1. Program description
APcSafe (A Pc Safe) - Rogue Security Software - is a type of misleading application that pretends to be legitimate security software, such as an antivirus scanner or registry cleaner, but which actually provides the user with little or no protection whatsoever. APcSafe is a new variant of the family Winisoft. The author of APcSafe also created the following software:
APcSecure, DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcsProtector, GreatDefender, APCprotect, ProtectPcs, SysDefence, TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, REAnti, KeepCop, SiteVillain, LinkSafeness, SecureKeeper, AntiAID, System Warrior, System Veteran, System Fighter, Block Protector, Block Keeper, Block Scanner, Block Watcher, SoftBarrier, Shield Safeness, Soft Stronghold, Soft Veteran, SoftCop, Soft Soldier, Trust Fighter, Trust Soldier, Safe Fighter, Trust Cop, Secure Warrior, Secure Fighter, Secure Veteran, Security Soldier, Security Fighter, Save Armor, Save Defender, Trust Warrior, Soft Safeness, Safety Keeper, Save Keeper, Quick Heal Cleaner, System Cop, Block Defense, Save Defense, Trust Ninja, Save Soldier, Save Keep, Winishield, Wini Fighter, WiniBlueSoft.
Kaspersky Lab’s experts do not recommend visiting the websites of the rogue security applications mentioned in this article because these sites may be unsafe and could potentially harm your computer.
2. Actions
After the installation APcSafe creates a definite number of empty files with different names on the computer. Once the computer scan is started APcSafe detects these files as malicious and offers to delete these files once you purchase the license for this program.
3. Files
During the installation APcSafe copies the following files to the hard drive:
%ProgramFiles%\APcSafe Software\ApcSafe\ApcSafe.exe %ProgramFiles%\APcSafe Software\ApcSafe\main_config.xml %ProgramFiles%\APcSafe Software\ApcSafe\uninstall.exe %AllUsersProfile%\Desktop\ApcSafe.lnk %AllUsersProfile%\Start Menu\Programs\ApcSafe\1 ApcSafe.lnk %AllUsersProfile%\Start Menu\Programs\ApcSafe\2 Homepage.lnk %AllUsersProfile%\Start Menu\Programs\ApcSafe\3 Uninstall.lnk
4. System registry
In order to function normally APcSafe creates the following branches in the system registry:
HKEY_LOCAL_MACHINE\software\ApcSafe HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ApcSafe HKEY_CURRENT_USER\software\ApcSafe HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “ApcSafe” HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “ApcSafe”
5. Screenshot of the program
|