Windows Antivirus Machine

By ESGI Advisor in Rogue Anti-Spyware Program | 290 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
More... More

Windows Antivirus Machine Description

Image Screenshot

[+] Click Image to Enlarge

The FakeVimes family of rogue security programs has been responsible for numerous infections. Windows Antivirus Machine is one of multiple fake security applications belonging to this family of malware. It is important to remember that Windows Antivirus Machine and its many clones are not real anti-malware programs, despite the fact that they use an interface that seems to indicate that they are. This is because Windows Antivirus Machine carries out a scam that involves convincing its victims to purchase a useless upgrade for this bogus security application. Rather than paying for Windows Antivirus Machine, the recommended course of action is to remove this program with a real anti-virus application.

Windows Antivirus Machine and Other 2012 FakeVimes Variants Are Particularly Nasty

Although fake security programs in the FakeVimes family have been around since 2009, the variants released in 2012 are particularly difficult to remove. This is because these variants, which include Windows Antivirus Machine, will often be bundled with a rootkit component from the Sirefef family of malware. This rootkit component makes Windows Antivirus Machine and other malware on the victim’s computer quite difficult to detect and remove with ordinary anti-malware software, and may require a more specialized anti-rootkit utility in order to be removed effectively. Other FakeVimes variants that tend to include the Sirefef rootkit include Windows Premium Console, Windows Active Defender and Windows Trojans Inspector.

Protecting Yourself from the Windows Antivirus Machine Scam

Fake security software scams are not new and have been used to prey on inexperienced computer users for many years. In fact, ESG security researchers note that the rogue security software scam is a simple variation of similar scams that dishonest repairmen and mechanics have been running for generations. Basically, Windows Antivirus Machine will claim that the victim’s computer is severely infected through alarming error messages and fake system scans. Windows Antivirus Machine also causes other problems, such as web browser redirects and issues accessing files on the infected machine. Windows Antivirus Machine will suggest that the victim purchase an expensive upgrade for this supposed anti-malware program. However, ESG security analysts have observed that Windows Antivirus Machine has no way of removing or detecting malware. You can stop many of Windows Antivirus Machine’s fake security notifications with the registration code 0W000-000B0-00T00-E0020. Although this will ‘register’ Windows Antivirus Machine, you will still need to annihilate this fraudulent security program from your machine with the help of a strong, fully-updated anti-malware solution.

Type: Rogue AntiSpyware Programs

How Can You Detect Windows Antivirus Machine?

‘How Windows Antivirus Machine Infects Your Computer’ Video

Windows Antivirus Machine Removal Details

Windows Antivirus Machine has typically the following processes in memory:

  • %AppData%\Protector-[RANDOM CHARACTERS].exe

Windows Antivirus Machine creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnOnHTTPSToHTTPRedirect” = 0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “UID” = “rudbxijemb”
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “net” = “2012-2-17_2″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings “ID” = 0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe

Important Article Disclaimer

ESG Support Center

This entry was last updated on 08/17/12 and posted on 08/1/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.