Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Trojan.Fake.AV (Antivirus Security Pro)




Antivirus Security Pro

Descr. Added:

October 9, 2013







At risk systems:

Windows 95/98/ME/XP/NT/2003



Malware problems?   We can help.  Free Removal Tools.





When Trojan.FakeAV.gen is executed, it performs the following activities:

It installs the fake security application “Antivirus Security Pro”.

Thirtyseven4 Detects and Removes Antivirus Pro Security

Once installed, it will display a fake alert showing that the system is badly infected.

Thirtyseven4 Detects and Removes Antivirus Pro Security

Thirtyseven4 Detects and Removes Antivirus Pro Security

It will then connect to the Internet and drop the following files:


The [random_name].exe is the roguewares main file which is responsible for generating the fake alerts, etc.
The "serv.bat" file is a batch file containing the registry entries pertaining to the dropped files:
"reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon"
/v Userinit /t REG_SZ /d

"C:\WINDOWS\system32\userinit.exe,,C:\Documents and Settings\All Users\Application Data\nhXgV333\nhXgV333.exe -sm," /f"

Due to the above registry entries the malware gets re-launched after each restart.

Thirtyseven4 customers are fully protected against this malware. Thirtyseven4 also has proactive detection for this type of rogueware within the Memory scan, the GUI Scanner, Online Protection, and Native Scan.  In addition, we have the path based detection as well.


Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4