1 of 3
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Slow internet connection
  • Annoying Pop-up's
  • Slow Computer
Other mutations known as:
WindowsSystemTasks

Windows System Tasks

There are always constant streams of serious threats to healthy PCs, and the only way to protect your PC against security threats such as Windows System Tasks and similar threats is by investing in properly functioning security software. This rogue antispyware application in particular forms part of the Fake Microsoft Security Essentials scam, and derives from the same family of rogues as Windows Activity Inspector and Windows Protection Tasks. It will work hard to convince its victims of its legitimacy, but Windows System Tasks certainly has no ability to detect or remove any type of threat from the system.

Download Spyware Removal Tool to Remove* Windows System Tasks
  • Quick & tested solution for Windows System Tasks removal.
  • 100% Free Scan for Windows

Windows System Tasks makes use of various established forms of infection, and will remain hidden on the system until it is ready to start its attack. Seditious browser hijacking websites and bogus online malware scanners are only some of the elements which form part of Windows System Tasks’ online marketing campaign.

The user will remain largely unaware of Windows System Tasks’ presence, and this will only change when it is ready to reveal itself to the user. Because of the rogue’s sly infiltration of the system, the user will find it difficult to identify and remove Windows System Tasks without some help. The first clue the user will have as to the presence of Windows System Tasks on the system will come when the rogue initiates a fake system scan. This rubbish system scan will report on various fake threats supposedly crippling the system, such as Unknown Win32/Trojan, or Backdoor.Win32.Rbot which supposedly infects c:\windows\system32\taskmgr.exe. None of the information received from can be trusted, and should always be regarded as extremely suspect in nature.

As a further attack on the system Windows System Tasks will prevent the user from being able to connect to the Internet, as well as make it impossible to run any programs on the system. This is done in an effort to prevent the user from downloading or running any application which may be able to get rid of Windows System Tasks. Poor system performance and increased erratic system behavior has also been widely reported. Windows System Tasks will proceed to constantly barrage the user with various false security pop ups, such as the following:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

Warning!
Location: c:\windows\system32\taskmgr.exe
Viruses: Backdoor.Win32.Rbot

Do not fall for the vindictive and clever lies of this rogue application. Take back your PC and destroy Windows System Tasks before it destroys your system. This can easily be achieved by making use of a genuine security tool which will not only annihilate Windows System Tasks but also protect against similar future attacks.

Download Spyware Removal Tool to Remove* Windows System Tasks
  • Quick & tested solution for Windows System Tasks removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows System Tasks

Files associated with infection (Windows System Tasks):

%AppData%\Microsoft\[random].exe

Processes to kill (Windows System Tasks):

%AppData%\Microsoft\[random].exe

Remove registry entries (Windows System Tasks):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
Disclaimer

Comments

  1. MARTIN May 19, 2011

    you very much! This is the only working description for this problem.

  2. James May 19, 2011

    Thank you very much! This is the only working description for this

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.