Antivirus IS

Antivirus IS Description

Antivirus IS is a rogue anti-virus program which imitates a system scan once executed. Antivirus IS comes from same rogueware family as Security Suite and Antivirus Soft. The rogue is distributed by Trojans that can surreptitiously enter computer systems and run in the background. When inside a system, Antivirus IS will display fake system scans, security alerts and pop-up warnings all claiming that the system is infected with dangerous malware.

The scans may list legitimate system files as infected in order to trick a victim into deleting important security services. Different types of Trojans, viruses and worms will also be listed on the fake scan report in order to scare a victim into action. Then Antivirus IS will prompt the victim to purchase its non-existent full version in order to remove the purportedly detected malware. Another scare tactic used by Antivirus IS, involves blocking a victim's access to programs such as Task Manager and Registry Editor as well as hijacking the internet browser to redirect a victim to malicious websites. This is a common scam that users should not fall for.

Aliases: Adware/AntivirusIS [Panda], Generic19.AIMK [AVG], Trojan.FakeAV, Trojan.Win32.Generic.pak!cobra [Sunbelt], Trojan.FraudPack.bnkx, High Risk Fraudulent Security Program, Trojan.Agent/Gen-FakeAlert, Rogue:Win32/FakeSpypro [Microsoft], Trojan/Win32.FraudPack [Antiy-AVL], Trojan/FraudPack.fja, Mal/FakeAV-DO [Sophos], Artemis!661868E93E57 [McAfee-GW-Edition], TROJ_FAKELRT.SMC [TrendMicro], TR/FraudPack.bnkx [AntiVir] and Trojan.Fakealert.19232 [DrWeb].

Technical Information

File System Details

Antivirus IS creates the following file(s):
# File Name Size MD5 Detection Count
1 %TEMP%\mjmjaboll\iwvleljlanw.exe 244,736 deba76db9c3f08549450f238ed91c053 78
2 %TEMP%\dvjbncpxw\gpcyrutlanw.exe 244,736 4925f772cd4317e385dd149d6ddef8fc 75
3 %TEMP%\askkiunku\wntsipplanw.exe 245,248 2d26db62ba2e8f90723c0d140c5e87a0 60
4 %TEMP%\kbncycjmn\nmfsenalanw.exe 245,248 883b01141d67af8034596237778ace01 43
5 %TEMP%\kkycjiorx\quulwxelanw.exe 245,248 46962b4956f855e9fd9abb632c58fded 42
6 %TEMP%\dvimttqed\njhpmrglanw.exe 244,736 278afddb612fddd2b81ba115fe11b54e 26
7 %TEMP%\mlmpgjsep\hkkvcnqlanw.exe 244,736 0aeff881a2355be5b360cf13d7a0ab0e 25
8 %TEMP%\ihbuwcmkm\hgrkkdplanw.exe 245,248 303a0c7a4654fdd5ecb672fa31640223 15
9 %TEMP%\vfamixpup\rnjkfhnlanw.exe 244,736 6298e4c4d6e8e6941b8a7f202676bd32 13
10 %TEMP%\njukecidl\vuofpitlanw.exe 244,736 04d7bffdadd4f638fb0292cf7c685a32 11
11 %TEMP%\wdpjnybyo\aeqdbrdlanw.exe 251,904 c0e1b1674fe10b499f00fdc090ed1027 8
12 %TEMP%\krtvcpbaj\axhertqlanw.exe 244,736 410045d4ea94360378161050a1a66573 6
13 %TEMP%\edkicdqiu\wsgcmbslanw.exe 244,736 7aa4b32bdd85ac66e81fa42eeaee0868 6
14 %TEMP%\kihcoaebr\pcqiarjlanw.exe 245,248 654da4ab5cb7ef10e3b1cd7c978d2281 5
15 %TEMP%\lnfltlrvj\nrkcbvjlanw.exe 251,392 2552fd53f01c40e5d00ad6b77d88905a 5
16 %TEMP%\xarwionny\leowayilanw.exe 251,904 ab8b43d947c0b00506dcd92296efcd42 4
17 %TEMP%\ebfpmihsm\sixvmqglanw.exe 244,736 b1f4b542ec4d4f31af76b1220958bfe1 4
18 %TEMP%\ejcyxdiqi\pjonbxrlanw.exe 244,736 42c276cf37920ab5ef792814fb7f60cc 4
19 %TEMP%\waefxcqde\rouwcgblanw.exe 245,248 1650048a2fe8301550b902dc5245d10a 3
20 %TEMP%\uhcwqrsip\hsjkdvalanw.exe 245,248 b22ef65d3a5b20c8b35585bc6466c574 3
21 %TEMP%\rhclbuucy\utbsmitlanw.exe 245,248 ef9cf5aacd57cecc870e7fa8e73acb3d 3
22 %TEMP%\vhnfkrutp\qstfhomlanw.exe 245,248 6b7c237bd0e7700e9fa67bbde780c592 3
23 %TEMP%\ebvvuqewg\wbpldlolanw.exe 245,248 42e92ef7e699c41260c49533b13de694 3
24 %TEMP%\qykjjgioh\ghepwiilanw.exe 251,904 6fe4ea97b27a3c3fec82e3d12f23de6f 3
25 %LOCALAPPDATA%\rdvsqsocb\lehvebilanw.exe 259,584 8752e0ce70360e0f61c9d6b8a31857fa 3
26 %TEMP%\ixopvgmcy\dpxuucclanw.exe 245,248 b9f9d6543d6c6bff443a33c7bbee61c5 3
27 %TEMP%\nyocuyunj\cyfdldklanw.exe 245,248 99c3b2315393e621a8bb94ff8943bdd0 3
More files

More Details on Antivirus IS

The following messages associated with Antivirus IS were found:
"Security warning
Application cannot be executed. The file [file_name].exe is infected. Do you want to activate your antivirus software now?"

"Security Warning
Application cannot be executed. The file notepad.exe is infected. Do you want to activate your antivirus software now."

"Antivirus software alert
INFILTRATION ALERT
Your computer is being attacked by an internet virus. It could be a password-stealing attack, trojan - dropper or similar.
Threat: Win32/Nuqel.E
Do you want to block this attack? Yes or No"

Related Posts

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

3 Comments

  • John Peoples:

    I have done the things I was requested to do, but I am being block by this antivirus and it will not allow the computer to run the downlosd. Can you help me with this problem?

  • Jayanta:

    Easiest way to remove Antivirus IS? I think I found it.

    Reboot computer and keep pressing F8. When you are given the option, choose to start Windows in "Safe Mode".

    When Windows has started up, click Start -> All Programs -> Accessories -> System Tools -> System Tools -> System Restore

    Choose a restore date sufficiently old so that it is prior to the Antivirus IS infection. I would say a couple of weeks should be enough.

    Restore system and problem should be gone. At least it was for me.

    Much easier than having to download all kinds of anti-malware software and messing with registries. If it works for you, you can send thanks to jaycal33 (at) yaboo (dot) com. It's not really yahoo, but you know what I mean.

  • Luckie:

    Extremely helpful article, plseae write more.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.