Emsisoft Malware-Info

Name: Adware.Win32.RegTool

Risklevel: Low Risk

Company: PC Utility, Inc. - regtool.exe

Description:

It is a rogue registry application, it may have exaggerated damage reports, then ask the user to purchase a registered version to remove the reported damage.

Removal instructions for Adware RegTool:

To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware RegTool.

Run a full scan on all drives and move all detected items to the quarantine.

More details about this danger:

Characteristics:

  • It also shows misleading scan results.
  • User must purchase a registered version to remove the damaged registry

Installation: Installed through EXE

Process: Reg Tool.exe

Screenshots:

RegToolRegToolRegToolRegToolRegToolRegToolRegToolRegToolRegToolRegToolRegToolRegTool

Used folders:

  • C:\Program Files\Downloaded Installers\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\
  • C:\Program Files\Reg Tool\
  • C:\Program Files\Reg Tool\PW\
  • C:\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\
  • C:\WINDOWS\
  • C:\WINDOWS\Installer\
  • C:\WINDOWS\Installer\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\
  • C:\WINDOWS\SoftwareDistribution\
  • C:\WINDOWS\SoftwareDistribution\DataStore\
  • C:\WINDOWS\SoftwareDistribution\DataStore\Logs\
  • C:\WINDOWS\SoftwareDistribution\EventCache\
  • C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\
  • C:\WINDOWS\system32\WBEM\Logs\
  • C:\WINDOWS\Tasks\
  • drive\D\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\
  • C:\Documents and Settings\All Users\Desktop\
  • C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Logs\
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\
  • C:\Documents and Settings\[USER]\Cookies\
  • C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\
  • C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\
  • C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092220090923\
  • C:\Documents and Settings\[USER]\Local Settings\Temp\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\

Used files:

  • C:\Program Files\Downloaded Installers\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\setup.msi
    [39488000 Bytes] MSI File
  • C:\Program Files\Reg Tool\definitions.db
    [33156 Bytes] DB File
  • C:\Program Files\Reg Tool\privacy.db
    [4324 Bytes] DB File
  • C:\Program Files\Reg Tool\PW.zip
    [1824 Bytes] ZIP File
  • C:\Program Files\Reg Tool\Reg Tool.exe
    [38282504 Bytes] EXE File
  • C:\Program Files\Reg Tool\Reg Tool.url
    [118 Bytes] URL File
  • C:\Program Files\Reg Tool\startup.db
    [115188 Bytes] DB File
  • C:\Program Files\Reg Tool\PW\general.html
    [249 Bytes] HTML File
  • C:\Program Files\Reg Tool\PW\optimizations.html
    [166 Bytes] HTML File
  • C:\Program Files\Reg Tool\PW\privacy.html
    [775 Bytes] HTML File
  • C:\Program Files\Reg Tool\PW\scheduler.html
    [374 Bytes] HTML File
  • C:\Program Files\Reg Tool\PW\startup.html
    [174 Bytes] HTML File
  • C:\Program Files\Reg Tool\PW\wizard.css
    [186 Bytes] CSS File
  • C:\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\INFO2
    [20 Bytes] File
  • C:\WINDOWS\WindowsUpdate.log
    [12559 Bytes] LOG File
  • C:\WINDOWS\Installer\85179b.msi
    [732160 Bytes] MSI File
  • C:\WINDOWS\Installer\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\Icon.exe
    [90112 Bytes] EXE File
  • C:\WINDOWS\SoftwareDistribution\ReportingEvents.log
    [432 Bytes] LOG File
  • C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb
    [1056768 Bytes] EDB File
  • C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk
    [8192 Bytes] CHK File
  • C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log
    [131072 Bytes] LOG File
  • C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb
    [65536 Bytes] EDB File
  • C:\WINDOWS\SoftwareDistribution\EventCache\{01D222EB-3EE4-42C4-AE31-4F261A8CE877}.bin
    [8 Bytes] BIN File
  • C:\WINDOWS\SoftwareDistribution\EventCache\{E7E877D5-DCB9-454A-ACB3-B5011E0302B4}.bin
    [462 Bytes] BIN File
  • C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab
    [9668 Bytes] CAB File
  • C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.xml
    [605 Bytes] XML File
  • C:\WINDOWS\system32\WBEM\Logs\wbemprox.log
    [252 Bytes] LOG File
  • C:\WINDOWS\Tasks\Reg Tool Scan.job
    [432 Bytes] JOB File
  • drive\D\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\INFO2
    [20 Bytes] File
  • C:\Documents and Settings\All Users\Desktop\Reg Tool.lnk
    [1848 Bytes] LNK File
  • C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\Reg Tool Help.lnk
    [1860 Bytes] LNK File
  • C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\Reg Tool on the Web.lnk
    [1848 Bytes] LNK File
  • C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\Reg Tool.lnk
    [1848 Bytes] LNK File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
    [898 Bytes] File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
    [95039 Bytes] File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
    [94 Bytes] File
  • C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
    [124 Bytes] File
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Logs\2009-09-22 23-09-040.log
    [84240 Bytes] LOG File
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Evidence.db
    [26036 Bytes] DB File
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Junk.db
    [7864 Bytes] DB File
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Registry.db
    [103976 Bytes] DB File
  • C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Update.db
    [60 Bytes] DB File
  • C:\Documents and Settings\[USER]\Cookies\index.dat
    [32768 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Cookies\virus demo@regtool[1].txt
    [71 Bytes] TXT File
  • C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
    [16384 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\index.dat
    [32768 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092220090923\index.dat
    [32768 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\Temp\~DF7ACE.tmp
    [32768 Bytes] TMP File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    [49152 Bytes] DAT File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\bg_main[1].jpg
    [2402 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\cr_mh_r[1].jpg
    [3721 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\cr_org_tl[1].gif
    [65 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\definitions[1].db
    [33156 Bytes] DB File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\logo_ft[1].gif
    [4419 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\logo_regtool[1].gif
    [4401 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\micro6[1].gif
    [3777 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\softpedia_clean_award_f2[1].gif
    [6873 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\bg_mh_l[1].jpg
    [680 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\bg_top_nav[1].jpg
    [479 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\cr_ft1[1].jpg
    [1922 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\error2[1].gif
    [2446 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\ic2[1].gif
    [6911 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\ic3[1].gif
    [6601 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\ic_sspg[1].gif
    [2099 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\13[1].gif
    [2680 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\bg_mh_r[1].jpg
    [678 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\box_register[1].jpg
    [13619 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\cr_mh_l[1].jpg
    [3696 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\cr_org_br[1].gif
    [66 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\cr_org_tr[1].gif
    [67 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\tucow_award2[1].jpg
    [2688 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bg_ft2[1].jpg
    [10147 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bg_ft[1].jpg
    [527 Bytes] JPG File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bg_hd_m[1].gif
    [1348 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\cr_org_bl[1].gif
    [66 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\global[1].css
    [4263 Bytes] CSS File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\ic1[1].gif
    [6747 Bytes] GIF File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\register_now[1].htm
    [34882 Bytes] HTM File
  • C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\spacer[1].gif
    [45 Bytes] GIF File

Additional information might be found here:

Search at Google for Adware RegTool Search at Google for Adware RegTool
Search at Bing for Adware RegTool Search at Bing for Adware RegTool
Search at Yahoo for Adware RegTool Search at Yahoo for Adware RegTool

How can I protect myself from Adware RegTool?

Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers. This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.

Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!

Only $40 for the security of your computer.

Buy Emsisoft Anti-Malware online:

Buy Emsisoft Anti-Malware now

Trust only on the best protection software!

Spring Offer!

Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.

Only a few days left! Order here

Best In Test!

Emsisoft Anti-Malware is the best of 19 tested antivirus programs - Test by MRG - Malware Research Group - Q1-Q3 2011
More independent reviews of anti-malware software