Home Malware Programs Rogue Anti-Spyware Programs Windows Managing System

Windows Managing System

Posted: March 12, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 55
First Seen: March 12, 2012
OS(es) Affected: Windows

Windows Managing System Screenshot 1The criminals behind the FakeVimes family still appear to be busy stamping out FakeVimes clones, as evidenced in the new-found Windows Managing System. Windows Managing System has all of the fraudulent features that you've come to expect from its predecessors – such as inaccurate pop-up warnings, scan results that are running over with fake threat detections, browser redirect attacks and attacks against your genuine security applications. Despite its pretensions at being a useful anti-virus program, Windows Managing System isn't any better at detecting viruses than its ancestors, and SpywareRemove.com malware researchers heartily endorse removing Windows Managing System with a legitimate alternative in anti-malware software.

Just How Poorly Does Windows Managing System Manage Your Computer's Safety?

Windows Managing System pretends to offer a multitude of advanced security functions that even well-known security companies haven't been able to provide, but, as far SpywareRemove.com malware experts are concerned, this offering to your altar might as well be made of straw for all the real benefits that Windows Managing System includes. Error messages from Windows Managing System will always contain inaccurate warnings, Windows Managing System's scan results are likewise useless, and other advanced features don't have any purpose except to block you from using legitimate programs to detect and remove Windows Managing System.

Grabbing Your Wallet Back from Windows Managing System's Anti-Competitive Grasp

Windows Managing System will also make efforts to shut down any competition on your PC, all to force you to spend money on the 'full' version of Windows Managing System to remove either Windows Managing System or symptoms that Windows Managing System is causing behind the scenes. However, SpywareRemove.com malware analysts recommend that you hold onto your money and use Safe Mode to avoid attacks such as these prior to deleting Windows Managing System via anti-malware software:

  • Your web browser may be hijacked to redirect you away from PC security sites or to direct you to Windows Managing System's website. SpywareRemove.com malware analysts stress the fact that browser hijacks from Windows Managing System don't use any browser-specific methodology to achieve their redirects. Changing your web browser or its settings will never achieve freedom from Windows Managing System-related redirects – a state of affairs that can only be acquired by deleting Windows Managing System itself.
  • Other security programs may be blocked by Windows Managing System or replaced by Windows Managing System's Advanced Process Control window. Blocked programs include both the Registry Editor and the Task Manager, although disabling Windows Managing System will allow you to access these tools normally.

Equivalent clones of FakeVimes and Windows Managing System include such examples as Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security.

Windows Managing System Screenshot 2Windows Managing System Screenshot 3Windows Managing System Screenshot 4Windows Managing System Screenshot 5Windows Managing System Screenshot 6Windows Managing System Screenshot 7Windows Managing System Screenshot 8Windows Managing System Screenshot 9Windows Managing System Screenshot 10Windows Managing System Screenshot 11Windows Managing System Screenshot 12Windows Managing System Screenshot 13

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Protector-cdw.exe File name: Protector-cdw.exe
Size: 1.97 MB (1970688 bytes)
MD5: 1e75ffdc5f6cc36d877bfd4012a126a3
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 13, 2012
%AppData%\result.db File name: %AppData%\result.db
Mime Type: unknown/db
Group: Malware file
%AppData%\NPSWF32.dll File name: %AppData%\NPSWF32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AppData%\Protector-[RANDOM 3 CHARACTERS].exe File name: %AppData%\Protector-[RANDOM 3 CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Desktop%\Windows Managing System.lnk File name: %Desktop%\Windows Managing System.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonStartMenu%\Programs\Windows Managing System.lnk File name: %CommonStartMenu%\Programs\Windows Managing System.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-3-11_2"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "origkboryd"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
Loading...