Windows Pro Safety

Windows Pro Safety Description

ScreenshotWindows Pro Safety belongs to a category of malware programs known as rogue security applications. Rogue security programs like Windows Pro Safety pretend to be legitimate anti-malware programs but have no actual anti-malware capabilities. These kinds of fake security applications are used as part of a pervasive online scam that preys on inexperienced computer users. Basically, criminals make the victims believe that their computer system is severely infested with all kinds of malware. However, trying to use Windows Pro Safety to fix these simply results in a message claiming that the victim needs to 'upgrade' to an also useless 'full version' of Windows Pro Safety. This supposed upgrade is not cheap, usually close to one hundred dollars. ESG security analysts strongly advise against purchasing Windows Pro Safety. Instead, this fake security application should be dealt with using a reliable anti-spyware program.

Windows Pro Safety, Rootkits and the FakeVimes Family of Malware


Windows Pro Safety belongs to a particularly large group of fake security software known as the FakeVimes family of malware. Because these bogus security applications have been active since 2009, most legitimate anti-malware programs are well equipped to deal with them. However, malware in the FakeVimes family released in 2012 will often include an accompanying rootkit infection (often a version of the Sirefef rootkit) that makes them much more difficult to remove than previous versions of FakeVimes malware applications. Some examples of clones of Windows Pro Safety released in 2012 and before include A-fast Antivirus, Windows Cleaning Tools, Windows Antivirus Booster, Security Master AV, Volcano Security Suite, Windows Daily Advisor, Windows Be-on-Guard Edition, Windows AntiBreach Patrol, Windows Defence Unit, Windows Activity Debugger, Windows Antivirus Patch, Smart PC Cleaner, Smart Internet Protection 2012, Windows Crucial Scanner, Windows Abnormality Checker, Windows Activity Booster, Fast Antivirus 2009, My Security Shield, Live Enterprise Suite, Windows Efficiency Accelerator, Smart Security, Windows Anti-Malware Patch, Personal Security Sentinel, Windows Advanced User Patch, Windows Cleaning Toolkit, Windows Care Taker, Total Anti Malware Protection, Windows Debug Center, Windows Antivirus Tool, Windows Antibreach Tool, CleanUp Antivirus, Windows Antihazard Solution, Best Antivirus Software, Windows Component Protector, Windows Antivirus Patrol, Antivirus Smart Protection, Internet Security Suite, Home Malware Cleaner, Windows AntiBreach Helper, VirusSecurity, Windows Command Processor, Virus Melt, My Security Engine, Internet Security Essentials, Best Malware Protection, Windows Active Guard, Windows Antivirus Care, Presto TuneUp, My Security Wall, Smart Anti-Malware Protection, Smart Virus Eliminator, Anti-Malware Lab, PC Security Guardian, Windows Daily Adviser, Windows Antivirus Machine, Windows Antivirus Adviser, Smart Engine, System Smart Security, Windows Custom Safety, Advanced Antispyware Solution, Virus Doctor, System Protection Tools, Live PC Care, Windows Advanced Toolkit, Windows Efficiency Console, Home Safety Essentials, Windows Custodian Utility, Security Antivirus, Windows Advanced Security Center, Windows Control Series, Windows Efficiency Master, Windows AntiBreach Suite, Windows Antivirus Release, Windows AntiHazard Center, Enterprise Suite, Windows Defending Center, Keep Center Keeper, Additional Guard, Malware Protection, Windows Antibreaking System, Windows Efficiency Kit, PC Live Guard, Windows Basic Antivirus, Windows Antivirus Helper, Personal Internet Security 2011, Smart Internet Protection 2011, Windows Defence Master, Windows Antibreach Module, Windows Antivirus Rampart, Windows AntiHazard Helper, Activate Ultimate Protection, Windows Antivirus Suite, Fake Windows Antivirus 2012, Windows Defence Counsel, Windows Active HotSpot, Windows Accelerator Pro, Windows Custom Management and Extra Antivirus. The presence of the rootkit component makes these newer versions of FakeVimes clones much more difficult to remove than their predecessors and will often require the help of a specialized anti-rootkit tool or a strong anti-malware program with anti-rootkit technology.

How You Can Protect Your Computer System from the Windows Pro Safety Scam


The culprit behind most rogue security software infections is usually a Trojan. Trojans associated with Windows Pro Safety will often enter a computer system disguised as a fake video codec, a harmless email attachment, or as a result of an exploit on an attack website. The most common causes for Trojan infections associated with Windows Pro Safety are online advertisements claiming to scan your computer system for malware. They will always claim that your computer is infected and urge you to install Windows Pro Safety. Almost all of these kinds of malicious advertisements will also attempt to exploit known vulnerabilities in order to install Windows Pro Safety in the background while the fake scan is distracting the computer user.

Infected with Windows Pro Safety? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect Windows Pro Safety

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Screenshots & Other Imagery

Tip: Turn your sound ON and watch the video in Full Screen mode to fully experience how Windows Pro Safety infects a computer.

How to Detect and Remove Windows Pro Safety?

Windows Pro Safety Image 1 Windows Pro Safety Image 2 Windows Pro Safety Image 3 Windows Pro Safety Image 4 Windows Pro Safety Image 5 Windows Pro Safety Image 6 Windows Pro Safety Image 7 Windows Pro Safety Image 8 Windows Pro Safety Image 9 Windows Pro Safety Image 10 Windows Pro Safety Image 11 Windows Pro Safety Image 12

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of Windows Pro Safety outbreaks and other threats from global to local level.

File System Details

Windows Pro Safety creates the following file(s):
# File Name Size MD5 Detection Count
1 Windows Pro Safety.lnk 53
2 %APPDATA%\Protector-bqtk.exe 2,072,576 dfa753380d0efa42bd7594c101346aa6 42
3 %AppData%\Protector-[RANDOM 4 CHARACTERS].exe N/A
4 %AppData%\Protector-[RANDOM 3 CHARACTERS].exe N/A
5 %AppData%\NPSWF32.dll N/A
6 %CommonStartMenu%\Programs\Windows Pro Safety.lnk N/A
7 %Desktop%\Windows Pro Safety.lnk N/A
8 %AppData%\result.db N/A

Registry Details

Windows Pro Safety creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_CURRENT_USER\Software\ASProtect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-5-20_4"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rohjjdbsbt"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe

More Details on Windows Pro Safety

The following messages associated with Windows Pro Safety were found:
Error
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.
Warning
Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning
Firewall has blocked a program from accessing the Internet
C:program filesinternet exploreriexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 8 + 11 ?