Home Malware Programs Rogue Anti-Spyware Programs VirusFighter

VirusFighter

Posted: December 12, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 16
First Seen: December 12, 2011
Last Seen: February 15, 2022
OS(es) Affected: Windows

VirusFighter (also known as VIRUSFighter Pro, VIRUSFighter or Virus Fighter) is a rogue anti-virus program that displays fake virus alerts and other forms of fraudulent system information instead of providing actual anti-virus functions. SpywareRemove.com malware research team has found that VirusFighter has been distributed throughout several websites that claim that VirusFighter is a genuine AV product; these sites may also attempt to install VirusFighter or a related type of PC threat (such as a dropper Trojan) by using browser exploits. If you find VirusFighter on your PC, don't attempt to remove VirusFighter by manual methods, since VirusFighter has been confirmed to survive standard deletion techniques. However, a competent anti-malware product can remove VirusFighter and all of its hidden components without any danger for your PC.

VirusFighter – Fighting for Your Attention with Trojan Assistance

In most cases, a VirusFighter infection will only occur after you've visited a scamware website or been infected by a Trojan that specializes in installing rogue AV programs like VirusFighter. Some websites that SpywareRemove.com malware analysts have confirmed to distribute VirusFighter (as well as other types of PC threats such as TR/Dropper.FakeAlert) include qweas.com, soft82.com and subdomains of smartcode.com. Avoiding all of these sites is critical to protecting your PC from VirusFighter since even a brief visit may result in drive-by-download attacks that install VirusFighter without your permission.

Other means of preventing VirusFighter-related attacks against your PC include:

  • Keeping your web browser up-to-date to reduce security flaws (although zero-day security holes are still possible).
  • Using an unpopular web browser that isn't targeted by common exploits and attacks.
  • Using strong security settings for your web browser (such as disabling scripts for strange websites).
  • Keeping an up-to-date anti-malware program to detect VirusFighter-related attacks as they occur.

What Makes VirusFighter More of a Fight for Your Own Computer's Survival

Once VirusFighter is installed, VirusFighter will engage in some of the standard attacks that rogue AV products are known to use, such as creating fake infection alerts and inaccurate system scans. VirusFighter and related PC threats may also attempt to redirect your web browser to harmful web sites or block your security software. Because VirusFighter launches itself as a background process even if VirusFighter appears to be removed from your installed programs list, SpywareRemove.com malware researchers recommend that you use a suitable anti-malware product to remove VirusFighter from your computer.

Any system scan to remove VirusFighter should also be complete enough to detect and remove related PC threats such as dropper Trojans, since there is a high probability of other forms of hostile software also being present. However, as long as you do this promptly and avoid any attempt to purchase VirusFighter, your computer should be unharmed by a temporary VirusFighter infection in the long term.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



mozcrt19.dll File name: mozcrt19.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
sqlite3.dll File name: sqlite3.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
unins000.exe File name: unins000.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
VDoca582.exe File name: VDoca582.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusFighterHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "URVDoc[]"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Doctor"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virus Doctor_is1
Loading...