| Bleeping Computer | Welcome Guide Blogs Chat Help Search RSS |
|
How to remove the fake Microsoft Windows Malicious Software Removal ToolPosted by Grinler on July 13, 2009 @ 12:12 PM · Views: 6,266
What this programs does: The Windows Malicious Software Removal Tool is a program that was released by Microsoft on January 2005, which is updated monthly and can be used to remove various types of infections on a Windows computer. A Trojan has been discovered by Bharath that impersonates the legitimate Microsoft Malicious Software Removal Tool, but instead of removing infections, it tries to sell you various anti-malware programs. When the program is installed it will create a file called c:\Program Files\MalwareRemoval\MalwareRemoval.exe, which will be launched every time you log into Windows. Once running, you will be presented with a screen that impersonates the legitimate MSRT program except that when it scans your computer it will state that the following malware were infecting your computer:
This program will then state that it was able to remove some of these infections. Then when you press the Finish button it will open a a windows titled OEM Purchase Center where it tries to sell you various software such as Norton 360 and McAfee Total Protection. If you then click on the purchase button it will bring you to a site called oem-micro-store.com where it tries to sell you further software. It is important to note, though, that none of the infections it states are on your computer actually in exist. In reality, the fake MSRT program is the actual infection.
This infection will also install a file called c:\Program Files\MalwareRemoval\Security Center.exe, that when run opens a fake Windows Security Center that contains a box stating there was no antivirus software found on the computer. When you click on the Recommendations button on this screen it will open the oem-micro-store.com and try to sell you software. Last but not least, you will occassionally see a security alert from your Windows taskbar stating that the following:
If you click on this message you will once again be prompted to purchase anti-malware software. If you find that you are infected with this malware, please do not purchase any software from this Trojan. Instead, please use the guide below to remove the fake MSRT from your computer for free.
Threat Classification:
Advanced information: View Fake Microsoft Windows Malicious Software Removal Tool files.
Tools Needed for this fix:
Symptoms that may be in a HijackThis Log: O4 - HKCU\..\Run: [MalwareRemoval] C:\Program Files\MalwareRemoval\MalwareRemoval.exe
Guide Updates: 07/13/09 - Initial guide creation.
Automated Removal Instructions for Fake Microsoft Windows Malicious Software Removal Tool using Malwarebytes' Anti-Malware:
Your computer should now be free of the Fake MSRT program. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Posting A Hijackthis Log
Associated Fake Microsoft Windows Malicious Software Removal Tool Files: c:\Program Files\MalwareRemoval
Associated Fake Microsoft Windows Malicious Software Removal Tool Windows Registry Information: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "MalwareRemoval"
This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.
|
|