Does your system constantly get scanned by some program called Windows No-Risk Center. If so, you might already be a victim of the creators of this rogue antivirus program and your computer has probably been infected with this scam application. So to begin with, Windows No-Risk pretends to be a security tool and imitates system scan. Afterwards, the program offers purchasing its license in order to supposedly provide security services.
The application is generating plenty of different pop ups and security tray alerts stating that your system is full of infections and your private data is at risk so you need to purchase a license of Windows No-Risk Center. The program promises to eliminate the existing parasites and protect from future spyware attacks.
Windows No-Risk Center infects the system with a help of Trojan viruses that actively spread on the Internet or through hacked websites. The Trojan enters the system without any notification and installs Windows No-Risk Center without any notification. Then it is configured to start automatically which each login to Windows.
You will definitely notice considerable computer slowdown, besides, after each restart of your PC, Windows No-Risk Center will run its scanner. The scanner will announce about a bunch of infections and recommend eliminating them as soon as possible. In reality, the files that are shown as infections are harmless and it is only a method used by computer hackers to make you fall for this trick.
Windows No-Risk Center will keep insisting you on purchasing the program; however, you shouldn't fall for it. You will only lose your money and get nothing return. Please get rid of Windows No-Risk Center using Malwarebytes or Reimage as soon as you detect its traces on your system. Moreover, if you are one of those who have already paid for this scam program, do not hesitate to contact your credit card company and dispute the charges.
The latest parasite names used by FakeVimes:
Windows No-Risk Center manual removal:
Delete registry values:
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\SoftwareMicrosoft\Windows\CurrentVersion\Settings "net" = "2012-3-11_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings ?"UID" = "origkboryd"
HKEY_LOCAL_MACHINE\SOFTWAREMicrosoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe
HKEY_LOCAL_MACHINE\SOFTWAREMicrosoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe
HKEY_LOCAL_MACHINE\SOFTWAREMicrosoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe
%CommonStartMenu%ProgramsWindows Managing System.lnk
%Desktop%Windows Managing System.lnk