Remove Windows Crucial Scanner. Removal instructions
Windows Crucial Scanner is a rogue security product that reports false malware infections and displays fake security alerts to make you think your computer is infected with all sorts of malicious software, spyware and viruses. Once installed, the rogue anti-spyware program will display non-existing infections or security threats and prompt you to pay for a full version of the program to remove those infections. Do not purchase Windows Crucial Scanner because it’s nothing more but a scam. It just want to steal money from you. Remove Windows Crucial Scanner from your computer as soon as possible. Otherwise it may download more malware onto your computer and make the whole situation worse.
Windows Crucial Scanner is promoted mostly through the use of fake online virus scanners, trojan downloaders and hacked websites. It can be also distributed using other malicious software and exploit packs. Fake online virus scanner usually display many infections on your computer and recommend you to use Windows Crucial Scanner to remove found infections and to make sure that your computer is protected against the latest malware threats. Do not install this rogue anti-spyware program and leave a misleading website immediately. Some of the fake security alerts may read:
Torrent Alert
Recomended: Please use secure encrypted protocol for torrent links.
Torrent link detected!
Receiving this notification means that you have violated the copyright laws. Using Torrent for downloading movies and licensed software shall be prosecuted and you may be sued for cybercrime and breach of law under the SOPA legislation.
Please register your copy of the AV to activate anonymous data transfer protocol through the torrent link.
Warning! Identity theft attempt Detected
Hidden connection IP: xxxxxxxxx
Target: Your passwords for sites
When running, Windows Crucial Scanner will display false scan results and flood your computer with fake system security alerts claiming that your PC is not protected and that your anti-virus software is disabled or out of date. However, the rogue program will block legit antivirus programs at the same time. So, you may not be able to run them. The parasite will impersonate Windows Security Center and display fake notifications from Windows task bar. The rogue program will likely slow down your computer and block task manager, registry editor and other tools. If you find that your PC is infected with this fake anti-spyware program, please use the removal guide below to remove Windows PC Defender from the system upon detection. If you can’t download or run recommended malware removal software, reboot your computer in safe mode with networking and try again.
Automatic Windows Crucial Scanner removal:
(2012-04-14 09:18:51)
(2012-04-14 09:18:51)
(2012-04-14 09:18:51)
Windows Crucial Scanner manual removal:
Kill processes:
Inspector-[rnd].exe Protector-[rnd].exe
how to kill malicious processes
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
how to remove registry entries
Delete files:
%AppData%\Inspector-[rnd].exe %AppData%\Protector-[rnd].exe
how to remove harmful files
Information updated: 2012-04-14 09:18:51