Antivirus Protection 2012

By JubileeX in Rogue Anti-Virus Program | 1 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (33 votes, average: 3.64 out of 5)
Loading ... Loading ...
More... More

Antivirus Protection 2012 Description

Image Screenshot

[+] Click Image to Enlarge

Antivirus Protection 2012 is one of the many rogue anti-virus programs belonging to the Rogue:Win32/Defmid family of scamware. These kinds of fake anti-virus applications will use the same interface repeatedly, only changing the name of each particular member of this family of malware in order to stay one step ahead of PC security researchers. ESG security researchers indicates that Antivirus Protection 2012 is designed to mislead its victims, providing fake error reports and system scans designed to convince this malware infection’s victims into purchasing a useless license for Antivirus Protection 2012. An Antivirus Protection 2012 infection will often be associated with the presence of other malware on your computer and should be regarded as a severe threat to your computer system’s security.

Despite Its Name, the Antivirus Protection 2012 Scam Goes Back Several Years

Do not be misled by the “2012″ appended to the ending of Antivirus Protection 2012’s name. This is simply added to the end of this rogue program’s name in an attempt to make this fake security program appear new and improved. However, malware like Antivirus Protection 2012 has been using what is basically the same interface and attack strategy since at least 2010. There are dozens of clones of Antivirus Protection 2012, some of which include fake security applications such as Security Center, Security Defender, Security Monitor 2012, Smart Internet Protection 2012, Antimalware Tool, Security Central, and Internet Defender. All of these clones have versions with the year “2011″ or “2012″ appended to the end (e.g. Microsoft Security Center 2012 or Internet Protection 2011) as a way to create multiple versions of the same malware threat with a minimum of effort.

How Antivirus Protection 2012 Attempts to Steal Your Money

Antivirus Protection 2012 is designed to display authentic-looking error messages and alerts indicating the presence of malware on the victim’s computer. However, ESG security researchers advise against paying attention to any of these so-called warnings, since Antivirus Protection 2012 is a malware infection itself and has no way of detecting or removing malware. This fake security program will insert links leading to its website in various places in order to attempt to direct its victim to a form asking for the victim’s credit card information in exchange for a useless registration code for its non-existent full version. The registration code LIC2-00A6-234C-B6A9-38F8-F6E2-0838-F084-E235-6051-18B3 has been known to diminish some of this rogue security program’s symptoms while you use a reliable anti-malware tool to remove it from your computer.

Type: Rogue Anti-Virus Program

How Can You Detect Antivirus Protection 2012?

Antivirus Protection 2012 Technical Report

As new Antivirus Protection 2012 details are reported by our customers and findings from our Threat Research Center, we will update this section.

Fake message for Antivirus Protection 2012:

The following fake error message(s) appears for Antivirus Protection 2012:

Your computer might be at risk
Antivirus detects viruses, worms, and Trojan horses. They can (and do) destroy data, format your hard disk or can destroy the BIOS. By destroying the BIOS many times you end up buying a new motherboard or if the bios chip is removable then that chip would need replacing

Antispyware software warningYour computer is infected with spyware and malware. Last scan results: 364 infected files found! Click this notification to fix the problem.

Security Center
Unauthorized remote connection!
Your system is making an unauthorized personal data transfer to a remote computer!
Warning! Unauthorized personal data transfer is detected! It may be your personal credit card details, logins and passwords, browsing habits or information about files you have downloaded.
To protect your private data, please click “Prevent Connection” button below.

System critical warning!
You have been infected by a proxy-relay Trojan server
Your query looks similar to automated requests from a spyware application.
Your system has come under attack of hostile software.
Click here to deactivate it.

Reported Insecure Browsing: Navigation Blocked
Insecure Internet Activity. Threat of virus attack
Due to insecure Internet browsing your PC can easily get infected with viruses, worms, and Trojans without your knowledge, and that can lead to system slowdown, freezes and crashes. Also insecure Internet activity can result in revealing your personal information.

Security Center Alert
To help protect your computer, Security Center has blocked some features of this program.
Name: Screen.Grab.J.exe
Risk: High

Antivirus Protection 2012
Your computer is being used as spamming machine. You can get sued for spam. Your computer WIL BE DISCONNECTED FORM INTERNET BECAUSE SPAMMING OTHER PCs.

You have been infected by a proxy-relay trojan server with new and danger “SpamBots”.
You have a computer with a virus that sends spam.
This is a mass-mailing worm with backdoor thus allowing un-authorized access to the infected system.
It spreads by mass-mailing itself to e-mail addresses harvested from the local computer or by querying on-line search engines such as google.com.
The IP address that YOU are getting from Internet Service Provider (ISP) for YOU personal computer is on some major blacklist.
Your computer has been used to send a huge amount of junk e-mail messages during the last days.
You IP will be marked in the Police log file as mass-mailing spam assist.
Upgrading to the full version Antivirus Protection 2012 it will eliminate the majority of Spam attempts.

Antivirus Protection 2012
The application excel.exe was launched successfully but it was forced to shut down due to security reasons. This application infected by a malicious software program which might present damage for the PC. It is highly recommended to make a full scan of your computer to exterminate the malicious programs from it.

Antivirus Protection 2012 Firewall Alert
Suspicious activity in your registry system space was detected. Rogue malware detected in your system. Data leaks and system damage are possible. Please use a deep scan option.

Antivirus Protection 2012 Firewall Alert
Your computer is being attacked from a remote machine!
Block Internet access to your computer to prevent system infection.
Attacker IP: [ip address]
Attack type: RCPT exploit

Antivirus Protection 2012
Spyware.IEMonster process is found. The virus is going to send your passwords from Internet browser (Explorer, Mozilla Firefox, Outlook & others) to the third-parties. Click here for further protection of your data with Antivirus Protection 2012.

‘How Antivirus Protection 2012 Infects Your Computer’ Video

Antivirus Protection 2012 Removal Details

Antivirus Protection 2012 has typically the following processes in memory:

  • %AppData%\Antivirus Protection\antivirusprotection2012.exe
  • %AppData%\Antivirus Protection\securitymanager.exe

Antivirus Protection 2012 creates the following files in the system:

  • %Desktop%\Antivirus Protection.lnk
  • %StartMenu%\Programs\Antivirus Protection\antivirus protection.lnk

Antivirus Protection 2012 creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run!Inspector

Important Article Disclaimer

ESG Support Center

This entry was last updated on 01/15/13 and posted on 02/17/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.