Threat Search: 

ThreatExpert's Statistics for RogueAntiSpyware.AntivirusXP2008 [PC Tools]:

RogueAntiSpyware.AntivirusXP2008 [PC Tools] is also known as:
Threat AliasNumber of Incidents
Generic PUP.x [McAfee]7,660
TROJ_RENOS.ACG [Trend Micro]7,128
AntiVirus2008 [Symantec]4,670
Troj/FakeVir-DE [Sophos]4,488
not-a-virus:FraudTool.Win32.XPAntivirus.ld [Kaspersky Lab]4,312
Program:Win32/Antivirus2008 [Microsoft]1,939
TROJ_RENOS.ZQ [Trend Micro]102
Trojan.Renos.NDB [Ikarus]88
Trojan:Win32/FakeXPA [Microsoft]88
FakeAlert-AQ [McAfee]49
Winfixer [McAfee]48
FakeAlert-AG [McAfee]40
XPAntivirus [Symantec]39
not-a-virus:FraudTool.Win32.MalwareProtector.d [Kaspersky Lab]34
Downloader.MisleadApp [Symantec]29
Trojan.FakeAlert [PC Tools]25
Troj/FakeAV-AQ [Sophos]20
Trojan:Win32/Renos.BAH [Microsoft]19
MalwareProtector2008 [Symantec]16
not-a-virus:FraudTool.Win32.XPAntivirus.qj [Kaspersky Lab]16
Trojan:Win32/XPAntiVirus.C [Microsoft]16
TROJ_FAKEALER.GJ [Trend Micro]13
Troj/FakeVir-CH [Sophos]12
AntiVirusXP2008 [Symantec]10
not-a-virus:FraudTool.Win32.XPAntivirus.qc [Kaspersky Lab]9
TROJ_FAKEALRT.CC [Trend Micro]9
Program:Win32/XPAntiVirus [Microsoft]8
Trojan:Win32/Antivirusxp [Microsoft]8
TROJ_XPANTIVIR.E [Trend Micro]7
Troj/FakeAV-Gen [Sophos]6
Trojan:Win32/Meredrop [Microsoft]6
not-a-virus:FraudTool.Win32.XPAntivirus.nz [Kaspersky Lab]5
Troj/FakeAle-ES [Sophos]5
Troj/FakeAle-EU [Sophos]5
TROJ_FAKEAV.ED [Trend Micro]5
BAT.AutoDelete.A [Ikarus]4
not-a-virus:FraudTool.Win32.AntivirusXP2008.q [Kaspersky Lab]4
not-a-virus:FraudTool.Win32.MalwareProtector.r [Kaspersky Lab]4
Troj/FakeAV-BS [Sophos]4
TROJ_FAKEALER.GA [Trend Micro]4
TROJ_FAKEALER.HO [Trend Micro]4
FakeAlert-AB.dldr [McAfee]3
Mal/EncPk-CZ [Sophos]3
Mal/EncPk-EP, Mal/TibsPk-D [Sophos]3
Troj/FakeAle-GL [Sophos]3
TROJ_FAKEAV.IF [Trend Micro]3
TrojanDownloader:Win32/Renos [Microsoft]3
Win-Trojan/Autodelete.106496 [AhnLab]3
Generic FakeAlert.a [McAfee]2
TROJ_RENOS.AAM [Trend Micro]2
Trojan.Fakealert.AAM [Ikarus]2
Trojan:Win32/Tibs.J [Microsoft]2
Virus.Win32.FraudTool.GI [Ikarus]2
Downloader [Symantec]1
Downloader.gen.a [McAfee]1
FakeAlert-AB [McAfee]1
FakeAlert-AB.gen.b [McAfee]1
FakeAlert-AG.gen [McAfee]1
FakeAlert-AG.gen.a [McAfee]1
Mal/FakeAV-B, Mal/EncPk-CZ [Sophos]1
not-a-virus:FraudTool.Win32.AntiVirusPro.h [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.MalwareProtector.ab [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.MalwareProtector.s [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.WinFixer.i [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntivirus.lh [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntivirus.md [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntivirus.nf [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntivirus.ri [Kaspersky Lab]1
Troj/FakeAV-AB [Sophos]1
Troj/FakeAV-BT [Sophos]1
Troj/FakeAV-DV [Sophos]1
Troj/PWS-ASA [Sophos]1
TROJ_DLOADER.XPB [Trend Micro]1
TROJ_FAKEALER.DD [Trend Micro]1
TROJ_FAKEALER.JC [Trend Micro]1
TROJ_FRAUDLOA.IP [Trend Micro]1
TROJ_RENOS.ACO [Trend Micro]1
TROJ_RENOS.AEP [Trend Micro]1
TROJ_RENOS.AFQ [Trend Micro]1
Trojan Horse [Symantec]1
Trojan.Dropper [Symantec]1
Trojan.Fakealert.abq [Ikarus]1
Trojan.Peed.JOA [Ikarus]1
Trojan.Win32.Agent.qox [Kaspersky Lab]1
Trojan:Win32/FakeAlert.A [Microsoft]1
Trojan:Win32/Tibs.HM [Microsoft]1
Trojan-Downloader.Win32.FraudLoad.gen [Kaspersky Lab]1
Trojan-Downloader.Win32.Small [Ikarus]1
Trojan-Downloader.Win32.Small.adrf [Kaspersky Lab]1
TrojanDownloader:Win32/Renos.gen!AU [Microsoft]1
Win-Trojan/Fakeav.106496 [AhnLab]1

RogueAntiSpyware.AntivirusXP2008 [PC Tools] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation91

RogueAntiSpyware.AntivirusXP2008 [PC Tools] is known to be created as:
%ProgramFiles%\rhc75dj0erc1\rhc75dj0erc1.exe
%ProgramFiles%\rhc75dj0erc1\rhc75dj0erc1skin.dll
%ProgramFiles%\whcc5dj0erc1\whcc5dj0erc1.exe
%System%\lphc35dj0erc1.exe
%System%\pphc35dj0erc1.exe
%Temp%\rhca7kj0e19g.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).