7/17/2012

Windows Virtual Firewall deserves to be erased ASAP

Windows Virtual Firewall is a fake antivirus application that comes from the same family as as most of the latest rogue programs – FakeVimes. It uses the same malicious techniques to get inside the system and perform its malicious plans there.most of the time it employs trojans and comes inside while you are downloading something or watching videos on the Internet.
The program generates fake security notifications and pop up ads which warn about system errors and claim your computer is infected. The purpose of these messages is to push you into purchasing a full version of Windows Virtual Firewall in order to eliminate malicious files from your system.
Windows Virtual Firewall gets into a machine with a help of Trojans by scamming people into downloading dangerous programs. This can done by showing convincing warnings in infected websites, or by using fake torrent files. Once the malware is there, it interrupts every step you do with your PC making work very annoying.To fix your computer, you should remove Windows Virtual Firewall as soon as you notice its activity on your PC. We recommend using up-to-date anti-m. Perform a full system scan and clean your computer from all viruses. Using automated programs will help to restore your regular antivirus device GridinSoft Trojan Killer, which will help you to deal with the viruses of all kinds and natures.


malware removal tool

Delete Windows Virtual Firewall files:
%AppData%\NPSWF32.dll
%AppData%\Protector-[rnd].exe
%AppData%\result.db
Delete Windows Virtual Firewall registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

No comments:

Post a Comment