AntiVirGear

AntiVirGear is a malicious software program (more commonly known as malware) that infects computers by pretending to be an antimalware application.

Infection
A trojan already on the computer (usually the Zlob trojan) may display an icon in the system tray that has a constant popup saying the computer has been infected, which, when clicked, downloads and then installs AntiVirGear. Once AntiVirGear is installed any malware it detects (including the trojan that installed it) requires the user to go to AntiVirGear's website and purchase the software before it will allow removal.

Symptoms
AntiVirGear may attempt to change the computer's wallpaper/desktop and permanently change Internet Explorer's homepage, even though a different one has been selected in "Tools - Internet Options - Home Page." This is done via group policy causing it to appear as if the network's administrator changed the home page.

Known Variants
There are several variants of this Smitfraud/Zlob infection. They include SpywareStrike, SpyAxe, SpySheriff, SpyFalcon, SpywareQuake, and MalwareWipe and many other pseudonyms.

Removal
SmitFraudFix is currently the most popular tool used to remove this infection.
 
< Prev   Next >