Registry Virus Scanner Description
Registry Virus Scanner is a fake registry optimization application and defragmenter from the FakeRean family that is part of a well-known online scam. Fake security programs and defragmenters are some of the most common malware infections which, although currently in decline, still form the majority of malware infections worldwide. Programs like Registry Virus Scanner are designed to cause problems on your computer system and then pester you with a barrage of fake error messages and alarming security alerts. These notifications will make the victim believe that the computer system is severely infected and that the best solution is to purchase a full copy of Registry Virus Scanner. ESG PC security researchers strongly recommends against downloading or installing Registry Virus Scanner on your computer system. Most problems on the infected computer are caused by Registry Virus Scanner itself. This is because Registry Virus Scanner contains no anti-malware or defragmenting capabilities. Rather, Registry Virus Scanner is composed of malicious scripts, Trojans and a flashy interface to perpetrate its scam.
How the Registry Virus Scanner Scam Works
Fake defragmenters and system optimization programs are a severe problem for malware analysts. There are countless versions of programs similar to Registry Virus Scanner, such as Windows Antivirus 2008, Vista Antivirus 2008, Antivirus Pro 2009, AntiSpy Safeguard, ThinkPoint, Spyware Protection 2010, Internet Antivirus 2011, Palladium Pro, XP Anti-Virus 2011, CleanThis, PC Clean Pro, XP Home Security 2012, Windows Clear Problems, XP Security 2012, Antivirus PRO 2015. These rogue security programs all use the same scan: they cause problems on the infected computer and then attempt to convince the victim to purchase a useless anti-malware or defragmenter solution. The Registry Virus Scanner rogue security program is able to make damaging changes to the Windows Registry and to the operating system's system settings. Due to these changes, Registry Virus Scanner can be quite difficult to remove completely. Usually, a strong, reliable, anti-malware tool is needed, in order to eradicate this threat from your computer system completely. Registry Virus Scanner has the capacity to block some of the most popular anti-malware applications as well as blocking access to the Internet, so it may also be necessary to start up Windows in Safe Mode. It is also important to understand that malware like Registry Virus Scanner almost never attacks alone. In fact, with the help of a Trojan designed to drop malicious applications onto its victim's hard drive, Registry Virus Scanner is able to infect a computer system. Because of this, it is a good idea to make sure that your sensitive data or personal information have not been compromised once you have removed Registry Virus Scanner from your computer.
Technical Information
File System Details
# | File Name | Size | MD5 | Detection Count |
---|---|---|---|---|
1 | %LOCALAPPDATA%7k5mp.exe | 82,432 | d1cf5bbf6c71aff081d89bcaae1248a9 | 10 |
2 | %LOCALAPPDATA%aririt.exe | 265,216 | 71540581d851d83f2e5c0bf398d5ed1b | 8 |
3 | %SystemDrive%\Documents and Settings\Harold Kallam\Local Settings\Application Data\rrvdaekt.exe | 82,432 | 5e7bce222e4d93cd0e4ec24ba12a562f | 5 |
4 | %LOCALAPPDATA%aauqobnb.exe | 82,432 | 48ba1563cbe0aa437a61844153d11c87 | 5 |
5 | %WINDIR%\Installer\{1BAB6219-5EBA-42B7-97CF-33CFB6224837}\msiexec.exe | 82,432 | be4fe5f94ee3e537bd364c1fe37cbfb8 | 3 |
6 | %LOCALAPPDATA%bwhviujc.exe | 82,432 | 34009b0cc5d10ded9f7c02ffbe03e6ce | 2 |
7 | %LOCALAPPDATA%ioundltt.exe | 82,944 | c209a9ca6f2943aa4554cdea599219ad | 2 |
8 | %LOCALAPPDATA%qx98w2d30d.exe | 82,432 | 90e109518c30037dff61d9c41ce1b7a4 | 2 |
9 | %LOCALAPPDATA%izc73.exe | 82,432 | 5572a9bac1c0af731eb2c3b919ab8504 | 2 |
10 | %LOCALAPPDATA%ebbnqthl.exe | 82,432 | b146d931ef456c135720796bb049870b | 2 |
11 | %LOCALAPPDATA%ac0mb4mzg.exe | 82,432 | a9341756e9e1f98c30f56d3802827b41 | 2 |
12 | %LOCALAPPDATA%todtarwg.exe | 82,432 | f19a2b485a53272aadda1038d3cafa36 | 1 |
13 | %SystemDrive%\Users\RNC7\AppData\Local\5cji4z.exe | 82,432 | 922a92c0737e65ff3b03891cff50c37a | 1 |
14 | %LOCALAPPDATA%cfwdufiv.exe | 82,432 | 062f6ea128d113a9e52e8c072d4884a0 | 1 |
15 | %TEMP%0a537219.exe | 82,432 | d0cc584abb264ab3b5707af35823db65 | 1 |
16 | %PROGRAM_FILES%\Registry Virus Scanner | N/A | ||
17 | c:\Documents and Settings\All Users\Registry Virus Scanner\ | N/A | ||
18 | c:\Documents and Settings\All Users\Start Menu\Registry Virus Scanner\ | N/A | ||
19 | 00f4bfab95685556e658bb5812900686f0837c285fee502860b8a03d2897a9f2.exe | 82,432 | e3d6e4af9bdb2bd2baf9b7b76fb88f7a | 0 |
20 | 16dac8c82038918c46592900157fdb8c8cc7d5a0085c545ac72f6a96f1f45f2c.exe | 82,432 | 5aaa58a91b90cfa93a4ca599ae4b9829 | 0 |
21 | 339e1ca336b0cf97e0b94218d58c8304287bd932439f7e7dcf6d42febc79b8fa.exe | 82,432 | 62417af4ee2bdbd5c9c8955b7dedebc2 | 0 |
22 | 42f7d9efed3d944fe1671034cc60673ea9e14d03f7e59ca8aa68ae0dc15c5d3f.exe | 82,432 | fab108e9fcdc8c26f00380772b6e4fa6 | 0 |
23 | 4afa8b782bf3bfd6b72985538e369708244bacf03a5c35b5f2ca60ce2c45c037.exe | 82,944 | 55fd4f673d7c1cd098b1444187cc1a21 | 0 |
24 | 4e9d7f6f18d2a7d40e0eac1daa8e8fb22e1c509defe7ec4f793f8acc0231128a.exe | 82,432 | 3f8f3f7676d8155849dc0c58f7e94dbb | 0 |
25 | 504e4c9af0115eb3dbc8c8c0646bbf5c2decc05b6e3ee25a1d23593befe29278.exe | 82,432 | 3578f24f00bfdfe107703bfd488f1720 | 0 |
26 | 888bb2f01d52ab5a1eada119ab8d68316ab8dbc2bf97b8f22cfdbc023f1443fa.exe | 82,432 | 759d125106bd4c4b1b438f8a24fa1e45 | 0 |
27 | cf50de9f0d30d4fbffcf30865a054bd153cc8f9c394b66bccb4cb6a1ef712ada.exe | 82,944 | 585d6eb842385840ea332cf62ff1adc3 | 0 |
28 | e296f023f0155ff870c76e7e646c64e4f37b7a324dbbc370d3aef2d258e18e07.exe | 82,944 | 4e4ce4a8e68b9e6ae4fa823ed8e330b6 | 0 |
29 | e6b3574875564ccf177f3550185ba7466808b25120dfdd5e661145c4bf2534a3.exe | 82,944 | 35520a42bd81730f7d2d497324b45ca1 | 0 |
30 | f75fe7436c7a8f966793ef36bf91e69aa597650a9e16b4db1235b94e6dfc13c7.exe | 82,432 | 0825d6e70acfbe209dfc79fe0278edfa | 0 |
31 | f80b225563e6c5e9babcb63d355c7e384abaa32ddcd131b373b1a37c78d13d08.exe | 82,432 | dad3d265882d724ddab646b44f477274 | 0 |
Registry Details
Site Disclaimer
This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.