Threat Database Rogue Anti-Spyware Program Windows Precautions Center

Windows Precautions Center

By Domesticus in Rogue Anti-Spyware Program

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 4
First Seen: May 24, 2011
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Precautions Center Image

Windows Precautions Center is part of a family of rogue anti-spyware with many clones. Programs like Windows Precautions Center are part of a scam to steal your money. These rogue anti-spyware programs disguise themselves as legitimate anti-spyware applications. Then they will begin an aggressive campaign to get you to purchase a "full version" to use them. As part of this aggressive campaign, they will deliberately provoke different problems on your computer system to convince you that you need the services they supposedly provide. Don't fall for this scam. Rogue anti-spyware programs like Windows Precautions Center are a severe threat to your computer's security. Use a legitimate anti-spyware tool to remove them from your computer for good.
 

Windows Precautions Center’s Many Clones

There are many clones of Windows Precautions Center. Clones are programs that are all identical, but with different names. Criminals usually create many clones of malicious software like Windows Precautions Center to fight against computer security measures. Windows Precautions Center has the following clones: Windows System Manager, Windows 7 System Repair, Windows Vista System Repair, Windows XP System Repair, Windows Startup Repair, Windows Inspection Utility, Windows Supervision Center, Windows Oversight Center, Windows Armature Master, Windows Easy Warden, Windows Armament Master, and many more. Here are some of the characteristics shared by all clones of Windows Precautions Center:

- All Windows Precautions Center clones share the same user interface. The only difference from one to the next is the program's name on the top left corner.

- All programs in this family of rogue security software are typically delivered by a Trojan that causes a fake Microsoft Security Essentials Alert. It is possible to become infected through other Trojans and pathways, but the fake Microsoft Security Essentials Alert is the most common.

- Programs like Windows Precautions Center will display similar symptoms. These include constant pop-up windows and phony security alerts, blocked access to applications and the Internet, and severely decreased computer performance.
 

Getting Rid of Windows Precautions Center for Good

A legitimate, fully updated anti-malware utility will usually detect and eliminate Windows Precautions Center and its associated Trojans. However, because of the measures taken by Windows Precautions Center, it may be difficult to start up or install your anti-malware application. Windows Precautions Center has been known to block executable files as a way of protecting itself. If a program refuses to open, it is often a question of trying a couple of times. This is because Windows Precautions Center may randomly block executable files from running. If the program you are trying to run is an anti-malware application, it may be on a Windows Precautions Center list of programs to prevent from running. Often, it is simply a case of changing your anti-malware tool's name to anything else so that Windows Precautions Center doesn't recognize it. If you are still having trouble running your anti-malware utility, starting up in Safe Mode will usually bypass Windows Precautions Center altogether.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Precautions Center

File System Details

Windows Precautions Center may create the following file(s):
# File Name MD5 Detections
1. prfnpx.exe be826952165aac22ef9029eaaed9f4b8 1
2. %UserProfile%\Application Data\Microsoft\[RANDOM CHARACTERS].exe

Registry Details

Windows Precautions Center may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_CURRENT_USER\Software\Windows Precautions Center
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Precautions Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "DisableSR " = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Windows Precautions Center

Messages

The following messages associated with Windows Precautions Center were found:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.
Safe Boot includes several tools allowing the operational system to better control application software, so that to achieve enhanced security and system stability. These elements make it possible for the operational system to perform tasks otherwise not feasible without relevant hardware support
System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
Warning!
Location: c:\windows\system32\taskmgr.exe
Viruses: Backdoor.Win32.Rbot
Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a serious possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press ‘OK’ to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

Trending

Most Viewed

Loading...