SafePcAv
SafePcAv Description
SafePcAv is a rogue anti-spyware application that is known to block .exe files and carry out a multitude of illicit actions to entice purchase. SafePcAv usually mimics a security program for PC’s where it displays popup messages warning computer users of a detected threat. In addition, SafePcAv will perform fake system scans only to return bogus parasite results.
SafePcAv or Safe Pc Av, is a clone of Windows Antivirus Pro, another fake security application. Fake security programs such as SafePcAv can potentially cause damage to a system’s registry making the computer run slowly or behave abnormally. It is best to detect and remove SafePcAv with a spyware detection application to limit potential damage to the effected computer.
Type: Spyware
How Can You Detect SafePcAv?
SafePcAv Technical Report
As new SafePcAv details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following SafePcAv files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| dkj9kaj5.exe | 1731956 | 7a0898d231890287beb0504889a6ddb0 |
| setup[1].exe | 63472 | 402e7908c2454bb6767cc2d16ab8a3ea |
| czg9s4nv.exe | 46 | 62f3fbcf504567c1c53530e16b3299bf |
| setup[1].exe | 46 | 62f3fbcf504567c1c53530e16b3299bf |
| SafePcAv.exe | 1632768 | 2a27baeb6e4f14d94fe7024e42e18c02 |
SafePcAv has typically the following processes in memory:
- SafePcAv.exe
- %Program Files%\SafePcAv Software\SafePcAv\uninstall.exe
- %Program Files%\SafePcAv Software\SafePcAv\SafePcAv.exe
SafePcAv created the following directories, files, paths:
- %ProgramFiles%\SafePcAv Software\SafePcAv
- %AllUsersProfile%\Start Menu\Programs\SafePcAv
SafePcAv creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafePcAv
- HKEY_LOCAL_MACHINE\SOFTWARE\SafePcAv
- HKEY_CURRENT_USER\Software\SafePcAv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “SafePcAv”
Important Article Disclaimer

SafePcAv 










