Virus.BAT.Gary.705

Virus.BAT.Gary.705 is a fake security notification created and issued by the rogue anti-spyware program called Windows Security Suite. Virus.BAT.Gary.705 is portrayed as being a threatening parasite in the falsified security alerts, though this is far from the truth. These Virus.BAT.Gary.705 pop-up windows read as follows:

"Your computer is infected. Warning! Spyware found! Detected: Spyware; File Name: exec.sys; Name: Virus.BAT.Gary.705... This is a dangerous non-memory resident BAT infector. It writes itself to the end of C:\AUTOEXEC.BAT file."

Virus.BAT.Gary.705 is nothing to be concerned about; however these security alerts will not go away until the user accepts the prompts and purchases Windows Security Suite, or until he removes both of these annoyances from the computer.

File System Details

Virus.BAT.Gary.705 may create the following file(s):
# File Name Detections
1. %UserProfile%\Recent\std.exe
2. %UserProfile%\Recent\runddl.dll
3. %UserProfile%\Recent\grid.dll
4. C:\Documents and Settings\\Application Data\345d567\mozcrt19.dll
5. %UserProfile%\Recent\grid.sys
6. %UserProfile%\Recent\CLSV.exe
7. %UserProfile%\Recent\kernel32.dll
8. %UserProfile%\Recent\PE.dll
9. %UserProfile%\Recent\energy.dll
10. %UserProfile%\Recent\dudl.sys
11. C:\Documents and Settings\\Application Data\345d567\WI345d.exe
12. %UserProfile%\Recent\snl2w.exe
13. %UserProfile%\Recent\SM.dll
14. %UserProfile%\Recent\tempdoc.dll
15. C:\Documents and Settings\\Application Data\345d567\sqlite3.dll
16. C:\Documents and Settings\\Application Data\345d567
17. %UserProfile%\Application Data\Windows Security Suite\Instructions.ini
18. c:\Program Files\Mozilla Firefox\searchplugins\search.xml
19. C:\Documents and Settings\\Application Data\345d567\working.log
20. %UserProfile%\Application Data\Windows Security Suite\cookies.sqlite
21. %UserProfile%\Desktop\Windows Security Suite.lnk
22. c:\ADWARE_LOG
23. C:\Documents and Settings\\Application Data\WINSSSys
24. C:\Documents and Settings\\Application Data\WINSSSys\winss.cfg
25. C:\Documents and Settings\\Application Data\345d567\WINSS.ico
26. %UserProfile%\Recent\DBOLE.drv
27. %UserProfile%\Start Menu\Programs\Windows Security Suite.lnk
28. %UserProfile%\Start Menu\Windows Security Suite.lnk
29. %UserProfile%\Application Data\Windows Security Suite
30. C:\Documents and Settings\\Application Data\345d567\WINSSSys
31. C:\Documents and Settings\\Application Data\345d567\WINSSSys\vd952342.bd
32. C:\Documents and Settings\\Application Data\345d567\26.mof
33. %UserProfile%\Recent\ANTIGEN.drv
34. %UserProfile%\Recent\PE.tmp
35. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Security Suite.lnk

Registry Details

Virus.BAT.Gary.705 may create the following registry entry or registry entries:
HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "698909210803"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Security Suite"
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}

Trending

Most Viewed

Loading...