Threat Database Rogue Anti-Spyware Program Windows Supervision Center

Windows Supervision Center

By Domesticus in Rogue Anti-Spyware Program

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 3
First Seen: May 11, 2011
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Supervision Center Image

Windows Supervision Center is just one more in a very long line of rogue security programs in the Fake Microsoft Security Essentials Alert family of rogue security programs. Windows Supervision Center targets computers with the Windows operating system. By pretending to be a legitimate security program, Windows Supervision Center tries to convince computer users to buy Windows Supervision Center to fix fake Trojan infections of Windows Supervision Center's own creation. ESG malware researchers recommend that you ignore all alerts, messages, and claims made by Windows Supervision Center. Don't become another victim of Windows Supervision Center. Windows Supervision Center is a dangerous rogue security program that should be removed immediately.

Windows Supervision Center’s Long List of Clones

Windows Supervision Center belongs to a particularly large family of rogue security programs. Some examples of clones of Windows Supervision Center include Windows Steady Work, Windows Work Checker, Windows Armament Master, Windows Armature Master, Windows Cleaning Tool, Windows Inspection Utility, and many others. All of these rogue security programs act in very similar ways that are typical of most rogue security programs. Some characteristics shared by Windows Supervision Center and Windows Supervision Center's clones are listed below.

  1. Windows Supervision Center and Windows Supervision Center's clones are typically installed by the Fake Microsoft Security Essentials Alert Trojan. This Trojan typically infects machines by disguising itself as a video codec on adult video websites or by exploiting browser security vulnerabilities through Flash or JavaScript exploits.
  2. Windows Supervision Center and Windows Supervision Center's clones use Microsoft and Windows logos in their interface. Their interface is designed mimic Windows Security Center in its layout and overall look.
  3. Windows Supervision Center and Windows Supervision Center's clones have very similar names. Typically the name will start with the word "Windows" followed by two synonyms of "guard" or "protector utility". ESG malware researchers suspect that these names may be, in part, randomly generated due to the extreme nonsensical nature of some of these titles (e.g. Windows Proofness Guarantor).

Preventing a Windows Supervision Center Infection

ESG malware researchers recommend being on the watch for symptoms of the Fake Microsoft Security Essentials Alert Trojan. A fake notification from Microsoft Security Essentials is usually the first indication that this Trojan has infected our computer. Typically, this Trojan will claim to find the Unknown Win32/Trojan and then will recommend that the computer user download Windows Supervision Center to remove it. If you receive any similar messages, it is important to ignore the alert and to run a full scan in Safe Mode with a legitimate anti-malware program.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows Supervision Center

File System Details

Windows Supervision Center may create the following file(s):
# File Name MD5 Detections
1. wwkeud.exe 3e231cf60007b424840a035928a67aff 1
2. %AppData%\Microsoft\[RANDOM CHARACTERS].exe
3. %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
4. %UserProfile%\Application Data\Windows Supervision Center\Instructions.ini
5. %UserProfile%\Application Data\Windows Supervision Center\cookies.sqlite
6. %UserProfile%\Application Data\Windows Supervision Center\

Registry Details

Windows Supervision Center may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe | Debugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1"
HKEY_CLASSES_ROOT\PersonalSS.DocHostUIHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe | Debugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Supervision Center"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell = "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"

Messages

The following messages associated with Windows Supervision Center were found:

Attention
Suspicious software activity is detected.
Please start system files scanning for details.
System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
Warning!
Name: taskmgr.exe
Name: C:\WINDOWS\taskmgr.exe.
Warning! Database update failed!
Database update failed!
Outdated viruses databases are not effective and can't [sic] guarantee adequate protection and security for your PC!
Click here to get the full version of the product and update the database!
Warning! Running trial version!
The security of your computer has been compromised!
Now running trial version of the software!
Click here to purchase the full version of the software and get full protection for your PC!

Trending

Most Viewed

Loading...