Home Malware Programs Rogue Anti-Spyware Programs Windows Safety Wizard

Windows Safety Wizard

Posted: June 4, 2012

Threat Metric

Ranking: 16,772
Threat Level: 2/10
Infected PCs: 316
First Seen: June 4, 2012
Last Seen: July 30, 2023
OS(es) Affected: Windows

Windows Safety Wizard Screenshot 1Windows Safety Wizard portrays itself as an anti-malware scanner that can work magic on your PC, but the only mystic tricks that SpywareRemove.com malware researchers have seen performing are hoaxes that warn you about fake PC threats. As an 2012-era derivative of the FakeVimes family of rogue anti-malware software, Windows Safety Wizard may not be able to detect or defend against actual Trojans, rootkits or spyware, but its inaccurate pop-up warnings and system scans will always include warnings about malicious software and attacks even if there's not a grain of truth to these alerts. Since Windows Safety Wizard, like other members of its family, may also hinder real security programs, tamper with Windows security features or even redirect your browser, SpywareRemove.com malware research team encourages you to remove Windows Safety Wizard with actual anti-malware products as expediently as possible.

The Catch Behind Windows Safety Wizard's Security Magic

Windows Safety Wizard may seem to have more security features than the average anti-virus scanner, but this is purely due to all of Windows Safety Wizard's being empty promises cloned from previous versions of FakeVimes-built scamware. Identical types of rogue security products include Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security. Shared (and fake) features such as an anti-phishing defense and an Advanced Process Control can help you to identify Windows Safety Wizard and its close relatives, although actual deletion of Windows Safety Wizard and other members of FakeVimes should always use anti-malware programs when practical.

Windows Safety Wizard is built to infect Windows, and as such, will abuse the Windows Registry to start itself without requiring your permission. Windows Safety Wizard's startup will quickly barrage you with a range of security hazards, which SpywareRemove.com malware experts note as follows:

  • Browser redirects to harmful websites. Your search results may be rerouted through inappropriate sites and PC security sites may be blocked.
  • Pop-up warnings that display inaccurate system security alerts; for example, Windows Safety Wizard may pretend to detect identity theft attacks, keyloggers or unauthorized changes to Windows (which, ironically, Windows Safety Wizard is guilty of causing on its own).
  • Fake system scans that always return unrealistically huge lists of high-level PC threats such as rootkits and banking Trojans.
  • Blocked security and anti-malware programs, especially including Windows utilities like Task Manager. These attacks may delete the corresponding Registry entries to make an application nonfunctional, or they may simply shut the relevant memory process down as soon as Windows Safety Wizard detects it.

Dispelling Windows Safety Wizard's Illusion of PC Safety

Since there isn't a single beneficial aspect to having Windows Safety Wizard's not-so-unique brand of scamware on your computer, purchasing Windows Safety Wizard is also, obviously, a bad idea. However, while Windows Safety Wizard is designed with the intent of making you spend money on a registration key, SpywareRemove.com malware researchers have provided one for free: 0W000-000B0-00T00-E0020. This code can be used to reduce the instances of Windows Safety Wizard's attacks, although it's no substitute for removing Windows Safety Wizard properly.

Windows Safety Wizard Screenshot 2Windows Safety Wizard Screenshot 3Windows Safety Wizard Screenshot 4Windows Safety Wizard Screenshot 5Windows Safety Wizard Screenshot 6Windows Safety Wizard Screenshot 7Windows Safety Wizard Screenshot 8Windows Safety Wizard Screenshot 9Windows Safety Wizard Screenshot 10Windows Safety Wizard Screenshot 11

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\NPSWF32.dll File name: %AppData%\NPSWF32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AppData%\Protector-[RANDOM 3 CHARACTERS].exe File name: %AppData%\Protector-[RANDOM 3 CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\Protector-[RANDOM 4 CHARACTERS].exe File name: %AppData%\Protector-[RANDOM 4 CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\result.db File name: %AppData%\result.db
Mime Type: unknown/db
Group: Malware file
%AppData%\1st$0l3th1s.cnf File name: %AppData%\1st$0l3th1s.cnf
Mime Type: unknown/cnf
Group: Malware file
%CommonStartMenu%\Programs\Windows Safety Wizard.lnk File name: %CommonStartMenu%\Programs\Windows Safety Wizard.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%Desktop%\Windows Safety Wizard.lnk File name: %Desktop%\Windows Safety Wizard.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-6-4_7"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "otbpxlqhjd"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\ASProtectHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"

Additional Information

The following messages's were detected:
# Message
1Error
Trojan activity detected. System data security is at risk.
It is recommended to activate protection and run a full system scan.

Loading...