Thursday, April 9, 2009

Antivirus XP Pro 2009

Antivirus XP Pro 2009 is a fake security software (rogue). It displays fake alerts and detects fake infections on the system. AntivirusXPPro2009 is from the same family as Renus 2008

A real malware modifies the desktop (desktop hijack) and promote the rogue with popups.

Looking into the code, we can see that just after being registered, the rogue removes the malware and its restriction that prevent users to restore the original desktop background. Then it displays the "Register Success" Message box.