Home Malware Programs Adware SpyContra

SpyContra

Posted: April 25, 2006

SpyContra is a fake anti-virus/anti-spyware program that promises to help users clean and block trojans and viruses, but in reality it installs malware and hijacks the systems desktop to scare the user into thinking the system was infected with spyware. Related products include SpyAxe, SpyFalcon, XSRemover, SpyContra, 1stAntiVirus, and others.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 1140554557.log
    2 app.exe
    3 extensions.pkg
    4 program.info
    5 registerspycontra.lnk
    6 securedisk.dcc
    7 spycontra.lnk
    8 spycontra.pkg
    9 startspycontra.lnk
    10 uninstall.exe
    11 uninstallspycontra.lnk
    12 update.exe
    13 xpdriver.sys

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\software\xxi\spycontraHKEY_CURRENT_USER\software\xxi\spycontra.comHKEY_CURRENT_USER\software\xxi\spycontra\scanoptionsHKEY_CURRENT_USER\software\xxi\spycontra\scriptsHKEY_CURRENT_USER\software\xxi\spycontra\scripts\variablesHKEY_CURRENT_USER\software\xxi\spycontra\updatesHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}spycontra
Loading...