Home Malware Programs Rogue Anti-Virus Programs BitMefender

BitMefender

Posted: January 23, 2014

Threat Metric

Ranking: 5,476
Threat Level: 1/10
Infected PCs: 10,853
First Seen: January 23, 2014
Last Seen: March 2, 2025
OS(es) Affected: Windows


BitMefender is a rogue anti-virus program of an as-of-yet undetermined family. Scamware like BitMefender make their bread and butter off of fake infection warnings and imitative system scans without any basis in reality, but BitMefender also may conduct other attacks on your PC, including redirecting your browser, blocking other programs, installing additional threats or mining Bitcoins. As malware researchers continue to identify more risks associated with BitMefender, you should use strong anti-malware defenses to block BitMefender's known distribution methods (as noted in this article) and, if it's required, remove BitMefender safely.

A Court Notice to Infect Your Computer

BitMefender is a traditional scamware product that's designed to resemble a normal anti-virus scanner, but BitMefender's scans turn up fake entries, and BitMefender isn't equipped with a real database for identifying any kind of legitimate PC threats. Unlike older variants of similar fake software than BitMefender, BitMefender only came to the eyes of malware researchers in early 2014, through attacks that appear to be using spam e-mail attachments to install BitMefender. BitMefender's installer is disguised as a fake Word document that's named with the appearance of a 'court notice' for cities like St Louis or Kansas City. Currently, it's unknown if these attacks are targeting individuals within specific regions, or are being distributed without any discrimination.

Although its fake anti-virus features are its primary symptoms, BitMefender also may be identified through related issues, such as additional memory processes and an excessive use of system RAM (which may worsen over time, thus causing performance problems). The latter may indicate that BitMefender is performing Bitcoin mining functions or other attacks that could cause long term damage to your computer if they're ignored. Depending on your PC's available memory, malware experts find that you may suffer from system slowdowns, crashes and other performance problems.

Defending Your Own Computer Against Threats in Sheep's Clothing

BitMefender may take its name from the popular Bitdefender product, but BitMefender has neither the features, nor the reputation of that program, and never should be considered anything like a real PC security program. Malware researchers weren't particularly surprised to note that BitMefender includes some basic self-defense mechanisms, such as reactivating itself after its main memory processes have been terminated. Considering these obstacles, deleting BitMefender with a strong anti-malware product and appropriate PC security strategies should be attempted before any manual removal efforts are made.

BitMefender's current distribution strategy of using spam e-mail and fake documents for installation can be blocked by similar anti-malware programs, and malware researchers have verified that most PC security products have a good record for identifying BitMefender. However, BitMefender may be identified by aliases indicative of a variety of PC threats, such as TrojanDownloader.Kuluoz, W32/Zbot.FG!tr or Trojan/Win32.Dofoil, not all of which are necessarily accurate. Updating your security software will let them access the most relevant database entries for the accurate detection of BitMefender and threatening files related to BitMefender.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Start Menu\Programs\BitMefender\ File name: %UserProfile%\Start Menu\Programs\BitMefender\
Group: Malware file
%UserProfile%\Desktop\BitMefender.lnk File name: %UserProfile%\Desktop\BitMefender.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Programs\BitMefender\BitMefender.lnk File name: %UserProfile%\Start Menu\Programs\BitMefender\BitMefender.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Programs\BitMefender\Uninstall BitMefender.lnk File name: %UserProfile%\Start Menu\Programs\BitMefender\Uninstall BitMefender.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPPHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpUXSrv.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe

Additional Information

The following messages's were detected:
# Message
1“Warning! Running Trial version
The security of your computer has been compromised!
Now running trial version of the software!
Click here to purchase the full version of the software and get full protection for your PC!
“System Security Alert”
Vulnerabilities found
Background scan for security breaches has been finished. Serious problems have been detected. Safeguard your system against exploits and malware right now by activating antivirus tool.
“Attention”
Suspicious activity is detected on your computer.
Please activate antivirus software for details.

Loading...