Beware of Windows Protection Master malware. This is a rogue security software. Instead of buying it please remove it without hesitation. Trojans, spyware, malicious links, corrupted downloads bundled with viruses and even social networks like Facebook can be the source of malware attacks that cause this rogue software to implant itself into your computer. From the screenshot of this fake anti-virus it becomes obvious that it tries to imitate legitimate Windows Security Center. Nevertheless, please differentiate between the true Security Center of Windows operating system (whatever version you have) and this hoax that has the similar interface. If you see Windows Protection Master program ignore all that it tells you and prepare for the battle to destroy this malware without hesitation.
Once Windows Protection Master enters the computer it modifies system settings to make itself launch automatically together with Windows. Each time you turn your machine on the window of the rogue comes up and it starts its fake system scan. It does not take too long for such scan to be ended, about 10 seconds or even less. It is ridiculous when the developers of this malware want users to consider it as certain great security tool. There is no any reliable anti-virus program that can run and complete full scan within just 10 seconds. Obviously, there is something really unusual and wrong with this Windows Protection Master program. It is a fake anti-spyware tool, so please avoid it. This means that you must not consider anything it tells you as serious. Below please find the examples of popups with outrageous lie that you might see to be reported by this scareware tool.
Error
Serious slowdown in system performance.
To eliminate the causes, full check is recommended.
Error
Trojan activity detected. System data security is at risk.
It is recommended to activate protection and fun full system scan.
Error
There’s a suspicious software running on your PC.
For more details, run a system file check.
Error
Potential malware detected.
It is recommended to activate the protection and perform a thorough system scan to remove the malware.
Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Error
System data security is at risk!
To prevent potential PC errors, run a full system scan.
Error
Attempt to run a potentially dangerous script detected.
Full system scan is highly recommended.
And here are some other examples of scary warnings the rogue reports to you to make you think your system is in danger:
Warning! Virus detected. Threat detected: Trojan.MSIL.Agent
Warning! Virus detected. Threat detected: Client-P2P
Warning! Virus detected. Threat detected: Trojan-ArcBomb
Warning! Identity theft attempt detected
Torrent Alert
Recommended: Please use secure encrypted protocol for torrent links.
Torrent link detected!
Receiving this notification means that you have violated the copyright laws. Using Torrent for downloading movies and licensed software shall be prosecuted and you may be sued for cybercrime and breach of law under the SOPA legislation.
Warning! Spambot detected!
Attention! A spambot sending viruses from your e-mail has been detected on your PC.
Warning
Firewall has blocked a program from accessing the Internet
File xx is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remove server.
The information that users receive from Windows Protection Master virus does not correspond with the truth. Do not panic and do not purchase the rogue, because this is what the program would instruct you to do. Get rid of this scareware using reliable anti-virus programs reviewed in this blog. As we said, avoid the purchase page of this virus and do not make the mistake some people made when they bought this malware.
There are many infected files and registry entries that have to do with Windows Protection Master malware. So, manual removal of it is not an easy undertaking. It is far much better to accomplish the removal job using the powerful anti-virus program.
Malware modifications brought into the system:
List of Windows Protection Master virus files:
- %AppData%\Inspector-
.exe - %AppData%\NPSWF32.dll
- %AppData%\result.db
- %UserProfile%\Desktop\Windows Protection Master.lnk
- %StartMenu%\Programs\Windows Protection Master.lnk
List of Windows Protection Master virus entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe “Debugger”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe “Debugger”
File Location Remarks and Explanations:
%Desktop% implies that the file is located straight on your PC’s desktop. The full and detailed location is C:\DOCUMENTS AND SETTINGS\\Desktop\ for Windows 2000/XP, and C:\Users\ \Desktop\ for Windows Vista and Windows 7.
%Temp% stands for the Windows Temp folder. By default, it has the location C:\Windows\Temp for Windows 95/98/ME, C:\DOCUMENTS AND SETTINGS\\LOCAL SETTINGS\Temp for Windows 2000/XP, and C:\Users\ \AppData\Local\Temp for Windows Vista and Windows 7.
%AppData% means the current users Application Data folder. By default, it has the location C:\Documents and Settings\\Application Data for Windows 2000/XP. For Windows Vista and Windows 7 it is C:\Users\ \AppData\Roaming.
%StartMenu% stands for the Windows Start Menu. For Windows 95/98/ME the location is C:\windows\start menu\, for Windows XP, Vista, NT, 2000 and 2003 it stands for C:\Documents and Settings\\Start Menu\, and for Windows Vista/7 it is C:\Users\ \AppData\Roaming\Microsoft\Windows\Start Menu.
%CommonAppData% means the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it has the location C:\Documents and Settings\All Users\Application Data\, and for Windows Vista/7 it is C:\ProgramData.

