Windows PC Aid

Windows PC Aid Image

Windows PC Aid is a fake anti-virus program that is created to cheat PC users and swindle them out of their money. Windows PC Aid attempts to fool PC users into thinking their machines have been corrupted by numerous malware threats. After that, Windows PC Aid urges PC users to buy its so-called full edition, which would allegedly remove found PC infections. Windows PC Aid is advertised through the use of Trojans. Once installed on the affected machine, Trojans will download and install Windows PC Aid onto your computer. When Windows PC Aid is running, it will execute a fictitious system scan and display a list of fabricated malware infections.

Windows PC Aid is part of the FakeVimes family. Other members of the FakeVimes family that are clones of Windows PC Aid include Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst.

PC Aid will also bombard your desktop with falsified warning messages that state your computer is at risk. Windows PC Aid will hijack your web browser and block anti-virus and anti-spyware software. Windows PC Aid may also block all programs, not only anti-virus or anti-spyware software. Finally, Windows PC Aid will ask you to pay for its supposed licensed version to allegedly fix nonexistent infections. ESG's malware researchers highly recommend you not to rely upon and purchase Windows PC Aid. Uninstall Windows PC Aid from your computer as quickly as possible with a genuine security tool.

Windows PC Aid Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows PC Aid may create the following file(s):
# File Name Detections
1. %CommonAppData%\58ef5\SP98c.exe
2. %AppData%\Windows PC Aid\ScanDisk_.exe
3. %Programs%\Windows PC Aid.lnk
4. %CommonAppData%\58ef5\SPT.ico
5. %AppData%\Microsoft\Internet Explorer\Quick Launch\Windows PC Aid.lnk
6. %CommonAppData%\SPUPCZPDET\SPABOIJT.cfg
7. %AppData%\Windows PC Aid\Instructions.ini
8. %Desktop%\Windows PC Aid.lnk
9. %StartMenu%\Windows PC Aid.lnk

Registry Details

Windows PC Aid may create the following registry entry or registry entries:
HKEY_CURRENT_USER\oftware\Microsoft\Windows\CurrentVersion\Run\Windows PC Aid”%CommonAppData%\58ef5\SP98c.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows PC Aid\DisplayVersion 1.1.0.1010
HKCU\Software\MicrosoftWindows\CurrentVersion\Uninstall\Windows PC Aid\Publisher UIS Inc.
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID\ [unknown file name].DocHostUIHandler
HKEY_LOCAL_MACHINE\Software\Classes\Dumped_.DocHostUIHandler\Clsid
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FWCFG\EnableConsoleTracing 0
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FWCFG\FileDirectory %windir%\tracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\Debugger svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows PC Aid\DisplayIcon [unknown dir]\[unknown file name].exe,0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows PC Aid\DisplayName Windows Malware Firewall
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows PC Aid\InstallLocation [unknown dir]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32\ [unknown dir]\[unknown file name].exe
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID
HKEY_LOCAL_MACHINE\Software\Classes\Dumped_.DocHostUIHandler\ Implements DocHostUIHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FWCFG\MaxFileSize 1048576
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FWCFG\ConsoleTracingMask -65536
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows PC Aid
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows PC Aid\UninstallString “[unknown dir]\[unknown file name].exe” /del
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ Implements DocHostUIHandler
HKEY_LOCAL_MACHINE\Software\Classes\Dumped_.DocHostUIHandler
HKEY_LOCAL_MACHINE\Software\Classes\Dumped_.DocHostUIHandler\Clsid\ {3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FWCFG\EnableFileTracing 0
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\FWCFG\FileTracingMask -65536
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV

Trending

Most Viewed

Loading...