Windows Anti-Malware Patch

By Domesticus in Rogue Anti-Spyware Program | 519 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 5.00 out of 5)
Loading ... Loading ...
More... More

Windows Anti-Malware Patch Description

Image Screenshot

[+] Click Image to Enlarge

Windows Anti-Malware Patch is neither a security patch nor an anti-malware tool. Windows Anti-Malware Patch is actually a malware infection labeled as a rogue anti-malware program. Rogue anti-malware programs such as Windows Anti-Malware Patch have the main goal of convincing PC users that their machine is infected with malware by posing as legitimate anti-virus tools. This is part of a known online scam designed to snatch away inexperienced computer users’ money. Windows Anti-Malware Patch itself belongs to a very large family of these kinds of malware threats known as FakeVimes.

The FakeVimes family of malware has existed in one way or another since 2009. In the years since, criminals have released dozens of these fake security programs. Although most reliable anti-malware applications are well prepared to deal with FakeVimes-related malware infection, variants of FakeVimes malware released in 2012 (including Windows Anti-Malware Patch itself) often include a rootkit component from the Sirefef family. This rootkit component makes these FakeVimes variants more difficult to remove and detect than ever before. Because of this, you may require the help of an anti-rootkit tool to remove Windows Anti-Malware Patch completely.

How Criminals Attempt to Rob Your Money Utilizing Windows Anti-Malware Patch

The main goal of the Windows Anti-Malware Patch scam is to persuade computer users that they must purchase an unnecessary and useless upgrade which is usually quite expensive. Some variants of FakeVimes that carry out this scam include programs such as Windows Web Commander, Windows Interactive Safety and Windows Virus Hunter. All of these fake security programs will notifications, browser redirects and application crashes. ESG malware analysts strongly advise not to purchase Windows Anti-Malware Patch or any other fake security applications that are part of the FakeVimes family.

Removing Windows Anti-Malware Patch Safely from Your Computer

Although it is entirely possible to remove Windows Anti-Malware Patch manually, ESG security researchers advise using a reliable anti-malware program with anti-rootkit technology. Incorrect removal of Windows Anti-Malware Patch can damage your operating system and be ineffective. You can ‘register’ Windows Anti-Malware Patch with the registration code 0W000-000B0-00T00-E0020 in order to stop Windows Anti-Malware Patch from displaying annoying error messages or causing other symptoms. ESG security researchers note that using the above code to ‘register’ Windows Anti-Malware Patch will not remove this malware intruder from your computer but can help as part of an overall treatment for your computer.

Type: Rogue AntiSpyware Programs

How Can You Detect Windows Anti-Malware Patch?

‘How Windows Anti-Malware Patch Infects Your Computer’ Video

Windows Anti-Malware Patch Removal Details

Windows Anti-Malware Patch has typically the following processes in memory:

  • %AppData%\Protector-[RANDOM].exe

Windows Anti-Malware Patch creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “[RANDOM]”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “ConsentPromptBehaviorAdmin” = 0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\”Debugger” = “svchost.exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “[DATE OF INSTALLATION]”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “ConsentPromptBehaviorUser” = 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\”Debugger” = “svchost.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “%AppData%\Protector-[RANDOM].exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = “4″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “EnableLUA” = 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\”Debugger” = “svchost.exe”

Important Article Disclaimer

ESG Support Center

This entry was last updated on 08/17/12 and posted on 08/11/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.