Home Malware Programs Rogue Anti-Spyware Programs Windows Antidanger Center

Windows Antidanger Center

Posted: June 21, 2011

ScreenshotWindows Antidanger Center is a threat that pretends to be a security program with the use of fake alerts and a misleading security-grading system. As a clone of similar rogue security programs, Windows Antidanger Center uses the attacks that have been seen in other members of Windows Antidanger Center's family, including browser hijacks, blocking applications and false positive infection warnings. You should never purchase Windows Antidanger Center or visit Windows Antidanger Center's website, since Windows Antidanger Center and sites that are affiliated with Windows Antidanger Center only want to steal your money and personal information. Deleting Windows Antidanger Center should be done as soon as possible but preferably with software-based assistance.

Close Relatives of the Windows Antidanger Center Threat

Windows Antidanger Center is just another copy of slightly older threats such as Windows Stable Work, Windows Steady Work, Windows Verifying Center, Windows Stability Alarm and Windows Accelerating Utility. Windows Antidanger Center and Windows Antidanger Center's cousins use a similar interface to mimic security and anti-virus functions; this interface pretends to judge your PC on 'hard disk optimization,' 'private data protection' and other security elements, but in actuality, Windows Antidanger Center is coded to create artificially low grades.

All of the above threats, including Windows Antidanger Center, are typically distributed by Fake Microsoft Security Essentials Alert, a Trojan that imitates Security Essentials Alert windows while it installs threats. Windows Antidanger Center or a similar rogue security program can be installed without your permission after Fake Microsoft Security Essentials Alert shows errors similar to the following:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

Warnings about Unknown Win32/Trojan infections are also a common symptom of a Fake Microsoft Security Essentials Alert attack. After Windows Antidanger Center is installed, Windows Antidanger Center and other threats can run automatically, since Registry changes place these threats directly into your basic Windows startup routine.

What You Need to Worry About with Windows Antidanger Center Itself

Windows Antidanger Center uses multiple attacks to create the impression that your PC is being threatened by a legion of threats that, in reality, don't exist. Probable Windows Antidanger Center attacks can consist of:

  • General fake system warnings that announce the presence of high-level threats or a problem with a serious OS component. Windows Antidanger Center's warnings may look similar to the following samples:

    System Security Warning
    Attempt to modify register key entries is detected. Register entries analysis is recommended.

    Warning! Database update failed!
    Database update failed!
    Outdated viruses databases are not effective and can'`t [sic] guarantee adequate protection and security for your PC!
    Click here to get the full version of the product and update the database!

    System component corrupted!
    System reboot error has occurred due to lsass.exe system process failure.
    This may be caused by severe malware infections.
    Automatic restore of lsass.exe backup copy completed.
    The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

    Warning! Running trial version!
    The security of your computer has been compromised!
    Now running trial version of the software!
    Click here to purchase the full version of the software and get full protection for your PC!

  • Windows Antidanger Center can also create alerts that are specific to particular programs; this gives Windows Antidanger Center an excuse to prevent those programs from running, and thus deny you access to security software.

    Warning!
    Location: [application file path]
    Viruses: Backdoor.Win32.Rbo

    Warning!
    Name: [application file name]
    Name: [application file path]
    Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

  • As a final attempt to steal your money and credit cared information, Windows Antidanger Center can hijack your browser to redirect you to Windows Antidanger Center's own website. This website will request that you purchase Windows Antidanger Center to remove all system problems and may use malicious scripts to force Trojans and other threats onto your PC.

Never purchase Windows Antidanger Center, since Windows Antidanger Center lacks all of the anti-virus and security features that Windows Antidanger Center advertises. Once you remove Windows Antidanger Center by using updated security software to scan your computer, all symptoms related to the Windows Antidanger Center infection will disappear. Safe Mode is the recommended environment for this scan since it may avoid Windows Antidanger Center's startup Registry entries.


ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"
Loading...