Home Malware Programs Rogue Anti-Spyware Programs FakeScanti

FakeScanti

Posted: November 30, 2010

Threat Metric

Threat Level: 10/10
Infected PCs: 6,642
First Seen: November 30, 2010
Last Seen: January 10, 2022
OS(es) Affected: Windows

FakeScanti is a label that's used for a subgroup of rogue anti-virus programs that include variants such as AV Security 2012, AV Protection Online and Security Guard 2012. Like other types of rogue AV programs, FakeScanti products will create fake infection warnings as an excuse to request money in exchange for getting rid of these fictitious infections. Advanced versions of FakeScanti can rewrite their own files to avoid deletion, can change your desktop image, will block a variety of programs from the Windows Registry and can even create pop-ups. Since FakeScanti scamware will create a convincing illusion of being a security program, you should use real security programs that you trust, to find and remove FakeScanti infections from your PC. Above all else, SpywareRemove.com malware experts advise against spending money on any FakeScanti product.

The Carefully-Crafted Illusion of FakeScanti's Antivirus Features

FakeScanti isn't the name that's used by any one of FakeScanti's products, but rather, a label that real security programs use to identify rogue security programs from the FakeScanti family. This family of rogue anti-virus programs typically is installed by a Trojan:Win32/FakeScanti, a Trojan that specializes in installing rogue anti-virus applications from the FakeScanti gang. Although the installation process may not show any major symptoms, the presence of a FakeScanti rogue anti-virus application on your PC will exhibit many types highly-visible signs, such as:

  • Locking your desktop to an error message that resembles the following example. (This behavior is exclusive to younger versions of FakeScanti.)

    DANGER!!!

    Your computer is INFECTED!

    Attention!!!

    Such infection will cause permanent loss of all information stored on your computer: documents, files, etc.

    All your secret data like logins, passwords, credit card information can be accessed by third-parties for malicious purposes.

    All your online activities like sending e-mails, visiting web-sites are logged and stored on your hard disk.
    Spyware blocks the deletion of such information from your computer and makes your online actions traceable.

    PROTECT YOURSELF!
    DELETE SPYWARE FROM YOUR COMPUTER RIGHT NOW!

  • Creating error messages that alert you about infections and other hard drive problems that don't really exist. Samples include:

    Security Warning
    Your computer continues to be infected with harmful viruses. In order to prevent permanent loss of your information and credit card data theft please activate your antivirus software. Click here to enable protection.

    Warning: Infection is Detected
    Windows has found spyware infection on your computer!
    Click here to update your Windows antivirus software...

    svchost.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

  • Blocked access to .exe files, with the exception of files that have been explicitly-allowed by FakeScanti, such as basic Windows processes and malicious software processes. This often creates the fake error message noted below:

    This application has failed to start because the application configuration is incorrect. Reinstalling the application may fix this problem.

  • Random system restarts.
  • Blocked websites. When you attempt to visit a blocked site, FakeScanti will create an error pop-up that tries to convince you that the website is harmful and then ask you to activate FakeScant's rogue AV product:

    [Rogue anti-virus program name] has denied Internet access of the program.
    Internet Explorer is possibly injected with [Random infection name]. This worm attempts to send your personal information to remote host through Internet Explorer.

FakeScanti products, which can include (but aren't limited to) AKM Antivirus 2010 Pro, BlueFlare Antivirus, Milestone Antivirus, OpenCloud Antivirus, Sysinternals Antivirus, Windows Antivirus Pro, Windows Police PRO, XJR Antivirus and Your PC Protector, are incapable of detecting or curing infections or other forms of system problems. In fact, SpywareRemove.com malware researchers have found that all variants of FakeScanti are only interested in creating fake warning messages as part of a cry wolf scam to steal your money.

Teaching FakeScanti a Lesson in Real PC Security

Although FakeScanti uses many names to conceal FakeScanti's actual nature as a rogue anti-virus program, all FakeScanti infections are roughly identical and can be removed by similar methods. SpywareRemove.com malware research team suggests Safe Mode for disabling FakeScanti to begin with; this lets you access any websites or programs that FakeScanti may have blocked.

Once FakeScanti is no longer active, system scans with suitable anti-malware programs can remove all FakeScanti components, including FakeScanti's dropper Trojan and Registry entries. Trying to remove these components by yourself isn't recommended unless no other options are open, since FakeScanti, as previously noted, can adjust FakeScanti's files to evade removal attempts.

Automatic Malware Detection Tool (Recommended)

<!--
document.write('

Why can\'t I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter\'s malware scanner.

');
-->

Is your PC infected with a Rogue Anti-Spyware Program? To safely & quickly detect rogue anti-spyware programs part of the FakeScanti family, we highly recommend you download the following malware detection tool.

<!--
document.write('');
-->

Aliases

TR/Fake.Scanti.626 [AntiVir]Backdoor.Win32.Gbot.qmq [Kaspersky]Backdoor.Gbot.qmq [CAT-QuickHeal]Gen:Heur.Conjar.9 [BitDefender]Trojan-PSW.Win32.Fareit.lc [Kaspersky]Generic26.GYK [AVG]Trojan-FakeAV.Win32.OpenCloud.ca [Kaspersky]TrojanFakeAV.OpenCloud.ca [CAT-QuickHeal]Generic26.DBG [AVG]W32/Sirefef.11L711!tr [Fortinet]Generic25.BVGI [AVG]Artemis!04E7ECC7F7AC [McAfee-GW-Edition]TR/PSW.Fareit.40 [AntiVir]Trojan.Win32.Jorik.Gbot.rlh [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]
More aliases (1585)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\java.exe File name: java.exe
Size: 2.78 MB (2789888 bytes)
MD5: b5ac23200df9524102f1f04de2ceba4f
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 22, 2011
%SystemDrive%\Users\<username>\AppData\Roaming\firefox.exe File name: firefox.exe
Size: 2.4 MB (2405888 bytes)
MD5: 12c269bc2b30d0a54bee59de6aba861a
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: January 14, 2013
%APPDATA%\java.exe File name: java.exe
Size: 2.94 MB (2940416 bytes)
MD5: 22dd77527a0698b1a3edc5cea7d01efc
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 22, 2011
%USERPROFILE%\Application Data\firefox.exe File name: firefox.exe
Size: 2.93 MB (2934272 bytes)
MD5: 6c527aa9b17ff8405e52a44465176620
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: December 1, 2011
%USERPROFILE%\Application Data\chrome.exe File name: chrome.exe
Size: 2.78 MB (2788352 bytes)
MD5: 8c348da2e1cb2660a9b003959fddd879
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: December 1, 2011
%APPDATA%\java.exe File name: java.exe
Size: 1.96 MB (1968640 bytes)
MD5: 20f5fb0b21a127ea1a5c91c9c638469d
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 23, 2012
%APPDATA%\java.exe File name: java.exe
Size: 2.93 MB (2939904 bytes)
MD5: c9a078fbb9f5e1df927f8de43fedc250
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: February 20, 2012
%APPDATA%\java.exe File name: java.exe
Size: 2.78 MB (2789376 bytes)
MD5: c21763e31fb15162feb65e78612e0b23
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 12, 2011
%WINDIR%\system32\Cloud AV 2012v121.exe File name: Cloud AV 2012v121.exe
Size: 2.04 MB (2044928 bytes)
MD5: 41096615e6206b00f9206caf5307ba6a
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 10, 2012
%USERPROFILE%\Local Settings\Application Data\atm.exe File name: atm.exe
Size: 328.7 KB (328704 bytes)
MD5: f126ed56bc868c1a941e9e016bc731ab
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 12, 2011
%USERPROFILE%\Application Data\iexplore.exe File name: iexplore.exe
Size: 2.92 MB (2929664 bytes)
MD5: 583700a254cfd66ad644b7da67df534b
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: December 5, 2011
%APPDATA%\java.exe File name: java.exe
Size: 1.97 MB (1976320 bytes)
MD5: 1eb3390d1fc4a26a92b8b8b89a2b3e1e
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: December 5, 2011
%APPDATA%\DibbD3pnGaQ\Cloud AV 2012v121.exe File name: Cloud AV 2012v121.exe
Size: 2.93 MB (2935296 bytes)
MD5: 11fd80a3de0c4461f96d966d935005b5
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\DibbD3pnGaQ
Group: Malware file
Last Updated: December 12, 2011
%USERPROFILE%\Application Data\firefox.exe File name: firefox.exe
Size: 2.78 MB (2788864 bytes)
MD5: dc4572c236c6eab67c4ddcedbe38ba8b
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: May 8, 2012
%APPDATA%\UcSS11ivD3onFa\Cloud AV 2012v121.exe File name: Cloud AV 2012v121.exe
Size: 2.05 MB (2051072 bytes)
MD5: b7f4641a84a3ba51b01c1386d440d443
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UcSS11ivD3onFa
Group: Malware file
Last Updated: January 16, 2012
%USERPROFILE%\Application Data\iexplore.exe File name: iexplore.exe
Size: 2.94 MB (2947584 bytes)
MD5: 670d36e7d3ae3d08c48a602ab4a72406
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: April 2, 2013
%APPDATA%\T22oobFF3pm5aJ6\Cloud AV 2012v121.exe File name: Cloud AV 2012v121.exe
Size: 2.93 MB (2939904 bytes)
MD5: 644a649c104f47d63b0f87ee7296024b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\T22oobFF3pm5aJ6
Group: Malware file
Last Updated: March 8, 2012
%USERPROFILE%\Application Data\firefox.exe File name: firefox.exe
Size: 2.79 MB (2791424 bytes)
MD5: 792eef348cacb5cdc974cfd60f142533
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: January 1, 2012
%USERPROFILE%\Application Data\iexplore.exe File name: iexplore.exe
Size: 2.94 MB (2942464 bytes)
MD5: ccf74c83faaab41fea45ed735b914565
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: December 27, 2011
%USERPROFILE%\Application Data\firefox.exe File name: firefox.exe
Size: 2.93 MB (2939904 bytes)
MD5: bb79fa479e3d4273e84c42985a8edb9f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: February 22, 2012
%USERPROFILE%\Local Settings\Application Data\tvq.exe File name: tvq.exe
Size: 324.09 KB (324096 bytes)
MD5: e5b10e4f60bc6005191d0ea509daaa2a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 12, 2011

More files

Related Posts

Loading...