Home Malware Programs Trojans SpyReaper

SpyReaper

Posted: July 31, 2007

SpyReaper is a fake anti-spyware program that is often downloaded and installed without user knowledge or consent by a Trojan or through browser security holes. SpyReaper launches on Windows startup and may generate large numbers of popup adverts. SpyReaper will also display notifications of imaginary security risks in its attempts to get the user to purchase the full version. SpyReaper program can be extremely difficult to remove manually, and will continue to try to recreate itself

File System Modifications

  • The following files were created in the system:
    # File Name
    1 actskn43.ocx
    2 AppRestart.exe
    3 BlockedCookies.dat
    4 ExeDefinition.dat
    5 Memman.vxd
    6 mscomct2.ocx
    7 RegistryDefinition.dat
    8 riched32.dll
    9 richtx32.ocx
    10 skinboxer43.dll
    11 Spy Reaper Pro Demo.lnk
    12 Spyreaper.com.url
    13 SpyReaperProDemo.exe
    14 tabctl32.ocx

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\"%ProgramFiles%\Spy Reaper Pro Demo\" = ""HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\"%UserProfile%\Application Data\Microsoft\Installer\{891573E5-0B2C-4E86-8236-E491DD9B8E9E}\" = ""HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\"%UserProfile%\Start Menu\Programs\P. A. Larson Enterprises Software\Spy Reaper Pro Demo\" = ""
Loading...