Home Malware Programs Rogue Anti-Spyware Programs Expert Antivirus 2009

Expert Antivirus 2009

Posted: January 12, 2009

Expert Antivirus 2009, also known as ExpertAntivirus is a rogue anti-spyware program. Expert Antivirus 2009 is often downloaded and installed by a Trojan, usually found bundled in video codecs, or through browser security holes. Zlob, Vundo and other variations of these polymorphic malware seem to be the most commonly found to come bundled with rogue anti-spyware programs. Trojans like Zlob may pop up fake security messages, similar to a Windows notification, that state it has detected malware on a computer.

Expert Antivirus 2009 will also display notifications of imaginary security risks in its attempts to get the user to purchase the full version. Expert Antivirus 2009 may run a fake system scanner and then display fake system scan results stating that your system is flooded with spyware. Expert Antivirus 2009 program may be difficult to remove manually, and will continue to try to recreate itself

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ExpertAntivirus.EXE
    2 ext32inc.dll
    3 wincom137.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_ALL_USERS\Software\Microsoft\Office\Outlook\Addins\ExpertAntivirus.Addin.1HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoaderHKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Shell\1dasHKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoaderHKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7
Loading...