Home Malware Programs Rogue Anti-Spyware Programs Security Antivirus

Security Antivirus

Posted: February 10, 2010

Threat Metric

Threat Level: 10/10
Infected PCs: 94
First Seen: February 12, 2010
Last Seen: November 16, 2022
OS(es) Affected: Windows

ScreenshotSecurity Antivirus is a rogue anti-virus program that, like its clones from the FakeVimes family can't do anything to provide security to your computer, even though their names suggest that they are real. Security Antivirus gains access the compromised computer with the help of Trojans and corrupt video codecs. Once active, Security Antivirus installs itself and changes the system registry to start automatically each time Windows launches. Security Antivirus runs a fake system scan of your computer, which produces false results to scare you into purchasing a useless rogue spyware remover. It is advisable to have Security Antivirus removed with a proven anti-virus program.

ScreenshotScreenshotScreenshotScreenshotScreenshotScreenshot

Aliases

Trojan.Win32.Generic.pak!cobra [Sunbelt]Suspicious.Insight [Symantec]Mal/Basine-C [Sophos]Win32:MalOb-AJ [Avast]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



SA4a49.exe File name: SA4a49.exe
Size: 5.79 MB (5795328 bytes)
MD5: b98e89110489b97ebed4ba963f883fed
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 1, 2010
SA2453.exe File name: SA2453.exe
Size: 2.46 MB (2467840 bytes)
MD5: 8ec80692588ca8f643708eeacea4a8f4
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 2, 2010
SA2bae.exe File name: SA2bae.exe
Size: 2.35 MB (2358272 bytes)
MD5: fba23ee09c325e009562481a7f685e22
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 2, 2010
SA4cbc.exe File name: SA4cbc.exe
Size: 2.35 MB (2359808 bytes)
MD5: cd73a2c099b170a9c7652e191ca1728d
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 2, 2010
SA1963.exe File name: SA1963.exe
Size: 2.49 MB (2494464 bytes)
MD5: 247c1d5c4df9b85cf57c0be512abcc5f
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 2, 2010
SA9ccf.exe File name: SA9ccf.exe
Size: 2.65 MB (2650624 bytes)
MD5: ab02c298a81e16446f20d99dfb41befe
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 23, 2010
SA9345.exe File name: SA9345.exe
Size: 2.58 MB (2587648 bytes)
MD5: d8ebb6106730d0bfabd33ef4257a63e6
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2010
SAbfb1.exe File name: SAbfb1.exe
Size: 2.6 MB (2601472 bytes)
MD5: 4a6e18ab36efde5a6d4ab061e4d04f60
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 19, 2010
SA6e27.exe File name: SA6e27.exe
Size: 2.59 MB (2595328 bytes)
MD5: 270b56738ce2f61a01ad7a88d01a070e
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 19, 2010
SA07f9.exe File name: SA07f9.exe
Size: 3.05 MB (3057152 bytes)
MD5: 6853155684c6cd42170b5462e39c5f0c
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 1, 2020

Registry Modifications

The following newly produced Registry Values are:

File name without pathSecurity Antivirus.lnk

Additional Information

The following directories were created:
%AppData%\Security Antivirus

Related Posts

5 Comments

  • Peter Guild says:

    Attempts to install McAfee Antivirus, etc. claims that Security Antivirus is installed. However, I have follwed instructions to remove Security Antivirus.

  • Ferid says:

    This doesn't work, please help, this is so nasty spyware.
    Program changed apperance and is somewhere else in pc.
    Please help

  • C.J. says:

    My computer was infected by Securty Antivirus on 3/1/10. Following your instruction above. I was able to get the computer back to work for two days. But, suddenly Internet Explore stop working. The top command line "File, Edit..., tooling" will not show up. Click on "X" will not close it. Tried to reinstall Internet Explore, and Foxfire, the same problem persists. I see your instruction was posted on 2/10/2010. Do you have an updated version on how to completely clean out this virus. I tried to install McAfee, it did give me a warning during installation that Security Antivurus exist and may interfere with McAfee virus scan. I had to skip the warning to install. After installation, McAfee can not find any virus.

    Thanks in advance!

  • Chuck Whittemore says:

    please cancel McAfee security with Verizon

  • Dakota Gillin says:

    I tried all above deletes. I found hotfix.exe and removed it but I was still getting this pop up and was blocked from internet and other functions on my computer. I then did a restore and Wala everything is back to normal now. Easy fix and should have done this first.

Loading...