Home Malware Programs Rogue Anti-Spyware Programs User Account Control

User Account Control

Posted: May 17, 2010

User Account Control is a rogueware program designed to trick users into spending their money. User Account Control stealthily invades computer systems via other malware such as Trojans. UserAccountControl conducts a fake system scan that displays bogus results of an alarming amount of malware on the system. These scare tactics are used to persuade a user to purchase the full version of User Account Control. Remove User Account Control from the system immediately using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Desktop\User Account Control.lnk
    2 %Documents and Settings%\All Users\Start Menu\Programs\User Account Control
    3 %Documents and Settings%\All Users\Start Menu\Programs\User Account Control\Purchase Licence.lnk
    4 %Documents and Settings%\All Users\Start Menu\Programs\User Account Control\User Account Control Home Page.lnk
    5 %Documents and Settings%\All Users\Start Menu\Programs\User Account Control\User Account Control.lnk
    6 %Program Files%\User Account Control
    7 %Program Files%\User Account Control\db\DBInfo.ver
    8 %Program Files%\User Account Control\db\ia080614.db
    9 %Program Files%\User Account Control\db\lists.ini
    10 %Program Files%\User Account Control\db\WMILib.dll
    11 %Program Files%\User Account Control\Languages
    12 %Program Files%\User Account Control\LiveSS.exe
    13 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\User Account Control.lnk
    14 %UserProfile%\Application Data\User Account Control
    15 %UserProfile%\Application Data\User Account Control\db
    16 %UserProfile%\Application Data\User Account Control\db\config.cfg
    17 %UserProfile%\Application Data\User Account Control\db\Timeout.inf
    18 %UserProfile%\Application Data\User Account Control\db\Urls.inf
    19 %UserProfile%\Application Data\User Account Control\settings.ini
    20 %UserProfile%\Application Data\User Account Control\uill.ini
    21 %UserProfile%\Application Data\User Account Control\unins000.exe
    22 %UserProfile%\Application Data\User Account Control\Uninstall User Account Control.lnk
    23 %UserProfile%\Desktop\LiveSS.exe.txt
    24 %UserProfile%\Desktop\User Account Control.lnk
    25 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
    26 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\FTP "SearchDir" = "%Program Files%\User Account Control\"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "uniname" = "User Account Control_is1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "User Account Control"HKEY_CURRENT_USER\Software\User Account ControlHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AVPath" = "\\.\root\SecurityCenter:AntiVirusProduct.instanceGuid="{653E64F8-62B6-4F96-B22D-4FFC6E44130E}""HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent "URLSS[2.0.3.0]"HKEY_LOCAL_MACHINE\SOFTWARE\User Account ControlHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}User Account Control_is1
Loading...