Home Malware Programs Rogue Anti-Spyware Programs Windows Safety Series

Windows Safety Series

Posted: August 14, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 9
First Seen: August 14, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Safety Series Screenshot 1Windows Safety Series is a fake anti-malware scanner that displays fraudulent messages about infections, application damage and attacks against your PC – especially attacks that attempt to steal confidential information. While pop-up alerts and fake system scans are Windows Safety Series's main symptoms, Windows Safety Series can also disable unrelated programs to heighten alarm in the victim and prevent itself from being removed. SpywareRemove.com malware researchers consider Windows Safety Series a standard example of rogue anti-malware software to be avoided at all costs, and particularly note that one should never spend money on Windows Safety Series, which doesn't have even a single functional anti-malware feature, in spite of its pretenses.

Windows Safety Series: Why a Brand Name Isn't Everything in the Anti-Malware Industry

While Windows Safety Series has a name that would make one inclined to trust it, Windows Safety Series is simply a clone of other types of equally-fake anti-malware scanners from the FakeVimes that display inaccurate information about threats attacking your PC. Most recent versions of rogue anti-malware programs from Windows Safety Series's family include identical interfaces, and can be identified by names such as Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security.

SpywareRemove.com malware experts have found that standard infection paths for Windows Safety Series and its clones include Trojan downloaders that disguise themselves as fake media updates and JavaScript applets that pretend to be system scanners. Ordinarily, avoiding suspicious sites and downloads will allow you to keep your PC uninfected by Windows Safety Series.

Following Windows Safety Series's Breadcrumb Trail of pop-up Alerts... Straight to Your Wallet

Windows Safety Series, as a typical form of scamware, doesn't have any ability to detect or delete malicious software of any type, but includes deceptive features to make Windows Safety Series appear otherwise. Due to Windows Registry modifications, Windows Safety Series will launch without your consent and can display an assortment of alerts regarding nonexistent infections and attacks, with a slight emphasis on spyware-related attacks (such as identity theft or bank account compromises).

The only point to such fake security information is to force you to spend money on Windows Safety Series, which SpywareRemove.com malware researchers naturally discourage as pointless. Deleting Windows Safety Series is the only thing that's required to put an end to its fake pop-up warnings, system scans and other misbehavior, although removing Windows Safety Series safely does ordinarily entail using anti-malware software.

If at all possible, Windows Safety Series should be deleted as soon as Windows Safety Series is detected, since Windows Safety Series may also block unrelated security applications, such as firewall utilities, default Windows tools (such as the Task Manager) and anti-virus applications. SpywareRemove.com malware analysts also have found some value in disabling Windows Safety Series prior to deletion, which can be accomplished either with Safe Mode or a USB drive-based system boot.

Windows Safety Series Screenshot 2Windows Safety Series Screenshot 3Windows Safety Series Screenshot 4Windows Safety Series Screenshot 5Windows Safety Series Screenshot 6Windows Safety Series Screenshot 7Windows Safety Series Screenshot 8Windows Safety Series Screenshot 9Windows Safety Series Screenshot 10

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Protector-ches.exe File name: Protector-ches.exe
Size: 2.61 MB (2616320 bytes)
MD5: b0c65f40ec130ec120c6169e551841ca
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 8, 2020
%AppData%\Protector-[RANDOM CHARACTERS].exe File name: %AppData%\Protector-[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exeHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"

Additional Information

The following messages's were detected:
# Message
1Error There’s a suspicious software running on your PC. For more details, run a system file check.
2Warning Firewall has blocked a program from accessing the Internet Windows XP USER API Clien: DLL User32.dll User32.dll is suspended to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server. Recommended: Please click “Prevent attack” button to prevent all attacks and protect your PC.

Loading...