Windows Secure Workstation
Windows Secure Workstation Description
When You Can’t Trust Windows Around Windows Secure Workstation
Windows Secure Workstation, as a rogue anti-malware scanner, isn’t able to protect your PC from Trojans, viruses or other types of malware, but its features will strive to imitate legitimate security programs. This can include subverting your Windows startup process to include fake warning messages before you’re even allowed to load your desktop, the presentation of fake Fake Microsoft Security Essentials Alert and announcements that prominent Windows tools (such as Task Manager) are infected or damaged. SpywareRemove.com malware analysts encourage you to ignore all unusual security warnings during a Windows Secure Workstation infection until you’ve disabled Windows Secure Workstation, which can be done with either Safe Mode or a system boot from a clean USB drive.
Like its identical kin (such as the equally-recent Windows Anti-Malware Patch, Windows Ultimate Safeguard or Windows Virtual Angel), Windows Secure Workstation’s only goal in displaying this fake security information is to make you spend money on a purchasable registration key. However, even once registered, Windows Secure Workstation can’t detect actual PC threats or protect your computer from them, and any financial information handed over in this process should be considered effectively compromised.
What Windows Secure Workstation Does to Make You PC Insecure
Although Windows Secure Workstation may be distributed by various means, its central method of infecting new PCs is through fraudulent system scans that are hosted on hostile websites. Since these scanner simulations often use JavaScript, disabling JavaScript or keeping it uninstalled can help to block content that installs Windows Secure Workstation without your consent. Although you may experience a prompt about downloading security software, most such attacks will install Windows Secure Workstation or a related type of fake anti-malware software regardless of what you click.
SpywareRemove.com malware researchers also note that Windows Secure Workstation may block many different types of applications while Windows Secure Workstation is active. Competing types of scamware, legitimate Windows security utilities and anti-virus scanners may all be blocked by Windows Secure Workstation, with corresponding fake pop-up warnings. Windows Secure Workstation’s startup process exploits the Windows Registry, and methods of booting that sidestep Registry settings (such as booting from a USB drive) can also let you access your PC and its software without launching Windows Secure Workstation.
Windows Secure Workstation Automatic Detection Tool (Recommended)
Is your PC infected with Windows Secure Workstation? To safely & quickly detect Windows Secure Workstation, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Windows Secure Workstation
What happens if Windows Secure Workstation does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %APPDATA%\ Protector-ytky.exe 337 2 %AppData%\Protector-[RANDOM CHARACTERS].exe N/A
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Settings\ID 4HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Settings\UID [RANDOM CHARACTERS]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[RANDOM CHARACTERS].exeHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exeDebugger svchost.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXEHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exeHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
Posted: August 13, 2012 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 26


More
