Windows Security Suite Rogue

by malwarekilla on July 24, 2009

Well, I figured I’d see a rogue that is pretending to be Microsoft Security Essentials and here it is. Windows Security Suite is a fake antivirus (rogue) that really registers itself (as an antivirus) in the Microsoft Security Center (first time I’ve seen that). This rogue terminates every user spawned exe except of course for itself. This is pretty bad. If a user wants their computer back they MUST purchase the fake antivirus or have their computer cleaned by a professional.

I removed this rogue along with 8 rootkits via bootable antimalware (UBCD4WIN).

072409 1553 WindowsSecu1 Windows Security Suite Rogue

{ 24 comments… read them below or add one }

Jimmy James July 24, 2009 at 4:16 pm

‘System Security’ has started doing this… I’ve heard on various forums that if you rename your antimalware executable to ‘explorer.exe’ then it will allow it to run, because it is needed by windows. Not sure though…

sandra July 24, 2009 at 8:11 pm

system security is the worst rouge i think to come across. that being said most rouges will not let you get to your anti virus. dose security essentials catch this rouge?

Jonathan July 24, 2009 at 8:49 pm

Yeah i have never seen that before.

Can anyone tell dose UBCD4WIN work on computers/laptops with vista installed, when i boot from the cd on my laptop with vista it restarts the laptop during it booting, the cd works on my XP machine. As i understood it was platform indepent becuase its a boot cd.

123zap July 24, 2009 at 10:05 pm

Well, rescue disks should work too. You don’t need UBCD4WIN, just a good avira rescue disk (if it detects it). I think MBAM and SAS should have rescue disks!

Guillermo July 25, 2009 at 12:06 am

Hey Matt,

Before trying UBCD4WIN, did you try Avira Antivir 9.0 to remove this rogue?

In another post made by you several weeks ago you commented that Avira is not god at removing rogue malware but in that article you didn’t specify what Avira setting you were using.

I would use EARLY LOAD, HEURISTICS to MAXIMUM, etc. to have it completely set to the maximum recommended settings for removing malware.

malwarekilla July 25, 2009 at 3:21 am

@Jonathan – UBCD4WIN works fine when scanning an HD with Vista present.

malwarekilla July 25, 2009 at 3:21 am

@123zap – updated signatures are very important.

Jordo July 25, 2009 at 3:36 am

I also had a feeling that someone would do this. And it terminates every .EXE? Wow…

Vasilis July 25, 2009 at 6:00 am

I think Avira Rescue Disk now can update via internet.Big improvement

elliotcroft July 25, 2009 at 9:13 am

I am sure I have run across it twice in the past week. Avira seems to prevent it’s download.

bogdan July 25, 2009 at 11:22 am

Found a link yesterday, Avira Personal doesn’t detect the installer yet. The rogue malfunctions (returns an error) with avira installed, but it still affects the OS. This is another virus killer. After a restart it prevents Avast free and AVG free from starting. Avira Personal starts but the malware stops guardgui.exe (avira will not show warnings on detected files, but it will block them)

MSE detects the installer as: TrojanDld:Win32/FakeVimes

Jonathan July 25, 2009 at 5:47 pm

@malwarekilla – Ok thanks, it must just be my laptop.

Bo July 26, 2009 at 12:32 am

I’ve been using the UBCD, but I find it always missing things. Why? For example, I run SAS on the UBCD and it cleans up what it finds…second scan is clean. I boot to Windows, install SAS and it fins a bunch more things. Why is that? It happens with Antivir and MBAM too. I thought the UBCD had full drive access.

Jonathan July 26, 2009 at 12:43 am

@Bo – Are your definitions/signatures up to date for SAS, Antivir and MBAM on your copy of UBCD4WIN?

You could have a root kit or trojan that downloads even more at start up that you have not cleared with UBCD4WIN.

123zap July 26, 2009 at 1:21 am

@malwarekilla
Well, I mean if you get a rescue disk with updated signatures.

Bo July 26, 2009 at 1:26 am

Yes, I update within UBCD every time. I don’t see how it misses things and then the same program within Windows catches things. This happens on multiple client computers.

Jonathan July 26, 2009 at 2:02 am

@Bo – Is it picking up the same things in windows as it did when using the UBCD4WIN?

Bo July 26, 2009 at 2:09 am

@Jonathan

No…it’s not the same things. That I could see if they were quarantined items, but that’s not the case. It’s new things that the same program running under UBCD missed. It makes no sense at all unless there are certain areas of the drive (i.e. user profile folders) the UBCD doesn’t have access to.

Jonathan July 26, 2009 at 3:27 am

@Bo – I think you have ‘hit the nail on the head’, when you open SAS i am not sure about the other progs on the UBCD4WIN it ask you to load a profile i always load the System profile.

Jose Martins July 26, 2009 at 9:01 am

Hi Matt. Thanks for the alert. It’s a scary rogue!
Do you know if a HIPS like Defense+ is able to neutralize it?
I’ve been noticing the danger rogues represent and the inability of most AV’s to fight them.
PegHorse, in youtube, got KAS 2010 killed by System Security 2009. A disapointment!

Bob July 27, 2009 at 2:02 am

I have been hearing spyware doctor removes the whole rogue pieces and all .

A guy talked about it on his website.
and gave a removal tool

http://www.removaltool.org/Remove-Windows-Security-Suite.html

the removal tool was spyware doctor.

many users commented saying thank you for helping me get rid of Windows Security Suite

sandra July 27, 2009 at 2:37 am

security essentials catches most rouges.
for preventing them is really good but for removing its not all that great.

evgeny July 27, 2009 at 7:05 am

@malwarekila i try to download ubcd4win
and i get “the instaler is blorken…”

Andy L Youtube (coputerman334) October 14, 2009 at 11:26 pm

Looks Like Windows Defender Is that cosidern copyright for using that same style

Leave a Comment

Previous post:

Next post: