Windows Safety Series
Windows Safety Series Description
Windows Safety Series: Why a Brand Name Isn’t Everything in the Anti-Malware Industry
While Windows Safety Series has a name that would make one inclined to trust it, Windows Safety Series is simply a clone of other types of equally-fake anti-malware scanners from the FakeVimes that display inaccurate information about threats attacking your PC. Most recent versions of rogue anti-malware programs from Windows Safety Series’s family include identical interfaces, and can be identified by names such as Windows Safeguard Upgrade, Windows Advanced Toolkit, Keep Center Keeper, Live PC Care, Activate Ultimate Protection, PrivacyGuard PRO, Windows Debug Center, Windows Ultimate Security Patch, Smart Engine, Windows Protection Master, Windows Interactive Security, Windows Malware Sleuth, Windows No-Risk Center, Windows Software Keeper, Windows Instant Scanner, Additional Guard, Windows Firewall Constructor, Windows First-Class Protector, Windows Guard Tools, Windows Pro Safety Release, Windows Virtual Angel, Windows Security Suite, Windows Be-on-Guard Edition, Windows Security Renewal, Windows Enterprise Defender, Windows Abnormality Checker, Windows Antivirus Rampart, Internet Security Suite, Windows Web Commander, Volcano Security Suite, Smart Internet Protection 2011, Windows Trouble Taker, Windows Crucial Scanner, Windows Secure Workstation, Windows Telemetry Center, Smart Virus Eliminator, Windows Multi Control System, Windows Premium Defender, Windows Functionality Checker, Windows Health Keeper, Windows Profound Security, Windows Safety Maintenance, Windows Protection Maintenance, Extra Antivirus, My Security Engine, Windows Smart Partner, Windows Pro Web Helper, Windows Antivirus Machine, Windows Safety Manager, Windows Performance Adviser, Windows Privacy Extension, Windows Defending Center, Windows Threats Destroyer, Windows Virus Hunter, Smart Anti-Malware Protection, Antivirus Smart Protection, Windows Problems Stopper, Windows Care Taker, Windows Premium Console, Fast Antivirus 2009, Windows Custom Management, Home Malware Cleaner, Windows Process Director, Personal Security Sentinel, Internet Security Essentials, Anti-Malware Lab, Windows Privacy Module, Virus Doctor, Smart Security, Windows Pro Defence, Windows Proprietary Advisor, Windows Risk Minimizer, Windows Antivirus Patch, Windows Tools Patch, Windows System Defender, Windows Efficiency Accelerator, Windows Basic Antivirus, Windows Private Shield, Windows Defence Counsel, Windows Enterprise Suite, Windows Smart Warden, Smart Internet Protection 2012, Windows Pro Rescuer, Windows Virtual Firewall, Windows Ultimate Safeguard, Windows Personal Doctor, Personal Internet Security 2011, Windows Advanced Security Center, Windows Anti-Malware Patch, My Security Wall, Windows Activity Debugger, Windows Custodian Utility, Windows Internet Booster, Windows Active Guard, CleanUp Antivirus, PC Live Guard, Total Anti Malware Protection, Windows Antivirus Care, Windows Interactive Safety, Home Safety Essentials, Windows Web Combat, Security Master AV, Windows Secure Workshop, Strong Malware Defender, Windows Safety Module, Windows Custom Safety, XP Smart Security, VirusSecurity, Windows Turnkey Console, Windows Proactive Safety, Windows Expert Series, Windows Security System, Windows PRO Scanner, Windows Guard Solutions, Windows Shield Tool, Windows Pro Solutions, Enterprise Suite, Windows Performance Catalyst, My Security Shield, Windows Secure Web Patch, Windows Home Patron, Windows Pro Safety, Windows Advanced User Patch, Windows Sleek Performance, Windows Safety Wizard, Windows Maintenance Guard, Best Malware Protection, Windows AntiHazard Helper, Windows Daily Adviser, Windows Antivirus Release, Windows PC Aid, Windows Safety Toolkit, Windows Maintenance Suite, Best Antivirus Software, Windows Secure Surfer, Windows Shielding Utility, Windows Protection Unit, Windows Antihazard Solution, System Protection Tools, Windows Privacy Counsel, Windows Control Series, Live Enterprise Suite, Windows Managing System, Windows AntiHazard Center, Windows Warding System, Windows Premium Guard, Windows Stability Guard, Windows Safety Checkpoint, Windows No-Risk Agent, Windows Guardian Angel, Windows Active Defender, Windows Software Saver, Security Antivirus, Windows Virtual Security, Windows ProSecurity Scanner, Windows ProSecure Scanner and Windows High-End Protection.
SpywareRemove.com malware experts have found that standard infection paths for Windows Safety Series and its clones include Trojan downloaders that disguise themselves as fake media updates and JavaScript applets that pretend to be system scanners. Ordinarily, avoiding suspicious sites and downloads will allow you to keep your PC uninfected by Windows Safety Series.
Following Windows Safety Series’s Breadcrumb Trail of pop-up Alerts… Straight to Your Wallet
Windows Safety Series, as a typical form of scamware, doesn’t have any ability to detect or delete malicious software of any type, but includes deceptive features to make Windows Safety Series appear otherwise. Due to Windows Registry modifications, Windows Safety Series will launch without your consent and can display an assortment of alerts regarding nonexistent infections and attacks, with a slight emphasis on spyware-related attacks (such as identity theft or bank account compromises).
The only point to such fake security information is to force you to spend money on Windows Safety Series, which SpywareRemove.com malware researchers naturally discourage as pointless. Deleting Windows Safety Series is the only thing that’s required to put an end to its fake pop-up warnings, system scans and other misbehavior, although removing Windows Safety Series safely does ordinarily entail using anti-malware software.
If at all possible, Windows Safety Series should be deleted as soon as Windows Safety Series is detected, since Windows Safety Series may also block unrelated security applications, such as firewall utilities, default Windows tools (such as the Task Manager) and anti-virus applications. SpywareRemove.com malware analysts also have found some value in disabling Windows Safety Series prior to deletion, which can be accomplished either with Safe Mode or a USB drive-based system boot.
Windows Safety Series Automatic Detection Tool (Recommended)
Is your PC infected with Windows Safety Series? To safely & quickly detect Windows Safety Series, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Windows Safety Series
What happens if Windows Safety Series does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %LOCALAPPDATA%\Protector-[RANDOM CHARACTERS].exe 586 2 %SystemDrive%\Documents and Settings\LocalService\Application Data\Protector-[RANDOM CHARACTERS].exe 365 3 %WINDIR%\system32\config\systemprofile\AppData\Roaming\Protector-[RANDOM CHARACTERS].exe 337 4 %APPDATA%\ Protector-ches.exe 262 5 %AppData%\Protector-[RANDOM CHARACTERS].exe N/A 6 %AppData%\Protector-[RANDOM CHARACTERS].exe N/A
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
Additional Information
- The following messages's were detected:
# Message 1 Error There’s a suspicious software running on your PC. For more details, run a system file check. 2 Warning Firewall has blocked a program from accessing the Internet Windows XP USER API Clien: DLL User32.dll User32.dll is suspended to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server. Recommended: Please click “Prevent attack” button to prevent all attacks and protect your PC.
Posted: August 14, 2012 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 281


More
