Home Malware Programs Rogue Anti-Spyware Programs ControlCnt

ControlCnt

Posted: May 3, 2010

ControlCnt is a rogue anti-spyware program designed to pilfer money form hapless computer users. ControlCnt reports bogus threats and displays fake security warnings on your computer to trick you into thinking that your computer is infected with malware. This fake program is from the same family of rogues as Control Center. ControlCnt uses Trojans, that come from fake online scanners or fake video sites, to do its dirty work. ControlCnt simulates a system scan and displays a list of malware infections. Soon popups will prompt you to pay for a full version of the program to remove the alleged infections. Do not fall for this blatant scam and have ControlCnt removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\CC
    2 %UserProfile%\Application Data\CC\agent.exe
    3 %UserProfile%\Application Data\CC\cc.exe
    4 %UserProfile%\Application Data\CC\faq
    5 %UserProfile%\Application Data\CC\faq\guide.html
    6 %UserProfile%\Application Data\CC\faq\images
    7 %UserProfile%\Application Data\CC\faq\images\05.png
    8 %UserProfile%\Application Data\CC\faq\images\06.png
    9 %UserProfile%\Application Data\CC\faq\images\07.png
    10 %UserProfile%\Application Data\CC\faq\images\08.png
    11 %UserProfile%\Application Data\CC\faq\images\09.png
    12 %UserProfile%\Application Data\CC\faq\images\10.png
    13 %UserProfile%\Application Data\CC\settings.ini
    14 %UserProfile%\Application Data\CC\uninstall.exe
    15 %UserProfile%\Desktop\Control center.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%UserProfile%\Application Data\CC\cc.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ControlCnt"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "agent.exe"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Control center
Loading...