Sunday, July 24, 2011

Windows Vista Fix is a counterfeit application which is designed to milk money from unwary users. The parasite is distributed online and is usually difficult to avoid if one does not employ a decent security program. As common for rogues, Windows Vista Fix also spreads via trojan which enters user’s computer through its vulnerable places. The parasite is designed to scan your computer after it is downloaded and installed to user’s computer that is done automatically without user’s knowledge and consent. Windows Vista Fix displays numerous fake security warnings and then offers to buy supposedly legitimate version of the program: Critical Error! Damaged hard drive clusters detected. Private data is at risk. Critical Error Hard Drive not found. Missing hard drive. Critical Error RAM memory usage is critically high. RAM memory failure. Critical Error Windows can’t find hard disk space. Hard drive error Critical Error! Windows was unable to save all the data for the file \System32\496A8300. The data has been lost. This error may be caused by a failure of your computer hardware. Critical Error A critical error has occurred while indexing data stored on hard drive. System restart required. System Restore The system has been restored after a critical error. Data integrity and hard drive integrity verification required. Activation Reminder Windows Vista Fix Activation Advanced module activation required to fix detected errors and performance issues. Please purchase Advanced Module license to activate this software and enable all features. Low Disk Space You are running very low disk space on Local Disk (C:). Windows – No Disk Exception Processing Message 0×0000013 Do not use it because this is a fraud. Malware seeks to trick you into spending your money. In fact, that money will go to bad people that do not care about your computer’s safety and protection. Use a reputable anti-spyware tool and terminate this dubious system as soon as possible [downloas os]

Windows Vista Fix registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = 0'
Help: How to edit windows registry entries

Other malicious Windows Vista Fix files:
%AllUsersProfile%\
%AllUsersProfile%\.exe
%AllUsersProfile%\~
%AllUsersProfile%\~
%StartMenu%\Programs\Windows Vista Fix\
%StartMenu%\Programs\Windows Vista Fix\Uninstall Windows Vista Fix.lnk
%StartMenu%\Programs\Windows Vista Fix\Windows Vista Fix.lnk
The manual removal of files and registries should be performed by experienced users. A system can be badly affected if any error is done during the manual removal. We recommend using automatic removal tools to delete Windows Vista Fix, if you are not familiar with deleting malware manually.

No comments:

Post a Comment