Windows Safety Toolkit is a rogue anti-spyware program that was designed to rip computer users off by displaying fake security alerts and reporting false scan results. This fake security product pretends to be a genuine malware removal tool that is essential in protecting your system from security threts and notorious infections but the truth is that it actual doesn't have abilities to perform any PC security related tasks at all. Windows Safety Toolkit was designed by computer criminals who have only one goal – to scare you into thinking that your computer is infected and to trick you into purhchasing useless anti-spyware product.
Basically, when this rogue anti-spyware program is installed it is run right after your Windows fully loads. Later on the same is repeated each time the system is restarted. Windows Safety Toolkit may look just like any other legitimate antispyware program because it's pretty well designed. It then runs a fake system scan and displays a bunch of files supposedly detected on your computer and then states they pose risk to your computer and can even steal your credit card details and passwords.
Windows Safety Toolkit recommends purchasing a full version of its program in order to remove threats that have been detected during the fake system scan. However, everything will end by swindling your money away as such version of a program doesn’t even exist. It will simply change the GUI to make it look like you are now using fully functional version that can protect your computer from malware and viruses. Besides, while Windows Safety Toolkit is running on the system it causes a bunch of pop up ads and security notifications that warn about system threats like Trojans, spyware and malware detected on your system and other security problems. All of them are also meant to make computer user pay for it.
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.
You are strongly advised to remove Windows Safety Toolkit as soon as possible. That’s is one and only way to get rid of all unwanted actions that are cause by this rogue anti-spyware program. Even though you may remove it manually we strongly recommend you to use malware removal tool give below because the rogue anti-spyware can download and install more malware on your computer.
The latest parasite names used by FakeVimes:
Windows Safety Toolkit manual removal:
Delete registry values:
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Settings "net" = "2012-3-11_2?
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "origkboryd"
HKEY_LOCAL_MACHINE\SOFTWAREMicrosoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe
HKEY_LOCAL_MACHINE\SOFTWAREMicrosoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe
HKEY_LOCAL_MACHINE\SOFTWAREMicrosoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe