Virus.BAT.Gary.705
Virus.BAT.Gary.705 Description
Virus.BAT.Gary.705 is a fake security notification created and issued by the rogue anti-spyware program called Windows Security Suite. Virus.BAT.Gary.705 is portrayed as being a threatening parasite in the falsified security alerts, though this is far from the truth. These Virus.BAT.Gary.705 pop-up windows read as follows:
“Your computer is infected. Warning! Spyware found! Detected: Spyware; File Name: exec.sys; Name: Virus.BAT.Gary.705… This is a dangerous non-memory resident BAT infector. It writes itself to the end of C:\AUTOEXEC.BAT file.”
Virus.BAT.Gary.705 is nothing to be concerned about; however these security alerts will not go away until the user accepts the prompts and purchases Windows Security Suite, or until he removes both of these annoyances from the computer.
Type: Fake Warning Messages
Automatic Detection of Virus.BAT.Gary.705
Virus.BAT.Gary.705 has typically the following processes in memory:
- %UserProfile%\Recent\std.exe
- %UserProfile%\Recent\runddl.dll
- %UserProfile%\Recent\grid.dll
- c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll
- %UserProfile%\Recent\grid.sys
- %UserProfile%\Recent\CLSV.exe
- %UserProfile%\Recent\kernel32.dll
- %UserProfile%\Recent\PE.dll
- %UserProfile%\Recent\energy.dll
- %UserProfile%\Recent\dudl.sys
- c:\Documents and Settings\All Users\Application Data\345d567\WI345d.exe
- %UserProfile%\Recent\snl2w.exe
- %UserProfile%\Recent\SM.dll
- %UserProfile%\Recent\tempdoc.dll
- c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll
Virus.BAT.Gary.705 creates the following registry entries:
- HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “698909210803″
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Windows Security Suite”
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
Important Article Disclaimer


English 

Virus.BAT.Gary.705 










