Windows Safety Maintenance automatic and manual removal guide

1 Star2 Stars3 Stars4 Stars5 Stars (56 votes, average: 5.00 out of 5)
loadingLoading...

Windows Safety Maintenance is another nefarious antivirus program fabricated by IT frauds, developers of FakeVimes rogue clan. The purpose of this badware is to rob some funds from gullible non-advanced Internet users. Just like its forerunner this badware declares about multiple insecure items spotted on your computer and recommends you buying the registered version of the program, as a superb solution for virus detection and removal. In fact neither demo nor full version can help you with virus deletion. Both of them are useless.

Windows Safety Maintenance only pretends to run the system checkup for virus presence. It ends up with invented scanning reports. It generates the list of files that either belongs to some of your legitimate programs or that do not exist at all. Although you are recommended to remove them, never do it, because you can uninstall the vital files of your system and cause much damage for PC. It goes without saying that Windows Safety Maintenance is a badware that deserves to be detected at once upon detection. GridinSoft Trojan Killer is recommended for this purpose. GridinSoft LLC offers you a shareware license and 24/7 support service. If you have any questions in the process of virus removal, contact us any time, we are always ready to help you.

Windows Safety Maintenance automatic remover:

Similar video guide at our Youtube channel:

Windows Safety Maintenance manual remover:

Delete Windows Safety Maintenance files:
%AppData%\NPSWF32.dll
%AppData%\Protector-[rnd].exe
%AppData%\result.db
Delete Windows Safety Maintenance registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

Leave a Comment

*