Home Malware Programs Rogue Anti-Spyware Programs Antimalware Tool

Antimalware Tool

Posted: April 1, 2011

Antimalware Tool is a rogue security program that fakes various features like malware detection and removal, software monitoring and malware information provisioning. Like many other rogue security applications before it, Antimalware Tool is unable to provide any of the features Antimalware Tool supposedly has, and may cause security problems if allowed to remain on your PC. Removing Antimalware Tool by using proven anti-malware software is strongly recommended, since Antimalware Tool will create confusing fake system alerts and may attempt to direct you to malicious websites.

Remove the 'Anti' From Antimalware Tool for an Accurate Software Name

Antimalware Tool's whole purpose is to scam PC users out of money by faking dangerous system conditions and then walking the user through a registration process. Accordingly, Antimalware Tool's design is an effort in minimal effort for maximum return, with much of the interface and functions borrowed from other rogue security programs like Best Malware Protection, Internet Security Essentials and Security Defender.

The most widely-reported infection technique for Antimalware Tool is through Trojans masquerading as fake video player updates such as codecs. After installing this Trojan by mistake, you may see an error message that prompts you to install fake security software like Antimalware Tool, or the Trojan may simply install Antimalware Tool without notifying you.

Antimalware Tool will start whenever Windows starts by placing new entries into your Registry, and may prompt you to scan your computer. Scanning results by Antimalware Tool will always show numerous infections that can supposedly be removed if you register the rogue security program. Since Antimalware Tool has no real anti-malware functions, the only thing registering Antimalware Tool will do is place fraudulent charges on your credit card!

An Error a Minute – More Reasons to Remove Antimalware Tool

In addition to not having any of Antimalware Tool's advertised capabilities, Antimalware Tool will use different error messages to instill fear in the PC user:

Antimalware Tool
Viruses have been found in your system. We highly recommend you to get license for Antimalware Tool to remove immediately harmful software.

Antimalware Tool Firewall Alert
Suspicious activity in your registry system space was detected. Malware detected in your system. Data leaks and system damage are possible. Please use a deep scan option.

Antimalware Tool
Your computer is being attacked from a remote machine!
Block Internet access to your computer to prevent system infection.
Attacker IP: [ip address]
Attack type: RCPT exploit

Harmful software detected
Antimalware Tool has detected malicious software that may cause crash of your computer. Click Remove All button to remove them now.

Messages like these and other alerts by Antimalware Tool can safely be ignored as fake. Clicking on them may be dangerous, since Antimalware Tool may try to redirect you to a malicious website that will steal information or download other malware onto your PC.

Rogue security programs like Antimalware Tool are also known for blocking security applications, altering firewall and other system settings, hijacking web browsers and creating pop-ups. With such potential security disasters waiting in the wings, you shouldn't wait around on removing Antimalware Tool with a good anti-malware program. Removing Antimalware Tool is possible but may run the risk of causing other problems like disabled Internet connectivity.

If Antimalware Tool tries to prevent your anti-malware program from running, reboot into Safe Mode. This will prevent most rogue security programs like Antimalware Tool from running at all and let you continue your scans until you've deleted Antimalware Tool.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%UserProfile%\Application Data\.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
Loading...