Home Malware Programs Trojans Antivirus XP

Antivirus XP

Posted: July 8, 2008

Threat Metric

Threat Level: 9/10
Infected PCs: 81
First Seen: July 24, 2009
OS(es) Affected: Windows

Antivirus XP, also known as AntivirusXP, is a rogue anti-spyware program that uses false spyware results to urge you to download Antivirus XP's full commercial version. Antivirus XP, as a member of the family is a clone of various other fake security tools such as

Antivirus XP may be downloaded and installed onto your computer via a Zlob Codec installer found on adult websites. Once Zlob is installed, it will prompt pop ups disguised as system notifications that lead to websites with rogue anti-spyware programs. Antivirus XP will also run a scan of your computer, and will then offer you to remove the parasites found with the purchase of the full Antivirus XP version. It is recommended not to click on any link provided by Antivirus XP.

Aliases

Cryp_FakeAV-2 [TrendMicro]Mal/FakeAV-B [Sophos]Adware/RogueAntimalware2009 [Panda]a variant of Win32/Kryptik.J [NOD32]Trojan.Win32.Malware.1 [K7AntiVirus]Virus.Win32.AdWare [Ikarus]Trojan.Win32.Monder.hjn [F-Secure]Win32/AMalum.DDVC [eTrust-Vet]Win32.Monder.hjn [eSafe]Trojan.Packed.600 [DrWeb]TrojWare.Win32.Monder.hjn [Comodo]Trojan.Monder.hjn [CAT-QuickHeal]Adware.XpAntivirus.AJ [BitDefender]Win32:Adware-gen [Avast]W32/FakeAV2008.AJ [Authentium]
More aliases (104)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



rhc13bj0e73j.exe File name: rhc13bj0e73j.exe
Size: 831.48 KB (831488 bytes)
MD5: f1692980a3ab58a22b33442cfd8f9c23
Detection count: 99
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
.tt89.tmp File name: .tt89.tmp
Size: 1.58 MB (1589014 bytes)
MD5: 626018abdf88b5134601723c9b6bde47
Detection count: 73
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
Last Updated: December 11, 2009
.tt7.tmp.exe File name: .tt7.tmp.exe
Size: 1.6 MB (1603919 bytes)
MD5: 07a690fe30506a1a1a4e4f997d044dd4
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
.tt5E.tmp.exe File name: .tt5E.tmp.exe
Size: 1.6 MB (1606431 bytes)
MD5: 0ac13469fe7054790800fd8e24d8c5df
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
rhcn7cj0ea59.exe File name: rhcn7cj0ea59.exe
Size: 831.48 KB (831488 bytes)
MD5: d7e1aa26666abea15e948da2c2d57452
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Related Posts

5 Comments

  • paul g says:

    what if it has taken command of the desk top and you can not get to the internet to download the removal program

  • Thomas Tran says:

    Is it normal for this thing to disable options in your Display configurations? It made the Desktop and Screen Saver tabs disappear on mine.

  • Josh says:

    I have found they have now mutated this software and it now hides in a directory on my machine titled "rhclp3j0etec" and the proccess in task manageer is entiled the same.

  • Rew says:

    I used Spyware recomended here, downloaded it and it detected the files and suposedly took it off the computer. However its still in my bottom ar with a pop-up telling me to download the software. I can not find it anywhere on my computer, and it is taking over my ability to search on my computer. It continues to be a problem for me. Also does any one know how to get rid of Microsfts Security Alerts and that systeym as well? It cam pre-loaded onto my computer, and I want to use only one spyware and not need to buy more than one service, Microsoft wants me to purchase another year or two of protection, and that one keeps poping up as well, though it's turned off.

    Need help!

  • Annie Mayers says:

    This antivirus has changed my background, desktop icons, blocked system restore and more importantly I cannot access any internet sites to get help as it redirects them. Using library computer for information as a first step to get rid of this obnoxious con

Loading...