1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Rogue:W32/Reanimator

Name : Rogue:W32/Reanimator
Detection Names : FraudTool.Win32.Reanimator
Aliases : WinReanimator (Symantec)
TrojanDownloader:Win32/Winreanimator.A (Microsoft)
Category:Riskware
Type:Rogue
Platform:W32

Summary

Dishonest antivirus software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected.

Additional Details

Rogue:W32/Reanimator is a rogue anti-malware program. When executed, it will produce an exaggerated scan result and attempt to pressure the users into buying the full version of the product in order to remove non-existent infections.


Installation


The installer must be executed manually in order to install the program. The main installation folder is:
  •  C:\Program Files\WinReanimator

The program also connects to www.winreanimator.com to download the following files:
  •  Binaries1.zip
  •  Binaries2.zip
  •  Binaries3.zip

and drop them in %USERPROFILE%\Local Settings\Temp.


Activity

Upon execution, the program will scan the computer and display exaggerated/fake scan results indicating infections on the system. It will then constantly display alert messages informing the users that they must register and buy the product in order to remove the "infections".