Home Malware Programs Trojans SafeandClean

SafeandClean

Posted: August 14, 2006

SafeandClean is a rogue anti-spyware programs that displays fake security messages in an attempt to trick the user into purchasing the software. SafeandClean is a variant of UnSpyPC and KillAndClean.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sac.ico
    2 safeandclean scanner & monitor.lnk
    3 safeandclean.exe
    4 safeandclean.lnk
    5 safeandcleanupdate.exe
    6 uninstall.exe
    7 uninstall.lnk
    8 warez.dat
    9 wover.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{BF69DF00-3734-477F-8257-27CD04F88779}HKEY_CURRENT_USER\Software\SafeAndCleanHKEY_LOCAL_MACHINE\SOFTWARE\SafeAndCleanHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SafeAndClean
Loading...