System Security 2012

System Security 2012 Description



System Security 2012 Screenshot 1System Security 2012 is another variant of an old rogue security program scam that’s been circulating under different names in the WinWeb Security or WinAVPro family. Although System Security 2012 looks and sounds like a useful program to protect your PC from malicious software, SpywareRemove.com malware experts have found that System Security 2012 has zilch to offer as far as legitimate anti-malware features are concerned. System Security 2012 infections can also be responsible for system crashes, blocked programs and browser hijacks, as long as System Security 2012 is active on your PC. Due to the multifaceted nature of System Security 2012, it’s recommended that you try to remove System Security 2012 with a real anti-malware program that can scan your Registry and other advanced Windows components with minimal fuss.

Why There Isn’t Anything to Rest Secure About with System Security 2012


System Security 2012 is from an especially-prolific family of rogue security programs that use a wide range of names to market themselves. Other branches of the System Security 2012 family of scamware include Winweb Security, System Security, Total Security 2009, AVASoft Antivirus Professional, Advanced Security Tool 2010, Windows Ultra-Antivirus, Security Shield, Smart Fortress 2012, Windows Secure Kit 2011, Disk Antivirus Professional, Total Security, System Care Antivirus, System Tool 2011, Security Tool, Advanced PC Shield 2012, System Adware Scanner 2010, Microsoft Antivirus 2013, Security Scanner 2012, Smart Protection 2012, Security Shield 2012, Security Shield/Scanner, Security Monitor 2012, Personal Shield Pro, MS Removal Tool, Live Essential Platinum, Live Security Platinum, System Progressive Protection, Security Sphere 2012 and Windows Attacks Preventor. Other than their similar looks, you should be able to recognize clones of System Security 2012, as well as System Security 2012, by noting the following attacks:
  • Fake error messages that appear without warning or cause. SpywareRemove.com malware analysts have noted that these pop-ups and alerts are System Security 2012′s most visible attack, but are also crammed full of fake information that may confuse you about your computer’s health. You should never trust an error message from System Security 2012, or any error message that resembles one of the following examples:
    Windows Security Alert
    To help protect your computer, Windows Firewall has blocked some features of this program.
    Do you want to keep blocking this program?
    Name: Zeus Trojan
    Publisher: Unauthorized


    Warning! Infection found
    Unauthorized sending E-MAIL with subject “RE:” to [FAKE EMAIL HERE] was CANCELLED.


    Security Warning
    Malicious programs that may steal your private information and prevent your system from working properly are detected on your computer.
    Click here to clean your PC immediately.


    Security Warning
    There are critical system files on your computer that were modified by malicious software.
    It may cause permanent data loss.
    Click here to remove malicious software.


    svchost.exe
    svchost.exe was replaced with unauthorized program.
    It has encountered a problem and needs to close.
    If you were in the middle of something, the information you were working on might be lost.
    Please tell Microsoft about this problem.
    We have created an error report that you can send to us.
    Download SpyHunter Spyware Scanner
    We will treat this report as confidential and anonymous.


    Warning! Infection found
    Unwanted software (malware) or tracking cookies have been found during last scan. It is highly recommended to remove it from your computer.
    Keylogger Zeus was detected and put in quarantine.
    Keylogger Zeus is a very dangerous software used by criminals to steal personal data such as credit card information, access to banking accounts, passwords to social networks and e-mails.


    Security Warning
    Your computer continues to be infected with harmful viruses. In order to prevent permanent loss of your information and credit card data theft please activate your antivirus software. Click here to enable protection.


    Windows Security Center
    Serious security vulnerabilities were detected on this computer. Your privacy and personal data may be unsafe. Do you want to protect your PC?


    Warning: Spyware Detected
    Windows has found spy programs running on your computer!
    Click here to update your Windows antivirus software


    Warning: Infection is Detected
    Windows has found spyware infection on your computer!
    Click here to update your Windows antivirus software
  • Web browser redirect attacks that take you to System Security 2012′s website or to the website of one of System Security 2012′s clones. Even a quick visit to one of these sites may infect you with System Security 2012 via drive-by-download attacks, although you can protect your web browser by using strong security settings and a competent anti-malware program.
  • ‘Blue screen of death’ style system crashes.
  • A general failure of your anti-virus and PC security programs. Although System Security 2012 may create alert pop-ups that make it sound like all of these applications are infected, the truth is that System Security 2012 is just blocking them.
  • Problems with viewing files, folders or even drives in Windows Explorer. An alternate program, such as the Command Prompt, may allow you to access all of this data and see that System Security 2012 hasn’t deleted anything – only made it appear as though things were deleted.

Upgrading to the New Year without System Security 2012 in the Way


Even though System Security 2012′s attacks are extremely-invasive, SpywareRemove.com malware researchers are happy to inform you that a System Security 2012 infection isn’t likely to cause permanent damage to your PC. As long as you act quickly to delete System Security 2012 with a proper anti-malware product, your computer shouldn’t suffer long-term harm from any of System Security 2012′s attacks.

Since System Security 2012 may try to stop you from using software that could remove System Security 2012, you may need to enact one of the following workarounds:
  • You may be able to run your anti-malware scanner while System Security 2012 is active, if you rename the scanner’s .exe file to a common file name like ‘explorer.exe.’
  • Safe Mode is also able to stop most forms of malicious software from launching themselves, which will allow you to use your anti-malware application without System Security 2012 ever being ‘awake’ to notice it.
  • If these measures fail, you can also boot Windows from an external device that bypasses the default Registry. This will stop System Security 2012 from being launched in almost all cases of infection.

Aliases


Mal/FakeAV-IS [Sophos]Suspicious file [Panda]Trojan.Win32.Heur.Gen [ByteHero]



System Security 2012 Automatic Detection Tool (Recommended)


Is your PC infected with System Security 2012? To safely & quickly detect System Security 2012, we highly recommend you run the malware scanner listed below.



Visual & GUI Characteristics


System Security 2012 Screenshot 2System Security 2012 Screenshot 3System Security 2012 Screenshot 4System Security 2012 Screenshot 5System Security 2012 Screenshot 6

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name Detection Count
    1 %APPDATA%\ dwme.exe 614
    2 %WINDIR%\ system32\ YTZkIVrlOtAuSiF.exe 475
    3 PnG44aQHsWKfE9.exe 337
    4 %UserProfile%\Start Menu\Programs\System Security 2012 14
    5 System Security 2012.lnk 7
    6 %AppData%\svhostu.exe N/A
    7 %AppData%\ldr.ini N/A
    8 %AppData%\[RANDOM CHARACTERS]\System Security 2012.ico N/A
    9 %UserProfile%\Desktop\System Security 2012.lnk N/A
    10 %Temp%\svhostu.exe N/A
    11 %Temp%\8.tmp N/A
    12 %StartMenu%\Programs\Startup\crss.exe N/A

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\C0AB6693AB3202B4B9D95716ED5CE4A6\SourceListHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:59232"HKEY_CURRENT_USER\Software\System Security 2012HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"

Additional Information

  • The following messages's were detected:
    # Message
    1Warning infection found
    Unwanted software (malware) or tracking cookies have been found during last scan. It is highly recommended to remove it from your computer.
    Keylogger Zeus Keylogger Zeus is a very dangerous software used by criminals to steal personal data such as credit card information, access to banking accounts, passwords to social networks and e-mails.
    2Warning! The file "taskmgr.exe" is infected. Running of application is impossible. Please activate your antivirus software
    3Windows Security Alert
    To help protect your computer, Windows Firewall has blocked some features of this program. Do you want to keep blocking this program? Name: Zeus Trojan Publisher: Unauthorized
Posted: November 4, 2011 | By
Share:
Follow Me on Pinterest More More
Threat Level: 10/10
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 4.50 out of 5)
Loading ... Loading ...
Rate this article:
Detection Count: 595

3 Comments

  • Hector Villez says:

    Woah this security program is a total fake. didn’t realize until i found this post. going to remove it now. thx for the help.

  • software-in-action says:

    Thanks , I have recently been searching for information approximately this subject for ages and yours is the best I’ve found out so far.

  • Rested says:

    Just got my laptop out of the shop. Took them two days to get it all removed. Insidious!

Leave a Reply

What is 14 + 9 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)