Windows Pro Solutions

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 15
First Seen: May 10, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Pro Solutions Image

The FakeVimes family of malware is a large group of fake anti-virus programs that has been active since 2009. New versions of malware in this family pop-up regularly, usually with only slight tweaks to the interface and to the malware program's attack. Windows Pro Solutions is one of the many fake security programs in this family of malware. Unfortunately, in 2012 ESG malware analysts have detected a rise of malware in this family. While malware programs like Windows Pro Solutions can be removed quickly with the help of a reliable anti-malware program, it seems that malware in the FakeVimes family released in 2012 is often bundled with some version of the ZeroAccess rootkit. This makes this current generation of fake security applications in the FakeVimes family particularly difficult to remove.

Apart from Windows Pro Solutions, other rogue anti-virus programs belonging to this 2012 batch of malware include Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

Windows Pro Solutions is designed to scare computer users into thinking that they need to purchase a useless fake security program. In order to carry out its scam, Windows Pro Solutions will display a constant barrage of alarming error messages. This tactic, coupled with a fake system scan, pop-up notifications from the Task Bar, and various computer problems (such as browser redirects and general system instability) are designed to maintain the illusion that the victim's computer system is severely infected with viruses and Trojans. Then, Windows Pro Solutions will offer to fix these nonexistent problems, but only if the victim is willing to pay for a 'full version' of Windows Pro Solutions. ESG security analysts advise against doing this; Windows Pro Solutions has no anti-virus capabilities and is merely designed to scam inexperienced computer users.

Recovering from a Windows Pro Solutions Infection

Most security software has no problem dealing with malware in the FakeVimes family. However, as was mentioned before, the rootkit component included in FakeVimes malware programs released in 2012 requires a specialized anti-rootkit tool or a strong anti-malware program with anti-rootkit technology. To aid you in removing Windows Pro Solutions, you can use the registration code 0W000-000B0-00T00-E0020 to make Windows Pro Solutions believe that you have paid for its 'full version'. While this will cause Windows Pro Solutions to stop displaying annoying error messages, it Windows Pro Solutions will remain on your computer system. It is still strongly recommended removing Windows Pro Solutions completely.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Pro Solutions

Windows Pro Solutions Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Pro Solutions may create the following file(s):
# File Name MD5 Detections
1. Protector-kxrh.exe 9403a1626698c8015648a506182d978b 6
2. Protector-upam.exe 782ccdfa7a087d267e2696b97d8d232c 4
3. Protector-kyrh.exe 804de6a1b2921ec579fe4e0e867aee89 1
4. %AppData%\Protector-[RANDOM CHARACTERS].exe
5. %AllUsersProfile%\Start Menu\Programs\Windows Pro Solutions.lnk
6. %UserProfile%\Desktop\Windows Pro Solutions.lnk
7. %AppData%\result.db

Registry Details

Windows Pro Solutions may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\
Debugger = svchost.exe
Inspector = %AppData%\Protector-[RANDOM CHARACTERS].exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\

Messages

The following messages associated with Windows Pro Solutions were found:

Error
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.
Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Error
Software without a digital signature detected.
Your system files are at risk. We strongly advise you to activate your protection.
Warning
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:Windowssystem32dllcachewmploc.dll
C:Windowssystem32dllcachewmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning! Identity theft attempt Detected
Warning! Spambot detected!
Attention! A spambot sending viruses from your e-mail has been detected on your PC.

Trending

Most Viewed

Loading...