Vz.exe

Vz.exe is a system name for fake anti-spyware disguised as an automatically installed Windows update. When inside a computer, Vz.exe will determine whether it should drop adware under the XP, Vista or Win 7 name. If Vz.exe infects a Vista system it will drop rogueware such as Vista Antimalware 2011 and coerce a victim into paying for the rogue. Use a reliable security tool to remove Vz.exe and associated malware from your PC as soon as possible.

File System Details

Vz.exe may create the following file(s):
# File Name Detections
1. %AppData%\vz.exe
2. %AppData%\{RANDOM}

Registry Details

Vz.exe may create the following registry entry or registry entries:
[HKEY_CLASSES_ROOT\.exe\shell\open\command]
"Content Type"="application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
HKEY_CURRENT_USER\Software\Classes\pezfile\shell
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\runas
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\start\command
HKEY_CURRENT_USER\Software\Classes\.exe | @ = "pezfile"
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | IsolatedCommand = ""%1″ %"
[HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
@="exefile"
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
HKEY_CURRENT_USER\Software\Classes\pezfile\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\start
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = ""%1" %*"
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command | @ = ""%AppData%\vz.exe" /START "%1" %*"
[HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[HKEY_CLASSES_ROOT\.exe]
[HKEY_CLASSES_ROOT\secfile]
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\pezfile
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = ""%AppData%\vz.exe" /START "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = "application/x-msdownload"

Trending

Most Viewed

Loading...