Webroot Threat Blog – Internet Security Threat Updates from Around the World

WEBROOT – INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS

Menu

Skip to content
  • Products
  • Support
  • Community & Resources
  • Partners
  • About Webroot
  • About the Bloggers

Tag Archives: Process Hacker

Windows Troubles Killer / Salvage System: Rogue of the Week

Posted on June 20, 2011 by glhaldeman

By Stephen Ham and Andrew Brandt

Add to FacebookAdd to DiggAdd to Del.icio.usAdd to StumbleuponAdd to RedditAdd to BlinklistAdd to TwitterAdd to TechnoratiAdd to Yahoo BuzzAdd to Newsvine

Windows Troubles Killer / Windows Salvage System logoThis week’s rogue, once again, mimics a system utility and not merely an antivirus product. Either way, the scam is the same: Convince the victim that their computer is broken, then coerce them to pay for useless snake oil.

These rogue system utilities go by the names Windows Troubles Killer or Windows Salvage System; They are, for all intents and purposes, identical programs which have been “skinned” with different names. They actually appear to be a hybrid rogue, carefully blending a customized mix of malarkey and baloney into some sort of shenanigans smoothie. The program claims not only to be able to scan your computer for problems with software settings and other system optimization-sounding stuff, but also to perform some sort of check of your “Computer Safety” and “Network Security.” Oh yes, and there’s an antivirus component too, just to round out the complete package.

All in all, it’s a fairly rudimentary rogue to remove (whether you choose to do it manually or use our software), but it performs some unique system modifications that disable some legitimate security software, turns off some important Windows features, mimics some of Microsoft’s own software, and generally acts as a nuisance while reducing the actual security level of an infected computer. I’ll detail those after the jump.
Continue reading →

Tell your friends:

  • Facebook
  • Twitter
  • Google +1
  • LinkedIn
  • Reddit
  • Email
  • More
  • Pinterest
  • Digg
  • StumbleUpon

Like this:

Like Loading...
Posted in Destructive behavior, Rogue Security Products, social engineering, Stupid malware tricks, Threat Research, Uncategorized | Tagged %appdata%\Microsoft, consentpromptbehavioradmin, consentpromptbehavioruser, disable System Restore, disable UAC, disable User Account Controls, disablesr, enablelua, IFEO, image file execution options, net stop msmpsvc, NirSoft CurrProcess, PrcView, Process Hacker, Safe Boot, TRxSH, User Account Controls, warnonhttpstohttpredirect, Windows Salvage System, Windows Troubles Killer | 3 Comments

Connect With Us

Enter your email address to subscribe to this blog and receive notifications of new posts by e-mail.

Join 773 other followers

Archives

Menu

  • Privacy Statement
  • Send Us Feedback
Blog at WordPress.com. | Theme: Customized Able by Automattic.
Follow

Get every new post delivered to your Inbox.

Join 773 other followers

Powered by WordPress.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.
%d bloggers like this: