Antivirus IS

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 2,609
First Seen: September 22, 2010
OS(es) Affected: Windows

Antivirus IS is a rogue anti-virus program which imitates a system scan once executed. Antivirus IS comes from same rogueware family as Security Suite and Antivirus Soft. The rogue is distributed by Trojans that can surreptitiously enter computer systems and run in the background. When inside a system, Antivirus IS will display fake system scans, security alerts and pop-up warnings all claiming that the system is infected with dangerous malware.

The scans may list legitimate system files as infected in order to trick a victim into deleting important security services. Different types of Trojans, viruses and worms will also be listed on the fake scan report in order to scare a victim into action. Then Antivirus IS will prompt the victim to purchase its non-existent full version in order to remove the purportedly detected malware. Another scare tactic used by Antivirus IS, involves blocking a victim's access to programs such as Task Manager and Registry Editor as well as hijacking the internet browser to redirect a victim to malicious websites. This is a common scam that users should not fall for.


15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Adware/AntivirusIS
AVG Generic19.AIMK
Sunbelt Trojan.Win32.Generic.pak!cobra
Microsoft Rogue:Win32/FakeSpypro
Antiy-AVL Trojan/Win32.FraudPack
Sophos Mal/FakeAV-DO
McAfee-GW-Edition Artemis!661868E93E57
AntiVir TR/FraudPack.bnkx
DrWeb Trojan.Fakealert.19232
Comodo UnclassifiedMalware
BitDefender Gen:Variant.Kazy.1060
Kaspersky Trojan.Win32.FraudPack.bnkx
Avast Win32:Adware-gen
Symantec Trojan.FakeAV!gen39

SpyHunter Detects & Remove Antivirus IS

File System Details

Antivirus IS may create the following file(s):
# File Name MD5 Detections
1. iwvleljlanw.exe deba76db9c3f08549450f238ed91c053 78
2. gpcyrutlanw.exe 4925f772cd4317e385dd149d6ddef8fc 75
3. wntsipplanw.exe 2d26db62ba2e8f90723c0d140c5e87a0 60
4. nmfsenalanw.exe 883b01141d67af8034596237778ace01 43
5. quulwxelanw.exe 46962b4956f855e9fd9abb632c58fded 42
6. njhpmrglanw.exe 278afddb612fddd2b81ba115fe11b54e 26
7. hkkvcnqlanw.exe 0aeff881a2355be5b360cf13d7a0ab0e 25
8. hgrkkdplanw.exe 303a0c7a4654fdd5ecb672fa31640223 15
9. rnjkfhnlanw.exe 6298e4c4d6e8e6941b8a7f202676bd32 13
10. vuofpitlanw.exe 04d7bffdadd4f638fb0292cf7c685a32 11
11. aeqdbrdlanw.exe c0e1b1674fe10b499f00fdc090ed1027 8
12. axhertqlanw.exe 410045d4ea94360378161050a1a66573 6
13. wsgcmbslanw.exe 7aa4b32bdd85ac66e81fa42eeaee0868 6
14. pcqiarjlanw.exe 654da4ab5cb7ef10e3b1cd7c978d2281 5
15. nrkcbvjlanw.exe 2552fd53f01c40e5d00ad6b77d88905a 5
16. leowayilanw.exe ab8b43d947c0b00506dcd92296efcd42 4
17. sixvmqglanw.exe b1f4b542ec4d4f31af76b1220958bfe1 4
18. pjonbxrlanw.exe 42c276cf37920ab5ef792814fb7f60cc 4
19. rouwcgblanw.exe 1650048a2fe8301550b902dc5245d10a 3
20. hsjkdvalanw.exe b22ef65d3a5b20c8b35585bc6466c574 3
21. utbsmitlanw.exe ef9cf5aacd57cecc870e7fa8e73acb3d 3
22. qstfhomlanw.exe 6b7c237bd0e7700e9fa67bbde780c592 3
23. wbpldlolanw.exe 42e92ef7e699c41260c49533b13de694 3
24. ghepwiilanw.exe 6fe4ea97b27a3c3fec82e3d12f23de6f 3
25. lehvebilanw.exe 8752e0ce70360e0f61c9d6b8a31857fa 3
26. dpxuucclanw.exe b9f9d6543d6c6bff443a33c7bbee61c5 3
27. cyfdldklanw.exe 99c3b2315393e621a8bb94ff8943bdd0 3
More files


The following messages associated with Antivirus IS were found:

"Security warning
Application cannot be executed. The file [file_name].exe is infected. Do you want to activate your antivirus software now?"

"Security Warning
Application cannot be executed. The file notepad.exe is infected. Do you want to activate your antivirus software now."

"Antivirus software alert
Your computer is being attacked by an internet virus. It could be a password-stealing attack, trojan - dropper or similar.
Threat: Win32/Nuqel.E
Do you want to block this attack? Yes or No"


I have done the things I was requested to do, but I am being block by this antivirus and it will not allow the computer to run the downlosd. Can you help me with this problem?

Easiest way to remove Antivirus IS? I think I found it.

Reboot computer and keep pressing F8. When you are given the option, choose to start Windows in "Safe Mode".

When Windows has started up, click Start -> All Programs -> Accessories -> System Tools -> System Tools -> System Restore

Choose a restore date sufficiently old so that it is prior to the Antivirus IS infection. I would say a couple of weeks should be enough.

Restore system and problem should be gone. At least it was for me.

Much easier than having to download all kinds of anti-malware software and messing with registries. If it works for you, you can send thanks to jaycal33 (at) yaboo (dot) com. It's not really yahoo, but you know what I mean.

Extremely helpful article, plseae write more.

Related Posts


Most Viewed