Windows Averting System

By ESGI Advisor in Rogue Anti-Spyware Program

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 12
First Seen: May 31, 2011
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Averting System Image

Windows Averting System – What Is It?

Windows Averting System is a rogue anti-spyware program. These programs pretend to be genuine security applications to steal computer users' money. A computer infected with Windows Averting System will start displaying false security alerts and symptoms of severe computer problems. Then, Windows Averting System will try to convince the user to purchase a Windows Averting System license to fix the problems. The main issue is that the very thing causing the computer problems, in the first place, is Windows Averting System itself.
 

Where does Windows Averting System Come from and Who Created It?

Windows Averting System is one of dozens of clones in the "Fake Microsoft Security Essentials Alert" family of rogue anti-spyware program. There are dozens of rogue anti-spyware programs that can be delivered by this fake alert, most of them with titles that sound vague like what a legitimate security tool would be named. Most of the time, these titles are somewhat nonsensical. In fact, they may be automatically generated, since names like "Windows Proofness Guarantor" or "Windows Saviour Firewall" don't really make a lot of sense. The bad English is probably due to the fact that these programs come from the Russian Federation. This country is well-known for being a hangout for some of the world's worst cyber criminals. The creators of Windows Averting System are still unknown, but versions of this scam first started appearing in 2010.
 

How Can I Tell Whether My Computer is Infected with Windows Averting System?

The best thing you can do is to catch this infection early. Been alert for any Microsoft Security Essentials alerts that look suspicious is the best way to do this. If you are getting an alert from Microsoft Security Essentials that prompts you to download and install Windows Averting System on your computer, it is a signal that you got a Trojan infection. However, Windows Averting System has not been downloaded and installed yet. This makes removing the Trojan much easier than if it were allowed to complete its invasion. Once Windows Averting System is installed, the infection is quite obvious. The first thing you will see when starting up your computer is the Windows Averting System splash screen, which cannot be closed until Windows Necessary Firewall runs a fake scan of your system. Other signs of a Windows Averting System infection are a slow and unresponsive system, blocked access to your files and constant error messages and security alerts.
 

Don’t Become a Victim of Windows Averting System

Whatever you do, don't give Windows Averting System your credit card information. You should also be very careful when accessing any sensitive files or when using your browser to access your bank account. There may be keyloggers installed on your system. This means that you should be extremely careful about entering your passwords when browsing the Internet. Most experts recommend that you use a real anti-malware solution to remove Windows Averting System. It is also possible to remove Windows Averting System manually. However, inexperienced computer users should not try to do this.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Averting System

File System Details

Windows Averting System may create the following file(s):
# File Name MD5 Detections
1. uddtpv.exe 25eaa5b27edca81348e624f7f21ed28b 1
2. %AppData%\Microsoft\[RANDOM CHARACTERS].exe

Registry Details

Windows Averting System may create the following registry entry or registry entries:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"

Messages

The following messages associated with Windows Averting System were found:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.
System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a serious possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.
Warning!
Location: c:\windows\system32\taskmgr.exe
Viruses: Backdoor.Win32.Rbot

Trending

Most Viewed

Loading...