Home Malware Programs Rogue Anti-Virus Programs Antivirus Action

Antivirus Action

Posted: December 20, 2010

Threat Metric

Threat Level: 10/10
Infected PCs: 7,729
First Seen: October 11, 2010
OS(es) Affected: Windows

ScreenshotAntivirus Action, a.k.a AntivirusAction, is a rogue anti-virus program that uses Trojans to penetrate a system and misleading system scans to scare users into purchasing the program. Antivirus Action comes on the heels of Security Antivirus, Security Suite, AV Security Suite, Security Suite Pro, and Security Tool — other popular rogue anti-spyware programs proliferating on the Web.

The most common methods through which rogue anti-virus programs are distributed include corrupt video codecs downloads bundled with Trojans, e-mail spam attachments, fraudulent or questionable websites, misleading advertisements, malicious links found on social networks, browser hijacking attacks, "poisoned" search results, and other aggressive, stealthy tactics.

Antivirus Action installs itself through the constant use of Trojans that exploit browser security holes, so it can enter a system without the user's knowledge. When the Trojan-bundled download is activated, it will install Antivirus Action and then a series of alarming bogus security alerts will appear on the Desktop. Antivirus Action will also perform a system scan and report numerous malware infections on the computer. Antivirus Action's fake security alerts redirect users to a rogue website which provides the paid licensed version of the useless software. The rogue website that distributes and promotes Antivirus Action is pcsecurityland.com.

The authors behind Antivirus Action have a clear and obvious strategy: to trick innocent users into believing that they have all types of malware problems on their computer and to ask payment for Antivirus Action's so-called services. AntivirusAction does not have a spyware detection or removal engine, so it will not be able to remove any malware. It is highly recommended that you use a reliable anti-spyware program and remove Antivirus Action from your PC. Do not click on anything which seems related to this blatant scam and have AntivirusAction removed as soon as it has been detected.

Aliases

Suspicious file [Panda]Mal/FakeAV-DO [Sophos]Trojan/Win32.FakeAV [AhnLab-V3]Rogue:Win32/FakeSpypro [Microsoft]Trojan.FakeAV.2534 [DrWeb]Trj/CI.A [Panda]Generic19.CKTO [AVG]Trojan.Win32.Generic!BT [Sunbelt]VirTool:Win32/Obfuscator.JM [Microsoft]Win32/AntivirusAction.O [eTrust-Vet]TR/Obfuscated.244736JM [AntiVir]Trojan.FakeAV.1254 [DrWeb]Win32:FakeAV-AUZ [Avast]Trojan.Gen [Symantec]a variant of Win32/Kryptik.HZQ [NOD32]
More aliases (19)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\ixoyqwddd\tomgggctsbl.exe File name: tomgggctsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 0031942d0205335f097fe21c15ba2ee0
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ixoyqwddd
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ppihpaywy\jiswvkutsbl.exe File name: jiswvkutsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: b0917d1066fce6ca5e3ee38dc4b12339
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ppihpaywy
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\lpdbbcwkr\guqjvbhtsbl.exe File name: guqjvbhtsbl.exe
Size: 241.15 KB (241152 bytes)
MD5: 1f6d0d4ff9a73bd17682a451837b19df
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\lpdbbcwkr
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ysggivppe\fligkfktsbl.exe File name: fligkfktsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: dcd0b1c2e428fbd85d149b04173d8223
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ysggivppe
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\scryfyegv\edbqjiptsbl.exe File name: edbqjiptsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: e044872b0a14d73a2c496d27b6232f74
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\scryfyegv
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\bolkywoth\mhhvhtatsbl.exe File name: mhhvhtatsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 7d161d4cd66b72504455d3dd06166825
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\bolkywoth
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\fypsqpbap\hyimnjgtsbl.exe File name: hyimnjgtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: f02b140ddab36d3d9d9c572a0db3b210
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\fypsqpbap
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\dhearglll\fbwilfttsbl.exe File name: fbwilfttsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 38d7d7f7ffe6002612eb06ffe36d8e92
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\dhearglll
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\wgaqofdnx\locpogytsbl.exe File name: locpogytsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: a6e0d5a876f6c098d0b89e3122aaac7f
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\wgaqofdnx
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\waupepdka\qqumhletsbl.exe File name: qqumhletsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 9d2b498694cca08670f7673c02546114
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\waupepdka
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\wfdkaoaqr\txqsqdutsbl.exe File name: txqsqdutsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: a7be3c4f59c04663ff3faa05f3d90704
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\wfdkaoaqr
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\plrktqmdj\ikuekrqtsbl.exe File name: ikuekrqtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 7dd0f0b6a0723f8ae65bb7e68de08dc3
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\plrktqmdj
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\xxmpijnus\eovhjxftsbl.exe File name: eovhjxftsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 957ea706776975b1f3f7572302fdea34
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\xxmpijnus
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\hvugnkqgb\nflthhetsbl.exe File name: nflthhetsbl.exe
Size: 246.78 KB (246784 bytes)
MD5: 80a49cc60c21619185970ccaad578cbd
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\hvugnkqgb
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\whyiqnmyx\lthdllhtsbl.exe File name: lthdllhtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 8ada13b2881ca7fcd889d6b2a260a6a1
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\whyiqnmyx
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\bncdwkvdp\qalhtmxtsbl.exe File name: qalhtmxtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 50183249bbfad7fb636c7f38c995b01b
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\bncdwkvdp
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\espmedwnu\xggrvhctsbl.exe File name: xggrvhctsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 05232ed8383e86081840b08e6c95de8e
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\espmedwnu
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\sgqgnokqm\unauenetsbl.exe File name: unauenetsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 303ed290f218207f3cd6dbb65a4d6e64
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\sgqgnokqm
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ycouxscaj\oletxivtsbl.exe File name: oletxivtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: d5ddc3187fa7440bb21b31088ca2d469
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ycouxscaj
Group: Malware file
Last Updated: November 30, 2010
%TEMP%\ddpeagnpe\uhblmjjtsbl.exe File name: uhblmjjtsbl.exe
Size: 240.64 KB (240640 bytes)
MD5: 8394abc8b63e0afd6c6eac3f3f1ae7be
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\ddpeagnpe
Group: Malware file
Last Updated: November 30, 2010

More files

Additional Information

The following URL's were detected:
193.106.34.1693.174.88.135 93.174.88.136 93.174.88.138 93.174.88.139antispydot.com antispylake.com antispylake.net antispyroad.com antispytag.net antispytask.com antispyway.comantispyway.net antisywire.com antivirboost.com antivirdrome.com antivirnet.com antivirnet.net antivirstress.com ns1.antispydot.com ns1.antispylake.com ns1.antispyroad.com ns1.antispytag.com ns1.antispytag.net ns1.antispytask.com ns1.antispyway.com ns1.antispyway.net ns1.antisywire.com ns1.antivirboost.com ns1.antivirdrome.com ns1.antivirnet.com ns1.antivirnet.net ns1.antivirstress.com ns1.antivirwall.com ns1.infinitetraffic.info ns1.pcsecurityland.com ns1.softwaretoolsstore.com ns1.versionantispy.com ns2.antispydot.com ns2.antispylake.com ns2.antispyroad.com ns2.antispytag.com ns2.antispytag.net ns2.antispytask.com ns2.antispyway.com ns2.antispyway.net ns2.antisywire.com ns2.antivirboost.com ns2.antivirdrome.com ns2.antivirnet.com ns2.antivirnet.net ns2.antivirstress.com ns2.antivirwall.com ns2.pcsecurityland.com ns2.softwaretoolsstore.com ns2.versionantispy.com server1.usdebtmodifiers.comsoftwaretoolsstore.com versionantispy.com
The following messages's were detected:
# Message
1Security Warning
Application cannot be executed. The file notepad.exe is infected. Do you want to activate your antivirus software now.
2Windows Security Alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now.

Related Posts

5 Comments

  • Gil StJames says:

    hep. cannot get rid of antivirus action. It seems to have found a way around your tools or blocks them.

  • joyce thompson says:

    I have a Security Tools antivirus on my computer which does not allow me to access any of the suggestions on how to get rid of it. What else can I do?

  • dingduck says:

    CREATE A NEW USER AND DELETE IT THEN

  • ldaley says:

    same as above, can't download any of suggested tools, blocks everything.

  • Glen DaCosta says:

    I'm having regular problem with my prowser freezing up on me so often i cant work properly on my computer. I will appreciate any help i can get to get rid of this problem

Loading...