Windows Health Keeper

Windows Health Keeper Image

Since 2009, the Rogue.FakeVimes family of malware has attacked computer users through fake security programs and system optimization tools. Most rogue security programs are pretty similar to each other with only small details differentiating one rogue security program from another. Malware in the FakeVimes family of malware is characterized by using file names with three random characters as well as including fake system optimization and defragmenter error messages among their alarming system alerts. The most recent batch of FakeVimes rogue security programs uses the string 'protector' before the three random characters, but apart from this slight detail, Windows Health Keeper shows no significant differences from previous rogue security programs in this family of malware. Like all rogue security programs, Windows Health Keeper has no way of solving any computer problem. In fact, according to ESG PC security analysts, the presence of Windows Health Keeper on a computer is a symptom of a severe malware problem that should be dealt with immediately.

Windows Health Keeper is a clone of numerous malware, going back to some of the original FakeVimes rogue security programs. Among its many clones we can point Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

Instead of Keeping Your PC Healthy Windows Health Keeper Tries to Steal Your Money

The main purpose of the Windows Health Keeper is to convince the PC user that their computers are almost breaking down in order to take advantage of their panic. After a stream of alarming messages and fake security alerts, Windows Health Keeper will offer to fix all the nonexistent problems on the victim's computer with the purchase of a useless 'full version' of Windows Health Keeper. Fortunately, you can stop all of the supposed problems on your computer by simply using a reliable anti-malware tool to remove Windows Health Keeper and all of its associated malware components. While it is possible to remove Windows Health Keeper manually, this course of action isn't recommended by ESG PC security analysts, unless you are particularly knowledgeable on computer security issues. Windows Health Keeper makes changes to the Windows Registry and system settings that need to be reversed. Apart from this, Windows Health Keeper will often attack along with other malware components, requiring that these associated infections be also removed. In most cases, automatic removal of Windows Health Keeper is the best course of action. ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Windows Health Keeper Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Health Keeper may create the following file(s):
# File Name Detections
1. %AppData%NPSWF32.dll
2. %AppData%Protector-[RANDOM 3 CHARACTERS].exe
3. %CommonStartMenu%ProgramsWindows Health Keeper.lnk
4. %Desktop%Windows Health Keeper.lnk
5. %AppData% esult.db

Registry Details

Windows Health Keeper may create the following registry entry or registry entries:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableTaskMgr" = 0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "EnableLUA" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "net" = "2012-3-17_2"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options apapp.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsfih32.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionswinav.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegistryTools" = 0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "ConsentPromptBehaviorUser" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "UID" = "rnkkhbcsqe"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionswservice.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsashAvast.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssweep95.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegedit" = 0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "ConsentPromptBehaviorAdmin" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "Inspector"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavwinnt.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmgavrtcl.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "net"

Messages

The following messages associated with Windows Health Keeper were found:

Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Warning
Firewall has blocked a program from accessing the Internet
C:program filesinternet exploreriexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning! Identity theft attempt Detected
Hidden connection IP: 58.82.12.124
Target: Your passwords for sites

Trending

Most Viewed

Loading...