Thursday, May 24, 2012

Windows Safety Maintenance virus. The removal guide.

Windows Safety Maintenance is a new virus that has almost the same aims and methods of work inside the system as any other virus in the web. For those who are sure that Windows Safety Maintenance can be perfect program for the scams’ detection we can prove that you are wrong about that. Windows Safety Maintenance just claims to be good program. Yes, it has the same design as many antiviruses have but you should look deeper. The only goal of Windows Safety Maintenance is your money. It will do averything for you to believe that your system is infected and needs to be repaired immediately. And of course it will suggest to use its product for the removal. But do not think it will do something good and useful. If you give your money for this product you will just be fooled.


Windows Safety Maintenance virus needs to be eliminated from the system as soon as possible. Be very careful when you have this ogue inside your system. There can be a lot of different pop-ups and messages. Just ignore everything Windows Safety Maintenance provides you with. All information you receive from the virus is totally fake.
We recommend you to use our anti-spyware program Loaris Trojan Remover for the successful elimination of Windows Safety Maintenance virus. Download the program here below and get rid of the virus in several minutes.

Windows Safety Maintenance malware remover:

Windows Safety Maintenance automatic remover:

Windows Safety Maintenance automatic remover

Windows Safety Maintenance similar video removal guide:


Windows Safety Maintenance manual removal guide:

Delete Windows Safety Maintenance files:

  • %AppData%\\Microsoft\\Internet Explorer\\Quick Launch\\Windows Safety Maintenance.lnk
  • %AppData%\\Windows Safety Maintenance\\Instructions.ini
  • %AppData%\\Windows Safety Maintenance\\ScanDisk_.exe
  • %Desktop%\\Windows Safety Maintenance.lnk
  • Programs%\\Windows Safety Maintenance.lnk
  • %StartMenu%\\Windows Safety Maintenance.lnk
  • %CommonAppData%\\58ef5\\SP98c.exe
  • %CommonAppData%\\58ef5\\SPT.ico
  • %CommonAppData%\\SPUPCZPDET\\SPABOIJT.cfg

Delete Windows Safety Maintenance registry files:

  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows Safety Maintenance "%CommonAppData%\\58ef5\\SP98c.exe" /s /d
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance\\DisplayIcon [unknown dir]\\[unknown file name].exe,0
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance\\DisplayName System Protection Tools
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance\\DisplayVersion 1.1.0.1010
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance\\InstallLocation [unknown dir]\
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance\\Publisher UIS Inc.
  • HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Windows Safety Maintenance\\UninstallString "[unknown dir]\\[unknown file name].exe" /del
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\LocalServer32\\ [unknown dir]\\[unknown file name].exe
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID
  • HKLM\\SOFTWARE\\Classes\\CLSID\\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\\ProgID\\ [unknown file name].DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\ Implements DocHostUIHandler
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid
  • HKLM\\SOFTWARE\\Classes\\Dumped_.DocHostUIHandler\\Clsid\\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\ConsoleTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableConsoleTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\EnableFileTracing 0
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileDirectory %windir%\\tracing
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\FileTracingMask -65536
  • HKLM\\SOFTWARE\\Microsoft\\Tracing\\FWCFG\\MaxFileSize 1048576
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AAWTray.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVCare.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVENGINE.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AVWEBGRD.EXE\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\About.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Ad-Aware.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AdwarePrj.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AlphaAV.exe\\Debugger svchost.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe
  • HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\AluSchedulerSvc.exe\\Debugger svchost.exe
  • And many others.

No comments:

Post a Comment