Windows Safety Toolkit
Windows Safety Toolkit Description
Windows Safety Toolkit – Everything That You’d Need to Keep Your PC Completely Unsafe
Windows Safety Toolkit markets itself as an anti-virus scanner with a good-sized parcel of other security features, and even includes seemingly advanced functions like phishing attack defenses, but these features are entirely fraudulent and their self-destructive advice should always be disregarded. System scans will include warnings about nonexistent infections, popup alerts will threaten you about live attacks that aren’t occurring and various programs may be announced as infected. SpywareRemove.com malware experts note that the latter is particularly likely for security programs that Windows Safety Toolkit intentionally blocks (such as anti-virus scanners and Windows diagnostic applications).
Since Windows Safety Toolkit makes it difficult for you to run appropriate anti-malware programs while it’s open, SpywareRemove.com malware researchers suggest that you try to launch Windows in a Windows Safety Toolkit-free boot before you try to delete Windows Safety Toolkit. Various solutions to disable Windows Safety Toolkit easily include:
- Launching Windows in Safe Mode by tapping F8 and selecting the appropriate menu option after the BIOS loads but prior to Windows loading.
- Booting Windows from a network-shared drive.
- Booting Windows from a removable drive, such as a CD or USB thumb drive.
Side Effects of Windows Safety Toolkit to Keep an Eye On
While fake pop-ups and other types of inaccurate security information are Windows Safety Toolkit’s definitive symptoms, as a member of Win32/FakeVimes, Windows Safety Toolkit may also launch other attacks against your PC. Besides Windows Safety Toolkit, this family also includes such members as Windows Premium Guard, Windows Security System, Windows Be-on-Guard Edition, Windows Secure Surfer, Windows Safety Maintenance, Enterprise Suite, Windows Risk Minimizer, Smart Anti-Malware Protection, Windows Antihazard Solution, Windows Safeguard Upgrade, PrivacyGuard PRO, Windows Interactive Security, Windows Pro Safety Release, Live Enterprise Suite, Windows Sleek Performance, PC Live Guard, VirusSecurity, Windows Stability Guard, Windows Efficiency Accelerator, Windows Custom Management, Windows Malware Sleuth, My Security Shield, Windows Functionality Checker, Windows Defending Center, Windows Antivirus Patch, Windows Custodian Utility, Windows Safety Module, Extra Antivirus, Volcano Security Suite, Windows Tools Patch, Windows Secure Workshop, Windows Basic Antivirus, Windows Protection Maintenance, XP Smart Security, Windows Smart Partner, Windows Security Renewal, Windows Privacy Extension, Windows Proactive Safety, Windows Control Series, Live PC Care, Windows Antivirus Machine, Windows First-Class Protector, Total Anti Malware Protection, Windows Ultimate Security Patch, Windows Secure Workstation, Virus Doctor, Windows Defence Counsel, My Security Wall, Windows Active Defender, Security Antivirus, Windows ProSecurity Scanner, Windows Telemetry Center, Windows Abnormality Checker, Windows Enterprise Suite, Windows Guard Solutions, Personal Security Sentinel, Windows Care Taker, Windows Privacy Module, Windows Premium Console, Windows Enterprise Defender, Windows No-Risk Agent, Smart Engine, Windows Expert Series, Windows Crucial Scanner, Windows Privacy Counsel, System Protection Tools, Windows Software Saver, Windows Warding System, Windows Maintenance Guard, Windows Managing System, Windows Performance Adviser, Home Safety Essentials, Smart Security, Antivirus Smart Protection, Home Malware Cleaner, Windows PRO Scanner, Windows Safety Manager, Best Antivirus Software, Windows Safety Checkpoint, Windows Anti-Malware Patch, Windows Antivirus Release, Windows Smart Warden, Windows Pro Rescuer, My Security Engine, Windows Trouble Taker, Windows Maintenance Suite, Windows System Defender, Windows Firewall Constructor, Windows Problems Stopper, Windows ProSecure Scanner, Windows Proprietary Advisor, Windows Performance Catalyst, Windows Interactive Safety, Windows Process Director, Best Malware Protection, Windows Protection Unit, Windows Protection Master, Windows Threats Destroyer, Windows Advanced Security Center, Windows Shield Tool, Windows Advanced Toolkit, Windows Virtual Security, Windows High-End Protection, Windows Advanced User Patch, Windows Pro Solutions, Strong Malware Defender, Windows Private Shield, Smart Virus Eliminator, Internet Security Essentials, Windows Activity Debugger, Windows Antivirus Rampart, Security Master AV, Windows Health Keeper, Windows Safety Wizard, Windows Pro Defence, Windows AntiHazard Center, Windows Shielding Utility, Keep Center Keeper, Fast Antivirus 2009, Windows No-Risk Center, Windows Instant Scanner, Windows Home Patron, Windows Pro Web Helper, Windows Web Commander, Smart Internet Protection 2011, Windows Custom Safety, Additional Guard, Personal Internet Security 2011, Windows Debug Center, Windows Multi Control System, Windows Profound Security, Windows Guardian Angel, Windows Web Combat, Windows Pro Safety, Windows Ultimate Safeguard, Windows Personal Doctor, Windows Turnkey Console, Windows Premium Defender, Smart Internet Protection 2012, Windows Daily Adviser, Windows Software Keeper, Windows Antivirus Care, Activate Ultimate Protection, Windows Secure Web Patch, Windows Safety Series, Windows Security Suite, Anti-Malware Lab, Windows Virtual Angel, Windows Virtual Firewall, CleanUp Antivirus, Windows Internet Booster, Windows Virus Hunter, Windows Guard Tools, Windows Active Guard, Windows AntiHazard Helper, Internet Security Suite and Windows PC Aid. If desired, you can also register Windows Safety Toolkit or its relatives with the code ’0W000-000B0-00T00-E0020,’ as SpywareRemove.com malware analysts have found this to be occasionally useful for removing Windows Safety Toolkit and other scamware from Win32/FakeVimes.
Even though its tendency to block security programs would, by itself, be ample reason to delete Windows Safety Toolkit ASAP, Windows Safety Toolkit may also include other attacks that are characteristic of Win32/FakeVimes-based rogue AV programs. Your web browser searches may be hijacked by Hosts file changes, the Windows UAC feature may be disabled, and you may fail to receive warnings when downloading files with improper signatures. All of these attacks should be considered threats to your computer’s security, and SpywareRemove.com malware experts encourage you to avoid them by deleting Windows Safety Toolkit with good anti-malware software as quickly as is convenient.
Windows Safety Toolkit Automatic Detection Tool (Recommended)
Is your PC infected with Windows Safety Toolkit? To safely & quickly detect Windows Safety Toolkit, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Windows Safety Toolkit
What happens if Windows Safety Toolkit does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %APPDATA%\ Protector-itrq.exe 651 2 %APPDATA%\ Protector-cpgy.exe 176 3 Windows Safety Toolkit.lnk 145 4 %AppData%\NPSWF32.dll N/A 5 %AppData%\result.db N/A 6 %AppData%\W34r34mt5h21ef.dat N/A 7 %AppData%\Protector-[RANDOM 3 CHARACTERS].exe N/A 8 %Desktop%\Windows Safety Toolkit.lnk N/A 9 %CommonStartMenu%\Programs\Windows Safety Toolkit.lnk N/A
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-4-21_3"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "pbxqbkjqxb"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\ASProtectHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
Additional Information
- The following messages's were detected:
# Message 1 Error
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.2 Warning
Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.3 Warning! Spambot detected!
Attention! A spambot sending viruses from your e-mail has been detected on your PC.
Posted: April 21, 2012 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 116


More
