The Spyware Detective

TheSpywareDetective is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats. It includes Elevated threats that are typically installed without adequate notice and consent, and may make unwanted changes to our system, such as reconfiguring our browser’s homepage and search settings. These threats may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain. These new add-ons and components may block or redirect our preferred network connections, and can negatively impact our computer’s performance and stability. Elevated threats may also collect, transmit, and share potentially sensitive data without adequate notice and consent.0

General information:

Malware Name: The Spyware Detective
Malware Type: Rogue Security program
Company Name: The Spyware Detective
Company URL: http://www.thespywaredetective.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

The Spyware Detective identifies spywares in any form they exist: Adware, Browser Hijacker, Trojan, RAT, Worms, Dialers, Tracking Cookies etc., by analyzing all possible infected items: processes running in memory, dlls, executables, files, registries, cookies. Using Spyware Detective, you'll be able to remove all spywares from your computer. Once found a threat in the system will be moved in quarantine section. The user can choose later to restore this item. If is a file, an executable, a cookie or a registry item will be restored. This way you can recover data you consider you will like to keep it.

Spyware Description:

TheSpywareDetective is a security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats. It includes Elevated threats that are typically installed without adequate notice and consent, and may make unwanted changes to our system, such as reconfiguring our browser’s homepage and search settings. These threats may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain. These new add-ons and components may block or redirect our preferred network connections, and can negatively impact our computer’s performance and stability. Elevated threats may also collect, transmit, and share potentially sensitive data without adequate notice and consent.0

Characteristics/Symptoms:

    -> False positives work as good to purchase -> False scan results -> Uses inadequate scan/detection scheme -> Uses out of date ref database0

Additional information might be found here:

google Search at Google for The Spyware Detective
bing Search at Bing for The Spyware Detective
yahoo Search at Yahoo for The Spyware Detective

Processes Running:

TheSpywareDetectivePro.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\The Spyware Detective Pro\skins\news_rollover.jpg 12706 JPEG Image
C:\Program Files\The Spyware Detective Pro\skins\scan.jpg 12421 JPEG Image
C:\Program Files\The Spyware Detective Pro\skins\skin.skn 28145 SKN File

Folder information Created after Installation:

Folder Location
C:\Program Files\The Spyware Detective Pro\backup
C:\Program Files\The Spyware Detective Pro\data

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{B6031713-7439-4709-B0A3-57DBB3E6322A}_is1 DisplayName
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{B6031713-7439-4709-B0A3-57DBB3E6322A}_is1 DisplayVersion
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstall{B6031713-7439-4709-B0A3-57DBB3E6322A}_is1 Inno Setup: Setup Version