Windows Warding Module

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 5
First Seen: December 5, 2013
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Warding Module Image

Windows Warding Module is a fake security product that is affiliated to a sizable family of rogue security programs known as FakeVimes. Windows Warding Module prevents computer users from accessing their Desktop or files and pesters computer users with numerous fake error messages and irritating system alerts that are programmed to induce novice computer users into been convinced that their machines are housing threats. Windows Warding Module is marketed as a legitimate security program and often distributed through corrupted advertisements promising free system scans and supposed solutions for imaginary threat problems. If Windows Warding Module is installed on your computer, PC security researchers strongly advise its immediate removal. Windows Warding Module is a known tactic that is designed to get your money and fool new PC users into acquiring a bogus 'full version' of Windows Warding Module.

Windows Warding Module makes changes to your computer's settings that allow this fake security program to load every time Windows is initiated. As soon as Windows Warding Module starts up, Windows Warding Module runs a bogus scan of the affected computer, claiming that Windows Warding Module has found a large quantity of threats on the affected computer. In fact, these are all false positives which goal is to fool inexperienced PC users into believing that they need to use Windows Warding Module to clean out the affected computer. If computer users try to use Windows Warding Module to remove these imaginary threats, Windows Warding Module will display a message claiming that it is indispensable to make an upgrade for a 'full version' of Windows Warding Module. However, since Windows Warding Module is a threat itself, 'upgrading' Windows Warding Module is completely useless.

Dealing with Windows Warding Module

Malware analysts dynamically advise PC users to avoid paying for the 'full version' of Windows Warding Module. Instead, Windows Warding Module should be removed from the computer using a strong, real anti-malware application. Fraudulent security applications such as Windows Warding Module are between the most popular types of threats and are used to trick inexperienced computer users. Among the numerous clones of Windows Warding Module are included Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.
ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Warding Module

File System Details

Windows Warding Module may create the following file(s):
# File Name MD5 Detections
1. setup.exe 96d3b1f95e3fde25ba8e8d0e62bc9d21 1
2. %AppData%\guard-[RANDOM CHARACTERS].exe
3. %AppData%\result1.db

Registry Details

Windows Warding Module may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation"=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "GuardSoftware" = "%AppData%\guard-[RANDOM CHARACTERS].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger"="svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"="C:\\Users\\User\\AppData\\Roaming\\guard-[RANDOM CHARACTERS].exe"
"LowRiskFileTypes"=".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger"="svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = "0"

Messages

The following messages associated with Windows Warding Module were found:

Error
Attempt to run a potentially dangerous script detected.
Full system scan is highly recommended.
Error
System data security is at risk!
To prevent potential PC errors, run a full system scan.
Firewall has blocked a program from accessing the Internet
c:windowssystem32iexplore.exe
is suspected to have infected your PC.
This type of virus intercepts entered data and transmits them
to a remote server.
Warning! Identity theft attempt detected
Hidden connection IP: xx.xxx.xxx.xxx
Target: Microsoft Corporation keys
Your IP: 127.0.0.1

Trending

Most Viewed

Loading...