FakeScanti
Posted: November 30, 2010
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Threat Level: | 10/10 |
|---|---|
| Infected PCs: | 6,642 |
| First Seen: | November 30, 2010 |
|---|---|
| Last Seen: | January 10, 2022 |
| OS(es) Affected: | Windows |
FakeScanti is a label that's used for a subgroup of rogue anti-virus programs that include variants such as AV Security 2012, AV Protection Online and Security Guard 2012. Like other types of rogue AV programs, FakeScanti products will create fake infection warnings as an excuse to request money in exchange for getting rid of these fictitious infections. Advanced versions of FakeScanti can rewrite their own files to avoid deletion, can change your desktop image, will block a variety of programs from the Windows Registry and can even create pop-ups. Since FakeScanti scamware will create a convincing illusion of being a security program, you should use real security programs that you trust, to find and remove FakeScanti infections from your PC. Above all else, SpywareRemove.com malware experts advise against spending money on any FakeScanti product.
The Carefully-Crafted Illusion of FakeScanti's Antivirus Features
FakeScanti isn't the name that's used by any one of FakeScanti's products, but rather, a label that real security programs use to identify rogue security programs from the FakeScanti family. This family of rogue anti-virus programs typically is installed by a Trojan:Win32/FakeScanti, a Trojan that specializes in installing rogue anti-virus applications from the FakeScanti gang. Although the installation process may not show any major symptoms, the presence of a FakeScanti rogue anti-virus application on your PC will exhibit many types highly-visible signs, such as:
- Locking your desktop to an error message that resembles the following example. (This behavior is exclusive to younger versions of FakeScanti.)
DANGER!!!
Your computer is INFECTED!
Attention!!!
Such infection will cause permanent loss of all information stored on your computer: documents, files, etc.
All your secret data like logins, passwords, credit card information can be accessed by third-parties for malicious purposes.
All your online activities like sending e-mails, visiting web-sites are logged and stored on your hard disk.
Spyware blocks the deletion of such information from your computer and makes your online actions traceable.PROTECT YOURSELF!
DELETE SPYWARE FROM YOUR COMPUTER RIGHT NOW! - Creating error messages that alert you about infections and other hard drive problems that don't really exist. Samples include:
Security Warning
Your computer continues to be infected with harmful viruses. In order to prevent permanent loss of your information and credit card data theft please activate your antivirus software. Click here to enable protection.Warning: Infection is Detected
Windows has found spyware infection on your computer!
Click here to update your Windows antivirus software...svchost.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
- Blocked access to .exe files, with the exception of files that have been explicitly-allowed by FakeScanti, such as basic Windows processes and malicious software processes. This often creates the fake error message noted below:
This application has failed to start because the application configuration is incorrect. Reinstalling the application may fix this problem.
- Random system restarts.
- Blocked websites. When you attempt to visit a blocked site, FakeScanti will create an error pop-up that tries to convince you that the website is harmful and then ask you to activate FakeScant's rogue AV product:
[Rogue anti-virus program name] has denied Internet access of the program.
Internet Explorer is possibly injected with [Random infection name]. This worm attempts to send your personal information to remote host through Internet Explorer.
FakeScanti products, which can include (but aren't limited to) AKM Antivirus 2010 Pro, BlueFlare Antivirus, Milestone Antivirus, OpenCloud Antivirus, Sysinternals Antivirus, Windows Antivirus Pro, Windows Police PRO, XJR Antivirus and Your PC Protector, are incapable of detecting or curing infections or other forms of system problems. In fact, SpywareRemove.com malware researchers have found that all variants of FakeScanti are only interested in creating fake warning messages as part of a cry wolf scam to steal your money.
Teaching FakeScanti a Lesson in Real PC Security
Although FakeScanti uses many names to conceal FakeScanti's actual nature as a rogue anti-virus program, all FakeScanti infections are roughly identical and can be removed by similar methods. SpywareRemove.com malware research team suggests Safe Mode for disabling FakeScanti to begin with; this lets you access any websites or programs that FakeScanti may have blocked.
Once FakeScanti is no longer active, system scans with suitable anti-malware programs can remove all FakeScanti components, including FakeScanti's dropper Trojan and Registry entries. Trying to remove these components by yourself isn't recommended unless no other options are open, since FakeScanti, as previously noted, can adjust FakeScanti's files to evade removal attempts.
Automatic Malware Detection Tool (Recommended)
<!--
document.write('
');
-->
<!--
document.write('
');
-->
Aliases
More aliases (1585)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%SystemDrive%\Users\<username>\AppData\Roaming\firefox.exe
File name: firefox.exeSize: 2.4 MB (2405888 bytes)
MD5: 12c269bc2b30d0a54bee59de6aba861a
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: January 14, 2013
%WINDIR%\SysWOW64\w666dWWK7fR9gXq.exe
File name: w666dWWK7fR9gXq.exeSize: 1.78 MB (1783296 bytes)
MD5: 50378c840a7009237a0c6f37b9bcce1c
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: November 10, 2011
%APPDATA%\rc1v2npH5Q7EXjV\rtPNycc1uD2b.exe
File name: rtPNycc1uD2b.exeSize: 1.77 MB (1775616 bytes)
MD5: 49bd1616bd849becef61feeda6b76c5b
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\rc1v2npH5Q7EXjV
Group: Malware file
Last Updated: November 10, 2011
%USERPROFILE%\Application Data\chrome.exe
File name: chrome.exeSize: 2.78 MB (2788352 bytes)
MD5: 8c348da2e1cb2660a9b003959fddd879
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: December 1, 2011
%APPDATA%\KkVrrcv4JZOiH8Z\ChhYXjUelBm5Q6E.exe
File name: ChhYXjUelBm5Q6E.exeSize: 1.78 MB (1781248 bytes)
MD5: 7b954ddfb6ba079a187548c94e5875de
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\KkVrrcv4JZOiH8Z
Group: Malware file
Last Updated: December 1, 2011
%WINDIR%\SysWOW64\System Security 2012v121.exe
File name: System Security 2012v121.exeSize: 1.67 MB (1671168 bytes)
MD5: 62da658bc50408e0e2f0df78fcf4e65e
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: November 14, 2011
%WINDIR%\SysWOW64\GIIBBrzPNyxA1.exe
File name: GIIBBrzPNyxA1.exeSize: 1.77 MB (1771008 bytes)
MD5: 7f503c78051f544da53d7f2622ec356c
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: January 10, 2012
%WINDIR%\system32\AV Protection 2011v121.exe
File name: AV Protection 2011v121.exeSize: 2.83 MB (2838016 bytes)
MD5: 0ba46d1839c0b8fa0236df2e0ea233ac
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 6, 2011
%WINDIR%\system32\Cloud AV 2012v121.exe
File name: Cloud AV 2012v121.exeSize: 2.04 MB (2044928 bytes)
MD5: 41096615e6206b00f9206caf5307ba6a
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 10, 2012
%APPDATA%\bZ99hhTXwjU\ZCCeelIIBrPNyA1.exe
File name: ZCCeelIIBrPNyA1.exeSize: 1.77 MB (1777664 bytes)
MD5: fe8c7ca516a0f4b514e9af50e5236186
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\bZ99hhTXwjU
Group: Malware file
Last Updated: January 30, 2012
%USERPROFILE%\Local Settings\Application Data\atm.exe
File name: atm.exeSize: 328.7 KB (328704 bytes)
MD5: f126ed56bc868c1a941e9e016bc731ab
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 12, 2011
%APPDATA%\damHW7dd8gRZqYw\OkUUVVelOBtz0.exe
File name: OkUUVVelOBtz0.exeSize: 1.76 MB (1766912 bytes)
MD5: 7e6f13016f72c8d1a153aeff2397d95c
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\damHW7dd8gRZqYw
Group: Malware file
Last Updated: November 28, 2011
%ALLUSERSPROFILE%\Application Data\MgKPyEORiQUvGj.exe
File name: MgKPyEORiQUvGj.exeSize: 400.88 KB (400880 bytes)
MD5: 75569ee34b3f47d54ad394adee6bf49d
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: January 10, 2022
%APPDATA%\Microsoft\A2B5\5DEB.exe
File name: 5DEB.exeSize: 1.91 MB (1915904 bytes)
MD5: 9d39d69135b8331f7c26a0e915bbd560
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\A2B5
Group: Malware file
Last Updated: November 23, 2011
%USERPROFILE%\Application Data\iexplore.exe
File name: iexplore.exeSize: 2.94 MB (2947584 bytes)
MD5: 670d36e7d3ae3d08c48a602ab4a72406
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Application Data
Group: Malware file
Last Updated: April 2, 2013
%WINDIR%\system32\oYCekIBrzNx1v2b.exe
File name: oYCekIBrzNx1v2b.exeSize: 1.78 MB (1788416 bytes)
MD5: 7934e9f3aab3afec9f8cb62fb8fb65cd
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 11, 2011
%APPDATA%\RHH66sWK7fE\VLTqjCkrtxP0cSi.exe
File name: VLTqjCkrtxP0cSi.exeSize: 1.77 MB (1777664 bytes)
MD5: c9b6ceb5cb37c9e50f96bb874ab9da35
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\RHH66sWK7fE
Group: Malware file
Last Updated: November 8, 2011
%APPDATA%\PTypTOiKk0D7U1d\QvKV26hz3LzSG7.exe
File name: QvKV26hz3LzSG7.exeSize: 1.78 MB (1783296 bytes)
MD5: e33568879f72b497307ef82c93647b24
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\PTypTOiKk0D7U1d
Group: Malware file
Last Updated: November 8, 2011
%WINDIR%\system32\CcccS2ibbDpnGa.exe
File name: CcccS2ibbDpnGa.exeSize: 1.78 MB (1788416 bytes)
MD5: bdb279078dae6d0661b2745c88988f85
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 10, 2011
%WINDIR%\system32\LNNNtxxA0uc2iF3.exe
File name: LNNNtxxA0uc2iF3.exeSize: 2.62 MB (2620928 bytes)
MD5: bf424f39001aa8b862548c275bed661b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 10, 2011
%APPDATA%\KQsKEgqCIrNPc\AV Security 2012v121.exe
File name: AV Security 2012v121.exeSize: 2.87 MB (2876928 bytes)
MD5: 7ed1f503b6b9105fad511af65f16cf15
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\KQsKEgqCIrNPc
Group: Malware file
Last Updated: November 21, 2011
%USERPROFILE%\Local Settings\Application Data\tvq.exe
File name: tvq.exeSize: 324.09 KB (324096 bytes)
MD5: e5b10e4f60bc6005191d0ea509daaa2a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: December 12, 2011
More files
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.