There is a new virus inside the web called Windows Interactive Security. What should users know about this new rogue? Though it is new but it has almost the same old aims and methods of work as many other viruses. The main goal of this scam is your moeny. It will do a lot of dirty stuff to your system to fool you into the purchasing of its product. Do not pay attention to anything it shows you and provides you with.
Do not buy its "commercial version" under any circumstances! If you do the purchase you will get nothing but lost time and moeny. And the virus will achieve its goal. Thar is why you should remove Windows Interactive Security virus from your system as soon as you notice it inside your machine. GridinSoft Trojan Killer can definitely help you to cope with the rogue. Download the program here below and the virus will be eliminated in several minutes.
Windows Custom Safety automatic remover:
Upon detection of viruses click Remove Selected. Reboot your computer if prompted.
Windows Interactive Security manual remover:
Delete Windows Interactive Security files:
Protector-[rnd].exe in %AppData% folder
Delete Windows Interactive Security registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe
No comments:
Post a Comment