Threat Database Rogue Anti-Spyware Program Windows Performance Adviser

Windows Performance Adviser

Windows Performance Adviser Image

Despite the fact that Windows Performance Adviser is marketed as a legitimate security program, Windows Performance Adviser is actually a cleverly disguised malware threat. To be specific, Windows Performance Adviser is a kind of malware known as a rogue security application and is part of the Rogue:FakeVimes family of malware. Windows Performance Adviser and its clones attempt to steal their victims' money by tricking them into purchasing useless, fake security applications. While clones of Windows Performance Adviser have been around since 2009, Windows Performance Adviser itself belongs to a group of FakeVimes rogue anti-virus applications released in 2012. Malware in this recent variant of FakeVimes is in itself not particularly difficult to remove, but is often bundled with a rootkit in the ZeroAccess family.

The presence of this rootkit on the victim's computer system can make the removal of Windows Performance Adviser quite difficult. This is because this rootkit component is designed to hide Windows Performance Adviser from legitimate security applications, making its detection and removal quite difficult. ESG security analysts recommend using a strong, reliable, anti-malware program with an anti-rootkit component, if your computer system is infected with Windows Performance Adviser or with clones of Windows Performance Adviser such as Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

An Overview of the Windows Performance Adviser Scam

Windows Performance Adviser uses various tactics in order to make its victim believe that their computer is under attack (with malware other than Windows Performance Adviser itself). Its main strategy is using a variety of misleading security alerts that can severely disrupt a computer user's activity. Windows Performance Adviser will also run a fake scan of the victims' computer system, with results claiming that the computer is severely infected.

Other ways in which Windows Performance Adviser carries out its scam include preventing access to certain files, causing system crashes and hijacking the victim's web browser. However, attempting to fix these problems with Windows Performance Adviser will result in a notification claiming that it is necessary to obtain a registration code by purchasing Windows Performance Adviser's "full version" which is, of course, not free. The registration code 0W000-000B0-00T00-E0020 can help stop most of Windows Performance Adviser's annoying error messages. However, this will not remove Windows Performance Adviser itself. To do that, the help of a reliable anti-malware application will still be necessary.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Windows Performance Adviser Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Performance Adviser may create the following file(s):
# File Name Detections
1. %AppData%\Protector-[RANDOM CHARACTERS].exe
2. %AppData%\Inspector-[RANDOM CHARACTERS].exe

Registry Details

Windows Performance Adviser may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe

Messages

The following messages associated with Windows Performance Adviser were found:

Error
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.
Error
Attempt to modify Registry key entries detected.
Registry entry analysis recommended.
Error
Keylogger activity detected. System information security is at risk.
It is recommended to activate protection and run a full system scan.
Warning
Firewall has blocked a program from accessing the Internet
C:\program files\internet explorer\iexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning
Firewall has blocked a program from accessing the Internet
C:program filesinternet exploreriexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning
Firewall has blocked a program from accessing the Internet.
Windows Media Player Resources
C:Windowssystem32dllcachewmploc.dll
C:Windowssystem32dllcachewmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning! Spambot detected!
Attention! A spambot sending viruses from your e-mail has been detected on your PC.

Trending

Most Viewed

Loading...