Home Malware Programs Rogue Anti-Spyware Programs Windows Pro Solutions

Windows Pro Solutions

Posted: May 10, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 35
First Seen: May 10, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Pro Solutions Screenshot 1It's no coincidence that Windows Pro Solutions's name bears a strong resemblance to scamware like Windows Guard Solutions or Windows Pro Scanner, as SpywareRemove.com malware analysts have found Windows Pro Solutions to have all the expected traits of another addition to FakeVimes. This group of rogue anti-virus products disables various security functions and programs while also displaying fake security alerts, and you should consider it a high priority to delete Windows Pro Solutions from your PC with a qualified anti-malware product instead of giving in to Windows Pro Solutions's attempts to promote its fraudulent anti-malware utility. Since Windows Pro Solutions is incapable of providing legitimate security information or removing PC threats of any stripe, spending money on Windows Pro Solutions is never appropriate, and you should feel guiltless in treating Windows Pro Solutions as just as hostile as any virus.

Why Windows Pro Solutions is More of a Problem Than an Answer to One

Windows Pro Solutions markets itself as an anti-virus program, and while its looks back this marketing up, its actual features are as fake as any other rogue anti-virus scanner's could be. System scans from Windows Pro Solutions will always contain countless examples of high-level PC threats that aren't, in reality, on your hard drive, while Windows Pro Solutions's pop-up alerts will use various fraudulent warnings about network-based attacks, identity theft and other issues that could plausibly be detected by a security or anti-malware program. SpywareRemove.com malware researchers warn against any attempt to follow the advice enclosed within a Windows Pro Solutions pop-up, since doing so has a high chance to cause you to harm innocent system files or send you off on a wild goose chase trying to catch malicious software that doesn't exist.

The upside to Windows Pro Solutions's poor pretensions at anti-malware security means that there's no need to spend money on Windows Pro Solutions – regardless of Windows Pro Solutions's opinion on the matter. On the other hand, SpywareRemove.com malware experts have found some use in faking registration for Win32/FakeVimes-based rogue AV programs like Windows Pro Solutions, which can be accomplished with the code '0W000-000B0-00T00-E0020.' Doing this may make it less difficult than usual to remove Windows Pro Solutions later, if you experience problems with removing Windows Pro Solutions in an initial anti-malware scan. Among the many FakeVimes family members are Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security.

Examples of Reasons Not to Delay Solving the Windows Pro Solutions Conundrum

While Windows Pro Solutions, as a rogue anti-virus scanner, is primarily defined by its fake security functions, Windows Pro Solutions may also use other attacks behind the scenes to reduce your computer's security. Some issues that SpywareRemove.com malware research team has frequently seen with similar FakeVimes programs have been noted here for reference:

  • Disabled Windows UAC features.
  • Disabled protection against downloading files with invalid signature identification (a method of protecting against malicious files and software).
  • Browser hijacks that interfere with your online searches by redirecting you to unusual sites.
  • Blocked security and anti-malware products – while Windows Pro Solutions will claim that all blocked programs are infected or otherwise damaged, you should, as always, ignore Windows Pro Solutions's fraudulent security advice.


Windows Pro Solutions Screenshot 2Windows Pro Solutions Screenshot 3Windows Pro Solutions Screenshot 4Windows Pro Solutions Screenshot 5Windows Pro Solutions Screenshot 6Windows Pro Solutions Screenshot 7Windows Pro Solutions Screenshot 8Windows Pro Solutions Screenshot 9Windows Pro Solutions Screenshot 10Windows Pro Solutions Screenshot 11

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Protector-kyrh.exe File name: Protector-kyrh.exe
Size: 2.26 MB (2261504 bytes)
MD5: 804de6a1b2921ec579fe4e0e867aee89
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2020
%APPDATA%\Protector-kxrh.exe File name: Protector-kxrh.exe
Size: 2.28 MB (2280448 bytes)
MD5: 9403a1626698c8015648a506182d978b
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 10, 2012
%APPDATA%\Protector-upam.exe File name: Protector-upam.exe
Size: 2.04 MB (2047488 bytes)
MD5: 782ccdfa7a087d267e2696b97d8d232c
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 10, 2012
%AppData%\Protector-[RANDOM CHARACTERS].exe File name: %AppData%\Protector-[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\result.db File name: %AppData%\result.db
Mime Type: unknown/db
Group: Malware file
%UserProfile%\Desktop\Windows Pro Solutions.lnk File name: %UserProfile%\Desktop\Windows Pro Solutions.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%AllUsersProfile%\Start Menu\Programs\Windows Pro Solutions.lnk File name: %AllUsersProfile%\Start Menu\Programs\Windows Pro Solutions.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\Debugger = svchost.exeHKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\Debugger = svchost.exeHKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Inspector = %AppData%\Protector-[RANDOM CHARACTERS].exe

Additional Information

The following messages's were detected:
# Message
1Error Attempt to modify Registry key entries detected. Registry entry analysis recommended.
2Error Keylogger activity detected. System information security is at risk. It is recommended to activate protection and run a full system scan.
3Error Software without a digital signature detected. Your system files are at risk. We strongly advise you to activate your protection.
4Warning Firewall has blocked a program from accessing the Internet. Windows Media Player Resources C:\Windows\system32\dllcache\wmploc.dll C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
5Warning! Identity theft attempt Detected

Loading...