Home Malware Programs Rogue Anti-Spyware Programs Windows AntiHazard Helper

Windows AntiHazard Helper

Posted: March 23, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 41
First Seen: March 23, 2012
OS(es) Affected: Windows

Windows AntiHazard Helper Screenshot 1Cosmetically, Windows Antihazard Helper may appear to be an anti-virus program with an unusually broad range of security features, but, as a scamware member of the Win32/FakeVimes family, Windows Antihazard Helper's real functions focus on providing inaccurate information, attacking your web browser and blocking legitimate security products. Windows Antihazard Helper is functionally identical to other members of its family, and in its goal to gain access to your money and fiscal information, will try to fool you into thinking that dozens of PC threats are attacking your computer. Since Windows Antihazard Helper doesn't have any ability to do anything about any kind of malicious software, SpywareRemove.com malware research team suggests that you put a stop to Windows Antihazard Helper's fake alerts by deleting Windows Antihazard Helper with a real anti-malware program. It's also recommended that you take additional steps to disable all active PC threats before you scan your PC as a way to insure that all components of a Windows Antihazard Helper infection are completely identified and removed.

Windows Antihazard Helper – Offering the Kind of Help That No Computer Needs

Windows Antihazard Helper pretends to be an ideal security program with a breadth of features that popular brands couldn't possibly compete against, but this vision of perfect security is spoiled by the fact that all of Windows Antihazard Helper's features are fraudulent. Although Windows Antihazard Helper will launch whenever Windows starts and proceed to display both automated system scans and a variety of pop-ups, SpywareRemove.com malware experts have found that diagnostic information from Windows Antihazard Helper is utterly inaccurate. You may see fake warnings from Windows Antihazard Helper, as well as from the rest of the FakeVimes family of rogue anti-virus products.

These attacks are caused with the singular purpose of making you spend money on Windows Antihazard Helper in a blind panic, but this is both unnecessary for deleting Windows Antihazard Helper and a waste of your finances. Additionally, any financial information that's given to Windows Antihazard Helper's criminal partners should be considered compromised until appropriate security countermeasures are taken.

Because Windows Antihazard Helper will launch with Windows and try to avoid being disabled, SpywareRemove.com malware researchers note that possibly you will need to make use of Safe Mode or a different alternative in system boot methodology before you can remove Windows Antihazard Helper. Deleting Windows Antihazard Helper while Windows Antihazard Helper is active or using manual methods to track down and delete Windows Antihazard Helper is generally considered inadvisable, since some of its components may remain undetected in either of these cases.

The Worst of Windows Antihazard Helper's Bag of Tricks

Windows Antihazard Helper can be thought of as an identical clone of recent members of Win32/FakeVimes. These members also include Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security. All of these examples of fake anti-virus programs are able to conduct additional attacks that SpywareRemove.com malware researchers have found to be negative influences on the infected computer's security. Such attacks by Windows Antihazard Helper and its kin can consist of:

  • Disabled UAC (User Account Control) features.
  • Having your Hosts file altered to hijack and redirect your web browser. Redirect attacks may block PC security sites or redirect you from search engines to hostile sites.
  • Having popular brands of anti-malware and security software blocked (until you disable Windows Antihazard Helper).


Windows AntiHazard Helper Screenshot 2Windows AntiHazard Helper Screenshot 3Windows AntiHazard Helper Screenshot 4Windows AntiHazard Helper Screenshot 5Windows AntiHazard Helper Screenshot 6Windows AntiHazard Helper Screenshot 7Windows AntiHazard Helper Screenshot 8Windows AntiHazard Helper Screenshot 9Windows AntiHazard Helper Screenshot 10Windows AntiHazard Helper Screenshot 11Windows AntiHazard Helper Screenshot 12Windows AntiHazard Helper Screenshot 13Windows AntiHazard Helper Screenshot 14Windows AntiHazard Helper Screenshot 15

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Protector-vdsl.exe File name: Protector-vdsl.exe
Size: 2.02 MB (2023424 bytes)
MD5: 6036599c9e687d43fba302a4a936e5b5
Detection count: 79
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 23, 2012
%appdata%\npswf32.dll File name: %appdata%\npswf32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%appdata%\Inspector-[rnd].exe File name: %appdata%\Inspector-[rnd].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%commonprograms%\Windows AntiHazard Helper.lnk File name: %commonprograms%\Windows AntiHazard Helper.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%desktopdir%\Windows AntiHazard Helper.lnk File name: %desktopdir%\Windows AntiHazard Helper.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run!Inspector
Loading...