1 of 3
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • System crashes
  • Annoying Pop-up's
  • Slow Computer

Windows Safety Master

Windows Safety Master will make you think twice before clicking on an advert or a link found in an email, visiting a suspicious website, etc, because this cunning program uses different ways of social engineering to steal into the system unnoticed and manipulate the users into buying a fake “licensed” version. That non-functional full version is completely worthless, because the very trial version is a scam; as a result, you should remove Windows Safety Master from the computer instead of thinking whether to activate it or not.

There is no need to trust this bogus application, because every single operation and a piece of information presented are simulated. For example, such Trojans or worms as presented by the program do not exist in the system, and there is no need to try to remove them. The same applies to bogus pop-up notifications claiming that it is highly advisable to activate Windows Safety Master to get rid of those simulated threats.

To kill the infection and have the system’s settings reverted to normal, find and install a reliable spyware removal application which will be able to remove Windows Safety Master and other potential infections. This method is by far the most suitable for every computer user, because it is enough to install a legitimate application and launch a scan. Therefore, if you want to delete the infection immediately without any damage caused to the system, remove Windows Safety Master automatically.

To remove Windows Safety Master from your system follow removal guide listed bellow or register the program with one of the keys given below and implement a antispyware removal tool. However if registration keys are not useful, just follow the our removal guide.

Registrations keys:

0W000-000B0-00T00-E0001

0W000-000B0-00T00-E0002

0W000-000B0-00T00-E0003

How to remove Windows Ultimate Booster

  1. Reboot the computer and get ready to continuously tap the F8 button once the BIOS screen loads.
  2. Using the up/down arrow keys, select Safe Mode with Command Prompt and hit Enter.
  3. Next to C:\Windows\system32\, type in cd.. and press Enter.
  4. When the line C:\Windows appears, type in C:\Windows\explorer.exe and press Enter.
  5. Open the Start menu.
  6. Type %appdata% into the search box. In the case of Windows XP, first launch the Run command.
  7. Press Enter.
  8. Delete guard-{4 random symbols}.exe when the directory loads.
  9. Reboot the computer.
  10. Open the Start menu.
  11. Enter regedit into the search box. If you use Windows XP, launch Run and then type in regedit.
  12. Go to HKEY_CURRECT_USER\Software\Microsoft\Windows NT\Current Version\Winlogon.
  13. On the right hand side, right-click on Shell and select Modify.
  14. To change the value, type in %WinDir%\Explorer.exe and click OK.
  15. Close Registry Editor.
  16. Go to http://www.pcthreat.com/download-sph to download SpyHunter.
  17. Install the application and remove Windows Ultimate Booster.
Download Spyware Removal Tool to Remove* Windows Safety Master
  • Quick & tested solution for Windows Safety Master removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows Safety Master

Files associated with infection (Windows Safety Master):

%AppData%\data.sec
%AppData%\svc-[random file name].exe

Processes to kill (Windows Safety Master):

svc-[random file name].exe

Remove registry entries (Windows Safety Master):

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%AppData%\svc-[random file name].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "GuardSoftware" = %AppData%\svc-[random file name].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\k9filter.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableVirtualization" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bckd "ImagePath" = "123123.sys"
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.