Threat Database Rogue Anti-Spyware Program Windows Performance Catalyst

Windows Performance Catalyst

Threat Scorecard

Ranking: 16,373
Threat Level: 20 % (Normal)
Infected Computers: 101
First Seen: February 16, 2012
Last Seen: August 8, 2023
OS(es) Affected: Windows

Despite its claims, Windows Performance Catalyst is not a real anti-malware program. According to ESG security researchers, Windows Performance Catalyst is a kind of malware infection known as a rogue anti-malware application. Windows Performance Catalyst in particular disguises itself as a legitimate security application with an interface very similar to Microsoft Security Essentials. The most important thing to understand about a rogue anti-malware program like Windows Performance Catalyst is that these kinds of fake security programs have absolutely no way to remove malware from your computer, especially since they are malware infections themselves. Like most rogue anti-malware programs, Windows Performance Catalyst is merely designed to display constant alarming error messages and attempt to convince you to hand over your money for this fake anti-malware program. Windows Performance Catalyst should be removed immediately following basic computer security strategies (such as restarting Windows in Safe Mode) and with the help of a reliable (and real) anti-malware tool.

Windows Performance Catalyst Comes from a Large Family of Malware

Windows Performance Catalyst is not alone; there are dozens of fake security programs that are exact copies of Windows Performance Catalyst except for slight changes in their interface and in each fake security program's name. This family of rogue anti-malware applications is often identified as the FakeVimes family, which are usually distributed by Trojans included in fake video codecs and spam email attachments. Some examples of fake anti-malware applications that are identical to Windows Performance Catalyst (commonly referred to as clones) include Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

All members of this family of rogue anti-malware tools will change the Windows Registry in order to attack you with a stream of fake and alarming system alerts and to give you no choice but to let Windows Performance Catalyst run automatically every time you start up Windows. Windows Performance Catalyst uses highly-convincing charts, fake scans, lists which include percentage analysis of your computer's security and authentic-looking error messages in order to make the PC user think that the computer is severely infected and that only Windows Performance Catalyst can remove this non-existent problem. Windows Performance Catalyst is more than a nuisance; Windows Performance Catalyst is often associated with other dangerous Trojans and is a high-level threat that should be eradicated immediately.

File System Details

Windows Performance Catalyst may create the following file(s):
# File Name Detections
1. %AppData%\NPSWF32.dll
2. %AppData%\Inspector-{3 random characters}.exe
3. %UserProfile%\Desktop\Windows Performance Catalyst.lnk
4. %StartMenu%\Programs\Windows Performance Catalyst.lnk
5. %AppData%\result.db

Registry Details

Windows Performance Catalyst may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\{random}.exe "Debugger"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0

URLs

Windows Performance Catalyst may call the following URLs:

protect-now.com

Trending

Most Viewed

Loading...