Home Malware Programs Rogue Anti-Spyware Programs Windows Privacy Agent

Windows Privacy Agent

Posted: February 25, 2011

As rogue product that succeeds on the basis of lying to the user, Windows Privacy Agent isn't a program you need within spitting distance of your system. Windows Privacy Agent is a clone of many other rogue products and behaves similarly, right down to using the same kinds of fake alerts and warnings. Because Windows Privacy Agent is mostly installed through the fake Microsoft Security Essentials Alert Malware, catching this Trojan in the act will usually let you avoid having to handle the rogue anti-virus infection at all.

Windows Privacy Agent has been observed to be a clone of other rogue anti-virus applications that use the same means of infecting computers as well as the same underhanded tactics to trick computer users. Similar hostile products include include Windows Health Center, Windows Software Guard, Windows System Optimizator, Windows Safety Protection and Windows Security & Control.

All of these are delivered stealthily by the Microsoft Security Essentials Alert Malware, through the following pop-up and resulting actions:

  • Microsoft Security Essentials Alert
    Potential Threat Details
    Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.
  • The Trojan will request a scan of your computer. This scan will always turn up the result of Trojan.Horse.Win32.PAV.64.a, which could not be removed. The only infection (hopefully) is just the Trojan itself, of course! The follow-up message will request that you install unknown software, as such:
  • Threat prevention solution found
    Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
    Risk of system files infection:
    The detected vulnerability may result in unauthorized access to private information and hard drive data with a serious possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

This software is actually the rogue product Windows Privacy Agent or a clone, and the installation of this malware will make life even harder for your computer.

More Fake Error Messages from Windows Privacy Agent

Windows Privacy Agent will consistently use error messages with preset and fake contents to alarm you into giving its criminal creators cash to register the program. Many of the same messages are found on other rogue anti-virus programs, and have nothing to do with your system's actual performance.

  • System component corrupted!
    System reboot error has occurred due to lsass.exe system process failure.
    This may be caused by severe malware infections.
    Automatic restore of lsass.exe backup copy completed.
    The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.
  • Warning!
    Name: firefox.exe
    Name: c:\program files\firefox\firefox.exe
    Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.
  • System Security Warning
    Attempt to modify register key entries is detected. Register entries analysis is recommended.

Other drawbacks that come with a Windows Privacy Agent infection include equally pointless and fake scans, possible browser hijacks, and reduced security due to deliberate interference with anti-malware programs and settings. Turn your chin up at this rogue product's bad faith offers and instead get about to deleting Windows Privacy Agent right off the bat.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%UserProfile%\Application Data\[random].exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
Loading...