Home Malware Programs Rogue Anti-Virus Programs Windows Clear Problems

Windows Clear Problems

Posted: June 21, 2011

ScreenshotWindows Clear Problems is a new member of a family of rogue security programs that are forced onto your PC by way of Trojan-based attacks. The start of a Windows Clear Problems infection is often accompanied by fake alerts about an Unknown Win32/Trojan threat. Thereafter, Windows Clear Problems will create fake alerts of its own, as well as prevent you from using important security-related programs and hijack your browsing activities. Delete Windows Clear Problems from your PC with the help of an anti-virus scanner, instead of purchasing Windows Clear Problems and Windows Clear Problems' worthless features.

The Frail Disguise Placed Over Windows Clear Problems

Windows Clear Problems infects most PCs by using Fake Microsoft Security Essentials Alert attacks. By abusing malicious downloading scripts, Fake Microsoft Security Essentials Alert can infect your PC secretly and install Windows Clear Problems, or a similar rogue security program without your consent. However, Fake Microsoft Security Essentials Alert will often pretend to request consent to make its payload look legitimate, by using pop-ups like the following:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.

Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a seriuos [sic] possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

Other rogue security programs that can install include

Windows Clear Problems uses the same interface as all of these other threats: a basic graphical skin adorned with the Windows logo. This interface fakes grading systems for 'computer safety,' 'network security,' 'media components,' 'memory & devices' and other broad areas of your computer's security. Even though Windows Clear Problems will insist on giving you dangerous-looking poor scores for most of these categories, there's no reason to panic – Windows Clear Problems can't analyze your security or find real threats on your PC.

Windows Clear Problems's entire purpose is built off of creating false positives to make it look like your PC is a wreck and imply that purchasing Windows Clear Problems will fix these errors. Doing this will make you the victim of credit card fraud; if you've made the mistake of trusting the criminals behind the Windows Clear Problems scam, talk to your credit card company about canceling the relevant credit card.<

A Painfully Clear Look at Windows Clear Problems

Windows Clear Problems will create many different issues for your PC, to make it really look as though multiple high-level threats are attacking. Standard Windows Clear Problems attacks include:

  • Fake pop-up errors that alert you to imaginary threats. In most cases, Windows Clear Problems will try to imply that important system components are infected.

    System Security Warning
    Attempt to modify register key entries is detected. Register entries analysis is recommended.

    Warning! Database update failed!
    Database update failed!
    Outdated viruses databases are not effective and can't [sic] guarantee adequate protection and security for your PC!
    Click here to get the full version of the product and update the database!

    System component corrupted!
    System reboot error has occurred due to lsass.exe system process failure.
    This may be caused by severe malware infections.
    Automatic restore of lsass.exe backup copy completed.
    The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

    Warning! Running trial version!
    The security of your computer has been compromised!
    Now running trial version of the software!
    Click here to purchase the full version of the software and get full protection for your PC!

    Warning!
    Location: [application file path]
    Viruses: Backdoor.Win32.Rbot

    Warning!
    Name: [application file name]
    Name: [application file path]
    Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

  • If you attempt to run a specific program, Windows Clear Problems is likely to announce that the program is also infected, and prevents you from using it. Windows Clear Problems will be particularly careful to tell you that anti-virus software and system maintenance programs like Task Manager are infected, but you shouldn't believe a word of it.
  • Windows Clear Problems will refrain from blocking your web browser, only to hijack it instead. Hijacks can alter your home website settings, redirect you to harmful sites, create fake errors, play audio files or deluge you with pop-ups.
  • Due to advanced Windows Registry changes, Windows Clear Problems will also run whenever your PC starts, under normal conditions. Since having Windows Clear Problems active while you try to remove Windows Clear Problems from your computer is a bad idea, it's recommended that you use Safe Mode to prevent Windows Clear Problems from launching itself. Then, apply whatever anti-virus or security software that you prefer to find and remove Windows Clear Problems, Fake Microsoft Security Essentials Alert and any other threats.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\[RANDOM CHARACTERS].exe
    2 C:\Documents and Settings\[username]\Local Settings\Application Data\Microsoft\[SIX RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"HKEY_CURRENT_USER\Software\Windows Clear ProblemsHKEY_LOCAL_MACHINE\SOFTWARE\Windows Clear ProblemsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Windows Clear Problems
Loading...