TROJ_FAKEAV.HUU
Posted: June 28, 2012
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Threat Level: | 9/10 |
|---|---|
| Infected PCs: | 27 |
| First Seen: | June 28, 2012 |
|---|---|
| OS(es) Affected: | Windows |
TROJ_FAKEAV.HUU is a Winwebsec-derived rogue anti-malware program, and like other Winwebsec scamware, TROJ_FAKEAV.HUU uses fake security information to convince you to purchase its software (although even TROJ_FAKEAV.HUU's purchase form is fake). While TROJ_FAKEAV.HUU's family members have been found to be distributed in multiple ways, including via e-mail spam, SpywareRemove.com malware analysts have found at least sports copycat site that's distributing TROJ_FAKEAV.HUU along with several other PC threats. Accordingly, anti-malware scans after any exposure to fake sports sites should be a common-sense precaution, and until TROJ_FAKEAV.HUU is removed, it's especially recommended for you to ignore TROJ_FAKEAV.HUU's fraudulent system scans, pop-ups and other means of displaying fake security data.
TROJ_FAKEAV.HUU: the Fake Fan in Your Virtual Soccer Stadium
TROJ_FAKEAV.HUU's current distribution method, although hardly unique to TROJ_FAKEAV.HUU, is a fake sports site that imitates the format of the official UEFA (a promotional organization for the sport of soccer, or as Europe knows it, football) site. This malicious site, [censored]uro2012.com, has been confirmed to use advertisement trackers and phishing surveys, and may also utilize browser exploits to install TROJ_FAKEAV.HUU and similar PC threats automatically. TROJ_FAKEAV.HUU, itself, AKA Security Shield, is a member of WinWebSec, a classification of rogue anti-malware programs that also counts System Tool, Security Sphere 2012, Security Tool, Winweb Security, Smart Protection 2012 and Live Security Platinum amongst its members.
Symptoms that you should anticipate with any TROJ_FAKEAV.HUU infection include:
- Blocked applications, particularly web browsers like Firefox or Internet Explorer. TROJ_FAKEAV.HUU may also display a fake firewall pop-up (that claims that a Trojan has infected the program) while TROJ_FAKEAV.HUU blocks these applications. However, non-web browser programs are also vulnerable to being blocked by TROJ_FAKEAV.HUU.
- Fake system alerts and warning messages that appear at random, as well as when you try to launch a TROJ_FAKEAV.HUU-blocked application.
- Fake system scans by TROJ_FAKEAV.HUU, which launches automatically and refuses to be turned off.
- Phishing attacks that take the form of purchase requests for Security Shield. This form serves no purpose except to steal financial information and other types of confidential data, and SpywareRemove.com malware analysts especially discourage spending money on any member of Winwebsec, including TROJ_FAKEAV.HUU.
Getting Rid of an Imposter of PC Security with a Legitimate Alternative
If you've visited a site like the one described earlier in this article, or otherwise have any reason to suspect that your PC has been compromised by TROJ_FAKEAV.HUU, a hasty and thorough disinfection is crucial for your PC's safety. Once unblocked, any updated and competent anti-malware program should be able to identify and remove TROJ_FAKEAV.HUU, which may also be detected by the following aliases:
- Win32/Adware.SecurityTool
- SecurityShieldFraud
- Trojan.Win32.FakeAV.wly
- Rogue:Win32/Winwebsec
- FakeAlert-AVPSec.k
- TROJ_FAKEAV.BKC
Besides TROJ_FAKEAV.HUU, [censored]uro2012.com also distributes TROJ_DLOADR.BGV, a Trojan downloader that installs the spyware Trojan TSPY_ZBOT.JMO, which is capable of stealing highly-confidential information from your PC.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:fas.exe
File name: fas.exeSize: 344.82 KB (344824 bytes)
MD5: bf66fb05004853b99a9e2712a7b25284
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 29, 2012
t.exe
File name: t.exeSize: 304.64 KB (304640 bytes)
MD5: cc55d20a32bfeb0693b92e000368b655
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 29, 2012
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.