Windows Internet Booster
Windows Internet Booster Description
Windows Internet Booster – a New Name for the Same Scamware Fresh Off the Assembly Line
Because Windows Internet Booster copies its interface and code wholesale from previous versions of rogue anti-virus scanners of the FakeVimes family, Windows Internet Booster can effectively be considered a clone or copy of such PC threats as Live Enterprise Suite, Windows Firewall Constructor, Windows Control Series, Virus Doctor, Best Antivirus Software, Activate Ultimate Protection, Windows Interactive Safety, Windows Guard Tools, Windows Managing System, Windows Antivirus Patch, Windows Ultimate Security Patch, Windows Care Taker, Windows No-Risk Center, Windows Telemetry Center, Windows Premium Guard, Windows Safeguard Upgrade, Windows Secure Workstation, Windows Protection Maintenance, Windows Profound Security, PC Live Guard, Windows Pro Safety, Windows Anti-Malware Patch, Antivirus Smart Protection, Windows Pro Solutions, Windows ProSecure Scanner, Smart Internet Protection 2012, My Security Shield, Windows Debug Center, Windows Trouble Taker, Windows Crucial Scanner, Windows Enterprise Defender, Windows Safety Module, Windows Custom Management, Home Malware Cleaner, Windows Efficiency Accelerator, Windows Defence Counsel, Personal Security Sentinel, Windows Sleek Performance, Volcano Security Suite, Windows Antivirus Machine, CleanUp Antivirus, Windows Process Director, Live PC Care, Windows Performance Catalyst, Windows Smart Warden, Windows Pro Rescuer, Windows Be-on-Guard Edition, Windows Privacy Module, XP Smart Security, PrivacyGuard PRO, Windows Performance Adviser, System Protection Tools, Windows Web Commander, Windows Functionality Checker, Windows Basic Antivirus, Windows AntiHazard Center, Windows Turnkey Console, Windows Advanced Toolkit, Enterprise Suite, Windows Safety Toolkit, Windows Antivirus Rampart, Windows Virtual Firewall, Windows Security System, Windows Malware Sleuth, Windows Pro Defence, Windows Software Saver, Windows Safety Manager, Windows High-End Protection, Windows Abnormality Checker, Windows Maintenance Suite, Windows Secure Workshop, My Security Wall, Windows Private Shield, Windows Security Renewal, Windows Advanced User Patch, Windows Virtual Angel, Windows Ultimate Safeguard, Fast Antivirus 2009, Windows No-Risk Agent, Windows Premium Defender, Windows Advanced Security Center, Windows Proactive Safety, Windows Guard Solutions, Windows Antivirus Release, Security Master AV, Windows Web Combat, Windows Antivirus Care, Windows Privacy Counsel, Windows Stability Guard, Windows Instant Scanner, Windows Protection Master, Internet Security Essentials, Windows Shield Tool, Windows Defending Center, Windows Warding System, Windows Problems Stopper, Best Malware Protection, Anti-Malware Lab, Smart Anti-Malware Protection, Windows Daily Adviser, Windows Pro Web Helper, Windows Home Patron, Keep Center Keeper, Windows Tools Patch, Windows First-Class Protector, Windows Maintenance Guard, Windows Proprietary Advisor, Windows Health Keeper, Windows Activity Debugger, Windows Shielding Utility, Windows Expert Series, Windows Safety Series, Smart Security, Windows Safety Wizard, Home Safety Essentials, Windows Privacy Extension, My Security Engine, Windows Multi Control System, Smart Internet Protection 2011, Windows Software Keeper, Windows Active Guard, Windows Threats Destroyer, Windows ProSecurity Scanner, Windows AntiHazard Helper, Windows Secure Surfer, Smart Virus Eliminator, Windows Pro Safety Release, Windows Active Defender, Windows Smart Partner, Extra Antivirus, Additional Guard, Internet Security Suite, Personal Internet Security 2011, Windows Safety Maintenance, Windows PRO Scanner, Windows Custodian Utility, Windows Protection Unit, Windows Guardian Angel, Windows Risk Minimizer, Windows Personal Doctor, Windows System Defender, Windows Virtual Security, Windows Security Suite, Windows Enterprise Suite, Security Antivirus, Smart Engine, Windows Custom Safety, Windows Interactive Security, Windows Safety Checkpoint, Windows Antihazard Solution, Windows Virus Hunter, Windows PC Aid, Windows Premium Console, VirusSecurity, Total Anti Malware Protection, Strong Malware Defender and Windows Secure Web Patch. These modern variants of Win32/FakeVimes can all be identified by their Windows Security Center-esque appearances, their fake anti-phishing features and their forcible substitute for Windows Task Manager – a ‘feature’ that’s called Advanced Process Control. However, SpywareRemove.com malware researchers also warn that Windows Internet Booster can take action against other programs besides Task Manager, and may block the Registry Editor or various anti-virus products.
Windows Internet Booster will claim that these applications are being blocked due to various infections or other forms of damage, but Windows Internet Booster, as scamware, doesn’t have any ability to detect real PC threats, including trojans, viruses, keyloggers or other types of high-level security hazards. While Windows Internet Booster will attempt to persuade you to spend money on a purchasable registration key, SpywareRemove.com malware researchers note that there never is any good justification for sending money to the criminals behind Windows Internet Booster – particularly when appropriate anti-malware programs can remove Windows Internet Booster easily enough.
Saving Your PC from Windows Internet Booster’s Phony Booster Shots
As a fake anti-virus program, Windows Internet Booster, unfortunately, gives its victims more to worry about than just software inaccessibility and fake system alerts. Because Windows Internet Booster will launch itself with Windows to conduct the following attacks, SpywareRemove.com malware experts suggest that you use any a Safe Mode boot or remote hard drive-based boot to stop the symptoms noted below before they can even start:
- Online search redirects to unusual or potentially harmful websites.
- Disabled UAC features that block potentially-harmful system changes.
- Disabled protection from files with invalid signatures – a common trait for fraudulent PC threats that install themselves by pretending to be legitimate products.
Windows Internet Booster can also be ‘registered’ for free with the code ’0W000-000B0-00T00-E0020,’ which can provide some minor assistance with making it easy to delete Windows Internet Booster.
Windows Internet Booster Automatic Detection Tool (Recommended)
Is your PC infected with Windows Internet Booster? To safely & quickly detect Windows Internet Booster, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect Windows Internet Booster
What happens if Windows Internet Booster does not let you open SpyHunter or blocks the Internet?
Visual & GUI Characteristics
Visual & GUI Characteristics
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 %APPDATA%\ Protector-bahj.exe 16 2 %APPDATA%\ Protector-vfor.exe 12 3 %AppData%\NPSWF32.dll N/A 4 %AppData%\result.db N/A 5 %AppData%\Protector-[RANDOM].exe N/A
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\InspectorHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\ID 4HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\net [Date of Installation]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings\UID [RANDOM]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXEHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorAdmin 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ConsentPromptBehaviorUser 0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA 0
Posted: May 5, 2012 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 105


More

Thanks for your excellent post!