Home Malware Programs Rogue Anti-Spyware Programs Windows Telemetry Center

Windows Telemetry Center

Posted: February 22, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 35
First Seen: February 22, 2012
Last Seen: January 8, 2020
OS(es) Affected: Windows

Windows Telemetry Center Screenshot 1Windows Telemetry Center is a fake anti-malware scanner that includes inaccurate warnings about the presence of high-level PC threats that actually aren't on your computer. Windows Telemetry Center's appearance may look professional and appear to be that of normal security software, but SpywareRemove.com malware researchers have observed that Windows Telemetry Center is, in both looks and functions, a clone of similar examples of scamware from the FakeVimes family. Since Windows Telemetry Center may also block unrelated applications under false premises of them being infected or damaged, you should consider Windows Telemetry Center to be no better than a Trojan or virus itself and remove Windows Telemetry Center by using your pick of real anti-malware software.

Windows Telemetry Center – a Foothold of Fraud on Your PC

Although Windows Telemetry Center's name, marketing and supposed update features all imply that Windows Telemetry Center is a legitimate anti-malware program that uses regularly updated threat definitions to detect and uproot malicious software, SpywareRemove.com malware analysts note contrarily that Windows Telemetry Center actually is a fairly self-contained application. Windows Telemetry Center doesn't have a genuine database of definitions for PC threats, nor does Windows Telemetry Center truly attempt to detect viruses, Trojans or other types of harmful software during its scans. Instead, scans and a variety of pop-up alerts are created automatically with randomly-generated warnings to create the illusion that your PC is always under the looming shadow of multiple infections.

Alerts from Windows Telemetry Center can take a wide range of seemingly-official formats, as noted in the samples below:

Warning! Database update failed!
Database update failed!
Outdated viruses databases are not effective and can't [sic] guarantee adequate protection and security for your PC!
Click here to get the full version of the product and update the database!

Warning! Running trial version!
The security of your computer has been compromised!
Now running trial version of the software!
Click here to purchase the full version of the software and get full protection for your PC!

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

Warning!
Name: [Application file name]
Name: [Application file path]
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

Warning!
Location: [Application file path]
Viruses: Backdoor.Win32.Rbot

Spending money on Windows Telemetry Center is unnecessary to bring a halt to its machinations, and SpywareRemove.com malware analysts generally discourage it, since Windows Telemetry Center not only wastes money on a fraudulent program, but may give criminals access to your financial information for future attacks. Any sign of Windows Telemetry Center's presence in your PC should be reacted to via anti-malware scans from appropriate software that can remove both Windows Telemetry Center and any other PC threats that may be related to its presence.

Breaking Down the Windows Telemetry Center Blockade

Windows Telemetry Center and similar members of its family are also capable of shutting down unrelated applications without your permission (including Privacy Guard Pro, PrivacyGuard Pro 2.0, Extra Antivirus, Fast Antivirus 2009, Presto TuneUp, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, Live PC Care, PC Live Guard, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus and Smart Security. Since Windows Telemetry Center launches itself automatically during Windows' startup process and can constantly scan your computer's memory for processes to shut down, this may interfere with your usage of a broad swathe of different programs. Instant messengers, script packages, Google and Adobe-brand products and even the Registry Editor are all likely to be blocked by Windows Telemetry Center.

However, booting your PC into Safe Mode with Networking, switching to a separate OS or booting Windows from a removable device will allow you to scan your computer without Windows Telemetry Center being launched. SpywareRemove.com malware researchers recommend that you use such techniques during scans whenever possible even if Windows Telemetry Center allows you to open your anti-malware software, since doing so will insure that other PC threats will not remain active to interfere with the deletion of Windows Telemetry Center.

Windows Telemetry Center Screenshot 2Windows Telemetry Center Screenshot 3Windows Telemetry Center Screenshot 4Windows Telemetry Center Screenshot 5Windows Telemetry Center Screenshot 6Windows Telemetry Center Screenshot 7

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Protector-guq.exe File name: Protector-guq.exe
Size: 2.14 MB (2147762 bytes)
MD5: c9613998ed8847b4f562a437d8716c5c
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 8, 2020
%AppData%\result.db File name: %AppData%\result.db
Mime Type: unknown/db
Group: Malware file
%AppData%\npswf32.dll File name: %AppData%\npswf32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%AppData%\Inspector-[3 RANDOM CHARACTERS].exe File name: %AppData%\Inspector-[3 RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DesktopDir%\Windows Telemetry Center.lnk File name: %DesktopDir%\Windows Telemetry Center.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%StartMenu%\Programs\Windows Telemetry Center.lnk File name: %StartMenu%\Programs\Windows Telemetry Center.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe

Additional Information

The following messages's were detected:
# Message
1Error Keylogger activity detected. System information security is at risk. It is recommended to activate protection and run a full system scan.
2Error Software without a digital signature detected. Your system files are at risk. We strongly advise you to activate your protection.
3Warning Firewall has blocked a program from accessing the Internet. Windows Media Player Resources C:\Windows\system32\dllcache\wmploc.dll C:\Windows\system32\dllcache\wmploc.dll is suspected to have infected your PC. This type of virus intercepts entered data and transmits them to a remote server.

Loading...