Description of Windows User Satellite and consequences of its residing on your PC

The adware is mostly known as Windows platform targeting threat.  It is not compatible with other operating systems, but is known to be unsafe for them.

Windows User Satellite Technical Details:

  • Full name: Windows User Satellite, Windows UserSatellite, WindowsUserSatellite
  • Version: 2011
  • Type: Rogue anti-spyware
  • Origin: Russian federation

Signs of being infected with Windows User Satellite:

Once your PC is infected with the infection to be classified as Windows User Satellite, the adware installation  may become evident instantly or the time between installation and first sign that any users can understand as a sign of the adware in question may last up to several dozens of hours.
An evident for any users sign of the adware is its popup that states it is generated by Windows User Satellite, for instance,  fake scan window generated by the program. Less evident sign of the threat infiltration is a popup suggesting to trust and use it, such as fake system alert. Third rate signs of the adware are popups without any occurrence of the adware name. However, they directly or through the set of popups lead to the website  dedicated to Windows User Satellite.
Negative system changes can hardly be considered as the particular adware signs of presence, for they are the same for many other threats, too.
Windows User Satellite automatical removal:

It is important to know the way the rogue has been introduced. This gives a clue whether  your PC has vulnerabilities that have enabled the adware infiltration.  In the other words, Windows User Satellite removal without overall system optimization, vulnerabilities detecting and patching covered, seems to be rather unreasonable unless the rogue antispyware has been installed in agreement with you (the way  users have been suggested to provide the agreement is not considered here).

Manual Removal of Windows User Satellite:

There is a great risk related to manual procedure of the adware extermination. Check properly your manual detections of the adware entries against the list of its entries specified below. Otherwise deletion of entries other than specified may appear to be a critical system files deletion with relevant consequences.

Remove Windows User Satellite files and dll’s:

%UserProfile%\Application Data\<random>.exe

Unregister Windows User Satellite registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell” = ‘%UserProfile%\Application Data\<random>.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe “Debugger” = ‘svchost.exe’

Windows User Satellite