Home Malware Programs Rogue Anti-Spyware Programs KeepCop

KeepCop

Posted: November 24, 2009

Threat Metric

Threat Level: 10/10
Infected PCs: 16
First Seen: December 1, 2009
Last Seen: January 10, 2019
OS(es) Affected: Windows

KeepCop is a rogue anti-spyware program from the notorious WiniGuard family, also known as Winisoft. KeepCop is usually installed without your knowledge and due to the fact that the fake application is spread by Trojans, it configures the Windows registry and creates additional files which are later recognized as infections. Registry keys are changed in such a way that KeepCop will start automatically every time you start-up Windows. The system will then be constantly scanned, and a list of "infections" will be found each time. These are tactics used to scare computer users and make them purchase Keep Cop. Do not trust the application and have KeepCop terminated immediately.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



KeepCop.exe File name: KeepCop.exe
Size: 1.63 MB (1636864 bytes)
MD5: 797095b893b636194544f06e3a2e1a3f
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
setup[1].exe File name: setup[1].exe
Size: 1.75 MB (1751869 bytes)
MD5: b486306d8552ae7278a1890f01a4f2d2
Detection count: 48
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
setup[1].exe File name: setup[1].exe
Size: 373.76 KB (373760 bytes)
MD5: a1fa58520ca969bcc71a638509c49fc8
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Additional Information

The following directories were created:
%ProgramFiles%\KeepCop Software\KeepCop
Loading...