Rogue:W32/UltimateFix

Classification

Riskware

Rogue

W32

-

Summary

Dishonest antivirus software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected.

Removal

Automatic action

Based on the settings of your F-Secure security product, it may block the file from running, move it to the quarantine where it cannot spread or cause harm, or ask you to select an action.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

This is the family description for the Rogue:W32/UltimateFix family of rogueware.

Variants in the UltimateFix rogueware family are rogue anti-malware programs that generate fake or misleading scan results,Â& in an attempt to trick users into purchasing their products.

Installation

UltimateFix variants commonly launch a downloader that installs the application. much like the one shown below:

Screenshots of known UltimateFix variants can be seen below :

During installation, the program creates these files :

  • %Desktop%\UltimateFixer 2007.lnk
  • %ProgramFiles%\UltimateFixer 2007\Register UltimateFixer 2007.lnk
  • %ProgramFiles%\UltimateFixer 2007\Start UltimateFixer 2007.lnk
  • %ProgramFiles%\UltimateFixer 2007\Uninstall UltimateFixer 2007.lnk
  • %ProgramFiles%\Ultimate Fixer\program.info
  • %ProgramFiles%\Ultimate Fixer\ufixer.pkg
  • %ProgramFiles%\Ultimate Fixer\UltimateFixer.db
  • %ProgramFiles%\Ultimate Fixer\UltimateFixer.exe
  • %ProgramFiles%\Ultimate Fixer\Uninstall.exe

Registry

During installation, the program creates the following registry key to automatically execute itself:

  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run = %ProgramFiles%\Ultimate Fixer\UltimateFixer.exe

Date Created: 2009-03-24 10:04:36.0

Date Last Modified: 2009-04-22 05:58:47.0