Home Possibly Unwanted Program Registry Dr.

Registry Dr.

Posted: February 18, 2014

Threat Metric

Ranking: 7,173
Threat Level: 1/10
Infected PCs: 9,790
First Seen: February 18, 2014
Last Seen: September 27, 2023
OS(es) Affected: Windows


Registry Dr. Screenshot 1Registry Dr. is a potentially unwanted program (PUP) created by EuroTrade A.L. Ltd which is categorized as a system optimizer. When installed on a PC, Registry Dr. may register itself to automatically run on the computer system whenever the PC user starts Windows. Registry Dr. can be a downloaded and installed from its official website; however, it may usually be installed from questionable download websites when downloading freeware.

Registry Dr. may launch faux system scans and display bogus security notifications declaring that numerous hard drive errors and security threats have been found on the computer. For removal of the so-called system issues and PC threats, Registry Dr. may encourage the computer user to buy its full version.

Registry Dr. Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



registrydrsetup.exe File name: registrydrsetup.exe
Size: 5.69 MB (5692688 bytes)
MD5: 228d76771c6f3bd244689444cdb586d1
Detection count: 17
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2014

Registry Modifications

The following newly produced Registry Values are:

File name without pathRegistry DR.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Installer\UpgradeCodes\240EC7800F0DE3948A4A9DD03CC17E1CSOFTWARE\EuroTrade A.L. Ltd\Registry DrSOFTWARE\Microsoft\Tracing\RegistryDr_RASAPI32SOFTWARE\Microsoft\Tracing\RegistryDr_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegistryDr_PopupSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegistryDr_StartSoftware\RegistryDrLanguageSOFTWARE\Wow6432Node\EuroTrade A.L. Ltd\Registry DrHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{982CB379-261E-4179-A4D7-E19F8141CC50}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Registry Dr%LOCALAPPDATA%\RegistryDR%PROGRAMFILES%\Registry Dr%PROGRAMFILES(x86)%\Registry Dr%USERPROFILE%\Documents\RegistryDr%USERPROFILE%\Local Settings\Application Data\RegistryDR%USERPROFILE%\My Documents\RegistryDr%WINDIR%\Installer\{A6A9374C-4A54-4F08-AF5A-F893F0B6B900}
Loading...