Home Malware Programs Rogue Anti-Spyware Programs Antivirus Suite

Antivirus Suite

Posted: April 1, 2010

Threat Metric

Threat Level: 10/10
Infected PCs: 82
First Seen: April 1, 2010
OS(es) Affected: Windows

Antivirus Suite (aka AntivirusSuite) is a rogue anti-spyware program which enters a targeted computer via a backdoor created by malware. AntivirusSuite displays similar tactics to its rogue cousin Antivirus Soft. The hackers behind this cyber-scam use malware to redirect Internet users to a fake scan page which produces bogus results claiming the system is infected with all sorts of malware. The fake scanner also produces popup warnings which urge users to purchase Antivirus Suite to remove the so-called threats. Do not fall for this trickery, it is a blatant scam.

Aliases

Generic Trojan [Panda]W32/FakeAV.APPO!tr [Fortinet]Win-Trojan/Fakealert.269312.C [AhnLab-V3]TROJ_FAKEAV.SM [TrendMicro]Trojan.Fakealert.14663 [DrWeb]Trojan.Win32.FraudPack.appo [Kaspersky]W32/Troj_Obfusc.N.gen!Eldorado [F-Prot]FakeAlert-SpyPro.gen.d [McAfee]W32/FraudPack.APPI!tr [Fortinet]Win-Trojan/Fakealert.269312.B [AhnLab-V3]Trojan/Win32.FraudPack.gen [Antiy-AVL]Win32/SystemGuard2009.CO [eTrust-Vet]Trojan.Fakealert.ahu [McAfee-GW-Edition]TROJ_FAKESPYP.V [TrendMicro]TR/Fakealert.ahu [AntiVir]
More aliases (69)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



gdtrmiptssd.exe File name: gdtrmiptssd.exe
Size: 270.59 KB (270592 bytes)
MD5: 7403cdd6ba1ad172a3d0bdcfc4f423a6
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
wvhstoctssd.exe File name: wvhstoctssd.exe
Size: 270.59 KB (270592 bytes)
MD5: 7afaf0e7d4819a7c8b030d071d526c96
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 6, 2010
mrkkuvktssd.exe File name: mrkkuvktssd.exe
Size: 270.59 KB (270592 bytes)
MD5: 0763919dca049123316a463fb646261a
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 3, 2010
cbrqicitssd.exe File name: cbrqicitssd.exe
Size: 269.31 KB (269312 bytes)
MD5: 4777c6b710ea2ab7919e7547da7b1e4a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 8, 2010
bqspgwktssd.exe File name: bqspgwktssd.exe
Size: 269.31 KB (269312 bytes)
MD5: 9af6771e6c251e7341de69ba27c0e67f
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 8, 2010
wciicaptssd.exe File name: wciicaptssd.exe
Size: 269.31 KB (269312 bytes)
MD5: 2bdffd2b36369d979a28f462c870c040
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 8, 2010

Related Posts

10 Comments

  • chet WINTERS says:

    WILL I BE ABLE TO RUN THE MALWARE SCANNER DOWN TO A CD AND RUN IT OR CAN I BUY THE PROGRAM. THANKS - I HAVE BEEN INFECTED BY THE ANTIVIRUS SUITE. THANKS

  • Andy says:

    What a saviour you are. Thank you.

  • nico says:

    Merci pour cette aide que j'ai suivi à la lettre.

    J'ai supprimé ce virus de mon PC

    Thanks a lot.

    Nico

  • John Williams says:

    I caught this nasty little infection probably from a (legal ?) film download site, which I have used several times before without problems.

    I was getting several different alarming-looking popups a minute (the bad English was a dead giveaway!) and my browser was redirected to a porn site. Certain programmes such as AVG and Task Manager would not launch.

    Before being able to follow your instructions (which I had open on my uninfected laptop), I had to reboot the infected computer and quickly launch Task Manager before the virus fired up, then kill the very obvious unwanted processes. It screamed warnings at me all the time I was doing this. However, the processes were stopped and this gave me the necessary breathing space.

    The infected files and registry entries were exactly as stated. I followed your instructions to the letter and the infection now appears to be cured. No need to download any extra software, as other sites were suggesting. The whole operation took 15 to 20 minutes. Many many thanks!

    PS. Neither AVG nor Spybot prevented this infection from taking hold.

  • Ernesto Rivera says:

    as much as I Hate to accept being taken I am one more of the Statistics that unfortunatelly we are victims, In my case happened exactly as descrived above by this page. But I hope this teaches me and some others reading this coment, most likely a cry outloud of greeff or hurt, and hopefully no body else would try that site. as far as the money goes, money comes. hope they can buy toillete paper. to clean the mess they\'re doing right now, and. Ice to cool down their butts when they get to hell. FROM THE BOTTOM OF MY HEART, HELL FOR THOSE WHO DESERVE IT.

  • Dee says:

    THANK YOU
    WHAT A PAIN IN THE A** THIS FRICKING PROGRAM WAS. BUT ITS GONE

    THANK YOU THANK YOU

  • patrick douglass says:

    Ihad AVS software it FAILED miserable and I got a nasty virus and had to set computer to factory settings and re load everything, i stayed up all night to accomplish this. I dont think AVS will be in business for long I reported then to severat sources including the trade commision,BBB.and put the word out on the net and asked all to pass it on, my son in minnesota got it in 24 hours and he is 2000 miles away, oh the word of mouth travels at the speed of sound

  • patrick douglass says:

    lost your download due to total reload to factory settings

  • jeff says:

    Oh, about forgot. This PIECE OF JUNK software CYBER DEFENDER I had installed let the virus right in the front door. After it started running it installed 199!!!! other programs (viruses) The Cyber Defencer software DID NOTHING to stop it!!!!

    I called them and they wanted $400 to remove the virus. WHAT A SCAM Cyber Defencer is. I thought I was protected, but they just let you get infected so they can try to charge you MORE to remove the virus.

    Stay AWAY from Cyber Defender,
    Jeff

  • Yuderca says:

    I have been charged 78.52 for semhtoing that I don't have installed on my computer. My billing statement has a partial number on it and need someone to help me find out whats going on with this. My statement reads as follows: PWRANTIVIRUS # 18002207 RIGA GA what is this and help direct me in the right direction. Thanks

Loading...