1 of 5
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Slow internet connection
  • System crashes
  • Annoying Pop-up's
  • Slow Computer

Windows Proofness Guarantor

Fake Microsoft Security Essentials scam consists of many rogue antispyware applications and Windows Proofness Guarantor is the newest addition to the family. The previous versions of the same fake security program include Windows Inviolability System, Windows AV Component, Windows Stable Work and many others. It just shows that the people behind this infection are very eager and continuing their dark deeds. Windows Proofness Guarantor comes forth with one main purpose in mind, and that is making easy money out of unsuspecting computer users.

With the very beginning of the infection you will receive a fake Microsoft Security Essentials security notification which will state that an Unknown Win32/Trojan has been detected in your computer. The message will be as follows:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

Afterwards you are asked to scan your computer. The scan performed by this rogue is obviously fake, but eventually it says that you are infected with Trojan.Horse.Win32.PAV.64.a. Take note, that the previous versions of this rogue have “detected” exactly the same parasite residing in the infected computer. Here is another proof, but Windows Proofness Guarantor is nothing but a useless piece of software, which should not be taken for granted.

If you install Windows Proofness Guarantor onto your computer, this rogue will reconfigure certain aspects of your system, so that it would load every single time you turn on your computer. And once your Windows will load, you will see Windows Proofness Guarantor’s screen popping into action and performing a fake system scan. It “finds” a lot of problems within your system, and keeps on sending you various fake security notifications such as:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
Warning!
Location: c:\windows\system32\taskmgr.exe
Viruses: Backdoor.Win32.Rbot

Keep in mind that everything is done in order to make you pay for the full version of Windows Proofness Guarantor. If you do so, your credit card information will be in the hands of cyber criminals and you will need to notify your bank immediately to limit access to your account because of the digital fraud. Remove Windows Proofness Guarantor if you want to keep your money and your computer safe. Invest in a reliable security tool which will help you to get rid of this rogue automatically and will protect your system against future attacks.

Download Spyware Removal Tool to Remove* Windows Proofness Guarantor
  • Quick & tested solution for Windows Proofness Guarantor removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows Proofness Guarantor

Files associated with Windows Proofness Guarantor infection:

wnnswr.exe
%AppData%\Microsoft\[random].exe

Windows Proofness Guarantor processes to kill:

%AppData%\Microsoft\[random].exe
wnnswr.exe

Remove Windows Proofness Guarantor registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.