Home Malware Programs Rogue Anti-Virus Programs Attentive Antivirus

Attentive Antivirus

Posted: July 27, 2013

Threat Metric

Threat Level: 10/10
Infected PCs: 101
First Seen: July 27, 2013
Last Seen: January 23, 2022
OS(es) Affected: Windows

Attentive Antivirus Screenshot 1Attentive Antivirus is a rogue anti-virus scanner that detects fake PC threats for the purpose of encouraging its victims to spend money on fake upgrades to its software that supposedly will let Attentive Antivirus disinfect your computer. Because Attentive Antivirus isn't a legitimate AV product and may even block you from using a wide range of other applications without any legitimate justification, SpywareRemove.com malware experts are perfectly comfortable in classifying Attentive Antivirus as scamware and recommending that you remove Attentive Antivirus as soon as possible. If at all accessible, real anti-malware software should be used to make sure that you've deleted all of Attentive Antivirus's hidden components and system changes.

Being Attentive to the Signs of Fraud in Attentive Antivirus

Attentive Antivirus, is a typical rogue anti-virus scanner from the WinWeb Security family and its clones include Antivirus Security, System Security, AntiSpyware Pro 2009, Total Security, Total Security 2009, Security Tool, Trojan.RogueAV.a.gen, System Adware Scanner 2010, FakeAlert-KW.e, Advanced Security Tool 2010, System Tool 2011, MS Removal Tool, Antivirus Center, Security Shield, Personal Shield Pro, Advanced PC Shield 2012, Security Sphere 2012 and Futurro Antivirus. Attentive Antivirus isn't able to detect legitimate viruses or other types of malware, but does include various methods of faking such functions. In addition to an intricately-crafted interface that pretends to offer updates, file-quarantining services, system scans and related security functions, Attentive Antivirus also includes a variety of fake pop-up warnings. These warnings may alert you to vaguely-defined threats, such as a generic 'network attack,' or list specific PC threats, such as variants of Conficker (a 2008-era worm that links infected PCs up to a botnet). SpywareRemove.com malware experts easily can verify that all security information provided by Attentive Antivirus is fake and cannot help you protect or disinfect your computer. Real anti-malware products, if allowed to launch, will not be able to corroborate Attentive Antivirus's scan results or other alerts.

The real motives behind Attentive Antivirus's 'security features' are to encourage you to purchase additional a fake upgrade to Attentive Antivirus to remove the fictitious malware that's being detected. Since Attentive Antivirus isn't a real AV program, spending money on Attentive Antivirus has no real results – other than giving your money and your financial information to criminals.

The Surefire Ant-Attentive Antivirus Solution

Attentive Antivirus isn't just scamware, but also a very real security hazard due to its ability to block other applications. Applications blocked by Attentive Antivirus infections are most likely to include baseline security utilities like the Registry Editor or the Task Manager, but also may extend to some brands of anti-malware software or even most other programs indiscriminately. Given the nature of the software lockdown related to the average Attentive Antivirus infection, you usually should seek to disable Attentive Antivirus through traditional security strategies (such as booting your computer from a flash drive) prior to deleting Attentive Antivirus.

While removing Attentive Antivirus is, of course, the appropriate response to any Attentive Antivirus infection, you shouldn't try to remove Attentive Antivirus with the Windows Control Panel or any of the other standard software-uninstalling methods. Since SpywareRemove.com malware researchers confirmed that Attentive Antivirus requires other PC threats to distribute itself and infect new PCs, any means of removing Attentive Antivirus should use anti-malware solutions that also can detect any other trojans that might be on your computer.

Attentive Antivirus Screenshot 2Attentive Antivirus Screenshot 3Attentive Antivirus Screenshot 4Attentive Antivirus Screenshot 5Attentive Antivirus Screenshot 6Attentive Antivirus Screenshot 7

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Documents and Settings\<username>\Documenti\Download\***s Rogue Pack\***'s Rogue Pack\Dump_00A00000_00075000.dmp_fixed.EXE File name: Dump_00A00000_00075000.dmp_fixed.EXE
Size: 981.5 KB (981504 bytes)
MD5: 23487126b783d2212eb3fec00a9a0632
Detection count: 28
File type: Executable File
Mime Type: unknown/EXE
Path: C:\Documents and Settings\<username>\Documenti\Download\***s Rogue Pack\***'s Rogue Pack\Dump_00A00000_00075000.dmp_fixed.EXE
Group: Malware file
Last Updated: August 17, 2022
%CommonAppData%\WaDprnV7\ File name: %CommonAppData%\WaDprnV7\
Group: Malware file
%CommonAppData%\WaDprnV7\DD1 File name: %CommonAppData%\WaDprnV7\DD1
Group: Malware file
%CommonAppData%\WaDprnV7\WaDprnV7.exe.manifest File name: %CommonAppData%\WaDprnV7\WaDprnV7.exe.manifest
Mime Type: unknown/manifest
Group: Malware file
%CommonAppData%\WaDprnV7\WaDprnV7.exe File name: %CommonAppData%\WaDprnV7\WaDprnV7.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%CommonAppData%\WaDprnV7\WaDprnV7.ico File name: %CommonAppData%\WaDprnV7\WaDprnV7.ico
Mime Type: unknown/ico
Group: Malware file
%CommonAppData%\WaDprnV7\WaDprnV7kassgxDq.lg File name: %CommonAppData%\WaDprnV7\WaDprnV7kassgxDq.lg
Mime Type: unknown/lg
Group: Malware file
%CommonAppData%\WaDprnV7\WaDprnV7kassgxDq.in File name: %CommonAppData%\WaDprnV7\WaDprnV7kassgxDq.in
Mime Type: unknown/in
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AA2014" = "%CommonAppData%\WaDprnV7\WaDprnV7.exe"

Additional Information

The following URL's were detected:
attentive-antivirus.com
The following messages's were detected:
# Message
1Warning! Infected file detected
Location: File System
Suspicious activity detected in the application cmd.exe to the behavior of the virus Win32/Conficker.X. For your security and to avoid loss of data, the operation of application cmd.exe has been temporarily restricted.
2Warning! Network attack attempt detected.
To keep the computer safe, the threat must be blocked.
3Warning! Network attack attempt detected.
We strongly recommend activating full edition of Attentive Antivirus for repairing threats.

Loading...