Remove MaCatte Antivirus 2009. Description and removal instructions

 
Title: MaCatte Antivirus 2009
Also known as: MaCatte Antivirus, MaCatte
Type: Spyware
Severity scale:MaCatte Antivirus 2009 severity is 72  (72 / 100)
 
MaCatte Antivirus 2009 is a misleading anti-virus application that attempts to impersonate well known and trusted McAfee security software. The rogue application gives false reports of system security threats or infections and displays fake alerts to trick you into purchasing a full version of the program to remove non-existing infections. This is a scam. Do not purchase this bogus application and uninstall MaCatte Antivirus 2009 from your computer upon detection. The graphical user interface of this malware is shown below.

MaCatte Antivirus 2009 graphical user interface
[Figure 1 - MaCatte Antivirus 2009 graphical user interface]

MaCatte Antivirus is promoted through the use of Trojans that comes from fake My Computer online scanners [Figure 2]. Fake online scanners display notifications and alerts stating that your computer is baldy infected with malware, mainly Trojans. One of such fake scanners is http://proscan5.info. Other distribution channels are peer-to-peer networks, newsgroup postings, social networking websites and etc.

MaCatte fake online scanner template
[Figure 2 - MaCatte Antivirus 2009 fake online scanner template]

Once installed, MaCatte Antivirus 2009 will be automatically configured to start system scan each time you log on into Windows. The scan results are of course false. You may safely ignore them. Then the rogue application will prompt you to pay for a full version of the program to remove the threats. To make things worse, MaCatte will display fake security alerts and notifications like every on or two minutes [Figure 3]. It will also impersonate Windows Security Center and state that your computer is unprotected and that you should purchase MaCatte Antivirus 2009 to ensure full system protection. As you may know, the legitimate Windows Security Center does not promote any antivirus software.

MaCatte Antivirus 2009 fake security alerts
[Figure 3 - MaCatte Antivirus 2009 fake security alerts]


Spyware activity alert!
Spyware.IEMonster activity detected. It is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other other programs, including logins and passwords from online baking sessions, eBay, PayPal.

What is more, MaCatte Antivirus 2009 will block currently installed or downloaded anti-virus software. It will hijack your web browser and redirect you to various misleading websites including the rogue program homepage www.macatte.com. If you find that your computer is infected with this malware, please use the removal guide below to remove MaCatte Antivirus from the system manually for free. If you have already purchased it, you should contact your credit card company and dispute the charges.


Related files: mstdll.exe, mcsa.exe, mcsa (in Windows Vista), mcsa, mac.exe, msca.lnk, WPtect.dll, mcull.exe, viruses.dat, mstdl.exe, msca.ico, msc.exe

MaCatte Antivirus 2009 properties:
• Changes browser settings
• Shows commercial adverts
• Stays resident in background

Automatic MaCatte Antivirus 2009 removal:

remover for MaCatte Antivirus 2009

MaCatte Antivirus 2009 manual removal:

Kill processes:
msc.exe mstdl.exe mcull.exe mac.exe
Delete registry values:
HKEY_CURRENT_USER\Software\msca
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{459b6bf8-5320-4c41-8833-85baedf31086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A73890FC-177F-4198-AE3D-C64F7D9E69D8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\NetworkNeighborhood\NameSpace\{459b6bf8-5320-4c41-8833-85baedf31086}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "msca"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wsc"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "msc"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\msca
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPost "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnonBadCertRecving "0"
Unregister DLLs:
WPtect.dll

Delete files:
mac.exe mcsa.exe mstdll.exe msc.exe mcull.exe msca.ico Viruses.dat msca.ico Viruses.dat WPtect.dll msca.lnk
Delete directories:
C:\Program Files\msca\
C:\Users\All Users\Application Data\mcsa
C:\Documents and Settings\All Users\Application Data\msca
C:\Documents and Settings\All Users\Start Menu\Programs\msca
C:\Documents and Settings\%User name%\Local Settings\Temp (delete only mac.exe file in this folder)
C:\Users\%User name%\AppData\Local\Temp\[RANDOM CHARACTERS.tmp]\

Other programs to remove MaCatte Antivirus 2009:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 05/11/09
Information updated: 06/11/09

Additional resources related to MaCatte Antivirus 2009:

Attention: If you know or you have a website or page about MaCatte Antivirus 2009 removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about MaCatte Antivirus 2009 parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: