Antivirus 2009: another fake antivirus application

Posted: December 2nd, 2008 | Tags: , , |

Antivirus2009, known also as Antivirus 2009, is one of last and hot counterfeit spies that devastates Internet community. Does this sound familiar to you? Yes, Antivirus 2009 is indeed a clone of the infamous Antivirus 2008. Antivirus 2009 usually comes up after you install a video codec that come with Trojan, malware and virus. Antivirus 2009 normally generates fake and misleading system popup error messages so end-users will be tricked into purchase Antivirus 2009. Antivirus 2009 constantly creates false error messages with those to end users will be a deceit in purchase Antivirus 2009.

Virustotal report

File antivirus.v.1.0.0.exe получен 2008.12.16 16:41:02 (CET)
Status: finished
Result: 7/38 (18.43%)

Antivirus Version Last update Result
AhnLab-V3 2008.12.17.0 2008.12.16 -
AntiVir 7.9.0.45 2008.12.16 -
Authentium 5.1.0.4 2008.12.16 -
Avast 4.8.1281.0 2008.12.16 -
AVG 8.0.0.199 2008.12.16 -
BitDefender 7.2 2008.12.16 -
CAT-QuickHeal 10.00 2008.12.16 -
ClamAV 0.94.1 2008.12.16 -
Comodo 760 2008.12.15 -
DrWeb 4.44.0.09170 2008.12.16 -
eSafe 7.0.17.0 2008.12.16 Suspicious File
eTrust-Vet 31.6.6263 2008.12.16 -
Ewido 4.0 2008.12.16 -
F-Prot 4.4.4.56 2008.12.16 -
F-Secure 8.0.14332.0 2008.12.16 -
Fortinet 3.117.0.0 2008.12.16 -
GData 19 2008.12.16 -
Ikarus T3.1.1.45.0 2008.12.16 -
K7AntiVirus 7.10.555 2008.12.16 -
Kaspersky 7.0.0.125 2008.12.16 -
McAfee 5465 2008.12.15 -
McAfee+Artemis 5465 2008.12.15 -
Microsoft 1.4205 2008.12.16 TrojanDownloader:Win32/Renos.FU
NOD32 3695 2008.12.16 -
Norman 5.80.02 2008.12.16 -
Panda 9.0.0.4 2008.12.15 -
PCTools 4.4.2.0 2008.12.16 -
Prevx1 V2 2008.12.16 Cloaked Malware
Rising 21.08.12.00 2008.12.16 Trojan.Win32.Undef.uhx
SecureWeb-Gateway 6.7.6 2008.12.16 -
Sophos 4.36.0 2008.12.16 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.16 Downloader
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.16 Possible_DLDER
VBA32 3.12.8.10 2008.12.16 -
ViRobot 2008.12.16.1521 2008.12.16 -
VirusBuster 4.5.11.0 2008.12.16 Trojan.FraudLoad.Gen
Additional information
File size: 67072 bytes
MD5…: 23eb13a6c21465c579651d4ff9f378e9
SHA1..: 27b2f0f52219f2b1176bdfbc648417d9765c779f
SHA256: 4401ec3e3a4bb706b9884c52f95140d1ecd19c4e7bc15b6efcbb98555d174c37
SHA512: 41b7490bca5200178ba80d38b16d69d8ac8b14550df6db4c4542777910a52a30
6903f994a01608c2e4ae34d7eaeeaf80bc92de74f72ac105b0247300c74c5037
ssdeep: 1536:BEoy0Zrf4WIJxfOQNX8oyWa0KI5PKbkffU:PvpI3DNX8oyWoI9AQ8
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×402240
timedatestamp…..: 0×49478079 (Tue Dec 16 10:18:33 2008)
machinetype…….: 0×14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0×22a1 0×2400 6.53 a3eb5d5da75d9712cc5f3a39e23f45c8
.rdata 0×4000 0×780 0×800 4.90 9e76dec14b7d0c26f5db4c6f36b07d5d
.data 0×5000 0×875c 0×8000 7.97 d8ccc40c2f68852dbbfbdf82817cc7fd
.rsrc 0xe000 0×5560 0×5600
6.68 b57ea76ec376f0a534ff22cf6f72f5bf

( 5 imports )
KERNEL32.dll: CreateFileA, CloseHandle,
DeviceIoControl, GetSystemDirectoryA, GetVolumeInformationA,
GetWindowsDirectoryA, ExitProcess, TerminateProcess,
SetProcessPriorityBoost, SetThreadPriority, GetCurrentThread, SetPriorityClass, GetCurrentProcess,
GetEnvironmentVariableA, GetShortPathNameA, GetModuleFileNameA, IsBadWritePtr,
GetComputerNameA, WriteFile, lstrlenA,
GetVersionExA, GetTempPathA, CreateProcessA
SHELL32.dll: ShellExecuteExA, SHChangeNotify
MSVCRT.dll: _except_handler3, atoi, rand, strncpy, sprintf, __CxxFrameHandler,_snprintf, _snprintf, srand,
time, strncat, _strdup, __3@YAXPAX@Z, _itoa
MSVCP60.dll: __Xlen@std@@YAXXZ,
__0_$basic_string@DU_$char_traits@D@std
@@V_$allocator@D@2@@std@@QAE@PBDABV_$allocator@D@1@@Z,
__Copy@_$basic_string@DU_$char_traits@D@st
d@@V_$allocator@D@2@@std@@AAEXI@Z,
__C@_1___Nullstr@_$basic_string@DU_$char_trai
ts@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB,
__1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ,
__Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z
WININET.dll: HttpQueryInfoA, InternetOpenUrlA, InternetOpenA, InternetReadFile, InternetCloseHandle

( 0 exports )

Related posts


Leave a Reply