Home Malware Programs Rogue Anti-Spyware Programs XP Service Centre

XP Service Centre

Posted: April 4, 2011

XP Service Centre is a rogue security program with a proclivity for faking helpful functions while secretly attacking your web browser, blocking downloads and preventing the launch of real security applications. Error messages produced by XP Service Centre are inaccurate and can be disregarded – attempting to delete supposed infected files may actually harm your PC! Deleting XP Service Centre is strongly advised, since this threat cripples your security and may also expose you to other malware threats.

A Display of the Multitudinous XP Service Centre Threats

Unlike a real security program, XP Service Centre is installed on your PC through disingenuous tactics like drive-by downloads jammed through your browser by script exploits or links hidden in fake online system scans. XP Service Centre may be related to known rogue security programs like XP Security 2011, Vista AntiVirus or Win 7 AntiSpyware – all rogue security programs that use identical attacks while changing their name to match the infected operating system.

The most noteworthy dangers proffered by XP Service Centre include:

  • Restricted downloads. XP Service Centre will try to prevent you from downloading any anti-malware utilities that could remove XP Service Centre. Renaming the downloaded file as a harmless or generic one may let you avoid XP Service Centre's download detection for specific programs.
  • Restricted application use, which may include basic tools like the Task Manager and will almost certainly include anti-malware scanners. XP Service Centre may use fake error messages to indicate that the program is corrupted or infected - don't be fooled by this simple misdirection.
  • Browser hijacks – these may cause your search results to be changed, alter your homepage, block websites with fake unsafe website alerts or even forcibly redirect you to a malicious website. Malicious sites like those linked to XP Service Centre can also force you to download other malware and should be avoided even passingly.

Diving Down Through the Errors to Fix Your PC

Although the above attacks are XP Service Centre's most worrisome traits, XP Service Centre will also create highly visible error messages that can alarm unprepared users. Some possible errors include:

“Privacy Threat!
Spyware intrusion detected. Your system is infected. System integrity is at risk. Private data can be stolen by third parties, including credit card details and passwords. Click here to perform a security repair.”

“Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.”

All alerts are designed to go off regardless of your PC's health, and can, therefore, be shrugged off. However, they may contain malicious links or make it more difficult for you to see real system alerts, as opposed to fake XP Service Centre pop-ups.

Removing XP Service Centre should be accomplished by using a known quality anti-malware product rather than trying to remove the files individually. If you've verified that XP Service Centre isn't running as a background memory process and have updated your scanner for the latest threats, there's no reason why you can't delete XP Service Centre in a matter of moments with no further problems.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[User Name]\Desktop\XP Service Centre.lnk
    2 %Documents and Settings%\[User Name]\Start Menu\Programs\XP Service Centre
    3 %Documents and Settings%\[User Name]\Start Menu\Programs\XP Service Centre\Uninstall XP Service Centre.lnk
    4 %Documents and Settings%\[User Name]\Start Menu\Programs\XP Service Centre\XP Service Centre.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
Loading...