Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

ROGUE.XPSECURITY2012

 

 

 

Name:

Rogue.XPSecurity2012

Added:

August 22, 2011

Type:

Fraudtool

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When Rogue.XPSecurity2012 is executed, it performs the following activities:

It runs as the polymorphic security software "XP Security 2012". It is configured to run automatically whenever the computer starts. It will run a quick scan of your computer and post misleading messages stating that there are malware infections and these infections can only be removed after you purchase a full version of the software.

It also injects its own entry in the Windows Security center under Virus Protection (as shown in the screenshot):

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware


It drops the following files:

%userprofile%\Local Settings\Application Data\[random_name].exe

It creates/modifies the following registry entries:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
"1653478294"="C:\\Documents and Settings\\[user account]\\Local Settings\\Application Data\\[3 digit random character].exe"

A screenshot of XP Security 2012 is shown below:

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4