October 9, 2009 3:23:08 PM
Misleading Application
Virus Doctor
Virus Doctor
Risk Impact:
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
The program may be downloaded from the following location:

The program reports false or exaggerated system security threats on the computer.

The user is then prompted to pay for a full license of the application in order to remove the threats.

When the program is executed, it creates the following folder:
%UserProfile%\Application Data\Windows Protection Suite

It also creates the following files:
  • %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Virus Doctor.lnk
  • %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite.lnk
  • %UserProfile%\Application Data\Virus Doctor\settings.ini
  • %UserProfile%\Application Data\Virus Doctor\uill.ini
  • %UserProfile%\Desktop\Virus Doctor.lnk
  • %UserProfile%\Desktop\Windows Protection Suite.lnk
  • %UserProfile%\Desktop\VirusDoctor.exe
  • %UserProfile%\Start Menu\Programs\Virus Doctor.lnk
  • %UserProfile%\Start Menu\Programs\Windows Protection Suite.lnk
  • %UserProfile%\Start Menu\Virus Doctor.lnk
  • %UserProfile%\Start Menu\Windows Protection Suite.lnk
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\Languages\VDDe.lng
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\Languages\VDFr.lng
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\Languages\VDIt.lng
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\System Data Configuration\DBInfo.ver
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\System Data Configuration\vd[RANDOM CHARACTERS].bd
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\unins000.dat
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\unins000.exe
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\VDo[RANDOM CHARACTERS].exe
  • C:\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\WI[RANDOM CHARACTERS].exe
  • C:\Documents and Settings\All Users\Application Data\System Data Configuration\config.cfg
  • C:\Documents and Settings\All Users\Application Data\WINSPSys\winps.cfg
  • C:\Documents and Settings\All Users\Application Data\System Data Configuration\DB.ini
  • C:\WINPS.ico

Next, the program creates the following registry entries so that it executes whenever Windows starts:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Windows Protection Suite" = "\"%SystemDrive%\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\WI[RANDOM CHARACTERS].exe\" \s \d"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Virus Doctor" = "%SystemDrive%\Documents and Settings\All Users\Application Data\[RANDOM CHARACTERS]\VDo[RANDOM CHARACTERS].exe" /s /d"

It also creates the following registry entry in order to add itself to the list of applications authorized by the Windows firewall:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%CurrentFolder%\[ORIGINAL FILE NAME].exe" = "%CurrentFolder%\[ORIGINAL FILE NAME].exe:*:Enabled:Windows Protection Suite"

The program then creates the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\"Debugger" = "svchost.exe"

Next, the program creates several registry entries with the following format:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\[APPLICATION NAME]\"Debugger" = "svchost.exe"

Where [APPLICATION NAME] is generated from a pre-determined list and may be any of the following:
  • _avp32.exe, _avpcc.exe, _avpm.exe, ~1.exe, ~2.exe

  • a.exe, aAvgApi.exe, AAWTray.exe, About.exe, ackwin32.exe, adaware.exe, Ad-Aware.exe, advxdwin.exe, AdwarePrj.exe, agent.exe, agentsvr.exe, agentw.exe, alertsvc.exe, alevir.exe, alogserv.exe, AluSchedulerSvc.exe, amon9x.exe, anti-trojan.exe, antivirus.exe, AntiVirus_Pro.exe, AntivirusPlus, AntivirusPlus.exe, AntivirusXP, AntivirusXP.exe, antivirusxppro2009.exe, ants.exe, apimonitor.exe, aplica32.exe, apvxdwin.exe, arr.exe, Arrakis3.exe, ashAvast.exe, ashBug.exe, ashChest.exe, ashCnsnt.exe, ashDisp.exe, ashLogV.exe, ashMaiSv.exe, ashPopWz.exe, ashQuick.exe, ashServ.exe, ashSimp2.exe, ashSimpl.exe, ashSkPcc.exe, ashSkPck.exe, ashUpd.exe, ashWebSv.exe, aswChLic.exe, aswRegSvr.exe, aswRunDll.exe, aswUpdSv.exe, atcon.exe, atguard.exe, atro55en.exe, atupdater.exe, atwatch.exe, au.exe, aupdate.exe, autodown.exe, auto-protect.nav80try.exe, autotrace.exe, autoupdate.exe, v360.exe, avadmin.exe, AVCare.exe, avcenter.exe, avciman.exe, avconfig.exe, avconsol.exe, ave32.exe, AVENGINE.exe, avgcc32.exe, avgchk.exe, avgcmgr.exe, avgcsrvx.exe, avgctrl.exe, avgdumpx.exe, avgemc.exe, avgiproxy.exe, avgnsx.exe, avgnt.exe, avgrsx.exe, avgscanx.exe, avgserv.exe, avgserv9.exe, avgsrmax.exe, avgtray.exe, avguard.exe, avgui.exe, avgupd.exe, avgw.exe, avgwdsvc.exe, avkpop.exe, avkserv.exe, avkservice.exe, avkwctl9.exe, avltmain.exe, avmailc.exe, avmcdlg.exe, avnotify.exe, avnt.exe, avp.exe, avp32.exe, avpcc.exe, avpdos32.exe, avpm.exe, avptc32.exe, avpupd.exe, avscan.exe, avsched32.exe, avsynmgr.exe, pgsvc.exe, AVWEBGRD.exe, avwin.exe, avwin95.exe, avwinnt.exe, avwsc.exe, avwupd.exe, avwupd32.exe, avwupsrv.exe, avxmonitor9x.exe, avxmonitornt.exe, avxquar.exe

  • b.exe, backweb.exe, bargains.exe, bd_professional.exe, bdagent.exe, bdfvcl.exe, bdfvwiz.exe, BDInProcPatch.exe, bdmcon.exe, BDMsnScan.exe, bdreinit.exe, bdsubwiz.exe, BDSurvey.exe, bdtkexec.exe, bdwizreg.exe, beagle.exe, belt.exe, bidef.exe, bidserver.exe, bipcp.exe, bipcpevalsetup.exe, bisp.exe, blackd.exe, blackice.exe, blink.exe, blss.exe, bootconf.exe, bootwarn.exe, borg2.exe, bpc.exe, brasil.exe, brw.exe, bs120.exe, bspatch.exe, bundle.exe, bvt.exe

  • c.exe, cavscan.exe, ccapp.exe, ccevtmgr.exe, ccpxysvc.exe, ccSvcHst.exe, cdp.exe, cfd.exe, cfgwiz.exe, cfiadmin.exe, cfiaudit.exe, cfinet.exe, cfinet32.exe, cfp.exe, cfpconfg.exe, cfplogvw.exe, cfpupdat.exe, Cl.exe, claw95.exe, claw95cf.exe, clean.exe, cleaner.exe, cleaner3.exe, cleanIELow.exe, cleanpc.exe, click.exe, cmd32.exe, cmdagent.exe, cmesys.exe, cmgrdian.exe, cmon016.exe, connectionmonitor.exe, control, cpd.exe, cpf9x206.exe, cpfnt206.exe, crashrep.exe, cssconfg.exe, cssupdat.exe, cssurf.exe, ctrl.exe, cv.exe, cwnb181.exe, cwntdwmo.exe

  • d.exe, datemanager.exe, dcomx.exe, defalert.exe, defscangui.exe, defwatch.exe, deloeminfs.exe, deputy.exe, divx.exe, dllcache.exe, dllreg.exe, doors.exe, dop.exe, dpf.exe, dpfsetup.exe, dpps2.exe, driverctrl.exe, drwatson.exe, drweb32.exe, drwebupw.exe, dssagent.exe, dvp95.exe, dvp95_0.exe

  • ecengine.exe, efpeadm.exe, egui.exe, ekrn.exe, emsw.exe, ent.exe, esafe.exe, escanhnt.exe, escanv95.exe, espwatch.exe, ethereal.exe, etrustcipe.exe, evpn.exe, exantivirus-cnet.exe, exe.avxw.exe, expert.exe, explore.exe

  • fact.exe, f-agnt95.exe, fameh32.exe, fast.exe, fch32.exe, fih32.exe, findviru.exe, firewall.exe, fixcfg.exe, fixfp.exe, fnrb32.exe, fprot.exe, f-prot.exe, f-prot95.exe, fp-win.exe, fp-win_trial.exe, frmwrk32.exe, frw.exe, fsaa.exe, fsav.exe, fsav32.exe, fsav530stbyb.exe, fsav530wtbyb.exe, fsav95.exe, fsgk32.exe, fsm32.exe, fsma32.exe, fsmb32.exe, f-stopw.exe

  • gator.exe, gbmenu.exe, gbpoll.exe, generics.exe, gmt.exe, guard.exe, guarddog.exe, guardgui.exe

  • hacktracersetup.exe, hbinst.exe, hbsrv.exe, History.exe, homeav2010.exe, hotactio.exe, hotpatch.exe, htlog.exe, htpatch.exe, hwpe.exe, hxdl.exe, hxiul.exe

  • iamapp.exe, iamserv.exe, iamstats.exe, ibmasn.exe, ibmavsp.exe, icload95.exe, icloadnt.exe, icmon.exe, icsupp95.exe, icsuppnt.exe, Identity.exe, idle.exe, iedll.exe, iedriver.exe, IEShow.exe, iface.exe, ifw2000.exe, inetlnfo.exe, infus.exe, infwin.exe, init.exe, init32.exe, intdel.exe, intren.exe, iomon98.exe, istsvc.exe

  • jammer.exe, jdbgmrg.exe, jedi.exe, JsRcGen.exe

  • kavlite40eng.exe, kavpers40eng.exe, kavpf.exe, kazza.exe, keenvalue.exe, kerio-pf-213-en-win.exe, kerio-wrl-421-en-win.exe, kerio-wrp-421-en-win.exe, killprocesssetup161.exe

  • launcher.exe, ldnetmon.exe, ldpro.exe, ldpromenu.exe, ldscan.exe, licmgr.exe, livesrv.exe, lnetinfo.exe, loader.exe, localnet.exe, lockdown.exe, lockdown2000.exe, lookout.exe, lordpe.exe, lsetup.exe, luall.exe, luau.exe, lucomserver.exe, luinit.exe, luspt.exe

  • MalwareRemoval.exe, mapisvc32.exe, mcagent.exe, mcmnhdlr.exe, mcmscsvc.exe, mcnasvc.exe, mcproxy.exe, McSACore.exe, mcshell.exe, mcshield.exe, mcsysmon.exe, mctool.exe, mcupdate.exe, mcvsrte.exe, mcvsshld.exe, md.exe, mfin32.exe, mfw2en.exe, mfweng3.02d30.exe, mgavrtcl.exe, mgavrte.exe, mghtml.exe, mgui.exe, minilog.exe, mmod.exe, monitor.exe, moolive.exe, mostat.exe, mpfagent.exe, mpfservice.exe, MPFSrv.exe, mpftray.exe, mrflux.exe, msa.exe, msapp.exe, MSASCui.exe, msbb.exe, msblast.exe, mscache.exe, msccn32.exe, mscman.exe, msconfig, msdm.exe, msdos.exe, msiexec16.exe, mslaugh.exe, msmgt.exe, msmsgri32.exe, mssmmc32.exe, mssys.exe, msvxd.exe, mu0311ad.exe, mwatch.exe

  • n32scanw.exe, nav.exe, navap.navapsvc.exe, navapsvc.exe, navapw32.exe, navdx.exe, navlu32.exe, navnt.exe, navstub.exe, navw32.exe, navwnt.exe, nc2000.exe, ncinst4.exe, ndd32.exe, neomonitor.exe, neowatchlog.exe, netarmor.exe, netd32.exe, netinfo.exe, netmon.exe, netscanpro.exe, netspyhunter-1.2.exe, netutils.exe, nisserv.exe, nisum.exe, nmain.exe, nod32.exe, normist.exe, norton_internet_secu_3.0_407.exe, notstart.exe, npf40_tw_98_nt_me_2k.exe, npfmessenger.exe, nprotect.exe, npscheck.exe, npssvc.exe, nsched32.exe, nssys32.exe, nstask32.exe, nsupdate.exe, nt.exe, ntrtscan.exe, ntvdm.exe, ntxconfig.exe, nui.exe, nupgrade.exe, nvarch16.exe, nvc95.exe, nvsvc32.exe, nwinst4.exe, nwservice.exe, nwtool16.exe

  • OAcat.exe, OAhlp.exe, OAReg.exe, oasrv.exe, oaui.exe, oaview.exe, ODSW.exe, ollydbg.exe, onsrvr.exe, optimize.exe, ostronet.exe, otfix.exe, outpost.exe, outpostinstall.exe, outpostproinstall.exe

  • padmin.exe, panixk.exe, patch.exe, pav.exe, pavcl.exe, PavFnSvr.exe, pavproxy.exe, pavprsrv.exe, pavsched.exe, pavsrv51.exe, pavw.exe, pc.exe, PC_Antispyware2010.exe, pccwin98.exe, pcfwallicon.exe, pcip10117_0.exe, pcscan.exe, pdsetup.exe, PerAvir.exe, periscope.exe, persfw.exe, perswf.exe, pf2.exe, pfwadmin.exe, pgmonitr.exe, pingscan.exe, platin.exe, pop3trap.exe, poproxy.exe, popscan.exe, portdetective.exe, portmonitor.exe, powerscan.exe, ppinupdt.exe, pptbc.exe, ppvstop.exe, prizesurfer.exe, prmt.exe, prmvr.exe, procdump.exe, processmonitor.exe, procexplorerv1.0.exe, programauditor.exe, proport.exe, protector.exe, protectx.exe, PSANCU.exe, PSANHost.exe, PSANToManager.exe, PsCtrls.exe, PsImSvc.exe, PskSvc.exe, pspf.exe, PSUNMain.exe, purge.exe

  • qconsole.exe, qh.exe, qserver.exe, Quick Heal.exe

  • rapapp.exe, rav7.exe, rav7win.exe, rav8win32eng.exe, ray.exe, rb32.exe, rcsync.exe, realmon.exe, reged.exe, regedt32.exe, rescue.exe, rescue32.exe, rrguard.exe, rscdwld.exe, rshell.exe, rtvscan.exe, rtvscn95.exe, rulaunch.exe

  • safeweb.exe, sahagent.exe, save.exe, SaveKeep.exe, savenow.exe, sbserv.exe, sc.exe, scam32.exe, scan32.exe, scan95.exe, scanpm.exe, sched.exe, scrscan.exe, seccenter.exe, Security Center.exe, serv95.exe, setloadorder.exe, setup_flowprotector_us.exe, setupvameeval.exe, sgssfw32.exe, sh.exe, shellspyinstall.exe, shield.exe, shn.exe, showbehind.exe, signcheck.exe, smartdefender.exe, smartprotector.exe, smc.exe, smrtdefp.exe, sms.exe, smss32.exe, snetcfg.exe, soap.exe, sofi.exe, sperm.exe, spf.exe, sphinx.exe, spoler.exe, spoolcv.exe, spoolsv32.exe, spywarexpguard.exe, spyxx.exe, srexe.exe, srng.exe, ss3edit.exe, ssg_4104.exe, ssgrate.exe, st2.exe, start.exe, stcloader.exe, supftrl.exe, support.exe, supporter5.exe, svc.exe, svchostc.exe, svchosts.exe, svshost.exe, sweep95.exe, sweepnet.sweepsrv.sys.swnetsup.exe, symlcsvc.exe, symproxysvc.exe, symtray.exe, system.exe, system32.exe, sysupd.exe

  • tapinstall.exe, taskmgr.exe, taumon.exe, tbscan.exe, tc.exe, tca.exe, tcm.exe, tds2-98.exe, tds2-nt.exe, tds-3.exe, teekids.exe, tfak.exe, tfak5.exe, tgbob.exe, titanin.exe, titaninxp.exe, TPSrv.exe, trickler.exe, trjscan.exe, trjsetup.exe, trojantrap3.exe, tsadbot.exe, tsc.exe, tvmd.exe, tvtmd.exe

  • uiscan.exe, undoboot.exe, updat.exe, upgrad.exe, upgrepl.exe, utpost.exe

  • vbcmserv.exe, vbcons.exe, vbust.exe, vbwin9x.exe, vbwinntw.exe, vcsetup.exe, vet32.exe, vet95.exe, vettray.exe, vfsetup.exe, vir-help.exe, virusmdpersonalfirewall.exe, VisthAux.exe, VisthLic.exe, VisthUpd.exe, vnlan300.exe, vnpc3000.exe, vpc32.exe, vpc42.exe, vpfw30s.exe, vptray.exe, vscan40.exe, vscenu6.02d30.exe, vsched.exe, vsecomr.exe, vshwin32.exe, vsisetup.exe, vsmain.exe, vsmon.exe, vsserv.exe, vsstat.exe, vswin9xe.exe, vswinntse.exe, vswinperse.exe

  • w32dsm89.exe, W3asbas.exe, w9x.exe, watchdog.exe, webdav.exe, WebProxy.exe, webscanx.exe, webtrap.exe, wfindv32.exe, whoswatchingme.exe, wimmun32.exe, win32.exe, win32us.exe, winactive.exe, winav.exe, win-bugsfix.exe, windll32.exe, window.exe, windows.exe, wininetd.exe, wininitx.exe, winlogin.exe, winmain.exe, winppr32.exe, winrecon.exe, winservn.exe, winssk32.exe, winstart.exe, winstart001.exe, wintsk32.exe, winupdate.exe, wkufind.exe, wnad.exe, wnt.exe, wradmin.exe, wrctrl.exe, wsbgate.exe, wscfxas.exe, wscfxav.exe, wscfxfw.exe, wsctool.exe, wupdater.exe, wupdt.exe, wyvernworksfirewall.exe

  • xpdeluxe.exe, xpf202en.exe

  • zapro.exe, zapsetup3001.exe, zatutor.exe, zonalm2601.exe, zonealarm.exe

It then creates the following registry subkeys:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virus Doctor_is1
  • HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}

Next, the program also adds the following entries to the hosts file:
  • 4-open-davinci.com
  • securitysoftwarepayments.com
  • privatesecuredpayments.com
  • secure.privatesecuredpayments.com
  • getantivirusplusnow.com
  • secure-plus-payments.com
  • www.getantivirusplusnow.com
  • www.secure-plus-payments.com
  • www.getavplusnow.com
  • www.securesoftwarebill.com
  • secure.paysecuresystem.com
  • google.ae
  • google.as
  • google.at
  • google.az
  • google.ba
  • google.be
  • google.bg
  • google.bs
  • google.ca
  • google.cd
  • google.com.gh
  • google.com.hk
  • google.com.jm
  • google.com.mx
  • google.com.my
  • google.com.na
  • google.com.nf
  • google.com.ng
  • google.ch
  • google.com.np
  • google.com.pr
  • google.com.qa
  • google.com.sg
  • google.com.tj
  • google.com.tw
  • google.dj
  • google.de
  • google.dk
  • google.dm
  • google.ee
  • google.fi
  • google.fm
  • google.fr
  • google.ge
  • google.gg
  • google.gm
  • google.gr
  • google.ht
  • google.ie
  • google.im
  • google.in
  • google.it
  • google.ki
  • google.la
  • google.li
  • google.lv
  • google.ma
  • google.ms
  • google.mu
  • google.mw
  • google.nl
  • google.no
  • google.nr
  • google.nu
  • google.pl
  • google.pn
  • google.pt
  • google.ro
  • google.ru
  • google.rw
  • google.sc
  • google.se
  • google.sh
  • google.si
  • google.sm
  • google.sn
  • google.st
  • google.tl
  • google.tm
  • google.tt
  • google.us
  • google.vu
  • google.ws
  • google.co.ck
  • google.co.id
  • google.co.il
  • google.co.in
  • google.co.jp
  • google.co.kr
  • google.co.ls
  • google.co.ma
  • google.co.nz
  • google.co.tz
  • google.co.ug
  • google.co.uk
  • google.co.za
  • google.co.zm
  • google.com
  • google.com.af
  • google.com.ag
  • google.com.ar
  • google.com.au
  • google.com.bn
  • google.com.br
  • google.com.by
  • google.com.bz
  • google.com.cu
  • google.com.ec
  • google.com.fj
  • bing.com
  • www.bing.com
  • search.yahoo.com
  • www.search.yahoo.com
  • search.live.com
  • search.msn.com
  • googleads.g.doubleclick.net
  • www.googleads.g.doubleclick.net
  • pubads.g.doubleclick.net
  • www.pubads.g.doubleclick.net
  • partner.googleadservices.com
  • www.partner.googleadservices.com
  • www.partner.googleadservices.com
