Windows Ultimate Safeguard is a program that has been been found to use provoking techniques when trying to rip its victims off. Typically to other FakeVimes threats, this scamware returns for its victims invented information about numerous cyber threats detected. Besides, it displays fake system scanners and then offers to purchase its licensed version in order to remove infections from the system. Although the official appearance of Windows Ultimate Safeguard tries to create an image that this is a trustworthy program which is worth to be purchased, we must warn you that this is a rogue anti-spyware which is capable to report only about invented viruses detected. Be sure that Windows Ultimate Safeguard seeks to swindle some money from you, so ignore its alerts instead of taking them for granted. In fact, this program has no helpful option and it must be eliminated without any delay. We highly recommend using reputable anti-malware programs to get rid of Windows Ultimate Safeguard for good.
HOW Windows Ultimate Safeguard INFECTS PC USERS?
The way how Windows Ultimate Safeguard gets inside the system is based on trojans. They download this scamware on the system without any user’s permission asked and additionally set it to start as soon as PC is rebooted. Windows Ultimate Safeguard simply exploits vulnerable spots on the target Operating System and makes itself perfectly comfortable there. After being installed, this rogue starts displaying misleading pop-ups, alerts and scanners that can be easily predetermined to report about numerous viruses detected. These false positives from Windows Ultimate Safeguard look like that:
Warning! Virus Detected
Threat Detected: Trojan-Downloader.Win32.Agent
Infected File: regedit.exe
Description: Programs classified as Trojan download and install new versions of malicious programs, including Trojans and AdWare, on victim computers.
Please click “remove All” button to erase all infected files and protect your PC
Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexpolre.exe
C:\program files\internet explorer\iexpolre.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Please click “Prevent attack” button to prevent all attacks and protect your PC
Keep in mind that Windows Ultimate Safeguard is a rogue anti-spyware program that is capable to return only fabricated information about your computer. It misinforms the user only for getting his money, so ignore its offers to purchase licensed Windows Ultimate Safeguard version. While it states that only the full its version can help you remove malicious items from your computer, we recommend to remove Windows Ultimate Safeguard from the system and use a reputable anti-malware program for that.
HOW TO REMOVE Windows Ultimate Safeguard?
As soon as you notice this threat on board, run a full system scan with Reimage and remove all infected files it reports.If you can't launch this program, you can firstly imitate its registration with a help of this code: 0W000-000B0-00T00-E0020. After stopping Windows Ultimate Safeguard, you still need to run a full system scan with anti-malware program. Besides, contact your credit card company to dispute the cherges if you have already purchased the licensed version of this scamware.
The latest parasite names used by FakeVimes:
Windows Ultimate Safeguard manual removal:
Delete registry values:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegedit" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegistryTools" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableTaskMgr" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "ID" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "net" = "2012-2-17_2"
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options_avp32.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options_avpcc.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsashDisp.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsdivx.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmostat.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsplatin.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionstapinstall.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionszapsetup3001.exe
There are more similar entries, you should let spyware Doctor to identify them.