Threat Database Malware AntiSpy2011Setup.exe

AntiSpy2011Setup.exe

By Domesticus in Malware

AntiSpy2011Setup.exe is a dangerous file. If you find AntiSpy2011Setup.exe on your computer, then your machine is infected with malware, because there is a very large family of fake security programs that use AntiSpy2011Setup.exe as one of its executable files. The malware that uses AntiSpy2011Setup.exe is part of a scam designed to trick you into believing that your PC is infected with viruses that only its fake anti-virus program can remove. Proceed with caution, and you can remove the fake anti-virus software, as well as AntiSpy2011Setup.exe.

Malware that Uses AntiSpy2011Setup.exe

The rogue anti-virus application most commonly associated with AntiSpy2011Setup.exe is XP Antispyware 2011, Antispy, AV7, and MS Removal Tool, one of the most recent and most common members of its malware family, which uses a distinctive (and very odd) pink interface. Because one of the goals of malware infections like MS Removal Tool is to go undetected for as long as possible, MS Removal Tool also uses other names for its executable file, and which name is used will vary from one infected PC to the next. Other fake anti-virus programs related to MS Removal Tool will do this same thing, sometimes using AntiSpy2011Setup.exe, or sometimes naming their executable files other things – although ultimately, no matter what a specific rogue anti-virus program calls this file, it is the same infection.

There is a strong correlation between infections with AntiSpy2011Setup.exe and some dangerous worms, such as Koobface. The malware that uses AntiSpy2011Setup.exe will often download this other malware to the infected computer, without your knowledge. Then, the worms found in conjunction with AntiSpy2011Setup.exe will try to spread themselves via social websites, particularly Twitter and Facebook, by exploiting any accounts that you have with those sites. The worm will target your contacts and send them an infected message, which means that the longer you leave the malware on your PC, the more you put other people at risk.

The family of fake anti-virus programs that use AntiSpy2011Setup.exe as one of the names for its main file is very large, although AntiSpy2011Setup.exe most likely occurs only with its recent members. Aside from MS Removal Tool, this group of fake security programs includes MS Recovery Tool, System Tool, System Security, Winweb Security, Security Tool, Total Security, Antispyware Pro 2009, System Security 2009, Security Shield, System Removal, System Tool 2011, PC Tool 2011, and Windows Smart Security.

File System Details

AntiSpy2011Setup.exe may create the following file(s):
# File Name Detections
1. %AppData%\AntiSpy2011Setup.exe
2. %AppData%\[RANDOM CHARACTERS]
3. %temp%\[RANDOM CHARACTERS]

Registry Details

AntiSpy2011Setup.exe may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AntiSpy2011Setup.exe"
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Trending

Most Viewed

Loading...