Windows Antivirus Pro

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 3
First Seen: December 1, 2009
Last Seen: January 10, 2019
OS(es) Affected: Windows

Windows Antivirus Pro Image

Windows Antivirus Pro is another rogue anti-spyware program variant designed to convince or force computer users to purchase the full version of the bogus product. Windows Antivirus Pro is similar to other rogue anti-spyware programs such as Home Antivirus 2010, Windows Antivirus 2008, Spyware Protect 2009, Antivirus System Pro, and AntivirusBEST. To distinguish itself from all the other popular rogue anti-spyware programs, the makers of Windows Antivirus Pro gave the program a new look with a new logo and user interface.

Windows Antivirus Pro distributes through the use of Svchast trojan (svchast.exe) that is commonly found in serial crack, warez or porn websites. With the help of the malicious file svchast.exe, Windows Antivirus Pro is able to populate the Windows registry and stay in memory so it can infect any program that loads on to memory.

Once installed, Windows Antivirus Pro's "System scan" runs a scan in the infected system returning several fictitious threat results. The "System scan" tool is nothing more than a pretty user interface that will continue to list the following threats: Email-Worm.Win32.Merond.a, Trojan.Win32.Agent.azsy, Trojan.Win32.Agent2.dtb, Trojan-Downloader.Win32.Small.ydh, Trojan-Downloader.Win32.Agent.ahoe, Trojan-Downloader.JS.Agent.crh, and Net-Worm.Win32.Kido.ih.

In addition, Windows Antivirus Pro changes the desktop wallpaper to a "Danger!!! Your computer is infected!" message and displays several misleading warnings alerts and system notifications. The misleading warnings alerts are meant to play on the computer user's fears of having spyware as well as the computer user's eagerness to have it fixed.

Another major concern associated with Windows Antivirus Pro is that it disables the ability to execute any program on the PC, including security software such as SpyHunter. When a computer user tries to open a program, for example Notepad, the following message appears on the system tray:

"Running of application is impossible. The file C:\WINDOWS\system32\notepad.exe is infected. Please activate your antivirus program."

Windows Antivirus Pro only allows Internet Explorer (IE) to execute since it needs the computer user to purchase the bogus product online. Because Windows Antivirus Pro blocks any program that uses files with the "exe" extension, we have changed the SpyHunter's download file from an .exe to a .bat format to allow computer users infected with Windows Antivirus Pro to download and execute SpyHunter. The .bat file to download SpyHunter is only available in this article.

If you cannot open any program on your PC and you want to detect Windows Antivirus Pro, open Internet Explorer and click on the SpyHunter download link provided in this article.ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
TrendMicro TROJ_TDSS.SMAL
Symantec Packed.Generic.277
Sunbelt FraudTool.Win32.RogueSecurity (v)
Sophos Mal/FakeAV-BT
NOD32 a variant of Win32/Kryptik.CMU
Microsoft Trojan:Win32/FakeCog
McAfee+Artemis Artemis!2845C3CE19DF
Ikarus Trojan.Win32.FakeCog
F-Secure Suspicious:W32/Malware!Gemini
eTrust-Vet Win32/WindowsAntivirusPro!generi
a-squared Trojan.Win32.FakeCog!IK
TrendMicro TROJ_FAKEALE.IH
Sophos Troj/BHO-NG
Panda Adware/AntivirusPro
McAfee-GW-Edition Trojan.Fakealert.Biz.1

SpyHunter Detects & Remove Windows Antivirus Pro

Windows Antivirus Pro Video

Tip: Turn your sound ON and watch the video in Full Screen mode.

File System Details

Windows Antivirus Pro may create the following file(s):
# File Name MD5 Detections
1. c:\Program Files\Windows Antivirus Pro\msvcm80.dll
2. C:\Program Files\Windows Antivirus Pro\tmp\dbsinit.exe
3. c:\WINDOWS\system32\dddesot.dll
4. dddesot.dll
5. c:\Program Files\Windows Antivirus Pro\ANTI_files.exe
6. c:\Program Files\Windows Antivirus Pro\msvcp80.dll
7. c:\WINDOWS\system32\desot.exe
8. desot.exe
9. c:\Program Files\Windows Antivirus Pro\Windows Antivirus Pro.exe
10. c:\Program Files\Windows Antivirus Pro\msvcr80.dll
11. c:\WINDOWS\svchast.exe
12. Windows Antivirus Pro.exe
13. dbsinit.exe
14. C:\Program Files\Windows Antivirus Pro\tmp\wispex.html
15. C:\Program Files\Windows Antivirus Pro\tmp\images\i1.gif
16. C:\Program Files\Windows Antivirus Pro\tmp\images\l1.gif
17. C:\Program Files\Windows Antivirus Pro\tmp\images\jj1.gif
18. C:\Program Files\Windows Antivirus Pro\tmp\images\j1.gif
19. C:\Program Files\Windows Antivirus Pro\tmp\images\t1.gif
20. C:\Program Files\Windows Antivirus Pro\tmp\images\up2.gif
21. C:\Program Files\Windows Antivirus Pro\tmp\images\wt3.gif
22. C:\Program Files\Windows Antivirus Pro\tmp\images\w2.gif
23. c:\WINDOWS\ppp3.dat
24. c:\WINDOWS\system32\sysnet.dat
25. %UserProfile%\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
26. C:\Program Files\Windows Antivirus Pro\tmp\
27. C:\Program Files\Windows Antivirus Pro\tmp\images\pix.gif
28. C:\Program Files\Windows Antivirus Pro\tmp\images\i3.gif
29. C:\Program Files\Windows Antivirus Pro\tmp\images\l3.gif
30. C:\Program Files\Windows Antivirus Pro\tmp\images\jj3.gif
31. C:\Program Files\Windows Antivirus Pro\tmp\images\j3.gif
32. C:\Program Files\Windows Antivirus Pro\tmp\images\up1.gif
33. C:\Program Files\Windows Antivirus Pro\tmp\images\wt2.gif
34. C:\Program Files\Windows Antivirus Pro\tmp\images\w11.gif
35. C:\Program Files\Windows Antivirus Pro\tmp\images\w3.jpg
36. c:\WINDOWS\system32\bennuar.old
37. %UserProfile%\Start Menu\Programs\Windows Antivirus Pro
38. Windows Antivirus Pro.lnk
39. c:\Program Files\Windows Antivirus Pro\
40. C:\Program Files\Windows Antivirus Pro\tmp\images\
41. C:\Program Files\Windows Antivirus Pro\tmp\images\i2.gif
42. C:\Program Files\Windows Antivirus Pro\tmp\images\l2.gif
43. C:\Program Files\Windows Antivirus Pro\tmp\images\jj2.gif
44. C:\Program Files\Windows Antivirus Pro\tmp\images\j2.gif
45. C:\Program Files\Windows Antivirus Pro\tmp\images\t2.gif
46. C:\Program Files\Windows Antivirus Pro\tmp\images\wt1.gif
47. C:\Program Files\Windows Antivirus Pro\tmp\images\w1.gif
48. C:\Program Files\Windows Antivirus Pro\tmp\images\w3.gif
49. c:\WINDOWS\ppp4.dat
50. %UserProfile%\Desktop\Windows Antivirus Pro.lnk
51. AntipPro2009_12
52. %ProgramFiles%\Windows Antivirus Pro
53. desot.exe 618e7701ebbde277ff08f54ef7a764fb
54. dddesot.dll 6763d5e252a4d9a8de44ad9a366ad13b
55. dbsinit.exe c56d7e972adfdd33b5edd30e5eaff45e
56. svchast.exe 90a91811c024dcdd991520bb2d5ca737
57. Windows Antivirus Pro.exe a76187284b976f8f5e24cfa57218374d
58. dddesot.dll 587a803376f1712a17453d8406ded418 0
59. dddesot.dll bc566e42659b3547d110513dcadbc3a9 0
60. dddesot.dll 11ed8c9e99d3262cfcde4c12ebe0043b 0
61. dddesot.dll 705288b23fdd60633610a3a3a09bbe20 0
62. dddesot.dll 535d76348f00d3ef56e306828e8f1fc5 0
63. dddesot.dll 7e7ca667283b23a173871a5b4c6be589 0
64. dddesot.dll ad950bd5f160d1fa0f74305964217685 0
65. dddesot.dll 1d5bcfd5231b1a7f909126f7c1be046d 0
66. dddesot.dll b0c8ac692ee6203e7ee6d3fe3e95eba0 0
67. dddesot.dll af1a7833166986de647101d06fd64825 0
68. dddesot.dll 4705a38e9cccf335691c73f1ad01e824 0
69. dddesot.dll eefb743892354fc34ab5100b14cfd623 0
70. dddesot.dll 735cde58dd0b849b8efa5d508140aebf 0
71. dddesot.dll 27fabb3ad35bbc12f9ad0171580b2c30 0
72. dddesot.dll 9da8622981bea6152eb07b3f3986758a 0
73. dddesot.dll bf23a7500222015313f30e1482a7836a 0
74. Windows Antivirus Pro.exe 25887d7d41b8e87a3ce469d7e5cc3162 0
75. dddesot.dll 759f44a0cde7f7462bf60698e8fe5d04 0
76. dddesot.dll 8828d2357583d39f4fde6e12300f3c8f 0
77. dddesot.dll 45eb54883f6004fabc456ba65e3d7b29 0
78. dddesot.dll bc9c8310f9d64727c642e8fad1f06f24 0
79. dddesot.dll ad085e1cd6bca06e06af50ecb6385e9a 0
80. dddesot.dll cb164962f615f908de6902e2fa43d1eb 0
81. dddesot.dll 119c7b1be6bdfbeb703f67ba42ba3100 0
82. dddesot.dll 4f033ed8ddfbba88ce45f8ce0cd1c8bc 0
83. eventcreatexp.exe 2845c3ce19df8f739c02e5306c216b55 0

Registry Details

Windows Antivirus Pro may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AntipPro2009_12
HKEY_CLASSES_ROOT\CLSID\{F54AF7DE-6038-4026-8433-CC30E3F17212}
F54AF7DE-6038-4026-8433-CC30E3F17212
HKEY_CURRENT_USER\Software\Softimer
HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F54AF7DE-6038-4026-8433-CC30E3F17212}
77DC0B63-1535-4ba9-8BE8-D59EB676FA02
HKEY_CURRENT_USER\Software\Windows Antivirus Pro
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AntipPro2009_12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win Antivirus Pro
76DC0B63-1533-4ba9-8BE8-D59EB676FA02

Directories

Windows Antivirus Pro may create the following directory or directories:

%ProgramFiles%\Windows Antivirus Pro

Messages

The following messages associated with Windows Antivirus Pro were found:

Internet attack attempt detected:

Somebody is truing to attack your PC:
This can result in loss of your personal information and infection other computers connected to your network.
Click here to prevent attack.
Security Warning

There are critical system files on your computer that were modified by malicious program. It will cause unstable work of your system and permanent data loss. Click here to undo performed modifications and remove malicious software (Highly recommended).
Warning: Infection is Detected

Windows has found spyware infection on your computer!
Click here to update your Windows antivirus software...

1 Comment

I DON T KNOW IF I GAVE A CORRECT SAMPLE? OR IF I HAVE A VIRUS AND IF IAM DOING THIS RIGHT? TOOK ME HOURS OF FIGHTING MY COMPUTER TO EVEN PUT A WORD IN HERE AND DOWNLOAD NORTON THAT WAS ALREADY ON HERE BUT SOME HOW WAS TAKEN OFF???

Related Posts

Trending

Most Viewed

Loading...