Severity scale  
  (67/100)

Windows Secure Workstation. How to Remove? (Uninstall Guide)

removal by - -   Also known as WindowsSecureWorkstation | Type: Malware
12

Windows Secure Workstation is a daily FakeVimes parasite that was spotted on 13 August, 2012. This rogue uses the same GUI, typical to FakeVimes, and displays identical alerts reporting about trojans, adware, malware and other viruses. If you see such alerts, keep in mind that they are worthless and should be simply ignored if you don't want to lose your money. The way how you can do that is really simple - Windows Secure Workstation offers to purchase its licensed version in order to remove its detected viruses. Of course, these 'viruses' are harmless system files and this 'licensed version' is nothing else but a tool used by scammers to swindle users' money. By entering your credit card details, you may also find yourself ripped off completely, so contact your credit card company immediately if you have already paid for useless Windows Secure Workstation version.

HOW CAN I GET INFECTED WITH Windows Secure Workstation?

The common way how all FakeVimes scarewares are distributed includes blackhat social engineering and corrupt downloads. Windows Secure Workstation is also spread through potentially unsafe or compromised web resources filled with infected freeware, shareware, updates and other programs. As soon as PC is infected, it's modified so that the malware could launch just after every computer's reboot. In addition, Windows Secure Workstation will start displaying misleading alerts and scanners claiming something like that:

Error
There’s a suspicious software running on your PC.
For more details, run a system file check.

Warning! Virus Detected
Threat Detected: Trojan-Downloader.Win32.Agent
Security Risk:
Infected File: regedit.exe
Description: Programs classified as Trojan download and install new versions of malicious programs, including Trojans and AdWare, on victim computers.
Recommended:
Please click “remove All” button to erase all infected files and protect your PC

Firewall has blocked a program from accessing the Internet
Internet Explorer
C:\program files\internet explorer\iexpolre.exe
C:\program files\internet explorer\iexpolre.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Recommended:
Please click “Prevent attack” button to prevent all attacks and protect your PC

As you can see, Windows Secure Workstation is a program that is capable to lead computer only to the deterioration of the machine’s performance. It is capable to display only fake security scanners and alerts that are designed to make user pay for its license. Be sure that Windows Secure Workstation is a rogue program that must be eliminated without any delay. As soon as you receive its alerts and spyware threats detected on your system, remove this scam. Otherwise, it will make your PC slow and laggy, will start tracking your browsing habits and will do other stuff which is categorized as 'illegal'.

HOW TO REMOVE Windows Secure Workstation?

In order to remove Windows Secure Workstation from the system, you shouldn't try doing that manually because you may remove wrong files from the system what may lead you to system danage. According to our research center, you should rely on Reimage and PlumbytesWebroot SecureAnywhere AntiVirus. Note that these programs must be updated before a scan. If you still can't launch them, disable Windows Secure Workstation by entering this code that will make your virus think you have purchased its license: 0W000-000B0-00T00-E0020. Additionally, scan with Reimage

The latest parasite names used by FakeVimes:
Windows Internet Guard, Windows Web Watchdog, Windows AntiBreach Patrol, Windows Antivirus Patrol, Windows Pro Defence Kit

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Windows Secure Workstation. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall Windows Secure Workstation. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
Plumbytes
We are testing Plumbytes's efficiency (2012-08-13 08:31)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency (2012-08-13 08:31)
Hitman Pro
Webroot SecureAnywhere AntiVirus
Windows Secure Workstation screenshot
Windows Secure Workstation snapshot

Windows Secure Workstation manual removal

Kill processes:
%AppData%\Protector-[rnd].exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
And there are much more similar entries...
Delete files:
%AppData%\Protector-[rnd].exe

Removal guides in other languages


Information updated:

Comments on Windows Secure Workstation

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)