Safety Center Virus

Safety Center is a fake multi-security program for Windows that is part of the operation of Windows Security Suite. To deceive computer users, the interface is adapting the looks of Windows own safety center to make it look like a part of operating system. It will have tools like Spyware Scanner, Surfing Protection, Cookies Remover, Registry Doctor, Firewall, Memory Manager and so on. Safety Center was being spreads and dropped on computers with the help of Trojan. This malware also modifies the registry to simultaneously load self in Windows start-up.

Once the virus got a hold on the system, warning messages will greet computer users after logon. An alert will contain the following message:

We are sorry but your query looks similar to requests from a computer infected by viruses or spyware applications. To protect our users, we can’t proceed with your request at the moment. We will restore your access as quickly as possible, so try again later. Meanwhile, if you suspect that your computer or network has been infected, you might want to run a virus checker or spyware remover to make sure that your system is free of viruses and other malicious software.

Rogue program such as Safety Center is less harmful than other on the same kind. Removing this threat from a computer is achievable with the help of a removal tool or authentic anti-malware application. There is no guarantee that manually removing Safety Center virus can get rid of hidden files and registry entries. So stick with automatic method.

Screen Shot Image:

Safety Center Virus

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Safety Center Removal Procedures

Safety Center REMOVAL TOOL:
In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected computer.

MANUAL REMOVAL PROCEDURE:
1. Press Ctrl+Alt+Del on keyboard to stop process associated to “Safety Center”. When Windows Task Manager opens, go to Processes Tab and find and end the following process:
(random characters).exe

2. You need to update installed antivirus application to have the latest database.

3. Thoroughly scan the system and any detected threats must be removed. If removal is prohibited, it is best to quarantine the infected item. Manually locating and deleting of malicious files should also be performed. Please see files below that are related to Safety Center Virus.

4. Registry entries created by Safety Center must also be removed from the Windows system. Please refer below for entries associated to the rogue program.
- For Windows 2000/XP: Go to Start > Run, type “regedit” on dialog box then press Enter on keyboard.
- For Windows Vista/7: Go to Start > Search Program and Files, type “regedit” and press Enter.

5. Exit registry editor.

6. Get rid of Safety Center start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
(random characters).exe

7. Click Apply and restart Windows.

Technical Details and Additional Information:

Malicious Files Added by Safety Center
c:\Documents and Settings\All Users\Application Data\[random characters].dat
c:\Documents and Settings\All Users\Application Data\[random characters].ico
c:\Documents and Settings\Bleeping\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Center.lnk
c:\Documents and Settings\Bleeping\Desktop\Security Center.lnk

Safety Center Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random characters]“