BehaviorThe program must be manually installed.
The program reports false or exaggerated system security threats on the computer.

The user is then prompted to pay for a full license of the application in order to remove the threats.
InstallationWhen the program is executed, it creates the following folders:
- %UserProfile%\Desktop\SpywareCease
- %ProgramFiles%\Spyware Cease\update
It also creates the following files:
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Spyware Cease.lnk
- %UserProfile%\Desktop\Spyware Cease.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\Spyware Cease\Spyware Cease on the Web.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\Spyware Cease\Spyware Cease.lnk
- C:\Documents and Settings\All Users\Start Menu\Programs\Spyware Cease\Uninstall Spyware Cease.lnk
- %ProgramFiles%\Spyware Cease\AutoUpdate.exe
- %ProgramFiles%\Spyware Cease\DefendLog.txt
- %ProgramFiles%\Spyware Cease\LSR.lsr
- %ProgramFiles%\Spyware Cease\md5.dll
- %ProgramFiles%\Spyware Cease\networkdll.dll
- %ProgramFiles%\Spyware Cease\opfile.dll
- %ProgramFiles%\Spyware Cease\RegDefend.ini
- %ProgramFiles%\Spyware Cease\RkHitApi.dll
- %ProgramFiles%\Spyware Cease\spkdll.dll
- %ProgramFiles%\Spyware Cease\SpywareCease.chm
- %ProgramFiles%\Spyware Cease\SpywareCease.exe
- %ProgramFiles%\Spyware Cease\SpywareCease.url
- %ProgramFiles%\Spyware Cease\swdb.ssk
- %ProgramFiles%\Spyware Cease\unins000.dat
- %ProgramFiles%\Spyware Cease\unins000.exe
- %ProgramFiles%\Spyware Cease\zlib1.dll
- %System%\drivers\RKHit.sys
Next, the program creates the following registry entry so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"SpywareCease.exe" = "C:\Program Files\Spyware Cease\SpywareCease.exe"
It also creates the following registry subkeys:
- HKEY_CURRENT_USER\Software\Spyware Cease
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spyware Cease_is1
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RkHit