows security