> Virus & Spyware Info

Virus & Spyware Info
We provide the latest information on new viruses, spyware, and other malware.

Name Adware/Rogueware.ActiveSecurity.A
Alias Trojan.FakeAV[Symantec], FraudTool.Win32.RogueSecurity (v)[Sunbelt], Trojan.FakeAV[PCTools]
Current Spread Level System Threat Level
Network Proliferation Potential Danger Level
Active Platform Windows Form/Type Rogueware
Method of Spread Download
Main Symptoms Induced payment through false/exaggerated detections.
Created Files antimalware.exe, uninstall.exe, amext.dll, wscsvc32.exe
File Size 1,585,152 Byte Activity Date 0000-00-00
Country of Origin Unspecified Detection Date 0000-00-00
Similar/Altered Viruses
Detectable Engine 2009.11.18.01 Reparable Engine 2009.11.18.01
Description

[Summary]

Adware/Rogueware.ActiveSecurity.A is downloaded and installed without the user's knowledge.  A list is shown with false adware or spyware detections and payment is induced in order to repair the malware.

[Propagation]

Adware/Rogueware.ActiveSecurity.A is downloaded and installed through other malware.

[Symptoms]

1. Creates files in the following path.

- (Program Folder)\AntiMalware\antimalware.exe
- (Program Folder)\AntiMalware\uninstall.exe
- (Program Folder)\AntiMalware\amext.dll
- (User Temporary Folder)\wscsvc32.exe

2. The following registry key is created in order to run automatically upon Windows startup.

- HKEY_LOCAL_MACHINE\
    SOFTWARE\
      Microsoft\
        Windows\
          CurrentVersion\
            Run

- Name: AntiMalware
- Data: "(Program Folder)\AntiMalware\antimalware.exe" -noscan

3. The registry created by Adware/Rogueware.AntiAID.B is shown below.

- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMalware
- HKCU\Software\AntiMalware

[Reference Information]

- In Windows, (Program Folder) generally refers to C:\Program Files

- (User Temporary Folder) generally refers to C:\Documents and Settings\(User Account)\Local Settings\Temp.

Manual Treatment Method

[Repairing with nProtect Netizen / nProtect Personal]

1. Run the product and clik on the ON-SCAN button by the top.
2. Check on all the files in Settings and click on the Scan Now button.
3. If a malware is detected through the scan, click on the Yes button in the Treatment Option Window.
4. Check if the malware has been successfully repaired.

[Repairing with nProtect Anti-Virus/Spyware 2007 / nProtect GameGuard Personal 2007]

1. Run the product and update the engine and patch file to the latest version. (Using the main window, tray icon, or start menu)
2. Select the Virus/Spyware tab and click on the Scan Now button.
3. If a malware is detected through the scan, click on the Repair button.
4. Check if the malware has been successfully repaired.


Contents Copyright Notice
The analyzed data above is copyright material by ISARC(INCA Internet Security Analysis & Response Center) and may not be used without permission.

Non-profit organizations or personal individuals may use the contents, but must cite the source, and any use of the information for commercial purposes or by corporations must first contact our contents manager and get our approval.

Information Contents Inquiries : sale@inca.co.kr
 
Company Info  l  Support  l  Contact Us  l  Terms of Service    
Copyright (C) INCA Internet Co., Ltd. All rights reserved.