1 of 5
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Shows commercial adverts
  • Normal system programs crash immediatelly
  • Slow internet connection
  • Annoying Pop-up's
  • Slow Computer

Windows Vulnerabilities Rescuer

Windows Vulnerabilities Rescuer is a fake antivirus program which belongs to the Fake Microsoft Security Essentials family. If you a prone to being attacked by various types of infections, then you must have encountered the previous versions of this rogue that include Windows Risks Prevention, Windows Proofness Guarantor, Windows Inviolability System and others. Due to the extensive number of clones Windows Vulnerabilities Rescuer does not differ from its predecessors in any significant way.

Just like all of the rogues before it, Windows Vulnerabilities Rescuer gets into your system with the help of a Trojan virus which also belongs to the Fake Microsoft Security Essentials scam. Due to the name this infection uses, it might seem like a legitimate thing at first so a lot of users get tricked into using Windows Vulnerabilities Rescuer, thinking it is a real antivirus program. However, that is a bad choice, because this rogue is a computer threat itself, and performing its instructions eventually leads to disaster.

Windows Vulnerabilities Rescuer starts interfering with the usual work you are performing your computer with this kind of message:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click ‘show details’ to learn more.

This message is generated by the Trojan which infects your computer before the rogue is fully downloaded and installed. Since this message is rather alarming, a lot of users click on “Show Details”, and then click through other instructions. This results in them having Windows Vulnerabilities Rescuer in their computers. It is impossible not to notice this rogue work. Windows Vulnerabilities Rescuer launches a fake system scan and makes it look like your computer is suffering from numerous infections.

What is more, Windows Vulnerabilities Rescuer can also block you from opening certain programs, making it look like various errors are present in these programs and they must be blocked in order to prevent the spread of the infection. Unfortunately, none of this information is true. Windows Vulnerabilities Rescuer only does it, because it wants to scare you into paying for the full version of the program.

Paying for this rogue is completely out of question; because it would also reveal your credit card information to a third party and then you will be robbed to the very last cent. Remove Windows Vulnerabilites Rescuer from your computer using a reliable antispyware product and secure your system against future attacks, because new rogues are spawned every single day.

Download Spyware Removal Tool to Remove* Windows Vulnerabilities Rescuer
  • Quick & tested solution for Windows Vulnerabilities Rescuer removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows Vulnerabilities Rescuer

Files associated with Windows Vulnerabilities Rescuer infection:

%AppData%\Microsoft\[random].exe

Windows Vulnerabilities Rescuer processes to kill:

%AppData%\Microsoft\[random].exe

Remove Windows Vulnerabilities Rescuer registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
Disclaimer

Comments

  1. James Jul 2, 2011

    I am very happy to get this antivirus because it has removed virus in my

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.