Windows Salvor Tool

By SpideyMan in Rogue Anti-Spyware Program

Screenshot

What Is Windows Salvor Tool?

Windows Salvor Tool is a rogue security application that belongs to a very large family. Rogue security applications are malicious software that try to scam computer users. Scams like Windows Salvor Tool usually follow these steps:

  1. The rogue anti-spyware application is downloaded and installed, usually via Trojan, inadvertently and without authorization. In the case of programs in this family of rogue anti-spyware programs, the installation will often come from a fake notification from Microsoft Security Essentials. This fake Microsoft Security Essentials alert is caused by the Trojan with the same name.
  2. Programs like Windows Salvor Tool will then cause numerous problems on the computer system. It will also start to display fake system scans and security alerts to convince the computer user that his/her machine is infected and that Windows Salvor Tool is the security tool needed to fix it.
  3. Rogue applications like Windows Salvor Tool will then notify the computer user that, in order to remove the problems, he/she will have to purchase Windows Salvor Tool.

Points to remember:

  • Windows Salvor Tool is a scam, not a legitimate security application.
  • Do not give Windows Salvor Tool your money, the very thing causing the problems on your computer is Windows Salvor Tool itself.
  • Windows Salvor Tool is a dangerous threat to your computer's security; use a genuine anti-malware tool to remove this rogue immediately.

What is a “Salvor” Anyways?

Programs in the Windows Salvor Tool family have several things that make them unique. One of these things is the fact that some of them can have hilariously nonsensical names, which are randomly generated. While many make sense, there are others (e.g. Windows Proofness Guarantor) which use words that are very outdated or make no sense in the context. This family of rogue security programs is thought to come from the Russian Federation, another possible reason for the bad English in Windows Salvor Tool's interface and fake security alerts.
 

Get Rid of Windows Salvor Tool for Good

To get rid of Windows Salvor Tool, use an updated anti-malware utility. Start up your computer in Safe Mode. It is also possible to remove Windows Salvor Tool manually, but it is not recommended if you don't fully understand what you're doing. Windows Salvor Tool seldom attack alone. That is why it is a good idea to run a full system scan to make sure there are no other nasty programs lurking around in your computer.

File System Details

Windows Salvor Tool may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\Microsoft\.exe

Registry Details

Windows Salvor Tool may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "DisableSR " = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'

Trending

Most Viewed

Loading...