Windows System Tasks

By ESGI Advisor in Rogue Anti-Spyware Program

Threat Scorecard

Ranking: 11,298
Threat Level: 100 % (High)
Infected Computers: 1,788
First Seen: July 7, 2011
Last Seen: September 15, 2023
OS(es) Affected: Windows

Windows System Tasks Image

Are You Getting Alerts from Windows System Tasks?

Be careful if your computer is showing messages from Windows System Tasks. Windows System Tasks is not a legitimate Windows component or security application. Windows System Tasks is a harmful rogue security program. These kinds of programs pretend to be helpful computer security utilities but, in reality, they're malicious software that causes harm to your computer. They do this to try to blackmail you into purchasing Windows System Tasks in order to remove the problems Total PC Defender is causing. If you are getting alerts from Windows System Tasks, use an anti-malware utility to remove this harmful rogue security program from your computer immediately. If you cannot access your anti-malware tool, try starting up Windows in Safe Mode.
 

A Typical Way of Getting Windows System Tasks on Your System

Malware like Windows System Tasks is usually delivered by a Trojan. While browsing the Internet, careless computer users may click on an advertisement promising something like a "Free Online Malware Scan!" Beware of these supposed malware scans. Most of the time, these are, in reality, websites that exploit vulnerabilities in JavaScript and Flash to install a Trojan into your computer. Another usual way of getting a Trojan infection is by being careless about what you download. Hackers disguise Trojans as popular files on file sharing networks, as video codecs on adult video websites, or as system updates from unauthorized sources. You may think you are downloading the latest movie or pirated game, but you will actually be downloading a Trojan. Once the Trojan has been downloaded and installed, it will usually trick the user into downloading and installing Windows System Tasks. It may also allow a hacker to control your computer remotely and directly force it to download Windows System Tasks.
 

The Fake Microsoft Security Essentials Alert Trojan and Windows System Tasks Clones

Windows System Tasks belongs to a very large family of rogue security applications. There are too many clones of Windows System Tasks to list here. A few examples are Windows Debugging Center, Windows Debugging Agent, and Windows Cleaning Tool. All members of this malware family have certain things in common:

  1. The most common way of becoming infected with Windows System Tasks and Windows System Tasks' clones is through the Fake Microsoft Security Essentials Alert Trojan. This Trojan displays a fake alert from Microsoft Security Essentials urging the computer user to download Windows System Tasks.
  2. Windows System Tasks and Windows System Tasks' clones share very similar interfaces. These will typically use replicas of trademarked Microsoft logos to lend them authenticity.
  3. Windows System Tasks and Windows System Tasks' clones will all cause numerous problems on the infected computer (e.g. blocked access to the Internet, blocked access to executable files, constant pop-up alerts, and general system instability).

ScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove Windows System Tasks

File System Details

Windows System Tasks may create the following file(s):
# File Name MD5 Detections
1. geheep.exe 5cee6a563b2195095e43b749c2b06ac3 1
2. %UserProfile%\Application Data\Microsoft\[random].exe

Registry Details

Windows System Tasks may create the following registry entry or registry entries:
Regexp file mask
%AppData%\Microsoft\[RANDOM CHARACTERS].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore "DisableSR " = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = '0'
File Execution Options\afwserv.exe "Debugger" = "svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell "%AppData%\Microsoft\[RANDOM CHARACTERS].exe"

Messages

The following messages associated with Windows System Tasks were found:

Caution! Overall system rating is low.
For full system cleanup please update the software!
Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click ‘show details’ to learn more.
System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.
Warning!
Location: c:\windows\system32\taskmgr.exe
Viruses: Backdoor.Win32.Rbot
The analysis of system data protection parameters revealed the low security level of system components. Potentially harmful software that may compromise your system integrity has been detected. The structure of some files shows code elements that can be considered as malicious.
Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a serious possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press ‘OK’ to install the software necessary to initiate system files check. To complete the installation process please reboot your computer
Warning!
Location: C:\Program Files\java\jre6\bin\jqs.exe
Viruses: Virus.Win32.Sality
Deny – Forbid the execution of potentially harmful software.
Enable Protection – Click to activate antivirus and remove all infections.

Trending

Most Viewed

Loading...