Home Malware Programs Rogue Anti-Virus Programs Antivirus Vista 2010

Antivirus Vista 2010

Posted: February 4, 2010

Antivirus Vista 2010 (or AntivirusVista2010) is a rogue anti-virus program that is part of the family, designed to con Internet users into spending money unnecessarily. AntivirusVista2010 gains access to compromised computers via backdoors created on the system by malicious Trojans. Once active, Antivirus Vista 2010 will produce fake system scan results which claim the computer is infected with all sorts of malware. AntivirusVista2010 will then urge the unwary user to purchase a "licensed" version of Antivirus Vista 2010 to remove the so-called threats detected. Do not fall for this trickery and use a reliable anti-spyware program to detect and remove AntivirusVista2010 and the Trojans associated with this rogue.

Among Antivirus Vista 2010 various clones are

File System Modifications

  • The following files were created in the system:
    # File Name
    1 av.exe
    2 WRblt8464P

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "av.exe" /START "%1? %HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "av.exe" /START "%1? %HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "av.exe" /START "firefox.exe"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "av.exe" /START "%1? %HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "av.exe" /START "%1? %

Additional Information on Antivirus Vista 2010

  • The following messages's were detected:
    # Message
    1 System hacked!
    Unknown program is scanning your system registry right now! Identity theft detected!
    Details
    Threat: Trojan-Clicker.Win32.stixo.d
    Do you want block this attack?
Loading...