Scan Spyware on Twitter
Saturday, March 20, 2010

Bookmark and Share



antiviruspro2010


Type: rogue

Alias: antivirus pro 2010, antiviruspro_2010

Company: XP AntiSpyware 2009.com

Description: AntivirusPro2010 is a rogue anti-spyware. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats. AntivirusPro2010 is also known as Antivirus Pro 2010.

Malware Threat

antiviruspro2010

Directories

  • C:\Documents and Settings\user-account-name\Start Menu\Programs\AntivirusPro_2010
  • C:\Documents and Settings\user-account-name\Start Menu\Programs\Antivirus Pro 2010
  • C:\Program Files\AntivirusPro_2010
  • C:\Program Files\Antivirus Pro 2010
  • C:\Program Files\AntivirusPro_2010\data
  • C:\Program Files\Antivirus Pro 2010\data

Files

  • %quicklaunchdir%\AntivirusPro_2010.lnk
  • %quicklaunchdir%\Antivirus Pro 2010.lnk
  • C:\Documents and Settings\user-account-name\Desktop\AntivirusPro_2010.lnk
  • C:\Documents and Settings\user-account-name\Desktop\Antivirus Pro 2010.lnk
  • C:\Documents and Settings\user-account-name\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
  • C:\Program Files\AntivirusPro_2010\wscui.cpl
  • C:\Program Files\AntivirusPro_2010\AVEngn.dll
  • C:\Program Files\AntivirusPro_2010\htmlayout.dll
  • C:\Program Files\AntivirusPro_2010\Uninstall.exe
  • C:\Program Files\AntivirusPro_2010\pthreadVC2.dll
  • C:\Documents and Settings\user-account-name\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
  • C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.cfg
  • C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe
  • antiviruspro_2010.lnk (md5:a1ba703dd710d1e9df01ae...)
  • antiviruspro_2010.exe (md5:a4b6177b5bf235a170c36b...)

Registry Keys

  • HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusPro_2010
  • HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus Pro 2010
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntivirusPro_2010
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus Pro 2010

Registry Values

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Antivirus Pro 2010