Registry Virus Scanner

Registry Virus Scanner Description

Registry Virus Scanner is a fake registry optimization application and defragmenter from the FakeRean family that is part of a well-known online scam. Fake security programs and defragmenters are some of the most common malware infections which, although currently in decline, still form the majority of malware infections worldwide. Programs like Registry Virus Scanner are designed to cause problems on your computer system and then pester you with a barrage of fake error messages and alarming security alerts. These notifications will make the victim believe that the computer system is severely infected and that the best solution is to purchase a full copy of Registry Virus Scanner. ESG PC security researchers strongly recommends against downloading or installing Registry Virus Scanner on your computer system. Most problems on the infected computer are caused by Registry Virus Scanner itself. This is because Registry Virus Scanner contains no anti-malware or defragmenting capabilities. Rather, Registry Virus Scanner is composed of malicious scripts, Trojans and a flashy interface to perpetrate its scam.
 

How the Registry Virus Scanner Scam Works

Fake defragmenters and system optimization programs are a severe problem for malware analysts. There are countless versions of programs similar to Registry Virus Scanner, such as Windows Antivirus 2008, Vista Antivirus 2008, PC Clean Pro, Antivirus Pro 2009, AntiSpy Safeguard, ThinkPoint, Spyware Protection 2010, Internet Antivirus 2011, Palladium Pro, XP Anti-Virus 2011, CleanThis, XP Home Security 2012, Windows Clear Problems, XP Security 2012, Antivirus PRO 2015. These rogue security programs all use the same scan: they cause problems on the infected computer and then attempt to convince the victim to purchase a useless anti-malware or defragmenter solution. The Registry Virus Scanner rogue security program is able to make damaging changes to the Windows Registry and to the operating system's system settings. Due to these changes, Registry Virus Scanner can be quite difficult to remove completely. Usually, a strong, reliable, anti-malware tool is needed, in order to eradicate this threat from your computer system completely. Registry Virus Scanner has the capacity to block some of the most popular anti-malware applications as well as blocking access to the Internet, so it may also be necessary to start up Windows in Safe Mode. It is also important to understand that malware like Registry Virus Scanner almost never attacks alone. In fact, with the help of a Trojan designed to drop malicious applications onto its victim's hard drive, Registry Virus Scanner is able to infect a computer system. Because of this, it is a good idea to make sure that your sensitive data or personal information have not been compromised once you have removed Registry Virus Scanner from your computer.

Technical Information

File System Details

Registry Virus Scanner creates the following file(s):
# File Name Size MD5 Detection Count
1 %LOCALAPPDATA%7k5mp.exe 82,432 d1cf5bbf6c71aff081d89bcaae1248a9 10
2 %LOCALAPPDATA%aririt.exe 265,216 71540581d851d83f2e5c0bf398d5ed1b 8
3 %SystemDrive%\Documents and Settings\Harold Kallam\Local Settings\Application Data\rrvdaekt.exe 82,432 5e7bce222e4d93cd0e4ec24ba12a562f 5
4 %LOCALAPPDATA%aauqobnb.exe 82,432 48ba1563cbe0aa437a61844153d11c87 5
5 %WINDIR%\Installer\{1BAB6219-5EBA-42B7-97CF-33CFB6224837}\msiexec.exe 82,432 be4fe5f94ee3e537bd364c1fe37cbfb8 3
6 %LOCALAPPDATA%bwhviujc.exe 82,432 34009b0cc5d10ded9f7c02ffbe03e6ce 2
7 %LOCALAPPDATA%ioundltt.exe 82,944 c209a9ca6f2943aa4554cdea599219ad 2
8 %LOCALAPPDATA%qx98w2d30d.exe 82,432 90e109518c30037dff61d9c41ce1b7a4 2
9 %LOCALAPPDATA%izc73.exe 82,432 5572a9bac1c0af731eb2c3b919ab8504 2
10 %LOCALAPPDATA%ebbnqthl.exe 82,432 b146d931ef456c135720796bb049870b 2
11 %LOCALAPPDATA%ac0mb4mzg.exe 82,432 a9341756e9e1f98c30f56d3802827b41 2
12 %LOCALAPPDATA%todtarwg.exe 82,432 f19a2b485a53272aadda1038d3cafa36 1
13 %SystemDrive%\Users\RNC7\AppData\Local\5cji4z.exe 82,432 922a92c0737e65ff3b03891cff50c37a 1
14 %LOCALAPPDATA%cfwdufiv.exe 82,432 062f6ea128d113a9e52e8c072d4884a0 1
15 %TEMP%0a537219.exe 82,432 d0cc584abb264ab3b5707af35823db65 1
16 %PROGRAM_FILES%\Registry Virus Scanner N/A
17 c:\Documents and Settings\All Users\Registry Virus Scanner\ N/A
18 c:\Documents and Settings\All Users\Start Menu\Registry Virus Scanner\ N/A
19 00f4bfab95685556e658bb5812900686f0837c285fee502860b8a03d2897a9f2.exe 82,432 e3d6e4af9bdb2bd2baf9b7b76fb88f7a 0
20 16dac8c82038918c46592900157fdb8c8cc7d5a0085c545ac72f6a96f1f45f2c.exe 82,432 5aaa58a91b90cfa93a4ca599ae4b9829 0
21 339e1ca336b0cf97e0b94218d58c8304287bd932439f7e7dcf6d42febc79b8fa.exe 82,432 62417af4ee2bdbd5c9c8955b7dedebc2 0
22 42f7d9efed3d944fe1671034cc60673ea9e14d03f7e59ca8aa68ae0dc15c5d3f.exe 82,432 fab108e9fcdc8c26f00380772b6e4fa6 0
23 4afa8b782bf3bfd6b72985538e369708244bacf03a5c35b5f2ca60ce2c45c037.exe 82,944 55fd4f673d7c1cd098b1444187cc1a21 0
24 4e9d7f6f18d2a7d40e0eac1daa8e8fb22e1c509defe7ec4f793f8acc0231128a.exe 82,432 3f8f3f7676d8155849dc0c58f7e94dbb 0
25 504e4c9af0115eb3dbc8c8c0646bbf5c2decc05b6e3ee25a1d23593befe29278.exe 82,432 3578f24f00bfdfe107703bfd488f1720 0
26 888bb2f01d52ab5a1eada119ab8d68316ab8dbc2bf97b8f22cfdbc023f1443fa.exe 82,432 759d125106bd4c4b1b438f8a24fa1e45 0
27 cf50de9f0d30d4fbffcf30865a054bd153cc8f9c394b66bccb4cb6a1ef712ada.exe 82,944 585d6eb842385840ea332cf62ff1adc3 0
28 e296f023f0155ff870c76e7e646c64e4f37b7a324dbbc370d3aef2d258e18e07.exe 82,944 4e4ce4a8e68b9e6ae4fa823ed8e330b6 0
29 e6b3574875564ccf177f3550185ba7466808b25120dfdd5e661145c4bf2534a3.exe 82,944 35520a42bd81730f7d2d497324b45ca1 0
30 f75fe7436c7a8f966793ef36bf91e69aa597650a9e16b4db1235b94e6dfc13c7.exe 82,432 0825d6e70acfbe209dfc79fe0278edfa 0
31 f80b225563e6c5e9babcb63d355c7e384abaa32ddcd131b373b1a37c78d13d08.exe 82,432 dad3d265882d724ddab646b44f477274 0

Registry Details

Registry Virus Scanner creates the following registry entry or registry entries:
RegistryKey
HKEY_LOCAL_MACHINE\Software\Registry Virus Scanner
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Registry Virus Scanner"

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.