Home Malware Programs Rogue Anti-Spyware Programs Windows Troubles Solver

Windows Troubles Solver

Posted: May 30, 2011

ScreenshotWindows Troubles Solver is a clone of other rogue security programs that are also distributed by the Fake Microsoft Security Essentials Alert Trojan. Windows Troubles Solver hides behind the appearance of an anti-virus utility to create fake warnings, hijack your web browser and disable security-related applications. Instead of heeding Windows Troubles Solver's call to purchase a valueless registration or activation key, you should use standard anti-malware procedures and good anti-virus scanners to delete Windows Troubles Solver from your PC.

The Trojan That Windows Troubles Solver Uses to Assail Your PC

Windows Troubles Solver shares its infection method, attacks and general appearance with many other closely-related rogue threats. Recent examples of Windows Troubles Solver relatives include Windows Necessary Firewall, Windows Custom Settings, Windows Risks Preventions, Windows Firewall Unit and Windows Profile System. All rogue programs in this general family use the Fake Microsoft Security Essentials Alert Trojan as a primary means for infecting new PCs.

Before Windows Troubles Solver is installed on your PC, the Fake Microsoft Security Essentials Alert Trojan will create an alert that imitates the look of a Microsoft Security Essentials Alert pop-up. This pop-up may begin with a warning like the sample below before telling you that your computer has been attacked by an 'Unknown Win32/Trojan' infection.

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

The only purpose of these errors is to confuse you into believing that the Fake Microsoft Security Essentials Alert Trojan is installing genuine anti-virus software onto your PC. In reality, what's being installed is Windows Troubles Solver or another rogue threat.

The Consequences of Trusting Windows Troubles Solver

Failing to remove Windows Troubles Solver by using quality anti-virus software will result in your computer suffering from a variety of attacks, all of which are typical to rogue security programs like Windows Troubles Solver:

  • Windows Troubles Solver will block your ability to use different programs, especially to prevent you from accessing anti-malware functions that could delete Windows Troubles Solver. Windows Troubles Solver's attacks may also use fake errors like the ones below:

    Warning!
    Location: [application file path]
    Viruses: Backdoor.Win32.Rbot

    Warning!
    Name: [application file name]
    Name: [application file path]
    Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

  • Windows Troubles Solver will also create fake errors in a more general sense, purely to convince you that it's doing its job as an anti-virus program. Fake warnings like the ones below will detect threats that don't exist all to make you purchase Windows Troubles Solver.

    Warning! Database update failed!
    Database update failed!
    Outdated viruses databases are not effective and can't [sic] guarantee adequate protection and security for your PC!
    Click here to get the full version of the product and update the database!

    System component corrupted!
    System reboot error has occurred due to lsass.exe system process failure.
    This may be caused by severe malware infections.
    Automatic restore of lsass.exe backup copy completed.
    The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

    Warning! Running trial version!
    The security of your computer has been compromised!
    Now running trial version of the software!
    Click here to purchase the full version of the software and get full protection for your PC!

  • In addition to using fake alerts, Windows Troubles Solver will use a highly misleading display that tells you that almost all aspects of your computer are insecure or out of date, backed up by the use of a Windows icon and other semi-official visuals. However, Windows Troubles Solver makes no attempt to analyze your system in the first place; all this information is faked.
  • Windows Troubles Solver may also hijack your web browser. Signs of this attack include an altered homepage, being redirected to harmful websites and error messages that block access to safe websites.
  • Windows Troubles Solver will continue to run even if you try to close it, and will launch itself automatically whenever Windows starts. The important exception to this is in cases where you boot from Safe Mode, a CD, or use an entirely separate operating system; any of these options will let you access your computer without Windows Troubles Solver's attacks impeding your ability to use anti-virus software to delete Windows Troubles Solver.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\[RANDOM CHARACTERS].exe
    2 %AppData%\Microsoft\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%AppData%\[RANDOM CHARACTERS].exe'
Loading...