Threat Database Trojans RogueAntiSpyware.VirusDoctor!rem

RogueAntiSpyware.VirusDoctor!rem

By LoneStar in Trojans

RogueAntiSpyware.VirusDoctor!rem is a Trojan Horse that supports other malware. Because RogueAntiSpyware.VirusDoctor!rem exists in order to install other malware, the longer you leave RogueAntiSpyware.VirusDoctor!rem on your computer, the more damage it can do. RogueAntiSpyware.VirusDoctor!rem is extremely dangerous.

What is RogueAntiSpyware.VirusDoctor!rem?

RogueAntiSpyware.VirusDoctor!rem is a Trojan with a long history. RogueAntiSpyware.VirusDoctor!rem initially appeared in 2009, as a Trojan that installed the VirusDoctor rogue security software. VirusDoctor was and is fake anti-virus software, which was created in order to manipulate PC users into paying for the malware through a combination of ransoming and scare tactics. In order to get VirusDoctor onto a computer in order to scam the user, RogueAntiSpyware.VirusDoctor!rem sneaks in – usually as the result of a download hidden in a video codec or player update, or bundled with some other software on a malicious site – and RogueAntiSpyware.VirusDoctor!rem installs VirusDoctor without the user's knowledge.

RogueAntiSpyware.VirusDoctor!rem continues actively to cause infections, and there appears to have been a sudden spike in the number of RogueAntiSpyware.VirusDoctor!rem infections in February 2011. For the most part, RogueAntiSpyware.VirusDoctor!rem is still used to install rogue security applications without the user's knowledge, including malware that is closely related to VirusDoctor. Therefore, the majority of legitimate anti-virus programs will detect this Trojan as something linked to the fake anti-virus software scams. RogueAntiSpyware.VirusDoctor!rem is only one name for the Trojan when RogueAntiSpyware.VirusDoctor!rem is detected and identified as malware supporting one of these scams; other names for the same Trojan are "Trojan.Win32.FakeAV.zsa" (Kaspersky) and simply "VirusDoctor" (Symantec).

Other Potential Danger from RogueAntiSpyware.VirusDoctor!rem Infections

However, some scanners (for example, Microsoft products) will identify RogueAntiSpyware.VirusDoctor!rem as a much more general and more serious threat, grouping RogueAntiSpyware.VirusDoctor!rem with Trojans that are capable of dropping almost anything onto the infected computer. Basically, they categorize RogueAntiSpyware.VirusDoctor!rem as a Trojan that is used to conceal a file so that RogueAntiSpyware.VirusDoctor!rem can be downloaded without the consent of the PC user.

In any case, RogueAntiSpyware.VirusDoctor!rem is a threat that should not be taken lightly. If RogueAntiSpyware.VirusDoctor!rem is detected on your computer, make sure you use real anti-virus software to remove RogueAntiSpyware.VirusDoctor!rem.

File System Details

RogueAntiSpyware.VirusDoctor!rem may create the following file(s):
# File Name Detections
1. %PROGRAM_FILES%\RogueAntiSpyware.VirusDoctor!rem
2. C:\Documents and Settings\\Start Menu\RogueAntiSpyware.VirusDoctor!rem\ C:\Documents and Settings\\RogueAntiSpyware.VirusDoctor!

Registry Details

RogueAntiSpyware.VirusDoctor!rem may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
HKEY_LOCAL_MACHINE\Software\RogueAntiSpyware.VirusDoctor!rem

Trending

Most Viewed

Loading...