Threat Database Rogue Anti-Spyware Program Windows Ultimate Safeguard

Windows Ultimate Safeguard

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 4
First Seen: August 4, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Ultimate Safeguard Image

Windows Ultimate Safeguard is a rogue security application in the FakeVimes family of malware, a group of malicious programs that have been active since 2009. ESG security researchers warn computer users that Windows Ultimate Safeguard has no anti-malware capabilities. Malware such as Windows Ultimate Safeguard uses misleading error messages, and other tactics to trick computer users into purchasing useless bogus anti-malware software. Since Windows Ultimate Safeguard cannot detect PC infections and is part of a malware attack itself, this fake security program should be removed with the assistance of a powerful, fully updated anti-malware program.

Windows Ultimate Safeguard Contains a Dangerous Rootkit Component

Although PC security analysts have been dealing with malware from the FakeVimes family for several years, rogue security programs in this family have started to use new tactics to become more effective and difficult to remove. Since early 2012, ESG malware analysts have observed that bogus security applications from the FakeVimes family of malware have started to use a rootkit component that makes them much more dangerous than previous variants in the FakeVimes family of malware. This rootkit belongs to the Sirefef family of rootkits and can disable many legitimate security programs as well as make the infected computer significantly more vulnerable to other malware attacks. Clones of Windows Ultimate Safeguard that also contain this dangerous rootkit component include programs such as Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

Dealing with Windows Ultimate Safeguard and Other FakeVimes Malware

The main goal of the Windows Ultimate Safeguard scam is to persuade the PC user that their machines are severely infected in an attempt to trick the victim into acquiring an expensive upgrade for this useless rogue security program. To do this, Windows Ultimate Safeguard uses misleading error messages and a fake system scan that will always return alarming results. The presence of Windows Ultimate Safeguard on a computer can also cause browser redirects and other problems, such as general decreased performance across the board.

Since Windows Ultimate Safeguard cannot actually detect or remove malware, this fake security program should be disabled with a reliable anti-malware application. You can stop many of Windows Ultimate Safeguard's most annoying symptoms by entering the registration code 0W000-000B0-00T00-E0020. It is important to remember that 'registering' Windows Ultimate Safeguard does not actually remove this malicious program from your computer but only stops some of its symptoms. Windows Ultimate Safeguard will still need to be removed from the infected computer.

SpyHunter Detects & Remove Windows Ultimate Safeguard

Windows Ultimate Safeguard Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Ultimate Safeguard may create the following file(s):
# File Name MD5 Detections
1. dbae19be89b393dead5ce7f0ff911ade85b6ed3c8f72a3be482cee9e8ebbd133.exe f684d4f64ce72902123e55374bff1667 3
2. %AppData%\Protector-[RANDOM].exe

Registry Details

Windows Ultimate Safeguard may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "[RANDOM]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\"Debugger" = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = "4"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\"Debugger" = "svchost.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "%AppData%\Protector-[RANDOM].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "[DATE OF INSTALLATION]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\"Debugger" = "svchost.exe"

Trending

Most Viewed

Loading...