Threat Database Rogue Anti-Spyware Program Windows Oversight Center

Windows Oversight Center

By Domesticus in Rogue Anti-Spyware Program

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 12
First Seen: May 9, 2011
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Oversight Center Image

Despite Windows Oversight Center's genuine-looking interface, this program is a rogue security application. Windows Oversight Center is designed to mimic the look of Windows Security Center to convince computer users that their computers are severely infected with numerous Trojans and viruses. In fact, any computer that has Windows Oversight Center installed is infected; the infection is Windows Oversight Center itself. ESG malware researchers strongly recommend immediate removal of Windows Oversight Center. A legitimate anti-malware program that is fully updated should take care of Windows Oversight Center. Most importantly, don't give Windows Oversight Center your money; this is not a real security program.
 

Windows Oversight Center’s Many Brothers and Sisters

Windows Oversight Center comes from a very large family of rogue security application. ESG security researchers have identified a very large number of clones for Windows Oversight Center. Some of these include Windows Supervision Center, Windows Proofness Guarantor, Windows Cleaning Tool, Windows Steady Work, Windows Work Checker, Windows Armature Master, Windows Armament Master, and Windows Inspection Utility. All of these programs have interfaces that are practically identical. The main difference from clone to clone lies in the program's name, which you can see at the highest left corner of the rogue security program's main window.
 

The Windows Oversight Center Infection Process

Typically, a Windows Oversight Center infection follows several steps before this rogue security program is fully downloaded and installed.

  1. First, the computer user will come in contact with a Trojan. This Trojan is typically the Fake Microsoft Security Essentials Alert Trojan, although, in some cases, Windows Oversight Center may be distributed by the Zlob Trojan. Trojans are commonly acquired through bad Internet browsing habits or by visiting high-risk websites.
  2. Once the Fake Microsoft Security Essentials Alert Trojan is installed, it will display a fake security alert from Microsoft Security Essentials of an Unknown Win32/Trojan infection. This supposed infection is completely fake and ESG malware researchers recommend ignoring it and dealing with the true culprit: the Fake Microsoft Security Essentials Alert Trojan.
  3. If the computer user allows it, the Fake Microsoft Security Essentials Alert Trojan will run a fake scan and then recommend that the computer user download Windows Oversight Center to remove a number of problems it pretends to find on the computer. If the computer user clicks on "Ok", Windows Oversight Center will be downloaded, installed, and then Windows will reboot.
  4. As part of its installation process, Windows Oversight Center will make harmful changes to the Windows Registry. These changes allow Windows Oversight Center to start up along with Windows and to block executable files (like most genuine security programs) from launching. Because of this, once Windows Oversight Center is installed, it is often necessary to start up Windows in Safe Mode to prevent this rogue security program from launching.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Oversight Center

File System Details

Windows Oversight Center may create the following file(s):
# File Name MD5 Detections
1. uorgbs.exe cff7ad5fc9e37e95fefa11d3afd05921 1
2. %AppData%\Microsoft\[RANDOM CHARACTERS].exe
3. freevideopplugin.exe
4. %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
5. %Temp%\[RANDOM CHARACTERS]\

Registry Details

Windows Oversight Center may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe | Debugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon Shell = "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe | Debugger

Messages

The following messages associated with Windows Oversight Center were found:

Install Windows Oversight Center

Windows Oversight Center setup will start automatically.
System configuration analysis and registry files checkup will run after reboot.
Microsoft Security Essentials Alert
Threat prevention solution found
System security parameters review has revealed critical security vulnerabilities that may compromise your system integrity.

Risk of system files corruption: High

The detected vulnerability may allow a remote attacker to gain access to private information or infiltrate system files and components. To prevent misuse please make sure your security parameters are configured correclty.
Press 'OK' to install the necessary software and run full system scan.
To complete the installation, please reboot your PC.
Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. Your access to these items may be suspended until you take an action. Click 'Show details' to learn more.

Trending

Most Viewed

Loading...