Emsisoft Malware-Info
Name: Adware.Win32.RegistryConvoy
Risklevel: Low Risk
Company: Registry Convoy Scanning Technologies, Ltd. - registryconvoy.com
Description:
It is a rogue security program that shows false warning messages. It also shows misleading scan results.
Removal instructions for Adware RegistryConvoy:
To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware RegistryConvoy.
Run a full scan on all drives and move all detected items to the quarantine.
More details about this danger:
Characteristics:
- Show fake warning messages.
- It also shows misleading scan results.
Installation: Installed through EXE
Process: RegistryConvoy.exe
Screenshots:
Used folders:
- C:\Program Files\Registry Convoy 2009\
- C:\WINDOWS\Tasks\
- C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\
- C:\Documents and Settings\[USER]\Cookies\
- C:\Documents and Settings\[USER]\Desktop\
- C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092820090929\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\
- C:\Documents and Settings\[USER]\Start Menu\Programs\Registry Convoy 2009\
Used files:
- C:\Program Files\Registry Convoy 2009\License.txt
[5694 Bytes] TXT File - C:\Program Files\Registry Convoy 2009\Registry Convoy.url
[55 Bytes] URL File - C:\Program Files\Registry Convoy 2009\RegistryConvoy.dll
[425472 Bytes] DLL File - C:\Program Files\Registry Convoy 2009\RegistryConvoy.exe
[1735168 Bytes] EXE File - C:\Program Files\Registry Convoy 2009\uninst.exe
[160749 Bytes] EXE File - C:\Program Files\Registry Convoy 2009\Update.exe
[1101824 Bytes] EXE File - C:\WINDOWS\Tasks\RegistryConvoy.job
[376 Bytes] JOB File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch.lnk
[631 Bytes] LNK File - C:\Documents and Settings\[USER]\Cookies\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Cookies\virus demo@Piwik[1].txt
[254 Bytes] TXT File - C:\Documents and Settings\[USER]\Cookies\virus demo@registryconvoy[2].txt
[374 Bytes] TXT File - C:\Documents and Settings\[USER]\Desktop\Registry Convoy 2009.lnk
[619 Bytes] LNK File - C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
[16384 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092820090929\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\index.dat
[65536 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\js[2].axd
[1621 Bytes] AXD File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\piwik[1].gif
[43 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\purchase[1].png
[25040 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_background[1].png
[688 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_bundle[1].png
[101988 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_bundle_platform[1].png
[23298 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_clickbank_logo[1].png
[2268 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_encrypt[1].png
[565 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_green_yes[1].gif
[2704 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_navigation_bg[1].gif
[257 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_navigation_right[1].gif
[603 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_Run[1].png
[15233 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\registryconvoy_Setup[1].png
[10159 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\css[1].css
[2 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\Help[1].htm
[21028 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\piwik[1].gif
[43 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\piwik[1].js
[8387 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\Register[1].png
[22349 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_banner_free_download[1].png
[4694 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_Download[1].png
[15525 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_Finish[1].png
[9579 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_hackersafe[1].gif
[4951 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_head[1].png
[402 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_ic_sspg[1].gif
[2099 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_logo[1].png
[10226 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\registryconvoy_payments[1].gif
[9509 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\css[2].css
[5498 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\js[2].axd
[2302 Bytes] AXD File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_agree[1].png
[25921 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_banner_check[1].png
[282 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_BBB_accredited[1].gif
[3174 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_bottom[1].png
[414 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_button_scan_your_pc_for_free[1].gif
[2366 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_Install[1].png
[8756 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_paypal[1].gif
[4216 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_promise[1].png
[556 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\registryconvoy_tab_off[1].gif
[1341 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\ga[2].js
[24095 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\Order[1].htm
[22989 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\piwik[1].gif
[43 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_banner[1].jpg
[51993 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_banner_free_scan[1].png
[13877 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_bundle_support[1].jpg
[18567 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_credit_card[1].gif
[3535 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_footer[1].gif
[44 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_guarantee[1].png
[502 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_navigation_left[1].gif
[612 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\registryconvoy_off[1].jpg
[10524 Bytes] JPG File - C:\Documents and Settings\[USER]\Start Menu\Programs\Registry Convoy 2009\Registry Convoy 2009.lnk
[631 Bytes] LNK File - C:\Documents and Settings\[USER]\Start Menu\Programs\Registry Convoy 2009\Uninstall.lnk
[591 Bytes] LNK File - C:\Documents and Settings\[USER]\Start Menu\Programs\Registry Convoy 2009\Website.lnk
[819 Bytes] LNK File
Additional information might be found here:
Search
at Google for
Adware RegistryConvoy
Search at Bing for
Adware RegistryConvoy
Search
at Yahoo for
Adware RegistryConvoy
How can I protect myself from Adware RegistryConvoy?
Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers.
This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.
Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!
Only $40 for the security of your computer.
Buy Emsisoft Anti-Malware online:
Trust only on the best protection software!
Spring Offer!
Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get
a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.
Only a few days left! Order here































