Windows Safety Checkpoint is a rogue anti-spyware program that pretends to be a legitimate antivirus software but actually it's just a piece of malware. It pretends to scan the infected computer for viruses, spyware and other malicious software and later states that your computer is infected and has to be cleaned using fake scammers' program. The rogue program is promoted mostly through the use of Trojans, fake virus scanners and compromised websites. Usually, such rogue programs have to be manually installed, but sometimes they masquerades as legitimate software, usually flash player or an update, so that the user thinks it's a genuine udpdate or software developed by reliable companies. When running it will display false scan results and fake security alerts to scare you into thinking that your computer is infected with all sorts of malware. Windows Safety Checkpoint will remind you about the fake infections all the time. And it will display fake security alerts and notifications like every one or two minutes.
Trojan activity detected. System data security is at risk.
It is recommended to activate protection and run a full system scan.
Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Please don't fall victim to this rogue anti-spyware program. If you find that your computer is infected, please use the removal instructions below to remove Windows Safety Checkpoint from the system using legitimate malware removal software.
It could be that Windows Safety Checkpoint will set up a local proxy server and hijack Internet Explorer and ther web browsers that you may use. In such case, you won't be able to visit any other websites than the payment page of the rogue program. It usually also blocks Task Manager, Registry Editor, and some other system utilities to protect itself from being removed. So first of all you will have to end the main processes of Windows Safety Checkpoint and then remove its files. Or you can reboot your computer in safe mode with networking and download an automatic remove tool given below. Also, note that this rogue program can download and install additional malware onto your computer. That's why it is very important to remove all the infections from your computer. We strongly recommend you scan your computer with anti-malware software given below. If you have already purchased it, then call your credit card company and dispute the charges.
The latest parasite names used by FakeVimes:
Windows Warding Module, Windows Active HotSpot, Windows Cleaning Toolkit, Windows Expert Console, Windows Protection Maintenance
We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
and agreement of use
Windows Safety Checkpoint manual removal:
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe