Home Malware Programs Rogue Anti-Spyware Programs Windows Antispy Network

Windows Antispy Network

Posted: June 24, 2011

Windows Antispy Network is rogue security software that pretends to scan your computer, grade your PC on its security and detect infections and other problems. This broad range of security features is a sham with no real functionality, however, other than letting Windows Antispy Network create false positives and disable programs. Windows Antispy Network may also hijack your web browser or change the visible files in your Startup folder. You can delete Windows Antispy Network by using any real security program to scan your PC, which is strongly recommended over purchasing Windows Antispy Network and thus making yourself the victim of credit card fraud.

The Fake Warnings That Windows Antispy Network Might Send Your Way

Windows Antispy Network uses similar tactics to other rogue threats by faking anti-virus and security features with the use of inaccurate error messages, alerts, scanner results and system security grades. Any scan that uses Windows Antispy Network will always show many infections on your PC, just like Windows Antispy Network's grading system for different areas of security will always rank your computer with poor numbers.

Windows Antispy Network uses this fake information to convince you that buying Windows Antispy Network is the only thing you can do to help your PC, but any problems with your computer actually are caused by Windows Antispy Network or related threats. Some of the common error messages that Windows Antispy Network recruits into this scheme are:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

Warning! Database update failed!
Database update failed!
Outdated viruses databases are not effective and can't [sic] guarantee adequate protection and security for your PC!
Click here to get the full version of the product and update the database!

System component corrupted!
System reboot error has occurred due to lsass.exe system process failure.
This may be caused by severe malware infections.
Automatic restore of lsass.exe backup copy completed.
The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

Warning! Running trial version!
The security of your computer has been compromised!
Now running trial version of the software!
Click here to purchase the full version of the software and get full protection for your PC!

Warning!
Location: [application file path]
Viruses: Backdoor.Win32.Rbot

Warning!
Name: [application file name]
Name: [application file path]
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

These alarming messages can be disregarded since Windows Antispy Network can't detect or even delete threats that are on your PC. Once you remove Windows Antispy Network any 'infected' programs will resume normal functionality despite Windows Antispy Network's warnings.

The More Convincing Attacks in the Windows Antispy Network Facade

Besides the errors seen above, Windows Antispy Network will also create various problems that make it difficult for you to access the security and diagnostic features that are on other software. You may find Windows Antispy Network causing some or all of the following:

  • Blocking programs from running at all. Windows Antispy Network will often use fake infection warnings such as the ones seen earlier to make it seem like Windows Antispy Network is protecting you, but the real purpose of this barricade is to stop you from accessing critical security functions. Windows Task Manager and anti-virus scanners are well-known targets of this Windows Antispy Network attack.
  • Windows Antispy Network may let your web browser run, but that's not an indication that all is well with your browser. Rogue programs in the Windows Antispy Network family have a reputation for hijacking browsers and redirecting them to malicious websites. Hijacks can fake error screens, change search results, change your homepage and create pop-ups.
  • Windows Antispy Network may run whenever Windows starts by exploiting the Windows Registry. This lets Windows Antispy Network create the above attacks without giving you the chance to shut down Windows Antispy Network or prevent it from starting.

Windows Antispy Network is related to Windows Stable Work, Windows Examination Utility, Windows Averting System, Windows Verifying Center and other rogue programs that share its interface and attack functions.

Because a Windows Antispy Network infection is often seen in the presence of other infections like Fake Microsoft Security Essentials Alert Trojans, you should remove Windows Antispy Network with a security program that can scan your entire computer for Windows Antispy Network components and all related threats. Updating your threat definitions for any scanner you use is also recommended since Windows Antispy Network is a recent threat as of June 2011.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Local\[RANDOM CHARACTERS].exe
    2 Uninstall Windows Antispy Network.lnk
    3 Windows Antispy Network.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%UserProfile%\Application Data\.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'.00HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'HKEY..\..\..\..{RegistryKeys}"Debugger" = 'svchost.exe'
Loading...