Antivirus Action

Posted: December 20, 2010
Threat Metric
Threat Level: 10/10
Infected PCs 7,729

Antivirus Action Description

ScreenshotAntivirus Action, a.k.a AntivirusAction, is a rogue anti-virus program that uses Trojans to penetrate a system and misleading system scans to scare users into purchasing the program. Antivirus Action comes on the heels of Security Antivirus, Security Suite, AV Security Suite, Security Suite Pro, and Security Tool — other popular rogue anti-spyware programs proliferating on the Web.

The most common methods through which rogue anti-virus programs are distributed include corrupt video codecs downloads bundled with Trojans, e-mail spam attachments, fraudulent or questionable websites, misleading advertisements, malicious links found on social networks, browser hijacking attacks, "poisoned" search results, and other aggressive, stealthy tactics.

Antivirus Action installs itself through the constant use of Trojans that exploit browser security holes, so it can enter a system without the user's knowledge. When the Trojan-bundled download is activated, it will install Antivirus Action and then a series of alarming bogus security alerts will appear on the Desktop. Antivirus Action will also perform a system scan and report numerous malware infections on the computer. Antivirus Action's fake security alerts redirect users to a rogue website which provides the paid licensed version of the useless software. The rogue website that distributes and promotes Antivirus Action is pcsecurityland.com.

The authors behind Antivirus Action have a clear and obvious strategy: to trick innocent users into believing that they have all types of malware problems on their computer and to ask payment for Antivirus Action's so-called services. AntivirusAction does not have a spyware detection or removal engine, so it will not be able to remove any malware. It is highly recommended that you use a reliable anti-spyware program and remove Antivirus Action from your PC. Do not click on anything which seems related to this blatant scam and have AntivirusAction removed as soon as it has been detected.

Aliases


Suspicious file [Panda]Mal/FakeAV-DO [Sophos]Trojan/Win32.FakeAV [AhnLab-V3]High Risk Cloaked MalwareRogue:Win32/FakeSpypro [Microsoft]Trojan.Win32.Generic.pak!cobraTrojan.FakeAV.2534 [DrWeb]Trj/CI.A [Panda]Generic19.CKTO [AVG]Trojan.Win32.Generic!BT [Sunbelt]Medium Risk Malware DropperVirTool:Win32/Obfuscator.JM [Microsoft]Win32/AntivirusAction.O [eTrust-Vet]TR/Obfuscated.244736JM [AntiVir]Trojan.FakeAV.1254 [DrWeb]
More aliases (19)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Antivirus Action may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\ixoyqwddd\tomgggctsbl.exe File name: tomgggctsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 0031942d0205335f097fe21c15ba2ee0
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ixoyqwddd\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ppihpaywy\jiswvkutsbl.exe File name: jiswvkutsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: b0917d1066fce6ca5e3ee38dc4b12339
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ppihpaywy\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\lpdbbcwkr\guqjvbhtsbl.exe File name: guqjvbhtsbl.exe
Size: 241.15 KB (241152 bytes)
MD5: 1f6d0d4ff9a73bd17682a451837b19df
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\lpdbbcwkr\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ysggivppe\fligkfktsbl.exe File name: fligkfktsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: dcd0b1c2e428fbd85d149b04173d8223
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ysggivppe\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\scryfyegv\edbqjiptsbl.exe File name: edbqjiptsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: e044872b0a14d73a2c496d27b6232f74
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\scryfyegv\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\bolkywoth\mhhvhtatsbl.exe File name: mhhvhtatsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 7d161d4cd66b72504455d3dd06166825
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\bolkywoth\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\fypsqpbap\hyimnjgtsbl.exe File name: hyimnjgtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: f02b140ddab36d3d9d9c572a0db3b210
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\fypsqpbap\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\dhearglll\fbwilfttsbl.exe File name: fbwilfttsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 38d7d7f7ffe6002612eb06ffe36d8e92
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\dhearglll\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\wgaqofdnx\locpogytsbl.exe File name: locpogytsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: a6e0d5a876f6c098d0b89e3122aaac7f
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\wgaqofdnx\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\waupepdka\qqumhletsbl.exe File name: qqumhletsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 9d2b498694cca08670f7673c02546114
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\waupepdka\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\wfdkaoaqr\txqsqdutsbl.exe File name: txqsqdutsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: a7be3c4f59c04663ff3faa05f3d90704
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\wfdkaoaqr\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\plrktqmdj\ikuekrqtsbl.exe File name: ikuekrqtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 7dd0f0b6a0723f8ae65bb7e68de08dc3
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\plrktqmdj\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\xxmpijnus\eovhjxftsbl.exe File name: eovhjxftsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 957ea706776975b1f3f7572302fdea34
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\xxmpijnus\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\hvugnkqgb\nflthhetsbl.exe File name: nflthhetsbl.exe
Size: 246.78 KB (246784 bytes)
MD5: 80a49cc60c21619185970ccaad578cbd
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\hvugnkqgb\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\whyiqnmyx\lthdllhtsbl.exe File name: lthdllhtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 8ada13b2881ca7fcd889d6b2a260a6a1
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\whyiqnmyx\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\bncdwkvdp\qalhtmxtsbl.exe File name: qalhtmxtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 50183249bbfad7fb636c7f38c995b01b
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\bncdwkvdp\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\espmedwnu\xggrvhctsbl.exe File name: xggrvhctsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 05232ed8383e86081840b08e6c95de8e
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\espmedwnu\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\sgqgnokqm\unauenetsbl.exe File name: unauenetsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 303ed290f218207f3cd6dbb65a4d6e64
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\sgqgnokqm\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ycouxscaj\oletxivtsbl.exe File name: oletxivtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: d5ddc3187fa7440bb21b31088ca2d469
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ycouxscaj\
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ddpeagnpe\uhblmjjtsbl.exe File name: uhblmjjtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 8394abc8b63e0afd6c6eac3f3f1ae7be
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ddpeagnpe\
Group: Malware file
Last Updated: November 30, 2010

More files

Additional Information

The following URL's were detected:
193.106.34.1693.174.88.135 93.174.88.136 93.174.88.138 93.174.88.139antispydot.com antispylake.com antispylake.net antispyroad.com antispytag.net antispytask.com antispyway.comantispyway.net antisywire.com antivirboost.com antivirdrome.com antivirnet.com antivirnet.net antivirstress.com ns1.antispydot.com ns1.antispylake.com ns1.antispyroad.com ns1.antispytag.com ns1.antispytag.net ns1.antispytask.com ns1.antispyway.com ns1.antispyway.net ns1.antisywire.com ns1.antivirboost.com ns1.antivirdrome.com ns1.antivirnet.com ns1.antivirnet.net ns1.antivirstress.com ns1.antivirwall.com ns1.infinitetraffic.info ns1.pcsecurityland.com ns1.softwaretoolsstore.com ns1.versionantispy.com ns2.antispydot.com ns2.antispylake.com ns2.antispyroad.com ns2.antispytag.com ns2.antispytag.net ns2.antispytask.com ns2.antispyway.com ns2.antispyway.net ns2.antisywire.com ns2.antivirboost.com ns2.antivirdrome.com ns2.antivirnet.com ns2.antivirnet.net ns2.antivirstress.com ns2.antivirwall.com ns2.pcsecurityland.com ns2.softwaretoolsstore.com ns2.versionantispy.com server1.usdebtmodifiers.comsoftwaretoolsstore.com versionantispy.com
The following messages's were detected:
# Message
1Security Warning
Application cannot be executed. The file notepad.exe is infected. Do you want to activate your antivirus software now.
2Windows Security Alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now.

Related Posts

5 Comments

Leave a Reply

Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter. If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.