Home Malware Programs Rogue Anti-Spyware Programs UnVirex

UnVirex

Posted: June 2, 2009

Threat Metric

Threat Level: 10/10
Infected PCs: 33
First Seen: July 24, 2009
Last Seen: January 10, 2019
OS(es) Affected: Windows

ScreenshotUnVirex is a rogue malware application that is usually disguised as a video codec. A computer user may be duped into thinking that they are downloading a new video codec that enables their system to view a video but in reality the video codec is associated with UnVirex. When a user attempts to install the video codec, or in this case, UnVirex, they are told that it will be scanned for viruses using UnVirex. Instead of a legitimate scan taking place, UnVirex may display bogus scan results. UnVirex may offer an application that the computer user supposedly needs to purchase to resolve or remove the threats it found. UnVirex is malicious and cannot be trusted for detection or removal of any type of malware infection. Removal of UnVirex should be handled with a spyware removal tool to safely rid your system of all traces of UnVirex and any related malware.

ScreenshotScreenshotScreenshot

Aliases

Unvirex [Symantec]Suspicious file [Panda]Trojan:Win32/FakeRean [Microsoft]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



UnVirex.exe File name: UnVirex.exe
Size: 13.02 MB (13025280 bytes)
MD5: 884a2ca2d31288483c0f8e295267228c
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
UnVirexInstall[1].exe File name: UnVirexInstall[1].exe
Size: 1.73 MB (1732376 bytes)
MD5: 6780076ba7af1149d876875da5bd635d
Detection count: 78
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
b0dmthvqvdbk.exe File name: b0dmthvqvdbk.exe
Size: 3.66 MB (3665920 bytes)
MD5: e8ed30c99f9fd9e9ff62e955ec14bedd
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2010
%ProgramFiles%\UnVirex\daily.cvd File name: %ProgramFiles%\UnVirex\daily.cvd
Mime Type: unknown/cvd
Group: Malware file
%ProgramFiles%\UnVirex\Drvfltip.sys File name: %ProgramFiles%\UnVirex\Drvfltip.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%ProgramFiles%\UnVirex\hjengine.dll File name: %ProgramFiles%\UnVirex\hjengine.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\IEAddon.dll File name: %ProgramFiles%\UnVirex\IEAddon.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\main.cvd File name: %ProgramFiles%\UnVirex\main.cvd
Mime Type: unknown/cvd
Group: Malware file
%ProgramFiles%\UnVirex\MFC71.dll File name: %ProgramFiles%\UnVirex\MFC71.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\MFC71ENU.DLL File name: %ProgramFiles%\UnVirex\MFC71ENU.DLL
File type: Dynamic link library
Mime Type: unknown/DLL
Group: Malware file
%ProgramFiles%\UnVirex\msvcp71.dll File name: %ProgramFiles%\UnVirex\msvcp71.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\msvcr71.dll File name: %ProgramFiles%\UnVirex\msvcr71.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\pthreadVC2.dll File name: %ProgramFiles%\UnVirex\pthreadVC2.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\shellext.dll File name: %ProgramFiles%\UnVirex\shellext.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\siglsp.dll File name: %ProgramFiles%\UnVirex\siglsp.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\UnVirex\uninstall.exe File name: %ProgramFiles%\UnVirex\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\UnVirex\UnVirex.exe File name: %ProgramFiles%\UnVirex\UnVirex.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\UnVirex.lnk File name: %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\UnVirex.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS]\ext.dll File name: %UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS]\ext.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS]\System.dll File name: %UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS]\System.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Documents and Settings\<username>\Desktop\UnVirex.lnk File name: C:\Documents and Settings\<username>\Desktop\UnVirex.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex File name: C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex
Group: Malware file
C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex.lnk File name: C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\How to Register UnVirex.lnk File name: C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\How to Register UnVirex.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\Register UnVirex.lnk File name: C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\Register UnVirex.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\Uninstall.lnk File name: C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\Uninstall.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\UnVirex.lnk File name: C:\Documents and Settings\<username>\Start Menu\Programs\UnVirex\UnVirex.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\"UnVirex" = "UnVirex"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\00000001\"PackedCatalogItem" = "%ProgramFiles%\UnVirex\siglsp.dll"HKEY..\..\..\..{Subkeys}HKEY_CLASSES_ROOT\AppID\IEAddon.DLLHKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\unvirex_contextscanHKEY_CLASSES_ROOT\IEAddon.StatusBarPaneHKEY_CLASSES_ROOT\IEAddon.StatusBarPane.1HKEY_LOCAL_MACHINE\SOFTWARE\UnVirexHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DrvFltIpHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DrvFltIpHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"UnVirex" = "C:\Program Files\UnVirex\UnVirex.exe"

Additional Information

The following directories were created:
%ProgramFiles%\UnVirex
Loading...