Windows Privacy Agent

By GoldSparrow in Rogue Anti-Spyware Program

Windows Privacy Agent is malware, plain and simple. If you have Windows Privacy Agent infecting your computer, you'll know it, because this rogue anti-virus program will interfere with almost everything you try to do on your PC.

Symptoms Caused by Windows Privacy Agent

Windows Privacy Agent is part of a scam, and the way the scam works is that one way or another, you download this fake anti-virus software, and then Windows Privacy Agent uses a combination of ransoming and scare tactics to try to manipulate you into paying for Windows Privacy Agent. Windows Privacy Agent has no actual functionality in any way, and Windows Privacy Agent can't scan for or remove threats. So, if Windows Privacy Agent is responsible for the problems you're having with your computer, you will know it beyond a shadow of a doubt. Windows Privacy Agent is there and to think that Windows Privacy Agent is actually some kind of security application.

The first signs of the presence of Windows Privacy Agent will appear the first time you re-start your computer after the malware installs itself. Before you even get to see the desktop, Windows Privacy Agent will show its fake user interface. In fact, Windows Privacy Agent will do this every time you start Windows, because before you even see Windows Privacy Agent, it alters the registry so that Windows Privacy Agent runs every time at startup. The interface that Windows Privacy Agent displays actually shows the Windows logo and name ? with no permission ? along with some icons that presumably represent various elements of your PC's security. No matter what, Windows Privacy Agent will rate your security as being very low. That's because the purpose of this bogus interface is to run fake system scans, which will always turn up results. Then, every time, Windows Privacy Agent will tell you that in order to remove these "threats" that Windows Privacy Agent has found, you need to activate the software by paying for Windows Privacy Agent. However, the files marked as threats are usually harmless Windows components that shouldn't be deleted, and Windows Privacy Agent doesn't become capable of doing anything useful if you pay for Windows Privacy Agent.

After you are forced to watch the fake virus scan, and you finally see the desktop and try to use your computer, Windows Privacy Agent will continue to interfere. Windows Privacy Agent will create alerts that pop up and warn you about security issues, in a continued attempt to get you to pay for the malware. These alerts are pre-programmed into Windows Privacy Agent, and they are the same for every other fake security program in its family. A few of these alerts are especially common, and there is one that says that Firefox is a keylogger, one that says that the lsass.exe service caused Windows to boot improperly, and one that says that someone is trying to alter your "register" keys. By now, it should be clear that these warnings don't refer to anything real.

Aside from these scare tactics, Windows Privacy Agent will prevent you from running any other program, including Task Manager. Windows Privacy Agent may give you a message saying that whatever program you're trying to open is a security threat. Furthermore, Windows Privacy Agent may cause your Internet browser to redirect you to malicious websites, or you may find that you are unable to access the Internet altogether. These invasive activities are the reason why Windows Privacy Agent is sometimes called ransomware ? even if you don't fall for the scare tactics, the malware wants you to think that you have to pay the money Windows Privacy Agent demands in order to regain control of your PC. That's not true, and you shouldn't believe for a minute that paying money for Windows Privacy Agent will get Windows Privacy Agent to leave you alone.

How an Infection with Windows Privacy Agent Begins

Like the other rogue anti-virus applications in its family, Windows Privacy Agent infects a computer by using what is referred to as the fake Microsoft Security Essentials Alerts Malware. As the name implies, the Trojan is hidden in something online that looks harmless. Once Windows Privacy Agent is on your computer, Windows Privacy Agent begins to generate alerts that pop up from the system tray, which look as if they are coming from Microsoft Security Essentials. First, the alerts will say that a Trojan (or other virus) has been found on the system. Later, subsequent alerts will say that a program has been found that can remove the detected threats, and the alert box will have a button you can click to okay the download of this recommended software. If you agree to this download, that's when Windows Privacy Agent is downloaded and installed on your computer. So, throughout the entire infection process, Windows Privacy Agent will claim to be associated with Microsoft, but Windows Privacy Agent has no legitimate connection whatsoever to Microsoft or Windows.

Windows Privacy Agent’s Background Information

The family of fake security programs that Windows Privacy Agent comes from is one that has been around and causing problems for weeks, if not months. The entire family is part of a single scam, which has been traced back to an origin in Russia. Windows Privacy Agent is only a slight variation on the malware that supports this scam, since it appears to be the case that the only difference between Windows Privacy Agent and its relatives – aside from its name – is the fact that its fake interface is silver-grey instead of orange or white. Windows Privacy Agent dates to the end of February 2011, but other rogue anti-virus applications in its family have been around longer, including Windows Optimal Settings, Windows Software Guard, Windows Health Center, Windows Problems Solution, and Windows Express Settings, along with many, many others.

File System Details

Windows Privacy Agent may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\[RANDOM CHARACTERS].exe

Registry Details

Windows Privacy Agent may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = '%UserProfile%\Application Data\[random].exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'

Trending

Most Viewed

Loading...