Threat Database Rogue Anti-Spyware Program Windows Anti-Malware Patch

Windows Anti-Malware Patch

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 12
First Seen: August 11, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Anti-Malware Patch Image

Windows Anti-Malware Patch is neither a security patch nor an anti-malware tool. Windows Anti-Malware Patch is actually a malware infection labeled as a rogue anti-malware program. Rogue anti-malware programs such as Windows Anti-Malware Patch have the main goal of convincing PC users that their machine is infected with malware by posing as legitimate anti-malware tools. This is part of a known online scam designed to snatch away inexperienced computer users' money. Windows Anti-Malware Patch itself belongs to a very large family of these kinds of malware threats known as FakeVimes.

The FakeVimes family of malware has existed in one way or another since 2009. In the years since, criminals have released dozens of these fake security programs. Although most reliable anti-malware applications are well prepared to deal with FakeVimes-related malware infection, variants of FakeVimes malware released in 2012 (including Windows Anti-Malware Patch itself) often include a rootkit component from the Sirefef family. This rootkit component makes these FakeVimes variants more difficult to remove and detect than ever before. Because of this, you may require the help of an anti-rootkit tool to remove Windows Anti-Malware Patch completely.

How Criminals Attempt to Rob Your Money Utilizing Windows Anti-Malware Patch

The main goal of the Windows Anti-Malware Patch scam is to persuade computer users that they must purchase an unnecessary and useless upgrade which is usually quite expensive. Some variants of FakeVimes that carry out this scam include programs such as Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst. All of these fake security programs will issue fake notifications, cause browser redirects and application crashes. ESG malware analysts strongly advise not to purchase Windows Anti-Malware Patch or any other fake security applications that are part of the FakeVimes family.

Removing Windows Anti-Malware Patch Safely from Your Computer

Although it is entirely possible to remove Windows Anti-Malware Patch manually, ESG security researchers advise using a reliable anti-malware program with anti-rootkit technology. Incorrect removal of Windows Anti-Malware Patch can damage your operating system and be ineffective. You can 'register' Windows Anti-Malware Patch with the registration code 0W000-000B0-00T00-E0020 in order to stop Windows Anti-Malware Patch from displaying annoying error messages or causing other symptoms. ESG security researchers note that using the above code to 'register' Windows Anti-Malware Patch will not remove this malware intruder from your computer but can help as part of an overall treatment for your computer.

SpyHunter Detects & Remove Windows Anti-Malware Patch

Windows Anti-Malware Patch Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Anti-Malware Patch may create the following file(s):
# File Name MD5 Detections
1. Protector-hebm.exe 63fb15b80a2d8a5b875e00d9fc74b202 1
2. %AppData%\Protector-[RANDOM].exe

Registry Details

Windows Anti-Malware Patch may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "[RANDOM]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\"Debugger" = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "[DATE OF INSTALLATION]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\"Debugger" = "svchost.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "%AppData%\Protector-[RANDOM].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = "4"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "EnableLUA" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\"Debugger" = "svchost.exe"

Trending

Most Viewed

Loading...