Home Malware Programs Rogue Anti-Spyware Programs Windows Error Correction

Windows Error Correction

Posted: March 7, 2011

Threat Metric

Threat Level: 10/10
Infected PCs: 35
First Seen: March 7, 2011
Last Seen: January 8, 2020
OS(es) Affected: Windows

ScreenshotThe Windows Error Correction program is a faux or rogue diagnostic application that infiltrates PCs through Trojan drops and other dishonest methods, afterwards trying to look the part of a genuine security tool. Although Windows Error Correction does offer system scan services and alerts for system threats and problems, all the information Windows Error Correction hands out is scripted and useless for judging the state of one's computer. Windows Error Correction and similar rogue PC threats have a strong tendency to interfere with computer security; deleting Windows Error Correction is best for your machine in both the immediate future and the long run.

Not All Alerts are from Microsoft!

Windows Error Correction has been documented to infect new PCs by spam email and through software bundles that include various Trojans and other malware along with programs available from free download websites. Trojans have several ways to infect computers themselves, such as being falsely labeled as popular application updates or being forced onto computers by malicious sites.
 
The infection most likely to spread Windows Error Correction is the fake Microsoft Security Essentials Alert Malware. This Trojan warns of an unknown Win32 infection and then requests that you install unspecified security software. The Microsoft Security Essentials Alert Malware specializes in dropping rogue anti-virus applications just like Windows Error Correction, but isn't limited to any one rogue anti-virus program.
 
The Windows Error Correction program may be new under this given name, but Windows Error Correction is strikingly similar to other rogue anti-virus products in its functions – Windows Privacy Agent, Windows Efficiency Manager and Windows Care Tool are just some of the many different malware that share similar code with brand name differences to fool the unwary.

Windows Error Correction – More Than a Mere Annoyance

If you get a Windows Error Correction infection, the rogue anti-virus program will prompt for scans that always show off a mind-boggling number of problems, supported by frequently-appearing system error messages. Typical errors include the failure of base Windows processes like lsass.exe and the supposed presence of a keylogger. Pay no heed to these warnings; Windows Error Correction only uses these predetermined displays to try to steal your credit card number through a fraudulent registration process.
 
Windows Error Correction is particularly dangerous due to being able to block programs from running, a hostile feature Windows Error Correction uses to prevent actual security programs from deleting Windows Error Correction. This is usually done with an accompanying keylogger warning or other error so that the user isn't immediately suspicious.
 
There's no mistaking Windows Error Correction's rogue anti-virus application for anything other than a danger to your security and a roadblock to your computer-based tasks; delete Windows Error Correction and the Trojan that dropped Windows Error Correction for a return to a comfortable computer-using experience.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\icsmeq.exe File name: icsmeq.exe
Size: 2.35 MB (2355200 bytes)
MD5: b01dc3f849d7a9d329c1ae44269e8548
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %AppData%
Group: Malware file
Last Updated: January 8, 2020

Additional Information

The following messages's were detected:
# Message
1"System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended."

"System component corrupted!
System reboot error has occurred due to lsass.exe system process failure.
This may be caused by severe malware infections.
Automatic restore of lsass.exe backup copy completed.
The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption."



Loading...