Windows Security Renewal scam. Successful elimination.

Windows Security Renewal is one more fake antivirus in computer world. The program wants only one thing from you – your money. And it actually can get it. When this rogue penetrates inside your system it starts to act like an antivirus. This is the main catch of this malicious program. It can easily fool users in such way. It shows you the list of threats it supposedly finds in your system and suggests you to buy its product for the further successful elimination of those above-mentioned threats. But do not believe anything it shows you! The virus creates its own fake names of the rogues for you to believe that your system is really infected with different malwares and needs to be repaired immediately. Do not do anything at all; ignore everything Windows Security Renewal provides you with.

Windows Security Renewal
Windows Security Renewal

We recommend you to use our anti-malware program GridinSoft Trojan Killer for the successful removal of Windows Security Renewal virus. You can download the program here below. Do not hesitate to eliminate the rogue from your system. Until then your system is just broken. It will not work as good as earlier. The sooner you remove the virus from your system the sooner you will get your computer’s stable state back.

Windows Security Renewal automatic remover:

Windows Security Renewal manual remover:

Delete Windows Security Renewal files:
Protector-[rnd].exe in %AppData% folder
Delete Windows Security Renewal registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

Leave a Comment

*