Threat Database Rogue Anti-Spyware Program Windows Sleek Performance

Windows Sleek Performance

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 5
First Seen: May 9, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Sleek Performance Image

ESG PC security analysts have been tracking the FakeVimes family of fake security software since its first appearance in 2009. Since then, this family of malware has been updated regularly with new members being released on a gradual basis. Windows Sleek Performance is one of the many rogue anti-malware programs in the FakeVimes family; this fake security program belongs to a batch of rogue security software that was released in 2012. This is significant because ESG malware analysts has received reports of particularly vicious FakeVimes malware programs released in 2012 that use some version of the ZeroAccess rootkit as part of their attack.

Examples of other malware in the FakeVimes family released in 2012 include such fake security programs as Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

How Criminals Profit from Infecting Your Computer System With Windows Sleek Performance

Scamware programs like Windows Sleek Performance carry out a common online scam that has the objective of convincing the victim that they need to purchase a useless fake security program. Basically, Windows Sleek Performance will display misleading error messages and a fake system scan claiming that the victim's computer system is severely infested with malware. Then, when the victim tries to fix these problems using Windows Sleek Performance, this fake anti-virus program will display an error message claiming that the selected problems can only be removed by purchasing a 'full copy' of Windows Sleek Performance. Of course, since Windows Sleek Performance has no actual anti-virus capabilities, paying for this fake security program is a waste of money. Another problem associated with Windows Sleek Performance is the fact that it affects the victim's computer system in a number of ways. These include causing browser redirects, blocking access to legitimate security software, and causing the infected computer system to become slow and unresponsive.

Dealing with a Windows Sleek Performance Infection

While Windows Sleek Performance can be easily removed with the help of a reliable anti-malware program, malware in the FakeVimes family released in 2012 will often include the Sirefef or ZeroAccess rootkit as part of the attack. Because of this, ESG malware analysts recommends using an anti-rootkit tool to remove this malicious component before attempting to remove Windows Sleek Performance. You can 'register' Windows Sleek Performance by entering the serial code 0W000-000B0-00T00-E0020 when prompted. This will cause Windows Sleek Performance to stop displaying annoying error messages. However, it will still be necessary to remove this bogus anti-virus program with a real, up-to-date anti-malware program.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Sleek Performance

Windows Sleek Performance Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Sleek Performance may create the following file(s):
# File Name MD5 Detections
1. Protector-wjib.exe 81a2659d009d86a856c73a24b8f00110 1
2. Protector-nblr.exe b74e6fe1039d704e9183e44b72779f35 1
3. Protector-mjga.exe f730bbae7b36bd5a69c663674c0710c2 1
4. %AppData%\Protector-[RANDOM CHARACTERS].exe
5. %AppData%\NPSWF32.dll
6. %Desktop%\Windows Sleek Performance.lnk
7. %AppData%\W34r34mt5h21ef.dat
8. %AppData%\result.db
9. %CommonStartMenu%\Programs\Windows Sleek Performance.lnk

Registry Details

Windows Sleek Performance may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-5-6_2"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe
HKEY_CURRENT_USER\Software\ASProtect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe
HKEY_CURRENT_USER\Software\Microsoft\Win
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "ungklgkqft"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe

Messages

The following messages associated with Windows Sleek Performance were found:

Error
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.
Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Warning
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:Windowssystem32dllcachewmploc.dll
C:Windowssystem32dllcachewmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning! Spambot detected!
Attention! A spambot sending viruses from your e-mail has been detected on your PC.

Trending

Most Viewed

Loading...