Home Malware Programs Rogue Anti-Virus Programs Windows Antivirus System

Windows Antivirus System

Posted: June 30, 2011

Windows Antivirus System is a clone of similar rogue security applications that all share an identical interface and recycle the majority of their code. Like the other threats Windows Antivirus System resembles, Windows Antivirus System may be installed by Trojans that imitate Windows Security Essentials Alert windows. Windows Antivirus System will pretend to offer your PC security features, but none of the problems that Windows Antivirus System pretends to detect is real and none of Windows Antivirus System's positive features is functional. You may also experience other problems with unrelated applications while Windows Antivirus System is on your computer, particularly hijacks that redirect your browser to dangerous websites. To restore your computer's normal state of health, you should uninstall Windows Antivirus System by using an anti-virus or other security program to scan for and remove all Windows Antivirus System components.

The Trojan That Slams Windows Antivirus System Down on Your PC

Just like other threats that are as good as identical to Windows Antivirus System, Windows Antivirus System can also be downloaded and installed by Trojan threats. One Trojan with a reputation for specializing in the installation of rogue security programs similar to Windows Antivirus System is Fake Microsoft Security Essentials Alert. You can notice a Fake Microsoft Security Essentials Alert by an occurrence of fake Security Essentials Alert windows that warn you about an unknown Trojan threat or use errors like this sample:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more
.

Fake Microsoft Security Essentials Alert Trojans may also install other rogue security programs besides Windows Antivirus System. Some likely possibilities include Windows AV Component, Windows Inviolability System, Windows Necessary Firewall, Windows Stable Work and Windows Examination Utility. The presence of any of these threats should be considered just as negative as the presence of Windows Antivirus System itself.

Don't Fall for Windows Antivirus System's Fake Threat Bluffs

Windows Antivirus System doesn't try to break new ground with Windows Antivirus System's tactics and is content to use the same fake alerts that you can see on other threats. Some, but far from all of the errors you might see Windows Antivirus System create can include:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

Warning! Database update failed!
Database update failed!
Outdated viruses databases are not effective and can't [sic] guarantee adequate protection and security for your PC!
Click here to get the full version of the product and update the database!

System component corrupted!
System reboot error has occurred due to lsass.exe system process failure.
This may be caused by severe malware infections.
Automatic restore of lsass.exe backup copy completed.
The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

Warning! Running trial version!
The security of your computer has been compromised!
Now running trial version of the software!
Click here to purchase the full version of the software and get full protection for your PC!

Warning!
Location: [application file path]
Viruses: Backdoor.Win32.Rbot

Warning!
Name: [application file name]
Name: [application file path]
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

Of course, Windows Antivirus System hasn't any ability to detect or remove threats from your PC and you should never assume that any problem that's announced by Windows Antivirus System is genuine. Even cases where a program fails to start along with an infection alert are just symptoms of Windows Antivirus System blocking the program deliberately to restrict your access to PC security software.

Windows Antivirus System may also start whenever Windows launches and hijack your browser to control which websites you're able to visit. All of these attacks combined make it difficult to remove Windows Antivirus System, but the proper use of anti-virus software and Safe Mode should let you undo all of Windows Antivirus System's harmful system changes.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 C:\Documents and Settings\{username}\Application Data\Microsoft

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}"ConsentPromptBehaviorAdmin"="0" "ConsentPromptBehaviorUser"="0" "EnableLUA"="0"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe][HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "WarnOnHTTPSToHTTPRedirect"="0"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe] "Debugger"="'svchost.exe'"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] "WarnOnHTTPSToHTTPRedirect"="0"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]HKEY..\..\..\..{RegistryKeys}"Debugger"="'svchost.exe'""Shell"="'C:\Documents and Settings\{username}\Application Data\Microsoft\bmemsl.exe'"

Related Posts

Loading...