Home Malware Programs Rogue Anti-Virus Programs Microsoft Debug System

Microsoft Debug System

Posted: March 27, 2011

Microsoft Debug System is one of the latest divergent branches from a large rogue security application family. The same Fake Microsoft Security Essentials Alert Malware that handles distribution for other rogue security programs in this family also distributes Microsoft Debug System, and Microsoft Debug System uses identical malicious tactics to stir up fear and manipulate the PC's user. A computer with Microsoft Debug System will suffer from numerous fake pop-up warnings, scans that offer inaccurate analyses, security and maintenance application malfunctions and web browser hijacks. Deleting Microsoft Debug System will, in turn, remove all of these symptoms of infection and allow you to secure your computer.

A Threat Without Originality (but with an Effective Delivery Method)

The only innovative aspect Microsoft Debug System lies in the name, which breaks from Microsoft Debug System's family's usual 'Windows' acronym formula and may be indicative of a newly-emerging subgroup of these rogue security applications. Microsoft Debug System has both malicious behavior and an appearance in common with rogue security programs like Windows Support System, Windows Optimal Tool, Windows User Satellite, Windows Efficiency Manager and Windows Wise Protection (as well as many, many others).

In terms of initial infection, you'll probably catch Microsoft Debug System the same way you would catch any of the other related malware programs – through a Fake Microsoft Security Essentials Alert infection.

The Fake Microsoft Security Essentials Alert is a Trojan that creates the following misleading error messages before dropping its rogue security program payload onto your machine:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a seriuos [sic] possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

Along with this, the Trojan will warn you about a fake Trojan infection, first identified as an Unknown Win32/Trojan, and later noted as Trojan.Horse.Win32.PAV.64.a. The Trojan uses this imaginary infection as an excuse to install Microsoft Debug System or one of Microsoft Debug System's many threat siblings onto your PC.

Microsoft Debug System will run every time your machine starts up after this point due to Registry exploitation, which you should notice right away, since the Trojan will typically force a reboot immediately after Microsoft Debug System's installation.

A Fake Debugger That's Definitely Not Microsoft-Approved

Your fake error troubles are far from over even if the Trojan's payload is delivered, because Microsoft Debug System has plenty more of its own to offer you. Here are a few samples that you may see:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

Warning!
Name: [application file name]
Name: [application file path]
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

System component corrupted!
System reboot error has occurred due to lsass.exe system process failure.
This may be caused by severe malware infections.
Automatic restore of lsass.exe backup copy completed.
The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

These warnings are just as false and inaccurate as the earlier Trojan-originating ones, and may be used to conceal security program crashes that are deliberately caused by Microsoft Debug System. Even if Microsoft Debug System isn't visible, Microsoft Debug System may still be active as a background process; if you experience unusual behavior in your security programs or in Windows tools like Task Manager, then Microsoft Debug System may be at the root of it.

Microsoft Debug System may also attack your ability to browse the web through changing your proxy server settings. Beneficial websites may be walled off by fake warning messages, you may be forced to visit Microsoft Debug System's homepage and your search results may be changed for the worse.

Purchasing registration for Microsoft Debug System is inadvisable, since you'll be giving money and your credit card information to criminals. Delete Microsoft Debug System by using reliable anti-malware software and your PC will no longer suffer any of the malicious attacks described above.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\random\RANDOM CHARACTERS.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "DisableSR " = '1'
Loading...