Threat Description

Rogue:​W32/XPAntivirus.gen!I

Details

Aliases:Rogue:​W32/XPAntivirus.gen!I, Rogue:​W32/XPAntivirus.gen!I
Category:Malware
Type:Rogue
Platform:W32

Summary



Deceptive antivirus software that pressures users into buying or installing it (e.g., infecting a computer; displaying false or alarming warnings or scanning results). Once installed, it may not function as claimed.



Removal


Automatic Disinfection

Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Rogue:W32/Antiviruspro.gen!I is a Generic Detection for a family of rogue antivirus programs.

Execution

On execution, this rogueware will display a false antivirus scanner window and run a "scan" that will find non-existent malware on the system:

It will then direct user to pay for a "registered version" to clean the malware.

It will also periodically display a warning message on the system tray:

File System Changes

Creates these files:

  • %programfiles%\AntivirusXP\AntivirusXP.exe
  • %desktop%\AntivirusXP.lnk
  • %startmenuprograms%\AntivirusXP\AntivirusXP.lnk
  • %appdata%\Microsoft\Internet Explorer\Quick Launch\AntivirusXP.lnk
  • %temp%\stylrit0.tmp

Create these directories:

  • %programfiles%\AntivirusXP
  • %programfiles%\AntivirusXP\Suspicious
  • %programfiles%\AntivirusXP\Infected
  • %startmenuprograms%\AntivirusXP

Registry Modifications

Sets these values:

  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders Programs = C:\Documents and Settings\user\Start Menu\Programs
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders Start Menu = C:\Documents and Settings\user\Start Menu
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders Common Start Menu = C:\Documents and Settings\All Users\Start Menu
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders My Pictures = C:\Documents and Settings\user\My Documents\My Pictures
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders CommonPictures = C:\Documents and Settings\All Users\Documents\My Pictures
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders CommonMusic = C:\Documents and Settings\All Users\Documents\My Music
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders CommonVideo = C:\Documents and Settings\All Users\Documents\My Videos
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run AntivirusXP.exe = C:\Program Files\AntivirusXP\AntivirusXP.exe [Launchpoint: Run]

Creates these keys:

  • HKCU\Software\AntivirusXP
  • HKLM\Software\AntivirusXP





SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More