Windows Firewall Constructor is a rogue anti-spyware program that uses fake security alerts and non-existent infection as a tactic to scare you into thinking that your computer in infected with malware. It is installed through fake online malware scanners, trojans and hacked sites. It may come bundled with other malware as well or use software vulnerabilities to enter the targeted system. However, most of the time Windows Firewall Constructor has to be manually installed. When the program performs a fake scan it will detect non-existent infections and won't allow you to remove them until you purchase the rogue program. Found infections either do not exist or can't actually damage your computer since they are not harmless. Do not purchase it. Otherwise, you will lose your money and you may be exposed to identity theft. Windows Firewall Constructor is a scam program, it won't remove any infections and it won't protect your computer from viruses whatsoever. If you are infected with this rogue program, use the removal guide below to remove Windows Firewall Constructor and related malware as soon as possible.
While Windows Firewall Constructor is running you will also see many fake security alerts and notifications on your computer. These warnings will state that your computer is infected.
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.
It blocks other programs on your computer and hijacks web browsers as well. It goes without saying that you should ignore anything this program reports to you and uninstall it immediately. Please note that Windows Firewall Constructor may come bundled with other malware or even rootkits so we strongly recommend you to use legit anti-spyware program to remove the rogue program and related malware from the system. Also, if you have already purchased it, then you please contact your credit card company and dispute the charges. If you can't run anti-spyware program in normal mode, then you can reboot your computer in safe mode with networking and try again.
The latest parasite names used by FakeVimes:
Windows Firewall Constructor manual removal:
Delete registry values:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegedit" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegistryTools" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableTaskMgr" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "ID" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "net" = "2012-2-17_2"
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options_avp32.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options_avpcc.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsashDisp.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsdivx.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmostat.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsplatin.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionstapinstall.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionszapsetup3001.exe
%appdata%Inspector-[3 random characters].exe
%desktopdir%Windows Firewall Constructor.lnk
%StartMenu%ProgramsWindows Firewall Constructor.lnk