Home Malware Programs Rogue Registry Cleaners RegDefense

RegDefense

Posted: August 19, 2009

RegDefense masquerades as a legitimate registry repair tool that typically displays misleading results after scanning your system for registry issues. RegDefense must be manually installed before it begins causing trouble.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Registry Defense\Logs
    2 %ProgramFiles%\Registry Defense\prep.cmd
    3 %ProgramFiles%\Registry Defense\RegistryDefense.exe.manifest
    4 %UserProfile%\Desktop\Registry Defense.lnk
    5 %UserProfile%\Start Menu\Programs\Help and Support.url
    6 %UserProfile%\Start Menu\Programs\Registry Defense.lnk
    7 %UserProfile%\Start Menu\Programs\Uninstall Registry Defense.lnk
    8 %UserProfile%\Start Menu\Programs\Upgrade Registry Defense.url

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Sysinternals\PsKill\"EulaAccepted" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\RegistryDefenseHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"RDAgent" = "%PROGRAMS_FILES%\Registry Defense\RDAgent.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"RDListener" = "%PROGRAMS_FILES%\Registry Defense\RDListener.exe"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}RegistryDefense

Related Posts

Loading...