Home Malware Programs Fake Warning Messages "Home Antivirus 33 Unwanted Files" Pop-up

"Home Antivirus 33 Unwanted Files" Pop-up

Posted: July 22, 2009

"Home Antivirus 33 Unwanted Files" pop-up is a fake security alert attempting to scare you into purchasing the rogue spyware remover Home Antivirus 2010, a completely useless application. The "Home Antivirus 33 Unwanted Files" pop-up reads as follows:

"WARNING! Home Antivirus 2010 has found 33 useless and UNWANTED files on your computer!
- 21 of those items are considered critical privacy compromising content
- 9 of those items are considered medium privacy threats
- 3 of those items are considered to be junk content of low privacy threats
Personal data at the reach of anyone's hand
Internet history records available
Compromising and adult material stored on your system
Chat sessions' logs and personal Emails easily reachable
You need to register Home Antivirus 2010 to clean the unwanted files found. Click "Register now" button below to obtain the license and remove useless and compromising material from your PC."

Be certain to remove Home Antivirus 2010 immediately upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\HomeAntivirus2010.lnk
    2 %UserProfile%\Application Data\rufa.exe
    3 %UserProfile%\Application Data\xatem.vbs
    4 %UserProfile%\Cookies\akywiweni.dll
    5 %UserProfile%\Cookies\atowu.exe
    6 %UserProfile%\Cookies\ufig.reg
    7 %UserProfile%\Cookies\upagyxej.lib
    8 %UserProfile%\Cookies\uwud.ban
    9 %UserProfile%\Desktop\HomeAntivirus2010.lnk
    10 %UserProfile%\Local Settings\Application Data\akufan.db
    11 %UserProfile%\Local Settings\Application Data\puqobu.bat
    12 %UserProfile%\Local Settings\Application Data\robomero.vbs
    13 %UserProfile%\Local Settings\Application Data\xojusiban.dat
    14 %UserProfile%\Local Settings\Temporary Internet Files\otakyhegem.sys
    15 %UserProfile%\Start Menu\Programs\HomeAntivirus2010
    16 %UserProfile%\Start Menu\Programs\HomeAntivirus2010\HomeAntivirus2010.lnk
    17 %UserProfile%\Start Menu\Programs\HomeAntivirus2010\Uninstall.lnk
    18 c:\Documents and Settings\All Users\Application Data\ovysenuv.ban
    19 c:\Documents and Settings\All Users\Documents\ecanynedy.pif
    20 c:\Documents and Settings\All Users\Documents\iwexuhor.inf
    21 c:\Documents and Settings\All Users\Documents\omupaw.scr
    22 c:\Documents and Settings\All Users\Documents\xonocyd.sys
    23 c:\Program Files\Common Files\rohysewys.lib
    24 c:\Program Files\HomeAntivirus2010
    25 c:\Program Files\HomeAntivirus2010\AVEngn.dll
    26 c:\Program Files\HomeAntivirus2010\data
    27 c:\Program Files\HomeAntivirus2010\data\daily.cvd
    28 c:\Program Files\HomeAntivirus2010\HomeAntivirus2010.cfg
    29 c:\Program Files\HomeAntivirus2010\HomeAntivirus2010.exe
    30 c:\Program Files\HomeAntivirus2010\htmlayout.dll
    31 c:\Program Files\HomeAntivirus2010\Microsoft.VC80.CRT
    32 c:\Program Files\HomeAntivirus2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
    33 c:\Program Files\HomeAntivirus2010\Microsoft.VC80.CRT\msvcm80.dll
    34 c:\Program Files\HomeAntivirus2010\Microsoft.VC80.CRT\msvcp80.dll
    35 c:\Program Files\HomeAntivirus2010\Microsoft.VC80.CRT\msvcr80.dll
    36 c:\Program Files\HomeAntivirus2010\pthreadVC2.dll
    37 c:\Program Files\HomeAntivirus2010\Uninstall.exe
    38 c:\Program Files\HomeAntivirus2010\wscui.cpl
    39 c:\WINDOWS\dicy.sys
    40 c:\WINDOWS\oxysa.dl
    41 c:\WINDOWS\system32\_scui.cpl
    42 c:\WINDOWS\system32\boxica.reg
    43 c:\WINDOWS\system32\jimysa.sys
    44 c:\WINDOWS\system32\ylekoxipe.bin
    45 c:\WINDOWS\vimufil.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\HomeAntivirus2010HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\InstallHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\Install\DEBUGHKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USER\Control Panel\don't load "scui.cpl"HKEY_CURRENT_USER\Control Panel\don't load "wscui.cpl"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Home Antivirus 2010"
Loading...