Home Malware Programs Rogue Anti-Spyware Programs Windows Efficiency Console

Windows Efficiency Console

Posted: December 17, 2013

Threat Metric

Ranking: 8,739
Threat Level: 1/10
Infected PCs: 2,907
First Seen: December 18, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

One of the many entrants in the FakeVimes family, Windows Efficiency Console is a clone of its previous siblings, and, like them, is classified as a rogue anti-malware scanner. The results of Windows Efficiency Console's fake system scans and error messages may imply that spending money on Windows Efficiency Console will let you correct problems that are damaging your PC, but Windows Efficiency Console has no true threat detection or removal functions. Instead, Windows Efficiency Console blocks necessary security products, and malware researchers would consider deleting Windows Efficiency Console to be an absolute necessity for your PC's health.

An Efficient Predator of Your Windows PC

Families of fake security programs and system optimizers are noted for their frequent shift in brand names, which may provide a thin disguise against some uninformed victims. However, the underlying programming and aesthetics rarely are shifted along with the name swaps, and, thus far, malware researchers consider Windows Efficiency Console just another typical example of the FakeVimes family. Some examples of other members, many of which are cloned from the same basic template as Windows Efficiency Console are Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security.

As a fake anti-malware scanner, Windows Efficiency Console's most iconic traits are its fraudulent system alerts and scans, which will detect threats such as viruses and Trojans that actually aren't on your PC. While these attacks are part of an essentially harmless illusion that can only damage your PC if you follow their advice, malware experts also have seen more aggressive behavior from Windows Efficiency Console:

  • Windows Efficiency Console will block many other applications from being launched. In part, this is to convince you that your PC is contaminated by high-level threats, but it also is used to disable security tools that could uninstall Windows Efficiency Console. Windows Efficiency Console will set a natural Windows component, Svchost.exe, as a debugger, thus forcing it to run in lieu of the intended program. Some particular security applications also may be disabled by further changes to the Registry.
  • Windows Efficiency Console may hijack your Web browser. Security-oriented sites, much like security-oriented programs, may be blocked, and your browser may be redirected to fake warning pages that recommend that you purchase Windows Efficiency Console. Your search engine also may be hijacked and redirected to an unwanted or compromised search site.
  • Last of all, Windows Efficiency Console changes a bevy of Windows security settings. For example, your Firewall may be forced to make an exception for Windows Efficiency Console's traffic.

Getting Efficient at the Only Thing that Matters: Your PC's Safety

The aim behind Windows Efficiency Console's attacks always is to make you purchase its software, which Windows Efficiency Console claims will fix all of the issues that Windows Efficiency Console actually is invested in causing. As a wholly inadequate substitute for a real anti-malware scanner, as well as a direct threat to your PC, Windows Efficiency Console always should be considered scamware to be deleted as fast as possible. Considering Windows Efficiency Console's software-blocking functions, you may wish to utilize some common threat-disabling security tactics, such as booting from an emergency OS loaded on a USB drive, before deleting Windows Efficiency Console actually is tried.

Specialized Trojan downloaders often install Windows Efficiency Console and other FakeVimes scamware, with the attacks sometimes originating from risky advertisements that claim that a download is required to disinfect your PC. Malware researchers never consider it a safe or savvy practice to accept downloads from sources that haven't been verified as safe, and feel it worth reminding all readers that you should trust qualified anti-malware products from reputable brands for ascertaining your computer's health.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\results1.db File name: %AppData%\results1.db
Mime Type: unknown/db
Group: Malware file
%AppData%\guard-[RANDOM CHARACTERS].exe File name: %AppData%\guard-[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "C:\Users\User\AppData\Roaming\guard-[RANDOM CHARACTERS].exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation"= "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exe "Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe "Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe "Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe "Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = "svchost.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "GuardSoftware" = "%AppData%\guard-[RANDOM CHARACTERS].exe"

Additional Information

The following URL's were detected:
brandclick.com
The following messages's were detected:
# Message
1Error
System data security is at risk!
To prevent potential PC errors, run a full system scan.
2Error
Trojan activity detected. System integrity at risk.
Full system scan is highly recommended.
3Firewall has blocked a program from accessing the Internet
C:\Program Files\Internet Explorer\iexplore.exe
is suspected to have infected your PC.
This type of virus intercepts entered data and transmits them
to a remote server.
4Warning! Identity theft attempt detected
Hidden connection IP: xx.xxx.xxx.xxx
Target: Microsoft Corporation keys
Your IP: 127.0.0.1

Loading...