1 of 4
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Slow internet connection
  • Annoying Pop-up's
  • Slow Computer

Windows Accelerating Utility

Windows Accelerating Utility is a new rogue antispyware application. It is distributed via various methods and can enter your computer with a Trojan infection. That is the reason, why you must be careful while opening unknown websites, or clicking on links which you have no information about. Cyber criminals find many ways to extort and abuse unsuspecting computer users, so Internet safety is the first safeguard against Windows Accelerating Utility infection. However, sometimes the lack of luck might lead to the infection, and if you get Windows Accelerating Utility in your system, you need to know how to deal with it.

Download Spyware Removal Tool to Remove* Windows Accelerating Utility
  • Quick & tested solution for Windows Accelerating Utility removal.
  • 100% Free Scan for Windows

The first thing which tells you that something is wrong is a message that you have been infected by Uknown Win32/Trojan. This is just a first symptom, and Windows Accelerating Utility hasn’t rooted in your computer, but this message will urge you to find out more:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

If you click on “show details”, then the infection will initiate a quick computer scan (which is obviously fake), and afterwards it will tell you, that your computer is at risk, because you have caught Trojan.Horse.Win32.PAV.64.a. Then it will really prompt you to get Windows Accelerating Utility program in order to check for any other errors in your computer, with this message:

Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a serious possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

Windows Accelerating Utility is downloaded and installed in your computer once you click “OK” button. Then the rouge automatically runs a fake system scan, and finds multiple errors, which it offers to fix immediately. However, if you choose the “Fix Errors” option, Windows Accelerating Utility asks to purchase the full version of the program. You cannot do that, because that way you would expose your bank account to third parties. You cannot also allow this rogue to remain in your computer, because it slows down your computer performance and can eventually cause a system crash.

You need to remove Windows Accelerating Utility using a suggested malware scanner, because manual rogue removal requires advanced IT skills. Make sure you erase this rogue efficiently from your computer and safeguard it against future attacks.

Download Spyware Removal Tool to Remove* Windows Accelerating Utility
  • Quick & tested solution for Windows Accelerating Utility removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows Accelerating Utility

Files associated with infection (Windows Accelerating Utility):

%AppData%\Microsoft\[random].exe

Processes to kill (Windows Accelerating Utility):

%AppData%\Microsoft\[random].exe

Remove registry entries (Windows Accelerating Utility):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\afwserv.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastsvc.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe "Debugger" = 'svchost.exe'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe "Debugger" = 'svchost.exe'
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.