Windows Vulnerabilities Rescuer

Windows Vulnerabilities Rescuer is a counterfeit hard drive utility application that was found to be using a Trojan to spread itself. This rogue application can be downloaded and installed without users intervention. Usually, Windows Vulnerabilities Rescuer virus will be introduced as a legitimate application that claims to have found virus on the system. Later, it will prompt to clean it by having the registered version of the program. If user attempts to do so, Internet browser will be pointed to a payment processing web site that will record credit card details of its victims. Once the process have finished, there is no way for buyers to ask for a refund once discovered that Windows Vulnerabilities Rescuer is useless.

One particular symptoms on the presence of Windows Vulnerabilities Rescuer virus is the frequent pop-up of alerts and warning messages that are considered as fake. An automated local virus scan is also considered as proof of the infection. The scan will be launched without users execution and is very noticeable that it will commence right after Windows has started. After scan, dozens of virus will be displayed that was known to be fabricated and falsified. It is important to carry out a remove once a sign is spotted. Use only legitimate anti-virus and anti-malware program to automatically remove Windows Vulnerabilities Rescuer.

Screen Shot Image:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Windows Vulnerabilities Rescuer Removal Procedures

Manual Removal:
1. Press Ctrl+Alt+Del on keyboard to stop process associated to “Windows Vulnerabilities Rescuer”. When Windows Task Manager opens, go to Processes Tab and find and end the following process:
(random characters).exe

2. You need to update your installed antivirus application to have the latest database.
3. Thoroughly scan the system and any detected threats must be removed. If removal is prohibited, it is best to quarantine the infected item. Manually locating and deleting of malicious files should also be performed. Please see files below that are related to Windows Vulnerabilities Rescuer Virus.
4. Registry entries created by Windows Vulnerabilities Rescuer must also be remove from the Windows system. Please refer below for entries associated to the rogue program. [how to edit registry]
5. Exit registry editor.
6. Get rid of Windows Vulnerabilities Rescuer start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
(random characters).exe

7. Click Apply and restart Windows.

Windows Vulnerabilities Rescuer Removal Tool:
In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

Using Portable SuperAntiSpyware:
To thoroughly remove the virus, it is best to do a separate scan of another security program so that other infected files not detected by anti-virus application can be get rid as well. Click here to download and run SAS Portable Scanner.

Scan with Norton Power Eraser:
A free removal tool from Norton Antivirus was developed to remove unfamiliar threats without using the traditional AV signatures. Download the tool from this location and start scanning the computer for viruses.

Technical Details and Additional Information:

Malicious Files Added by Windows Vulnerabilities Rescuer:

%UserProfile%\Start Menu\Programs\Windows Vulnerabilities Rescuer\Windows Vulnerabilities Rescuer.lnk
%UserProfile%\Start Menu\Programs\Windows Vulnerabilities Rescuer\Uninstall Windows Vulnerabilities Rescuer.lnk
%AllUsersProfile%\[random].dll
%AllUsersProfile%\[random].exe
%AllUsersProfile%\[random].exe

Windows Vulnerabilities Rescuer Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random].exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“

What to do next...