Home Malware Programs Rogue Anti-Spyware Programs 007 Anti-Spyware

007 Anti-Spyware

Posted: August 3, 2009

007 Anti-Spyware is a fake spyware remover that issues fake system scans reporting fabricated infection results, along with false security alerts, in order to fool you into believing your PC is compromised. You are then prompted to purchase and download 007 Anti-Spyware in order to combat these exaggerated threats.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\007 Anti-Spyware
    2 %ProgramFiles%\007 Anti-Spyware\asdb.dat
    3 %ProgramFiles%\007 Anti-Spyware\License.txt
    4 %ProgramFiles%\007 Anti-Spyware\LSR.lsr
    5 %ProgramFiles%\007 Anti-Spyware\RegDefend.ini
    6 %ProgramFiles%\007 Anti-Spyware\update
    7 %SystemRoot%\RKHit.sys
    8 %UserProfile%\Desktop\007 Anti-Spyware.lnk
    9 %UserProfile%\Start Menu\Programs\007 Anti-Spyware
    10 %UserProfile%\Start Menu\Programs\007 Anti-Spyware\007 Anti-Spyware.lnk
    11 %UserProfile%\Start Menu\Programs\007 Anti-Spyware\Uninstall 007 Anti-Spyware.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Spyware CeaseHKEY_LOCAL_MACHINE\SOFTWARE\007AntiSpyware.comHKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BC00E47F-1016-25DD-E208-74A12348F178}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RkHitHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”007-Anti-Spyware.exe” = “%ProgramFiles%\007 Anti-Spyware\007-Anti-Spyware.exe”HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}007 Anti-Spyware
Loading...