Threat Database Rogue Anti-Spyware Program Windows Spyware Protection

Windows Spyware Protection

By Domesticus in Rogue Anti-Spyware Program

Please do not purchase the fake security program that calls itself Windows Spyware Protection. Not only is Windows Spyware Protection not affiliated with Microsoft and not capable of protecting your computer from anything, but Windows Spyware Protection is malware. Windows Spyware Protection is part of a scam, and Windows Spyware Protection will try to scare you into believing that your computer is infected with viruses that can only be removed if you purchase a Windows Spyware Protection license.

Symptoms Caused by Windows Spyware Protection

Once Windows Spyware Protection is active on an infected PC, Windows Spyware Protection's presence is impossible to ignore, because Windows Spyware Protection is extremely disruptive. Windows Spyware Protection can render your computer absolutely useless, for as long as the malware is installed. Every time Windows starts, Windows Spyware Protection will load its fake home screen, where Windows Spyware Protection will play a progress animation in order to simulate a scan of your system. Then Windows Spyware Protection will tell you that Windows Spyware Protection has found a large number of threats on your computer, and Windows Spyware Protection will prompt you to "activate" or "license" the Windows Spyware Protection software in order to remove the so-called threats. There is even a payment website where you can enter your credit card number, but unfortunately, you will not get anything for your money if you do that. Windows Spyware Protection can't detect or remove threats, so everything Windows Spyware Protection tells you about the state of your PC is a lie, and no amount of money can turn the malware into real security software.

Even after Windows Spyware Protection has finished its phony scan of your computer, Windows Spyware Protection will continue to cause problems. As soon as the fake scanner interface clears, Windows Spyware Protection will create an almost constant stream of fake security alert messages to appear. Even if you try to close every single one as it appears, they can pop-up too frequently for anyone to be able to keep up. There have been reports that, between the fake scan and all of the pop-up windows, it can take a PC infected with Windows Spyware Protection an hour to boot and then clear all of the malware junk enough for the user to do anything with the computer.

Even if you manage to get past the scanner and pop-ups, Windows Spyware Protection makes sure that you can't really do much with your computer. Windows Spyware Protection will prevent almost all of your other programs from running, including any anti-virus or anti-spyware software that you have, as well as Task Manager. You will likely be able to start your web browser, because it tends to be the only program that Windows Spyware Protection will allow to run – but you will not be able to view any websites other than a fake site that claims to be selling Windows Spyware Protection licenses.

Where Does Windows Spyware Protection Come From?

Like most other rogue security applications, Windows Spyware Protection installs itself onto victim PCs through Trojans and drive-by downloads. A common mode of infection with Windows Spyware Protection is for a malicious website to claim to offer movies that can be watched online if you download a video player, but the file that you download is actually Windows Spyware Protection. Aside from fake video codecs or players, Windows Spyware Protection can find a way into your computer by using a Trojan, which is frequently bundled with freeware downloads or files from peer-to-peer file sharing sites. The problem is that the Trojan will be downloaded unnoticed and you will not be aware that anything unusual is happening. Then, once the Trojan is on your computer, it drops the necessary files to install and run Windows Spyware Protection.

Windows Spyware Protection is very likely a clone of another rogue anti-virus application called Best Malware Protection. Both of these threats are relatively new, and Windows Spyware Protection only appeared in April 2011. If you have Windows Spyware Protection on your computer, it is extremely important to remove the malware as soon as possible, because the longer you leave Windows Spyware Protection alone, the slower and more difficult to use your PC will get.

File System Details

Windows Spyware Protection may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\Application Data\23077d\CB130_287.exe
2. %UserProfile%\Start Menu\Windows Spyware Protection.lnk
3. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Spyware Protection.lnk
4. %UserProfile%\Application Data\Windows Spyware Protection
5. %UserProfile%\Start Menu\Programs\Windows Spyware Protection.lnk
6. %UserProfile%\Application Data\Windows Spyware Protection\cookies.sqlite
7. %UserProfile%\Desktop\Windows Spyware Protection.lnk
8. %UserProfile%\Application Data\Windows Spyware Protection\Instructions.ini

Registry Details

Windows Spyware Protection may create the following registry entry or registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "13" = "avgchsvx.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "10" = "avgscanx.exe"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "5" = "avcenter.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "7" = "avgfrw.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "3" = "egui.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun ""1" = "MSASCui.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "14" = "avgcmgr.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "11" = "avgcfgex.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "8" = "avgui.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "4" = "avgnt.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "Windows Spyware Protection"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "15" = "avgwdsvc.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "12" = "avgemc.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "9" = "avgtray.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "6" = "avscan.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "2" = "ekrn.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "0" = "msseces.exe"

Related Posts

Trending

Most Viewed

Loading...