| Visit ThreatExpert web site | | | Close Report |
[PCTools]
[Symantec]
[McAfee]
[Ikarus]| What's been found | Severity Level |
| Contains characteristics of a rogue antispyware application that uses aggressive and deceptive advertising along with false reports of exaggerated system security threats to persuade users to download and purchase their product. | ![]() |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %DesktopDir%\Antivirus 2009.lnk | 670 bytes | MD5: 0xC24EC1BFB13297C89781292CC35E2285 SHA-1: 0x6C5F32ADDB3CAE92906FED44333D8EF5686F899B |
(not available) |
| 2 | %StartMenu%\Antivirus 2009\Antivirus 2009.lnk | 676 bytes | MD5: 0x8DB16EA4E759C2F128AA545923D1CF98 SHA-1: 0xE5EA44089F6DBEE89C31BDDA85FCDDBEBA83A96C |
(not available) |
| 3 | %StartMenu%\Antivirus 2009\Uninstall Antivirus 2009.lnk | 698 bytes | MD5: 0x4578BEDC2754B587A975818E45A51902 SHA-1: 0x2507F12C366184CF2A6CC3735C6CEFB60A317932 |
(not available) |
| 4 | %System%\ieupdates.exe.tmp | 0 bytes | MD5: 0xD41D8CD98F00B204E9800998ECF8427E SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709 |
(not available) |
| 5 | [file and pathname of the sample #1] | 2,277,376 bytes | MD5: 0x73FE2CCB755F2993D3812A76335690B4 SHA-1: 0x495C9FD82D7DD8E1A740BD2B08D6E912FA485F94 |
HeurEngine.MaliciousPacker [PCTools]Packed.Generic.187 [Symantec]Trojan-FakeAV.Win32.XPAntivirus.aae [Kaspersky Lab] Generic Dropper.bw [McAfee]Troj/FakeVir-JP [Sophos] Trojan-FakeAV [Ikarus] |
| 6 | %System%\scui.cpl | 78,336 bytes | MD5: 0xB69DAF8D44CBBB438DD86240C4960D07 SHA-1: 0x8AC658BDB8F999FE81A0182606A12D9C8B7F2D46 |
RogueAntiSpyware.AntiVirusPro [PCTools]AntiVirus2009 [Symantec]Trojan-FakeAV.Win32.XPAntivirus.ty [Kaspersky Lab] FakeAlert-AB [McAfee]TROJ_FAKEALER.GV [Trend Micro]Troj/FakeAle-GZ [Sophos]Rogue:Win32/FakeXPA [Microsoft] not-a-virus:FraudTool.Win32.XPAntivirus [Ikarus]Win-Trojan/Fakealert.78344 [AhnLab]packed with UPX [Kaspersky Lab] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 5,455,872 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Russian Federation |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.