Windows Virtual Security
Windows Virtual Security Description
Why Windows Virtual Security’s ‘Virtual’ More Closely Resembles ‘Imaginary’
Windows Virtual Security is a direct clone of other members of the FakeVimesfamily of fake anti-malware products, with similar variants encompassing such titles as Windows Defending Center, Windows Privacy Module, Best Antivirus Software, Windows Profound Security, Windows Custom Safety, Windows Safety Toolkit, Windows Performance Adviser, Security Master AV, Windows Safety Series, Windows Antivirus Patch, Windows Pro Web Helper, Enterprise Suite, Home Malware Cleaner, Windows Efficiency Accelerator, Windows Daily Adviser, Windows Interactive Safety, Windows Proprietary Advisor, Best Malware Protection, Internet Security Essentials, Windows Antivirus Release, Windows Shield Tool, Windows Health Keeper, Windows Turnkey Console, Personal Internet Security 2011, My Security Shield, Windows AntiHazard Helper, Windows Pro Safety, Windows Virtual Firewall, Windows Care Taker, Windows Protection Master, Windows Stability Guard, Windows Enterprise Defender, Windows PC Aid, Security Antivirus, Smart Internet Protection 2011, Windows AntiHazard Center, Windows Shielding Utility, Windows Active Guard, Antivirus Smart Protection, Smart Anti-Malware Protection, Windows PRO Scanner, Windows Guard Solutions, Windows Personal Doctor, Windows Crucial Scanner, Live PC Care, Keep Center Keeper, Windows Security Suite, Windows Smart Warden, Windows Premium Guard, Windows Safety Module, Windows Guard Tools, Windows Debug Center, Windows Safety Checkpoint, Windows No-Risk Agent, Activate Ultimate Protection, Windows Security System, Windows Warding System, Windows Protection Unit, Windows Private Shield, Windows Secure Surfer, Windows Advanced Toolkit, Windows Premium Console, Windows Secure Workstation, My Security Wall, Smart Engine, Windows Trouble Taker, PC Live Guard, Windows Tools Patch, Windows Custodian Utility, Windows Interactive Security, XP Smart Security, Windows Antivirus Care, Windows Malware Sleuth, Windows Risk Minimizer, Windows Privacy Counsel, Personal Security Sentinel, Windows Advanced Security Center, System Protection Tools, PrivacyGuard PRO, Windows Web Combat, Windows Active Defender, Windows Secure Web Patch, Windows Defence Counsel, Windows Premium Defender, Windows Safeguard Upgrade, Windows Maintenance Suite, Windows Pro Defence, Fast Antivirus 2009, Windows Basic Antivirus, Windows Antivirus Machine, Windows Managing System, Windows Antihazard Solution, Windows Software Keeper, Windows Software Saver, Windows High-End Protection, Smart Virus Eliminator, Windows Guardian Angel, Windows Safety Manager, Windows Antivirus Rampart, Windows Virus Hunter, Volcano Security Suite, VirusSecurity, Windows Problems Stopper, Windows System Defender, Windows Enterprise Suite, Windows Custom Management, Strong Malware Defender, Windows Protection Maintenance, Windows Sleek Performance, Windows Web Commander, Smart Security, Virus Doctor, Windows Safety Maintenance, CleanUp Antivirus, Windows Telemetry Center, Windows ProSecure Scanner, Windows Maintenance Guard, Windows Secure Workshop, Windows Virtual Angel, Windows ProSecurity Scanner, Smart Internet Protection 2012, My Security Engine, Windows Functionality Checker, Windows Multi Control System, Windows Firewall Constructor, Windows Instant Scanner, Windows Abnormality Checker, Anti-Malware Lab, Windows Privacy Extension, Windows Pro Solutions, Windows Home Patron, Windows Ultimate Safeguard, Windows Advanced User Patch, Windows Anti-Malware Patch, Live Enterprise Suite, Windows Internet Booster, Windows Process Director, Extra Antivirus, Windows Activity Debugger, Windows Be-on-Guard Edition, Windows Expert Series, Windows Ultimate Security Patch, Windows Control Series, Additional Guard, Total Anti Malware Protection, Windows Pro Safety Release, Windows Safety Wizard, Windows Proactive Safety, Windows First-Class Protector, Internet Security Suite, Home Safety Essentials, Windows Threats Destroyer, Windows No-Risk Center, Windows Pro Rescuer, Windows Security Renewal, Windows Smart Partner and Windows Performance Catalyst. Most infections by Windows Virtual Security and related PC threats are acquired through fake codec downloads and other forms of fraudulent software updates, although SpywareRemove.com malware experts note that other means (such as drive-by-download exploits) can also be used.
Windows Virtual Security is neither capable of finding nor removing hostile software from your PC. However, Windows Virtual Security’s attacks include a heavy variety of fake pop-up alerts to convince you otherwise, by announcing the presence of nonexistent types of spyware and attacks against your computer (including its Registry and other Windows components). To add believability to these claims, Windows Virtual Security may even generate randomly-named junk files that contain no code while looking like the byproduct of poorly-coded PC threats. In spite of this bad marketing ploy, SpywareRemove.com malware researchers can’t recommend purchasing Windows Virtual Security, which is never a legitimate security product even in its registered form.
Where Windows Virtual Security’s Antisecurity Stopgaps Come In
Besides being a bad security product in and of itself, Windows Virtual Security may also hamper security with respect to your web browser and Windows OS. Attacks that SpywareRemove.com malware researchers have associated with recent versions of Windows Virtual Security’s family of rogue anti-malware programs include such issues as:
- Browser hijacks that block search engine sites, redirect you to unusual websites, alter your browser’s error pages or prevent you from accessing PC security domains.
- Blocked security programs, including firewall utilities, Windows products like Task Manager and some brands of anti-malware scanners.
- Registry changes that reduce your web-browsing security by disabling alerts against potentially-malicious file downloads and website content.
While spending money on Windows Virtual Security is never safe for your finances or PC, SpywareRemove.com malware analysts can recommend using free codes to fake Windows Virtual Security’s registration prior to deleting Windows Virtual Security with anti-malware software.
Windows Virtual Security Automatic Detection Tool (Recommended)
Is your PC infected with Windows Virtual Security? To safely & quickly detect Windows Virtual Security, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Windows Virtual Security
What happens if Windows Virtual Security does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %APPDATA%\ Protector-exsh.exe 255 2 %AppData% Protector-[rnd].exe N/A
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exeHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exeDebugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
Additional Information
- The following messages's were detected:
# Message 1 "Error Key-logger activity detected. System information security is at risk. It is recommended to activate protection and run a full system scan" 2 "Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. You need to clean your computer immediately to prevent the system crash" 3 "Trojan-PSW.Win32.launch Hack Tool:Win32/Welevate.A Adware.Win32.Fraud" 4 "Warning! Identity theft attempt Detected Hidden connection IP: 58.82.12.124 Target: Your passwords for sites" 5 "Warning! Virus Detected Threat detected: FTP Server Infected file: C:\Windows\System32\dllcache\wmploc.dll"
Posted: August 9, 2012 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 316


More
