Home Malware Programs Trojans Attn! Low performance!

Attn! Low performance!

Posted: September 26, 2008

"Attn! Low performance!" popup is a false and misleading message making computer users believe that they must purchase a fake security tool to fix an issue. If the "Attn! Low performance!" popup message is clicked on it may redirect you to a website that promotes a fake anti-spyware program.

The "Attn! Low performance!" popup may read similar to the statement below.

"Attn! Low performance!
Cpu performance has degranded significantly. Probable cause: malware infection. Click here to perform system security audit."

Many times fake popup messages such as the “Attn! Low performance!” popup have misspellings that identify them as being preposterous.

Fake anti-spyware programs are not viable for removal of spyware or repair of your computer issues. "Attn! Low performance!" popup messages is part of a scam and may be the result of the Zlob Trojan infection being present on your computer. Trojans have proven to be difficult to manually detect and remove. It is advisable to utilize a reputable spyware scan tool to detect the infection causing the "Attn! Low performance!" popup message.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CurrentFolder%\smmain.exe
    2 %CurrentFolder%\smmon.exe
    3 %CurrentFolder%\smunst.exe
    4 %CurrentFolder%\splug.dll
    5 %CurrentFolder%\spunst.exe
    6 %ProgramFiles%\Video ActiveX Access\iesmin.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{F0993251-2512-4710-AF6E-0A13EA199D02}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0993251-2512-4710-AF6E-0A13EA199D02}HKEY_CURRENT_USER\Software\Protection Tools\"65005" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F0993251-2512-4710-AF6E-0A13EA199D02}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\"rare" = "%CurrentFolder%\smmain.exe"