Net Studio

How to remove Windows Scan in 5mn

How to remove Windows Scan in 5mn

Post 22 January 2011
Rate this item
(0 votes)

Windows Scan is another spyware from the HDD repair, HDD Tools, HDD Low... family. Windows Scan is not a legit program; It is a fake, a counterfeit. Windows Scan claims to fix your system, but not, do not trust in it. Do not believe in the scan results of this pretentious, It is a scam, and the only flaw in your system is this Windows Scan. Windows Scan is just another fake Antispyware whose purpose is to trick you to pay this useless program. Uninstall Windows Scan immediately from your system.

This Removal Tool for Windows Scan is not an Antivirus, It is a program designed to remove Windows Scan and Windows Scan only but may also remove some other malwares.

The differences between an Antivirus and a Removal Tool are :

  1. A Removal Tool is a Stand Alone Application so it does not need to be installed. You can remove the application once your system is clean.
  2. An Antivirus removes infected files and registry keys but a Removal Tool removes infected files, Windows malware's registry keys and restores any parameters altered by malicious softwares.
  3. Antivirus takes time to scan your computer but it only takes at the very most 20s for a Removal Tool to remove malware's files and registry keys and to restore your computer default parameters. That is because a Removal Tool is designed for one specific malicious program and it does not need to scan your computer. It knows exactly which files to remove and where they are located, which registry keys to restore or to remove.
  4. All Removal Tools from http://www.net-studio.org are free and free from virus but be aware, most of the time, security programs are most of the time treated by other security programs as malicious softwares, for instance Norton Antivirus is treated by Avast as a malicious software and some of our Removal Tools are treated by some Antivirus programs as Probably Unknown Virus. That is because a Removal Tool removes malicious registry keys and removes malware's files.
    You can trust in us and our programs, our goal is to fight against those people who want to harm your system or to scam you and we will NEVER NEVER NEVER be one of them.

To remove Windows Scan Software (Uninstall Windows Scan Software) :

  • Restart your computer and as soon as your computer turns on hit the F8 key (repeatedly) until a screen comes up
  • Choose Start computer in SAFE MODE with network support
  • Open Internet Explorer
  • Go to Tools => Internet Options => Connections Tab => LAN Settings
  • Uncheck "Use a proxy server"
  • Recheck "Automatically detect settings"
  • Download this free removal tool for Windows Scan Software
  • Extract it
  • Launch
  • Click on the delete button

Windows Scan Software will be removed from your system in 10s. Restart your computer when It is finished.

Processes :

  • [random].exe

Files :

  • %CommonAppData%\[Random].dll
  • %CommonAppData%\[Random].exe
  • %Temp%\tmp1.tmp
  • %CommonAppData%\[Random]
  • %CommonAppData%\[Random].exe
  • %CommonAppData%\~[Random]
  • %CommonAppData%\~[Random]
  • %DesktopDir%\Windows Scan.lnk
  • %Temp%\[Random].tmp
  • %Temp%\[Random].tmp
  • %Programs%\Windows Scan\Uninstall Windows Scan.lnk
  • %Programs%\Windows Scan\Windows Scan.lnk

Registry

Created registry keys :

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\PersistentHandler
  • HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\CCSelect\.Current
  • HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\.current
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments

Created registry values :

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\PersistentHandler
    • (Default) = "{5e941d80-bf96-11cd-b579-08002b30bfeb}"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\DefaultIcon
    • (Default) = "%System%\url.dll,0"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\shell
    • (Default) = "open"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile
    • EditFlags = 0x00010000
    • BrowserFlags = 0x00000008
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\DefaultIcon
    • (Default) = "%ProgramFiles%\Internet Explorer\iexplore.exe,1"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HTTP\shell
    • (Default) = "open"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https
    • BrowserFlags = 0x00000008
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\https\shell
    • (Default) = "open"
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    • ProxyEnable = 0x00000000
  • HKEY_CURRENT_USER\Software
    • 12B79064-EB17-4f82-9DFE-B975BD26D1DC = ""
  • HKEY_CURRENT_USER\Software\Microsoft
    • BootData = 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00 5C 00 41 00 6C 00 6C 00 20 00 55 00 73 00 65 00 72 00 73 00 5C 00 41 00 70 00 70 00 6C 00 69 00 63 0
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
    • TabProcGrowth = 0x00000001
    • Use FormSuggest = "Yes"
    • Check_Associations = "no"
    • Play_Background_Sounds = "no"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    • WarnOnZoneCrossing = 0x00000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
    • LowRiskFileTypes = "/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
    • SaveZoneInformation = 0x00000001
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • [Random].exe = "%CommonAppData%\[Random].exe"
    • [Random] = "C:\DOCUME~1\ALLUSE~1\APPLIC~1\[Random].exe"

Registry values deleted :

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\DefaultIcon
    • (Default) = "%System%\msieftp.dll,0"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\DefaultIcon
    • (Default) = "%ProgramFiles%\Internet Explorer\iexplore.exe,1"
  • HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating\.Current
    • (Default) = "%SystemRoot%\media\Windows XP Start.wav"

Registry values modified :

  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\CLSID
    • (Default) =
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\shell\print\command
    • (Default) =
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut\shell\printto\command
    • (Default) =
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    • Cookies =
    • Cache =
    • History =
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
    • CheckExeSignatures =
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
    • 1601 =

 


Leave a comment

Make sure you enter the (*) required information where indicated.
Basic HTML code is allowed.

You are here: How to remove Windows Scan in 5mn