Threat Database Rogue Anti-Spyware Program Windows Problems Stopper

Windows Problems Stopper

Windows Problems Stopper Image

The Rogue.FakeVimes family of malware has been around since at least 2009. Windows Problems Stopper is one of the many fake security programs that belong to this family of malware. Malware in this family of rogues carries out the typical strategy of a rogue security program attack. One of the key points that characterize the FakeVimes of rogue security programs is the names that it assigns to its files, usually composed of the prefix 'protector' followed with a random three character string. These files names made up of three random characters have characterized these fake security programs practically since the very first known instance of these rogue anti-virus applications. Windows Problems Stopper sports a highly convincing interface that imitates a legitimate security program similar to the Windows Security Center. However, the similarities between Windows Problems Stopper and real security applications stop at its interface. Beyond its interface, Windows Problems Stopper has absolutely no anti-malware capabilities. Windows Problems Stopper is a form of malware itself which should be stopped immediately with the help of a reliable anti-malware program.

Clones of Windows Problems Stopper include Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

Taking a Deeper Look at the Windows Problems Stopper Scam

Criminals use Windows Problems Stopper and similar fake security programs in order to convince computer users that they need to purchase useless security tools. According to ESG PC security analysts, Windows Problems Stopper is part of a multi-component malware attack. Basically, Windows Problems Stopper infects a computer and makes critical alterations to the Windows Registry and System settings. These changes allow Windows Problems Stopper to start up automatically and display error messages that mimic closely legitimate error messages that Windows displays when it is in trouble. Once the infected computer reboots, Windows Problems Stopper starts up automatically and displays a fake system scan claiming that the computer is severely infected. Then, Windows Problems Stopper will continue to pester its victim with a flood of fake error messages and warnings escalating the threat until the victim panics and believes that their computer system is on the verge of complete breakdown. Finally, Windows Problems Stopper directs its victims to a website where Windows Problems Stopper offers a 'full version' of Windows Problems Stopper in order to fix these nonexistent problems. Obviously, giving criminals your money is not a good idea; instead, remove Windows Problems Stopper as soon as possible. ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Windows Problems Stopper Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Problems Stopper may create the following file(s):
# File Name Detections
1. %AppData%Protector-[RANDOM 3 CHARACTERS].exe
2. %AppData%NPSWF32.dll
3. %Desktop%Windows Problems Stopper.lnk
4. %CommonStartMenu%ProgramsWindows Problems Stopper.lnk
5. %AppData% esult.db

Registry Details

Windows Problems Stopper may create the following registry entry or registry entries:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableTaskMgr" = 0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "EnableLUA" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "UID" = "qfsbuqlsme"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsatcon.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsidef.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsfsm32.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegistryTools" = 0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "ConsentPromptBehaviorUser" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "Inspector"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssperm.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionszonealarm.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsprmt.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "DisableRegedit" = 0
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem "ConsentPromptBehaviorAdmin" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettings "net" = "2012-3-18_2"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsvsecomr.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmscache.exe

Messages

The following messages associated with Windows Problems Stopper were found:

Error
Attempt to modify registry key entries detected. Registry entry analysis is recommended.
Warning
Firewall has blocked a program from accessing the Internet
C:program filesinternet exploreriexplore.exe
is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.
Warning! Identity theft attempt Detected
Hidden connection IP: 58.82.12.124
Target: Your passwords for sites

Trending

Most Viewed

Loading...