Friday, July 20, 2012

Windows Security Renewal is categorized as a fake software

Windows Security Renewal is a money-oriented fake anti-virus that aims aim to gain a commercial profit by taking advantage of users’ credulity.

It is programmed to imitate a computer scan after what a list of warnings and alerts is presented. These messages are created to make you believe that your PC is seriously damaged and needs repair as soon as possible. Of course the only way to do it, according to Windows Security Renewal, is to purchase a full version of the program.
Windows Security Renewal gets into the system using Trojans, masqueraded as video files. It is also distributed by infected websites that redirect to fake online scanners. A user chooses to download a useful software or video file but he/she gets a rogue instead. Once installed, Windows Security Renewal takes complete control of an infected computer. After Windows Security Renewal imitates a computer scan and presents with a list of problems, some of the detected items might have a full path to the system files shown, but not all of them. The alerts include 2 versions of all parasites which are not related to each other. This only proofs that Windows Security Renewal is not a legitimate antivirus but only a scam. The next thing this virus does is recommending removing listed files. It asks to pay for a full version of Windows Security Renewal in order to complete the action. Do not fall for this trick. You would end up losing your money and having worthless purchase. The removal of this badware is the only correct decision.

In order to remove Windows Security Renewal rogue you need to install GridinSoft Trojan Killer and run full scan with it. Make sure to update the program before you run it. Then, when the scan has been completed, remove all infections it finds and reboot your system. If you have difficulties deleting this virus please contact us via support channels available at this site.


malware removal tool

Delete Windows Security Renewal files:
%AppData%\Protector-[rnd].exe
Delete Windows Security Renewal registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe

No comments:

Post a Comment