Antivirus 2009 is considered as one of the widely spread and most successful rogue antivirus application that infects vast number computers around the world. It disguises as a a security program but crated primarily to sell the rogue security product by using unfair method of fake scanning to assure the victim of its importance.

Aliases:
Antivirus2009

Risk Level: Medium

File Size: Varies

Affected System: Windows

Common Symptoms:
1. Presence of the following Antivirus 2009 Files:
c:\WINDOWS\system32\ieupdates.exe
c:\WINDOWS\system32\scui.cpl
c:\WINDOWS\system32\winsrc.dll

c:\Program Files\Antivirus 2009
c:\Program Files\Antivirus 2009\av2009.exe
%UserProfile%\Desktop\Antivirus 2009.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\S96PZM7V\winsrc[1].dll
%UserProfile%\Start Menu\Antivirus 2009
%UserProfile%\Start Menu\Antivirus 2009\Antivirus 2009.lnk
%UserProfile%\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk

2. Presence of Windows Registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion \Run “75319611769193918898704537500611″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion \Run “ieupdate”  
HKEY_CURRENT_USER\Software \75319611769193918898704537500611
HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{037C7B8A-151A-49E6-BAED-CC05FCB50328}

3. Web browser can be redirected to the following sites and downloads the malware:

  • freeonlinescanner9.com
  • vassariumbig.com
  • securedownloadcenter.com

4. Issues fake alert from scanning done by Antivirus 2009 and display malware presence and prompts to register the program.