Monday, July 2, 2012

Windows Interactive Security virus deletion lesson

Are you searching for a solution to effectively get rid of Windows Interactive Security rogue , Learn How To deal with it Easily and quickly. You should just follow "Virus Removal Guide with both manual and automatic options".

Windows Interactive Security downloads and installs itself automatically without user’s knowledge and consent. The parasite comes to your system with the help of trojan. Once active rogue program starts to imitate computer scans and shows numerous fake warning messages:

Error
Attempt to modify registry key entries detected. Registry entry analysis is recommended.

Error
Attempt to run a potentially dangerous script detected.
Full system scan is highly recommended.

Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.

Do not fall for this scam because malware is not capable of rendering any security service. Windows Interactive Security is designed to pilfer money from unwary users. Use decent anti-spyware application such as GridinSoft Trojan KIller and wipe Windows Interactive Security off immediately.

3. Files

In the process of the installation, Windows Interactive Security copies the following files to the hard disk.

  • %AppData%\NPSWF32.dll
  • %AppData%\Protector-[rnd].exe
  • %AppData%\result.db

4. System registry

Windows Interactive Security creates the following registry entries:

  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector %AppData%\Protector-[rnd].exe
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\UID [rnd]
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Settings\net [date of installation]
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin

No comments:

Post a Comment