Severity scale  
  (72/100)

Windows Safety Series. How to Remove? (Uninstall Guide)

removal by - -   Also known as WindowsSafetySeries | Type: Malware
12

Windows Safety Series is a sneaky program, which comes inside its target computer through security holes found. Be sure that this threat belongs to the 'famous' FakeVimes family that keeps releasing its parasites while trying to rip their victims off. If you have also been 'surprised' by Windows Safety Series appearance on your computer, be sure that you must ignore all alerts and notifications got from this scamware because they are fake and useless. In order to trick its victims, this rogue firstly imitates a scan of the system and then reports about numerous problems and harmful executables detected. Instead of falling for them, you should simply remove Windows Safety Series with a help of automated removal tools, such as Reimage or PlumbytesWebroot SecureAnywhere AntiVirus.

HOW CAN I GET INFECTED WITH Windows Safety Series?

FakeVimes parasites are usually distributed with a help of trojan horse, which appears on the system unexpectedly, together with fake updates, codecs and other infected files. This trojan will additionally upload a bunch of malicious files, what eventually will distort the system completely and make your Internet sessions almost impossible to make. That's because Windows Safety Series starts running forged virus scans and then returns completely fake results based on invented viruses. Typically, this rogue reports that victim has hundreds of malicious files that are associated with backdoor viruses and then claims that only its licensed version is capable to remove them:

Error
There’s a suspicious software running on your PC.
For more details, run a system file check.

Warning! Virus Detected
Threat Detected: Trojan-Downloader.Win32.Agent
Security Risk:
Infected File: regedit.exe
Description: Programs classified as Trojan download and install new versions of malicious programs, including Trojans and AdWare, on victim computers.
Recommended:
Please click “remove All” button to erase all infected files and protect your PC

Firewall has blocked a program from accessing the Internet
Internet Explorer
C:\program files\internet explorer\iexpolre.exe
C:\program files\internet explorer\iexpolre.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Recommended:
Please click “Prevent attack” button to prevent all attacks and protect your PC

We must warn you that the idea of all this campaign is to make you believe in the false information that your machine is at the risk of malware activity and that only licensed Windows Safety Series version is capapble to stop it. However, you must ignore all those requests and remove Windows Safety Series from your computer. Be sure that this program will do anything to get you out of your money and may cause such problems and browser redirections or system slow downs. As you can clearly see, you must get rid of this rogue immediately otherwise it will mess up your system badly.

HOW TO REMOVE Windows Safety Series?

In order to remove Windows Safety Series from your computer, you should run a full system scan with reputable anti-spyware program, such as Reimage or PlumbytesWebroot SecureAnywhere AntiVirus. Be sure that you update them first before you run a full system scan with those programs. We will also give you one trick if you can't launch your anti-spyware programs - enter this fake registration code to make it think that you have already purchased it: 0W000-000B0-00T00-E0020 . Now scan with updated Reimage version and remove this scam for good.

The latest parasite names used by FakeVimes:
Windows Internet Guard, Windows Web Watchdog, Windows AntiBreach Patrol, Windows Antivirus Patrol, Windows Pro Defence Kit

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Windows Safety Series. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Windows Safety Series. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2012-08-16 04:41)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-08-16 04:41)
Hitman Pro
Webroot SecureAnywhere AntiVirus
Windows Safety Series screenshot
Windows Safety Series snapshot

Windows Safety Series manual removal

Kill processes:
Protector-[rnd].exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
There are more similar entries...
Delete files:
Protector-[rnd].exe

Removal guides in other languages


Information updated:

Comments on Windows Safety Series

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)