IEAntiVirus

IEAntiVirus Description



ScreenshotIEAntiVirus, or IE AntiVirus 3.2, is a rogue anti-spyware program due to its deceptive and aggressive advertising practices. IE AntiVirus and its marketing affiliates are distributing and installing IE AntiVirus’s anti-spyware program through a download which is bundled with a trojan triggered by a browser helper object (BHO). Many of these trojan bundled downloads are located in sites which offer a “video codec” to be able to view free adult entertainment videos.

After your PC is infected with the trojan bundled download, it keeps showing up a popup stating “NOTICE: Your system is infected and your computer performance is not at the highest level.
Download SpyHunter Spyware Scanner
Full system optimization will greatly increase your computer’s performance and prevent data loss”. When you click on the popup, it will direct your IE to www.IEAntiVirus.com to download IE AntiVirus’s anti-spyware program.

In addition, the trojan which came bundled from either IE AntiVirus and/or its affiliates hijacks your search engines, such as Google, Yahoo and MSN, and displays a fake error message within your search results claiming that your system is infected and offering to buy the IE AntiVirus program. Once you click on this fake error message you will be redirected to IE AntiVirus’s home site where you will be tricked into buying IE AntiVirus’s anti-spyware application.

Aliases


Virus.Win32.FileInfector.gen!90 (suspicious) [Webwasher-Gateway]Heuristic: Suspicious File With Covert Attributes [Prevx1]not-a-virus:FraudTool.Win32.IeDefender.cl [Kaspersky]Win32.SuspectCrc [Ikarus]Trojan.FakeAlert.IC [VirusBuster]Trojan.Win32.BHO.17055 [ViRobot]TROJ_FAKEALER.AO [TrendMicro]Trojan/BHO.ebx [TheHacker]BehavesLike.Win32.Malware (v) [Sunbelt]Trojan.Win32.Generic.51E8D70E [Rising]

More aliases (408)


IEAntiVirus Automatic Detection Tool (Recommended)


Is your PC infected with IEAntiVirus? To safely & quickly detect IEAntiVirus, we highly recommend you run the malware scanner listed below.




Technical Details

Visual & GUI Characteristics

Screenshot

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name Detection Count
    1 intefltr.dll 696
    2 siebho.dll 621
    3 iefltr.dll 614
    4 pm_dll.dll 475
    5 ieflt.dll 454
    6 avid.dll 337
    7 amosv.dll 321
    8 iefl.dll 241
    9 nvflt.dll 220
    10 domiebho.dll 117

    More files

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY..\..\{Value}Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, value: {5F920865-38C9-40DA-8FCF-D9DC83F84EC5}Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, value: {D46BEAA4-A304-40B3-A9DA-EC7F7F501F25}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IE AntiVirus
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {74C9B719-AC3F-457F-9071-C858F1401C00}{29BF1B1F-0106-4881-A7C7-A71035C54825}{99E591B6-A5AD-4A2D-B349-334020760EF2}{171fc83d-2a8e-41cc-b28e-a117feac3def}{7FBB2D91-9964-4196-BAC5-D5E751762EC3}{A83359CE-23D4-4E1A-9D4E-C94AEDD1A67C}{CEAF8FFD-A61C-46EF-A970-D77D90246918}{3F1CEB16-3615-47ED-B153-3E98A4B9F3F5}{47FE9CB0-BFEE-4EBB-8BE2-F65F8811CEE7}{E706737E-92FE-467F-BE77-8BAA0006A3C0}{D26AAB3B-B0DD-456C-A7E5-4DA9565FD6EE}{67956585-9B5C-4E2B-ABE1-A01BF3046EE1}{9ea114bd-3d3e-2aa0-8af5-3b97bf0f905a}{8BF7284F-65D7-44C0-A451-47BF391C0B3E}{26980093-cbf2-4213-ad59-4a76a202e699}{9873E994-669E-4044-BA64-E5D9AD534A55}{76086C05-4D0A-4B92-9219-2E3FE8C553F9}{FBE58CC0-D14B-45FE-A717-57BB8247F652}{F65E955E-26C0-42FF-8EE2-443A05EA286A}{7D76D0EB-AE56-4DF4-AFFC-20AFF4344AC6}{4AD3A71E-8ED4-40F5-9A81-69245BDCBB75}{19B8572F-894F-41E0-9309-00091B688905}{8B2AE9C0-1555-4C92-905A-531532F15698}{E014A78F-34DC-4BE5-83BB-58CA12E384B6}{1AB6932F-92FE-42E6-870C-544AE458EA78}{6D0386B3-FD72-488E-9740-90355AE21735}{28F51CDA-3BD1-4F06-8F7B-2A881411983F}{2FF811E6-8925-4084-A649-C159955E67E8}{5F920865-38C9-40DA-8FCF-D9DC83F84EC5}{E913BA95-1ADE-4D25-AC0E-E27BD8E1E43D}{B095AF15-2FB6-4239-95AD-D1E27ECC11C7}{43D65102-A7BE-4C88-9737-44D2AD81394A}{7EA5E375-6136-496E-9616-E03B4F9EA1C0}{567462FE-24DF-44DC-9D49-D296CDB35844}{C12FC24B-A7B9-487F-9603-5481EBF00C6F}{FD36BBE5-1AF4-47D3-8681-2214DD85E152}{616D534C-3CA8-43AB-B439-618F850F1D2B}{45245B53-72FB-46CA-B5F5-ABA01D9B8E51}{5F841E5A-AA28-4037-BE7A-96E943E91F4D}{f578aaed-b736-c8df-6021-609621428b8b}{DD556A76-A85E-4606-9239-40A8B9FC4ECB}{7445DC17-44B7-4818-A9CB-2BC24E67E8D7}{D21DF669-7207-4EF5-BA64-8D0DC0CCD068}{F8A0D89E-875F-41AF-83BE-6B5780224682}{21BC9DFA-3E14-4753-9CBD-16A009AE1144}{597AED5A-2DEA-431D-BE7E-F03BAB2AFB15}{681147C4-D615-461A-960F-655871E315C3}{96488BA0-1A53-4583-8AC8-DB77560E8876}{69F6C0AE-0C78-4999-B6D1-62932A265C5D}{F856BB9E-855B-498D-883E-3509C550A031}
Posted: April 25, 2008 | By
Share:
Follow Me on Pinterest More More
Threat Level: 10/10
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Rate this article:
Detection Count: 26

5 Comments

  • prafulla says:

    My computer is not infected with ieantivirus but it regularly prompts to download this antivirus.I havent installed yet.How can i remove this prompt.

  • rebecca says:

    This got onto my computer and completely crashed but ty for all this information.It has helped me get my puter running again.

  • tom drysdale says:

    what an excellent tutorial, first class, well done, many thanks!!!

  • eetoday says:

    it couldn’t remove this IE Antivirus on my client PC , pls help to advise..

  • Ray Tao says:

    wow…i actually fell for IEAntiVirus…………………

Leave a Reply

What is 4 + 8 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)