Threat Database Rogue Anti-Spyware Program AVASoft Antivirus Professional

AVASoft Antivirus Professional

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 58
First Seen: March 19, 2013
Last Seen: May 1, 2023
OS(es) Affected: Windows

AVASoft Antivirus Professional Image

AVASoft Antivirus Professional is a fake security application and another member of the WinWeb Security family. Typically, AVASoft Antivirus Professional will be installed on a computer without the computer user's authorization, through illegal methods typically used to distribute malware. AVASoft Antivirus Professional is part of a scam that involves using fake anti-virus software to convince computer users to pay for expensive upgrades in order to remove nonexistent malware threats on their computer. If AVASoft Antivirus Professional is installed on your computer, it is important to remove AVASoft Antivirus Professional immediately with the help of a reliable anti-malware application.

Removing AVASoft Antivirus Professional can be difficult because this fake anti-virus program has several components that AVASoft Antivirus Professional uses to defend itself. For example, AVASoft Antivirus Professional can block computer users from running certain applications or opening certain files. This means that most computer users dealing with an AVASoft Antivirus Professional infection will not be able to access their web browser, security software or Windows components like the Task Manager and System Restore. When the computer user tries to open any of these components, AVASoft Antivirus Professional will display a message claiming that the file is infected and then claim that it has been blocked for the computer user's own protection.

AVASoft Antivirus Professional is designed to start up automatically as soon as the victim logs into Windows. AVASoft Antivirus Professional then runs a bogus system scan. The fake scan will always have negative results, indicating that the victim's computer is infested with extremely dangerous viruses, Trojans and worms. Despite the fact that AVASoft Antivirus Professional looks like an anti-virus program, using AVASoft Antivirus Professional to remove these supposed threats results in supplementary error messages alleging that the user must upgrade AVASoft Antivirus Professional to an expensive 'full version.' Of course, since AVASoft Antivirus Professional has no way of detecting or removing malware, ESG malware researchers advise computer users to avoid following AVASoft Antivirus Professional's instructions and to, instead, remove this threat with a real anti-virus application. To prevent future AVASoft Antivirus Professional infections, ESG security researchers advise computer users to avoid opening email attachments from unknown sources or that seems suspicious, avoid clicking on unknown links and to never download files without being absolutely sure of their source and contents.

AVASoft Antivirus Professional is a clone of fake security programs such as System Security, Antivirus Security, Total Security 2009, Security Tool, Trojan.RogueAV.a.gen, System Adware Scanner 2010, FakeAlert-KW.e, Advanced Security Tool 2010, System Tool 2011, Security Shield, MS Removal Tool, Total Security, System Security 2011, Essential Cleaner, Security Shield Pro 2011, Personal Shield Pro, Security Shield 2011, Security Sphere 2012, Advanced PC Shield 2012, Futurro Antivirus.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

SpyHunter Detects & Remove AVASoft Antivirus Professional

File System Details

AVASoft Antivirus Professional may create the following file(s):
# File Name MD5 Detections
1. 12D973C4A70F481A000012D960EF4C20.exe ae21c2538241941374047ae10b7d2ca8 2
2. %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
3. %Programs%\AVASoft Antivirus Professional\AVASoft Antivirus Professional.lnk
4. %Desktopdir%\AVASoft Antivirus Professional.lnk
5. %CommonAppData%\[RANDOM CHARACTERS AND NUMBERS]\
6. %CommonAppData%\[RANDOM CHARACTERS AND NUMBERS]\[RANDOM CHARACTERS AND NUMBERS]
7. %CommonAppData%\[RANDOM CHARACTERS AND NUMBERS]\[RANDOM CHARACTERS AND NUMBERS].exe
8. %CommonAppData%\[RANDOM CHARACTERS AND NUMBERS]\[RANDOM CHARACTERS AND NUMBERS].ico

Registry Details

AVASoft Antivirus Professional may create the following registry entry or registry entries:
File name without path
AVASoft Professional Antivirus.lnk
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVASoft Antivirus Professional
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVASoft Antivirus Professional\DisplayIcon = "%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVASoft Antivirus Professional\DisplayName = "AVASoft Antivirus Professional"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVASoft Antivirus Professional\ShortcutPath = "%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe" -u"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVASoft Antivirus Professional\UninstallString = "%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe" -u"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce = "[RANDOM CHARACTERS AND NUMBERS]"
HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM] = "%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe"

Directories

AVASoft Antivirus Professional may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\AVASoft Professional Antivirus
%ProgramFiles%\AVASoft Professional Antivirus
%ProgramFiles(x86)%\AVASoft Professional Antivirus

URLs

AVASoft Antivirus Professional may call the following URLs:

tech-ava-soft.org

Messages

The following messages associated with AVASoft Antivirus Professional were found:

AVASoft Professional Antivirus Firewall Alert
AVASoft Professional Antivirus Firewall has blocked a program from accessing the Internet.
Internet Explorer Internet Browser is infected with worm SVCHOST.Stealth.Keyloger. This worm is trying to send your credit card details using Internet Explorer Internet Browser to connect to remote host.
AVASoft Professional Antivirus Warning
Intercepting programs that may compromise your privacy and harm your system have been detected on your PC.
Click here to remove them immediately with AVASoft Professional Antivirus.
AVASoft Professional Antivirus Warning
Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss.
Click here to block unauthorised modification by removing threats (Recommended)
AVASoft Professional Antivirus Warning
Your PC is still infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid the theft of your credit card details.
Security Monitor: WARNING!
Attention! System detected a potential hazard (TrojanSPM/LX) on your computer that may infect executable files. Your private information and PC safety is at risk.
To get rid of unwanted spyware and keep your computer safe your need to update your current security software.
Click Yes to download official intrusion detection system (IDS software).
Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs.
Click here to remove it immediately with AVASoft Professional Antivirus.
Warning!
Application cannot be executed. The file cmd.exe infected.
Please activate your antivirus software.
Warning! The site you are trying visit may harm your computer!
Your security setting level puts your computer at risk!
Activate AVASoft Professional Antivirus, and enable safe web surfing (recommended).
Ignore warnings and visit that site in the current stat (not recommended).
Warning: Your computer is infected
Detected spyware infection!
Click this message to install the last update of security software...

Trending

Most Viewed

Loading...