Home Malware Programs Rogue Anti-Spyware Programs Windows Emergency System

Windows Emergency System

Posted: March 18, 2011

The fake Microsoft Security Essentials Alert Malware has added one more rogue security program to its delivery list with Windows Emergency System. After infecting your computer stealthily, the rogue security application Windows Emergency System imitates genuine system alerts about various kinds of damage and infection threats along with offering Windows Emergency System's inaccurate scanning services. However, Windows Emergency System's real goal is to steal your money, and towards this end, Windows Emergency System will create warnings that are always false positives as well as reducing your PC's security. Deleting Windows Emergency System is the first thing that should cross your mind when you get a glance at this threat - the criminals who made Windows Emergency System are certainly thinking equally hostile things about you and your computer.

Windows Emergency System is Not the Kind of Security You Need

Although the fake Microsoft Security Essentials Alert Malware can deliver many different types of rogue security programs, most of them, like Windows Emergency System, are quite similar in coding and behavior. The first step to avoiding Windows Emergency System infection is to recognize Windows Emergency System's fake warning messages:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a seriuos [sic] possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

These messages aren't really from Windows, and the Trojan.Horse.Win32.PAV.64.a infection Windows Emergency System claims is on your computer isn't actually there. You do have to worry about the Trojan causing these messages, however, because if you do what Windows Emergency System tells you, in a matter of seconds Windows Emergency System or another rogue security program will be on your computer in a matter of seconds.

Windows Emergency System is the Emergency!

Windows Emergency System doesn't give you any protection or security against malware; this rogue security product's sole purpose is to pretend that Windows Emergency System is useful and then extract money and personal information from the PC's user. You may see error messages like the following (often linked to crashing programs):

Warning!
Name: [application file name]
Name: [application file path]
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

System component corrupted!
System reboot error has occurred due to lsass.exe system process failure.
This may be caused by severe malware infections.
Automatic restore of lsass.exe backup copy completed.
The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

Program crashes and other errors are all due to Windows Emergency System trying to play you for a sucker. Since not removing Windows Emergency System places your computer at risk due to constant exposure to the rogue security program's malicious website, you should attack Windows Emergency System without remorse.

Industry-standard methods of deleting malware will also serve to delete Windows Emergency System in most cases. Just remember to catch the fake Microsoft Security Essentials Alert Malware along with Windows Emergency System, lest you find yourself struggling against a new rogue security product shortly thereafter!

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell "%AppData%\[RANDOM CHARACTERS].exe"

One Comment

  • Ramy says:

    I would like to thank spy hunter management for this amazing software as i tried many free software to remove the windows emergency system but did not work.

    i would advice all my friends to down load spy hunter as it is realy important and active.

    Thanks again

Loading...