SiteVillain
SiteVillain Description
SiteVillain, also known as Site Villain, is a fraudulent security application from the same malicious rogueware family as AntiAID. SiteVillain attempts to convince victims to purchase it by tricking them into believing that numerous parasite infections were detected on their computers. SiteVillain will conduct a fake scan, display random warning and alert messages as well as display annoying pop-ups in order to scare a victim. Site Villain may enter a computer system via a sneaky Trojan that can exploit security vulnerabilities. Site Villain can deteriorate the performance of an operating system; therefore it should be removed immediately after it is detected.
Type: Rogue AntiSpyware Programs
How Can You Detect SiteVillain?
SiteVillain Technical Report
As new SiteVillain details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following SiteVillain files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| setup[1].exe | 1734072 | 51deebf6100c7826265a0f4292bba733 |
| setup[2].exe | 373760 | 61754587a03d1d05466f0c6c68e11431 |
| SiteVillain.exe | 1634304 | dc960cd129e8a4181b3f9973c2a74a14 |
SiteVillain has typically the following processes in memory:
- %Temp%\2gbk87zj.exe
- %Program Files%\SiteVillain Software\SiteVillain\uninstall.exe
- SiteVillain.exe
- %Program Files%\SiteVillain Software\SiteVillain\SiteVillain.exe
- %Temp%\8enyqcv1.exe
SiteVillain created the following directories, files, paths:
- %AllUsersProfile%\Start Menu\Programs\SiteVillain
- %ProgramFiles%\SiteVillain Software\SiteVillain
SiteVillain creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\SiteVillain
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “%ProgramFiles%\SiteVillain Software\SiteVillain\SiteVillain.exe -min”
- SiteVillain
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “%System%\8enyqcv1.exe”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SiteVillain
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
SiteVillain 










