Emsisoft Malware-Info
Name: Adware.Win32.RegTool
Risklevel: Low Risk
Company: PC Utility, Inc. - regtool.exe
Description:
It is a rogue registry application, it may have exaggerated damage reports, then ask the user to purchase a registered version to remove the reported damage.
Removal instructions for Adware RegTool:
To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware RegTool.
Run a full scan on all drives and move all detected items to the quarantine.
More details about this danger:
Characteristics:
- It also shows misleading scan results.
- User must purchase a registered version to remove the damaged registry
Installation: Installed through EXE
Process: Reg Tool.exe
Screenshots:
Used folders:
- C:\Program Files\Downloaded Installers\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\
- C:\Program Files\Reg Tool\
- C:\Program Files\Reg Tool\PW\
- C:\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\
- C:\WINDOWS\
- C:\WINDOWS\Installer\
- C:\WINDOWS\Installer\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\
- C:\WINDOWS\SoftwareDistribution\
- C:\WINDOWS\SoftwareDistribution\DataStore\
- C:\WINDOWS\SoftwareDistribution\DataStore\Logs\
- C:\WINDOWS\SoftwareDistribution\EventCache\
- C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\
- C:\WINDOWS\system32\WBEM\Logs\
- C:\WINDOWS\Tasks\
- drive\D\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\
- C:\Documents and Settings\All Users\Desktop\
- C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\
- C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\
- C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\
- C:\Documents and Settings\[USER]\Application Data\Reg Tool\Logs\
- C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\
- C:\Documents and Settings\[USER]\Cookies\
- C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092220090923\
- C:\Documents and Settings\[USER]\Local Settings\Temp\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\
Used files:
- C:\Program Files\Downloaded Installers\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\setup.msi
[39488000 Bytes] MSI File - C:\Program Files\Reg Tool\definitions.db
[33156 Bytes] DB File - C:\Program Files\Reg Tool\privacy.db
[4324 Bytes] DB File - C:\Program Files\Reg Tool\PW.zip
[1824 Bytes] ZIP File - C:\Program Files\Reg Tool\Reg Tool.exe
[38282504 Bytes] EXE File - C:\Program Files\Reg Tool\Reg Tool.url
[118 Bytes] URL File - C:\Program Files\Reg Tool\startup.db
[115188 Bytes] DB File - C:\Program Files\Reg Tool\PW\general.html
[249 Bytes] HTML File - C:\Program Files\Reg Tool\PW\optimizations.html
[166 Bytes] HTML File - C:\Program Files\Reg Tool\PW\privacy.html
[775 Bytes] HTML File - C:\Program Files\Reg Tool\PW\scheduler.html
[374 Bytes] HTML File - C:\Program Files\Reg Tool\PW\startup.html
[174 Bytes] HTML File - C:\Program Files\Reg Tool\PW\wizard.css
[186 Bytes] CSS File - C:\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\INFO2
[20 Bytes] File - C:\WINDOWS\WindowsUpdate.log
[12559 Bytes] LOG File - C:\WINDOWS\Installer\85179b.msi
[732160 Bytes] MSI File - C:\WINDOWS\Installer\{FCC1B3CE-5F3C-4B2B-B0CF-609D72C995E1}\Icon.exe
[90112 Bytes] EXE File - C:\WINDOWS\SoftwareDistribution\ReportingEvents.log
[432 Bytes] LOG File - C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb
[1056768 Bytes] EDB File - C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk
[8192 Bytes] CHK File - C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log
[131072 Bytes] LOG File - C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb
[65536 Bytes] EDB File - C:\WINDOWS\SoftwareDistribution\EventCache\{01D222EB-3EE4-42C4-AE31-4F261A8CE877}.bin
[8 Bytes] BIN File - C:\WINDOWS\SoftwareDistribution\EventCache\{E7E877D5-DCB9-454A-ACB3-B5011E0302B4}.bin
[462 Bytes] BIN File - C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab
[9668 Bytes] CAB File - C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.xml
[605 Bytes] XML File - C:\WINDOWS\system32\WBEM\Logs\wbemprox.log
[252 Bytes] LOG File - C:\WINDOWS\Tasks\Reg Tool Scan.job
[432 Bytes] JOB File - drive\D\RECYCLER\S-1-5-21-1715567821-1844237615-725345543-1003\INFO2
[20 Bytes] File - C:\Documents and Settings\All Users\Desktop\Reg Tool.lnk
[1848 Bytes] LNK File - C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\Reg Tool Help.lnk
[1860 Bytes] LNK File - C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\Reg Tool on the Web.lnk
[1848 Bytes] LNK File - C:\Documents and Settings\All Users\Start Menu\Programs\Reg Tool\Reg Tool.lnk
[1848 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
[898 Bytes] File - C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
[95039 Bytes] File - C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
[94 Bytes] File - C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
[124 Bytes] File - C:\Documents and Settings\[USER]\Application Data\Reg Tool\Logs\2009-09-22 23-09-040.log
[84240 Bytes] LOG File - C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Evidence.db
[26036 Bytes] DB File - C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Junk.db
[7864 Bytes] DB File - C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Registry.db
[103976 Bytes] DB File - C:\Documents and Settings\[USER]\Application Data\Reg Tool\Results\Update.db
[60 Bytes] DB File - C:\Documents and Settings\[USER]\Cookies\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Cookies\virus demo@regtool[1].txt
[71 Bytes] TXT File - C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
[16384 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092220090923\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temp\~DF7ACE.tmp
[32768 Bytes] TMP File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\index.dat
[49152 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\bg_main[1].jpg
[2402 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\cr_mh_r[1].jpg
[3721 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\cr_org_tl[1].gif
[65 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\definitions[1].db
[33156 Bytes] DB File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\logo_ft[1].gif
[4419 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\logo_regtool[1].gif
[4401 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\micro6[1].gif
[3777 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\softpedia_clean_award_f2[1].gif
[6873 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\bg_mh_l[1].jpg
[680 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\bg_top_nav[1].jpg
[479 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\cr_ft1[1].jpg
[1922 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\error2[1].gif
[2446 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\ic2[1].gif
[6911 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\ic3[1].gif
[6601 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\ic_sspg[1].gif
[2099 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\13[1].gif
[2680 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\bg_mh_r[1].jpg
[678 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\box_register[1].jpg
[13619 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\cr_mh_l[1].jpg
[3696 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\cr_org_br[1].gif
[66 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\cr_org_tr[1].gif
[67 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\tucow_award2[1].jpg
[2688 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bg_ft2[1].jpg
[10147 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bg_ft[1].jpg
[527 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bg_hd_m[1].gif
[1348 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\cr_org_bl[1].gif
[66 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\global[1].css
[4263 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\ic1[1].gif
[6747 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\register_now[1].htm
[34882 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\spacer[1].gif
[45 Bytes] GIF File
Additional information might be found here:
Search
at Google for
Adware RegTool
Search at Bing for
Adware RegTool
Search
at Yahoo for
Adware RegTool
How can I protect myself from Adware RegTool?
Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers.
This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.
Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!
Only $40 for the security of your computer.
Buy Emsisoft Anti-Malware online:
Trust only on the best protection software!
Spring Offer!
Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get
a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.
Only a few days left! Order here






























