Home Malware Programs Rogue Anti-Spyware Programs Fake Windows Malicious Software Removal Tool

Fake Windows Malicious Software Removal Tool

Posted: July 13, 2009

Fake Windows Malicious Software Removal Tool is an illicit security application that should not be confused with the legitimate program from Microsoft, the Windows Malicious Software Removal Tool. Hackers seldom develop illicit applications that have a name similar to that of a legitimate security application. In the case of the Fake Windows Malicious Software Removal Tool program, it is exploited by a Trojan which is part of a scam to get computer users to purchase fake anti-malware applications.

Instead of being able to detect and remove infections, Fake Windows Malicious Software Removal Tool creates a malicious file called MalwareRemoval.exe which resides in the C:\Program Files\ directory. Once infected, your system will load MalwareRemoval.exe which will then launch a screen that mimics the legitimate Microsoft Malicious Software Removal Tool. You may witness system scans on your screen that displays bogus results. In addition to the bogus results, Fake Windows Malicious Software Removal Tool may redirect you to a purchase screen to buy other security software.

Removal of the Fake Windows Malicious Software Removal Tool application is necessary to eliminate the risk of damage to your system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\MalwareRemoval
    2 %UserProfile%\Application Data\MalwareRemoval\MalwareRemoval.ini
    3 %UserProfile%\Application Data\SetupMalwareRemoval
    4 %UserProfile%\Application Data\SetupMalwareRemoval\spl.ini
    5 C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemoval
    6 C:\Program Files\MalwareRemoval
    7 C:\Program Files\MalwareRemoval\MalwareRemoval.exe
    8 C:\Program Files\MalwareRemoval\Security Center.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsMaliciou SoftwareRemovalTool"
Loading...