Home Malware Programs Rogue Anti-Virus Programs Windows Software Saver

Windows Software Saver

Posted: March 24, 2012

Threat Metric

Ranking: 9,591
Threat Level: 2/10
Infected PCs: 20,833
First Seen: March 24, 2012
Last Seen: October 10, 2023
OS(es) Affected: Windows

Windows Software Saver Screenshot 1Windows Software Saver advertises itself as a security program with more features than you can shake a stick at, but Windows Software Saver's real features are all involved in dumping fraudulent system info, attacking your web browser and hindering your actual security software. Since Windows Software Saver is a confirmed clone of identical types of scamware of FakeVimes origin, SpywareRemove.com malware researchers encourage treating Windows Software Saver as a threat to your PC and ignoring its various attempts to mislead you with false alerts or encourage you to hand money over to its criminal developers. Windows Software Saver is removable by competent brands of anti-malware software, but since Windows Software Saver will launch when Windows start and may block such programs, you may need to use an especially secure method of booting Windows to disable Windows Software Saver before you can delete Windows Software Saver in its entirety.

Windows Software Saver – the Software That Secretly Damns Your PC

While Windows Software Saver acts as though it has system-scanning features, virus detection, phishing-blockers and even a process manager that replaces the Task Manager, SpywareRemove.com malware experts have found each and every one of these features to be a sham. Rogue anti-virus scanners like Windows Software Saver are known for creating heavily exaggerated warning messages to make their services seem needed, and Windows Software Saver is no exception, with a multitude of fake pop-ups to supplement its fake scanner results:

Because Windows Software Saver doesn't have real threat detection or diagnostic features, any system information from Windows Software Saver should be automatically discarded as deceptive, and you should never purchase Windows Software Saver as a method of disinfecting your computer. SpywareRemove.com malware analysts further note that Windows Software Saver may also engage in attacks such as:

  • Changing your Hosts file settings to hijack your web browser, particularly in the case of search engine-based websites.
  • Disabling security-related programs and memory processes, as well as some types of competing rogue anti-virus applications.
  • Reducing your web browser's security by enabling it to download files with invalid signatures without any warning messages.

True Salvation from the Problems That Windows Software Saver Can Cause

Even though Windows Software Saver is a very new addition to the Win32/FakeVimes family, FakeVimes has been around for years, and new variants of Windows Software Saver and similar PC threats are emerging on an ongoing basis. The majority of these clones are visually identical to Windows Software Saver and bear names such as Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security.

Since any of the above examples of rogue AV products, along with Windows Software Saver, may work to disable your security software, you may have to disable them before you can disinfect your PC. SpywareRemove.com malware research team has found Safe Mode to be an effective countermeasure to the startup routines for PC threats like Windows Software Saver, which will allow you to remove Windows Software Saver with a simple scan by appropriate software.

Windows Software Saver Screenshot 2Windows Software Saver Screenshot 3Windows Software Saver Screenshot 4Windows Software Saver Screenshot 5Windows Software Saver Screenshot 6Windows Software Saver Screenshot 7Windows Software Saver Screenshot 8Windows Software Saver Screenshot 9Windows Software Saver Screenshot 10Windows Software Saver Screenshot 11Windows Software Saver Screenshot 12Windows Software Saver Screenshot 13Windows Software Saver Screenshot 14

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\result.db File name: %AppData%\result.db
Mime Type: unknown/db
Group: Malware file
%AppData%\NPSWF32.dll File name: %AppData%\NPSWF32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AppData%\Protector-[RANDOM 3 CHARACTERS].exe File name: %AppData%\Protector-[RANDOM 3 CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%CommonStartMenu%\Programs\Windows Software Saver.lnk File name: %CommonStartMenu%\Programs\Windows Software Saver.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%Desktop%\Windows Software Saver.lnk File name: %Desktop%\Windows Software Saver.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"

Additional Information

The following URL's were detected:
discussmercurydifferently.com
Loading...