Threat Database Rogue Anti-Spyware Program Windows Multi Control System

Windows Multi Control System

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 3
First Seen: May 23, 2012
OS(es) Affected: Windows

Windows Multi Control System Image

Windows Multi Control System's name seems to indicate that this is a security program, or an application for system optimization and management. However, despite its name, Windows Multi Control System does not provide any actual security for your computer system. Quite the opposite, Windows Multi Control System is actually part of a malware attack itself. Malware applications like Windows Multi Control System are known as rogue security programs. They carry out a common online scam which consists in tricking computer users into purchasing useless upgrades for a 'full version' of this bogus anti-virus application.

Rogue security programs are among the most common types of online scams. Their degree of malignancy varies from one to another. While some rogue security programs limit themselves to displaying alarming error messages and little else, many of these bogus security programs use malicious scripts, Trojans, and rootkits to take over the infected computer system. Windows Multi Control System belongs to this kind of intrusive rogue security application. Most of the time, Windows Multi Control System will be associated with a Trojan and dangerous rootkit infection which will not be easy to remove. ESG security researchers consider that Windows Multi Control System poses a severe security risk and that Windows Multi Control System should be removed from an infected computer system immediately with a strong, up-to-dated anti-malware application.

Windows Multi Control System’s Malicious Family of Rogue Security Software

Windows Multi Control System is part of a family of fake security programs that is referred to as FakeVimes. Malware in the FakeVimes family has been active and continually updated since summer of 2009. This means that there are dozens of programs identical to Windows Multi Control System with names like Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

ESG security researchers have observed that you can trick Windows Multi Control System into thinking that Windows Multi Control System has been registered with the serial number 0W000-000B0-00T00-E0020. It is important to understand that this registration code does not serve to remove Windows Multi Control System; it will simply help relieve some of its most annoying symptoms. It will still be necessary to remove Windows Multi Control System with a reliable anti-malware tool in order to prevent criminals from infecting your computer system in other ways or your operating system from becoming irreparably corrupted.

SpyHunter Detects & Remove Windows Multi Control System

Windows Multi Control System Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Multi Control System may create the following file(s):
# File Name MD5 Detections
1. Protector-xttr.exe 197c0e1d2bdc924a13642947a234bee6 2
2. Protector-bjlk.exe 2997dde628f207336149dcbf0f5404a0 1
3. %AppData%\Protector-{RANDOM 4 CHARACTERS}.exe
4. %AppData%\Protector-{RANDOM 3 CHARACTERS}.exe
5. %AppData%\NPSWF32.dll
6. %StartMenu%\Windows Multi Control System.lnk

Registry Details

Windows Multi Control System may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = 2012-2-20_1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\{RANDOM CHARACTERS}.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0

Trending

Most Viewed

Loading...