Antivirus Scan

By JubileeX in Rogue Anti-Virus Program | 187 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
Translate To:     Español  |   Português
More... More

Antivirus Scan Description

Image Screenshot

[+] Click Image to Enlarge

Antivirus Scan uses fake pop-ups, security alerts and system scanners to convince victims that they have to purchase it. Antivirus Scan advertises itself as a legitimate anti-virus application however it is a malicious rogue that should not be trusted or purchased. Antivirus Scan is not able to detect or even remove any real malware let alone the malware it claims to detect on the fake pop-ups and scan reports. Antivirus Scan spreads with the help of Trojans or associated websites that advertise the rogue. If you encounter security notifications from Antivirus Scan, use a legitimate security tool to remove this rogue from your PC.

Type: Rogue Anti-Virus Program

How Can You Detect Antivirus Scan?

‘How Antivirus Scan Infects Your Computer’ Video

Antivirus Scan Removal Details

Antivirus Scan has typically the following processes in memory:

  • [random characters]agnz.exe

Antivirus Scan creates the following files in the system:

  • Antivirus Scan.lnk

Antivirus Scan creates the following registry entries:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus Scan
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ?ProxyOverride? = ??
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ?[random characters] gnz.exe?
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run ?Antivirus Scan?
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter ?Enabled? = ?0″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ?ProxyEnable? = ?1″
  • HKEY_CURRENT_USER\Software\Antivirus Scan
  • HKEY_CURRENT_USER\Software\[random characters]
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ?ProxyServer? = ?http=127.0.0.1:33921″
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ?[random characters]agnz.exe?

Important Article Disclaimer

ESG Support Center

This entry was last updated on 12/17/10 and posted on 12/17/10. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.