| Visit ThreatExpert web site | | | Close Report |
[Ikarus]| What's been found | Severity Level |
| Contains characteristics of a rogue antispyware application that uses aggressive and deceptive advertising along with false reports of exaggerated system security threats to persuade users to download and purchase their product. | ![]() |
| Downloads/requests other files from Internet. | ![]() |
| Packed with a packer that is known to be used by malware (e.g. to complicate threat analysis or detection). | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
RogueAntiSpyware.Antivir64![]() |
Antivir64 acts as an antivirus program which produces false detections. It requests the user to subscribe or purchase in order to remove detections. |
RogueAntiSpyware.AntiVirusPro![]() |
RogueAntiSpyware.AntiVirusPro is a Rogue Anti-Spyware product which comes bundled along with a malicious downloader. It is downloaded and installed without the users consent. |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | %DesktopDir%\Antivirus 2009.lnk | 670 bytes | MD5: 0xCE121BFD31850C56EF5A26FFD6564545 SHA-1: 0xF91D090391194B46CCD17EFC62D1BD4035EDD359 |
(not available) |
| 2 | %StartMenu%\Antivirus 2009\Antivirus 2009.lnk | 676 bytes | MD5: 0x8706D33AD5964554DE4240D577181FA7 SHA-1: 0x970E39627FD91BE407E5DE63FB34B9648865165B |
(not available) |
| 3 | %StartMenu%\Antivirus 2009\Uninstall Antivirus 2009.lnk | 698 bytes | MD5: 0xAB0B227D981A393E567F58892A85F36E SHA-1: 0xA9543F4B1372D5BC9CF678E800DD44A2A5A42C61 |
(not available) |
| 4 | [file and pathname of the sample #1] | 1,098,752 bytes | MD5: 0x973F20B0E26D6FF19793CF1662752C72 SHA-1: 0x2DE05C54D5EB59CCEDF266DC2561FA8B5FA640E0 |
Trojan.Win32.FakeXPA [Ikarus]packed with Molebox [Kaspersky Lab] |
| 5 | %System%\scui.cpl | 78,336 bytes | MD5: 0xB69DAF8D44CBBB438DD86240C4960D07 SHA-1: 0x8AC658BDB8F999FE81A0182606A12D9C8B7F2D46 |
RogueAntiSpyware.AntiVirusPro [PCTools]AntiVirus2009 [Symantec]not-a-virus:FraudTool.Win32.XPAntivirus.oj [Kaspersky Lab]FakeAlert-AB [McAfee]TROJ_FAKEALER.GV [Trend Micro]Troj/FakeAle-GZ [Sophos]Trojan:Win32/FakeXPA [Microsoft]PHISH.FraudTool.XPAntivirus [Ikarus] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 3,153,920 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() |
Russian Federation |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.