Home Malware Programs Rogue Anti-Spyware Programs AntiMalware

AntiMalware

Posted: November 9, 2009

Threat Metric

Threat Level: 10/10
Infected PCs: 77
First Seen: December 1, 2009
OS(es) Affected: Windows

ScreenshotAntiMalware is an updated version of older types of rogue anti-malware programs that claim to detect and protect your PC from Trojans, rootkits and other types of malicious software while actually causing problems for your computer and begging for money. By using a popular PC security brand's logo and a Windows-friendly interface, AntiMalware attempts to goad you into spending money on its fake security features to stop all of the attacks that, in fact, originate from AntiMalware itself. AntiMalware is capable of blocking security-related programs and due to this function, should be shut down before any attempt to remove AntiMalware from your PC. However, SpywareRemove.com malware researchers are happy to note that once this is achieved, actual anti-malware products can remove AntiMalware harmlessly and without incurring longterm damage to your computer.

AntiMalware – a Fraudulent Program That Masquerades As Its Mortal Enemy

AntiMalware is just a recent version of rogue anti-malware programs like Zentom System Guard, Internet Security 2011, Internet Defender, Antimalware Tool, Security Defender and Antimalware Defender. Like its duplicates, AntiMalware will display misleading alerts and scanner results that announce the presence of high-level PC threats such as Rootkit.Win32.Agent.pp, Net-Worm.Win32.Mytob.t, Trojan-Downloader.HTML.Agent.aq or Virus.Win32.Hala.a. Because SpywareRemove.com malware experts have found zero evidence that AntiMalware can detect anything except for figments of its imagination, it's recommended that you ignore any unusual warning messages while AntiMalware is on your PC.

The point behind AntiMalware's fake alerts is to siphon money towards AntiMalware's criminal creators, since AntiMalware will only offer to remove all PC threats after you've purchased its full version. Doing this can endanger your bank account or credit card, and actually will put your PC farther from safety than simply getting rid of AntiMalware would do.

For the sake of reference, SpywareRemove.com malware analysts have provided these samples of AntiMalware's multitude of fake warnings (although this list shouldn't be considered conclusive):

"Antimalware security update for [operating system] (KB961118)"

Warning!
Infections on your PC can cause:
- Applications won’t start
- Unwanted advertising displaying
- Loss of Internet communication
- Lost documents and settings
- Some files can disappear from PC
- You need registered version of Zentom System Guard to remove these infections.
Click "Remove threats" to activate protection and eliminate these security hazards.

Attention! Network attack detected!
Your computer is being attacked from remote host. Attack has been classified as Remote code execution attempt.

Network intrusion detected! Warning! Network attack detected!
Process is trying to steal your passwords listed below. It is highly recommended to block this threat now.
Your computer is being attacked from a remote PC.
Attack from: 145.7.151.43:34630

Trojan.Spy threat has been detected.
This threat module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click button below to locate and remove this threat now.

Warning! Removed attack detected!
AntiMalware has detected that somebody is trying to stole Your private data remotely via Trojan.Win32.Generic!BT.
Transfer for Your private data via Internet will start in: 10 seconds
We strongly recommend You to block attack immediately.

AntiMalware – Hacker attack detected
Your computer is subjected to hacker attack. Zentom System Guard has detected that somebody is trying to transfer Your private data via Internet. We strongly recommend you to block attack immediately.

Attention! Threat detected!
[Program_name].exe is infected with Trojan-BNK.Keylogger.gen
Private data can be stolen by third parties including card details and passwords.
It is strongly recommended to perform threat removal on your system.

Firewall file transfer detected
Hidden file transfer to remote host was detected
AntiMalware has detected that somebody is trying to transfer Your private data via Internet. We strongly recommend you to block attack immediately.

Warning! Threat detected!
Threat module detected on your PC!
Zlob.Porn.Ad threat has been detected. This threat module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click button below to locate and remove this threat now.

Scorching Out AntiMalware's Fake Security with the Real Deal

Since AntiMalware considers real anti-malware products to be both a threat to itself and competition, you may need to exert a little extra effort to remove AntiMalware with an appropriate anti-malware program – in most cases, AntiMalware will attempt to block, not only security-related programs, but also unrelated applications. Starting Windows in Safe Mode, renaming a blocked program file to a generic name (like 'explorer.exe') or even booting Windows from an external device can help to stop AntiMalware from blocking its own deletion.

Until AntiMalware is removed, you should also be cautious of the possibility of browser redirect attacks that force your browser to load AntiMalware's website. SpywareRemove.com malware research team warns that any contact with AntiMalware's site or other scamware sites can result in further infections via scripted attacks. Using a browser with strong security settings can lower this possibility, although this shouldn't be considered a substitute for having anti-malware software to guard against AntiMalware infections as they occur.

Initial installations of AntiMalware and similar types of rogue anti-malware programs have often been noted to include pop-ups about fake anti-malware security updates. However, since related types of Trojan droppers may install AntiMalware regardless of what you select, you should consider your PC potentially-infected after any encounter with an unusual update window.
ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Aliases

Trojan.FakeAV [Symantec]Suspicious file [Panda]Artemis!7BB7211CD996 [McAfee+Artemis]Suspicious:W32/Riskware!Online [F-Secure]Sus/UnkPacker [Sophos]FraudTool.Win32.RogueSecurity (v) [Sunbelt]Mal/FakeAV-BP [Sophos]a variant of Win32/Kryptik.BFC [NOD32]Trojan:Win32/FakeCog [Microsoft]Trojan.PCK.Tdss.AA.636 [McAfee-GW-Edition]Artemis!6B53DC5751F6 [McAfee+Artemis]Packed.Win32.TDSS.aa [Kaspersky]Packed.Win32.Tdss [Ikarus]SHeur2.BVVU [AVG]TR/PCK.Tdss.AA.636 [AntiVir]
More aliases (18)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



antimalware.exe File name: antimalware.exe
Size: 1.6 MB (1601536 bytes)
MD5: 4689058a0d017dc865f4969e8f4d3892
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2010
antimalware.exe File name: antimalware.exe
Size: 1.6 MB (1601536 bytes)
MD5: a15d8b2aba915c9d01ece6aed792a7e8
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2010
AntiMalware.exe File name: AntiMalware.exe
Size: 37.47 MB (37471560 bytes)
MD5: b7f355a106a75ad266ac85ef00e6faa3
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 21, 2010

Related Posts

14 Comments

  • Jennifer says:

    THis page was awesome at helping me solve my problem.

  • Sarah says:

    Is there an easy way to do step 3? ive tried just searching for it and deleting but is that all i need to do?

  • christy says:

    will downloading this make my computer go faster..

  • andy foster says:

    Please help me get rid of this virus.

  • Jennifer Leatherman says:

    Computer antivirus, please help get out of this confusion.

  • john hoggan says:

    please help me to remove this antivirus

  • Jeffrey says:

    Do i need to edit my registry?

  • Wil says:

    i've deleted everything I've found that says Antimalware, but the pop ups persist. Where could this thing be hiding. When I searc my computer it says no matches found now, but the problem is still there

  • Dan Fearon says:

    Has anyone got a way of contacting the companies that own this shit, i [REMOVED WORD]ing hate this virus shit on my computer.

    Youtube: Fearon856
    Someone please message me a number.

  • tianee says:

    yea i cant stand the pop ups heellllppp mmmeee!! i have spywere on my comp now but its stil not gettin rid of it !!!!!!!!!!!

  • tianee says:

    I pressed [ Alt + Ctrl + delete ] then [Applications] and clicked on the bug (mine was antimalwere) the pop ups now gone! YAY FINALY! I hope its not still infecting my comp though !

  • john sires says:

    um yeah.... this is some f&*%in bulls&^t antimalware has my comp by the throat. cant enter safe mode and cant get on long enough before it crashes..... any suggestions????

  • Juani says:

    Buena idea

  • carol says:

    I just purchased speedyPC, then nothing happened?? I hope this isn't a scam or hacker?!?!?!??!

Loading...