IEAntiVirus
IEAntiVirus Description
After your PC is infected with the trojan bundled download, it keeps showing up a popup stating “NOTICE: Your system is infected and your computer performance is not at the highest level. Full system optimization will greatly increase your computer’s performance and prevent data loss”. When you click on the popup, it will direct your IE to www.IEAntiVirus.com to download IE AntiVirus’s anti-spyware program.
In addition, the trojan which came bundled from either IE AntiVirus and/or its affiliates hijacks your search engines, such as Google, Yahoo and MSN, and displays a fake error message within your search results claiming that your system is infected and offering to buy the IE AntiVirus program. Once you click on this fake error message you will be redirected to IE AntiVirus’s home site where you will be tricked into buying IE AntiVirus’s anti-spyware application.
Aliases
Virus.Win32.FileInfector.gen!90 (suspicious) [Webwasher-Gateway]Heuristic: Suspicious File With Covert Attributes [Prevx1]not-a-virus:FraudTool.Win32.IeDefender.cl [Kaspersky]Win32.SuspectCrc [Ikarus]Trojan.FakeAlert.IC [VirusBuster]Trojan.Win32.BHO.17055 [ViRobot]TROJ_FAKEALER.AO [TrendMicro]Trojan/BHO.ebx [TheHacker]BehavesLike.Win32.Malware (v) [Sunbelt]Trojan.Win32.Generic.51E8D70E [Rising]
More aliases (408)
IEAntiVirus Automatic Detection Tool (Recommended)
Is your PC infected with IEAntiVirus? To safely & quickly detect IEAntiVirus, we highly recommend you run the malware scanner listed below.
Download SpyHunter's* Malware Scanner to detect IEAntiVirus
What happens if IEAntiVirus does not let you open SpyHunter or blocks the Internet?
Technical Details
Visual & GUI Characteristics
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read
the tutorials on how to find malware,
kill unwanted processes,
remove malicious DLLs and
delete other harmful files. Always be
sure to back up your PC before making any changes.
- The following files were created in the system:
# File Name Detection Count 1 intefltr.dll 696 2 siebho.dll 621 3 iefltr.dll 614 4 pm_dll.dll 475 5 ieflt.dll 454 6 avid.dll 337 7 amosv.dll 321 8 iefl.dll 241 9 nvflt.dll 220 10 domiebho.dll 117
More files
Registry Modifications
Tutorial: To edit and delete registry entries manually, read the tutorial on
how to remove malicious registry entries.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
- The following newly produced Registry Values are:
HKEY..\..\{Value}Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, value: {5F920865-38C9-40DA-8FCF-D9DC83F84EC5}Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, value: {D46BEAA4-A304-40B3-A9DA-EC7F7F501F25}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IE AntiVirus - The following CLSID's were detected:
HKEY..\..\{CLSID Path} {74C9B719-AC3F-457F-9071-C858F1401C00}{29BF1B1F-0106-4881-A7C7-A71035C54825}{99E591B6-A5AD-4A2D-B349-334020760EF2}{171fc83d-2a8e-41cc-b28e-a117feac3def}{7FBB2D91-9964-4196-BAC5-D5E751762EC3}{A83359CE-23D4-4E1A-9D4E-C94AEDD1A67C}{CEAF8FFD-A61C-46EF-A970-D77D90246918}{3F1CEB16-3615-47ED-B153-3E98A4B9F3F5}{47FE9CB0-BFEE-4EBB-8BE2-F65F8811CEE7}{E706737E-92FE-467F-BE77-8BAA0006A3C0}{D26AAB3B-B0DD-456C-A7E5-4DA9565FD6EE}{67956585-9B5C-4E2B-ABE1-A01BF3046EE1}{9ea114bd-3d3e-2aa0-8af5-3b97bf0f905a}{8BF7284F-65D7-44C0-A451-47BF391C0B3E}{26980093-cbf2-4213-ad59-4a76a202e699}{9873E994-669E-4044-BA64-E5D9AD534A55}{76086C05-4D0A-4B92-9219-2E3FE8C553F9}{FBE58CC0-D14B-45FE-A717-57BB8247F652}{F65E955E-26C0-42FF-8EE2-443A05EA286A}{7D76D0EB-AE56-4DF4-AFFC-20AFF4344AC6}{4AD3A71E-8ED4-40F5-9A81-69245BDCBB75}{19B8572F-894F-41E0-9309-00091B688905}{8B2AE9C0-1555-4C92-905A-531532F15698}{E014A78F-34DC-4BE5-83BB-58CA12E384B6}{1AB6932F-92FE-42E6-870C-544AE458EA78}{6D0386B3-FD72-488E-9740-90355AE21735}{28F51CDA-3BD1-4F06-8F7B-2A881411983F}{2FF811E6-8925-4084-A649-C159955E67E8}{5F920865-38C9-40DA-8FCF-D9DC83F84EC5}{E913BA95-1ADE-4D25-AC0E-E27BD8E1E43D}{B095AF15-2FB6-4239-95AD-D1E27ECC11C7}{43D65102-A7BE-4C88-9737-44D2AD81394A}{7EA5E375-6136-496E-9616-E03B4F9EA1C0}{567462FE-24DF-44DC-9D49-D296CDB35844}{C12FC24B-A7B9-487F-9603-5481EBF00C6F}{FD36BBE5-1AF4-47D3-8681-2214DD85E152}{616D534C-3CA8-43AB-B439-618F850F1D2B}{45245B53-72FB-46CA-B5F5-ABA01D9B8E51}{5F841E5A-AA28-4037-BE7A-96E943E91F4D}{f578aaed-b736-c8df-6021-609621428b8b}{DD556A76-A85E-4606-9239-40A8B9FC4ECB}{7445DC17-44B7-4818-A9CB-2BC24E67E8D7}{D21DF669-7207-4EF5-BA64-8D0DC0CCD068}{F8A0D89E-875F-41AF-83BE-6B5780224682}{21BC9DFA-3E14-4753-9CBD-16A009AE1144}{597AED5A-2DEA-431D-BE7E-F03BAB2AFB15}{681147C4-D615-461A-960F-655871E315C3}{96488BA0-1A53-4583-8AC8-DB77560E8876}{69F6C0AE-0C78-4999-B6D1-62932A265C5D}{F856BB9E-855B-498D-883E-3509C550A031}
Posted: April 25, 2008 | By SpywareRemove
Share:
Threat Level: 10/10
Rate this article:
Detection Count: 26


More

My computer is not infected with ieantivirus but it regularly prompts to download this antivirus.I havent installed yet.How can i remove this prompt.
This got onto my computer and completely crashed but ty for all this information.It has helped me get my puter running again.
what an excellent tutorial, first class, well done, many thanks!!!
it couldn’t remove this IE Antivirus on my client PC , pls help to advise..
wow…i actually fell for IEAntiVirus…………………