Home
/
Spyware Encyclopedia
/ Fake Anti Spyware.WistaAntivirus
Fake Anti Spyware.WistaAntivirus Technical Details
Category
Fake Anti Spyware
Discovered
7/7/2008 15:49:00 PM
Modified
7/7/2008 17:34:00 PM
Threat Level
Critical
Description
WistaAntivirus is a Fake Anti Spyware program. WistaAntivirus displays the misleading result after scanning by it. WistaAntivirus display fake security messages. WistaAntivirus is a fake spyware remover and a clone of WinDefender 2008. This parasite uses Trojans, such as Zlob and Vundo, to enter the system.
Summary
The hosts file was updated with the following url-to-ip mappings :
n/a
The following http urls were started :
www.wista-antivirus.com
Generated smtp traffic :
n/a
There was a new connection established with a remote IRC Server :
n/a
The Following Hidden Entries Created :
n/a
The following internet connection was established:
85.255.118.107:80
Processes
Wistaantivirus.exe
Drivers
N/A
Folders created
%PFDIR%\WistaAntivirus
%COMMON_PROGRAMS%\WistaAntivirus
Browsed Sites
Wista-Antivirus.com
When the Fake Anti Spyware is executed, it creates the following files:
Name
Version
Publisher
Signature (MD5)
File Size (in Bytes)
..\quick launch \wistaantivirus.lnk
612
..\dll\antirootkit.sys
18cfec0b4c874e2b9b34a8e1fad65ecb
252688
..\dll\loader.sys
a4fe777063811a6cfbe765a0bc4ef2c6
354416
..\dll\realscanner.dll
efb37d09d006be2e3175627eb4e2a906
272240
..\wistaantivirus \wistaantivirus.exe
9bc5bfa9af5d94566f594e811b87ed72
143360
..\setup_en.exe
1.0.0.0
Wista-Antivirus
ef8aa89c0b30d6e0376148ce1e821cc8
3107242
..\desktop\wistaantivirus.lnk
594
When the Fake Anti Spyware is executed, it creates the following Registry entries:
•
..\software\microsoft\windows\currentversion\run\"wistaantivirus"
•
..\software\wistaantivirus
•
..\software\microsoft\windows\currentversion\uninstall\wista antivirus_is1
Snapshot
Recommendation to remove Fake Anti Spyware.WistaAntivirus
Spyware Detector can remove Fake Anti Spyware.WistaAntivirus, and thousands of other Spyware definitions, automatically and instantly.
Click here
to download Spyware Detector and scan for free.
Personalized e-Mail support
by our Research Team. You send an "Export Log" report to us, we then add new definition and you eliminate spyware found on YOUR PC in the next Live Update. So, not only do you benefit but the whole community enjoys the feedback.
Speed up your computer
and increase browsing performance by deleting Spyware & Adware
Enjoy continuous protection and security with
frequent spyware definition updates
so you never have to worry about new threats and outdated software.
Surf the web with confidence
knowing your online activities aren't being tracked, and your
confidential data is secure
from prying eyes.
Search Threats
Testimonials
Read More
Information Desk
Spyware & Adware Categories we scan
List of Spyware &
Adware we remove
Submit a Threat
Submit a threat to be reviewed by our research team
Submit a Threat
Home
|
About Us
|
Purchase
|
Contact Us
|
FAQ
|
Privacy Policy