Anti-Virus-1

Domesticus By Domesticus in Rogue Anti-Spyware Program | 246 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 4.33 out of 5)
Loading ... Loading ...

Anti-Virus-1 Description

Anti-Virus-1 is a rogue anti-spyware program similar to Antivirus 2010. Anti-Virus-1 may have been installed by a Trojan known as Zlob or Vundo. Zlob and Vundo Trojans infect users without their knowledge and permission and will attempt to scare or trick the user into buying the full Anti-Virus-1 version of the program. Anti-Virus-1’s common unscrupulous tactics to persuade the user may be bogus system notifications or fake security alerts stating that the computer is infected with an exaggerated amount of spyware. In order to to remove the supposed threats, the user should purchase Anti-Virus-1’s commercial version.

Anti-Virus-1 may also imitate a computer system scan and list supposed spyware infections as a result. However, these resulting entries are created by Anti-Virus-1 itself to make the user believe Anti-Virus-1’s scanner has detected actual threats. Anti-Virus-1 is a threat and should be removed without hesitation.

Type: Rogue AntiSpyware Programs

How Can You Detect Anti-Virus-1?

 
 
 
 

Anti-Virus-1 Technical Report

As new Anti-Virus-1 details are reported by our customers and findings from our Threat Research Center, we will update this section.

The following Anti-Virus-1 files with its MD5s were created in the system:

File Name File Size MD5
AV1i.exe 151040 8bc18b1d6cec2f4160c1d21083a557eb
Stage2[1].exe 151040 8bc18b1d6cec2f4160c1d21083a557eb
AV1i2.exe 59392 b99b9bfa28c119d6089b5dfa1b49647b
StageThree[1].exe 59392 b99b9bfa28c119d6089b5dfa1b49647b
svchost[1].exe 59059 e205763aae5db6ae563e6f32244f2f4d
svchost.exe 59059 e205763aae5db6ae563e6f32244f2f4d
QWProtect[1].dll 113664 0a45c57d5277b7e8a55e08e84c08afeb
av1.exe 113664 0a45c57d5277b7e8a55e08e84c08afeb
QWProtect.dll 113664 0a45c57d5277b7e8a55e08e84c08afeb
install[1].exe 70144 27a882668aeda52450ef78a0d6e42a30
svchost[1].exe 83968 c198517864cc71849ac3b6d3ed44b2bf
av1.exe 10618368 35897905169443ff92d47b26bb1bbbac
qwprotect.dll 111104 90a0e1a41c13147528eca2b8cf930a8c
qwprotect.dll 698368 da4394f47a6e99fa2088d64597deeeda
av1.exe 494592 603047aaec6041575caf6aa1c509c586
AV1i.exe 151552 4860a1de4b2848d55f9476e3968ea759
AV1i2.exe 59904 1a57648c4b6a47e5d183dfbaa01e358f
AV1i.exe 130048 b4ee2e29c0c22f0703e021dacedfe96a
av1.exe 10551296 e8441c520ce81060fb63a4418b1286ca
QWProtect.dll 697856 1061b0cc632ba60fac3563b5d1674bca
QWProtect.dll 113152 6d8d7d02dc27e1f6c0cdfe58301fa4a1
n1.exe 11122688 03241ef13e3b4cc264691de922fd707f
svchost.exe 80896 e89160a57bf4f971e3030ecd679d6c28

Anti-Virus-1 has typically the following processes in memory:

  • av1.exe
  • QWProtect.dll
  • %\WINDOWS%\system32\wingamma.exe
  • AV1i.exe

Anti-Virus-1 created the following directories, files, paths:

  • %AllUsersProfile%\Start Menu\Programs\Anti-virus-1

Anti-Virus-1 creates the following registry entries:

  • AppID\29256442-2C14-48CA-B756-3EE0F8BDC774
  • QWProtect.QWProtectBHO
  • 8D187DFF-423F-41d3-A331-A60DE5886675
  • AV1\AV1\F275E931-AFEC-4f70-B0D4-CC2731B945E0
  • 051C9A06-FB08-486F-B09B-8B33B261637D
  • 512E801E-2F02-4ADE-ACAA-58F08A22B2F8
  • 70FEAD04-A7FD-4B89-B814-8A8251C90EF7
  • AppID\QWProtect.DLL
  • QWProtect.QWProtectBHO.1

Important Article Disclaimer

ESG Support Center

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 02/16/09 and is filed under Rogue Anti-Spyware Program. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.