Home Malware Programs Rogue Anti-Virus Programs VirusCure

VirusCure

Posted: August 17, 2010

VirusCure (or Virus Cure) is the latest rogue malware remover in a growing series of Korean-language computer viruses. Once active, Virus Cure will report false threats and display fake security alerts on your PC. VirusCure does this to convince you that your computer is infected with malware. This fake program is promoted and installed through the use of Trojans and often comes bundled with other malicious software. Virus Cure is part of a blatant scam used to con you into paying for removal of infections which don't exist. Remove VirusCure and all associated threats using an updated anti-virus program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 C:\Documents and Settings\{username}\Desktop\viruscure_setup.exe
    2 C:\Program Files\VirusCure\conf.ini
    3 C:\Program Files\VirusCure\db\addb.dat
    4 C:\Program Files\VirusCure\db\adsub.dat
    5 C:\Program Files\VirusCure\db\adtc.dat
    6 C:\Program Files\VirusCure\db\avmon.dat
    7 C:\Program Files\VirusCure\db\filter.dll
    8 C:\Program Files\VirusCure\db\inter.dll
    9 C:\Program Files\VirusCure\db\pwdb.dat
    10 C:\Program Files\VirusCure\db\vsdb.dat
    11 C:\Program Files\VirusCure\etc\avsrv.exe
    12 C:\Program Files\VirusCure\etc\avsrvc.exe
    13 C:\Program Files\VirusCure\etc\avSubEngine.exe
    14 C:\Program Files\VirusCure\etc\VCFilterDriver.SYS
    15 C:\Program Files\VirusCure\etc\vcMon.exe
    16 C:\Program Files\VirusCure\etc\vcReg.exe
    17 C:\Program Files\VirusCure\etc\VCreport.exe
    18 C:\Program Files\VirusCure\Lang\kr.xml
    19 C:\Program Files\VirusCure\Log\Report.txt
    20 C:\Program Files\VirusCure\partner.ini
    21 C:\Program Files\VirusCure\skin\default.avs
    22 C:\Program Files\VirusCure\Uninstall.exe
    23 C:\Program Files\VirusCure\VCAutoUpdate.exe
    24 C:\Program Files\VirusCure\VCUpdateServer.dat
    25 C:\Program Files\VirusCure\VirusCure.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\VirusCureHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\viruscuremainHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}VirusCureMain
Loading...