Power Antivirus 2009 another fake Antivirus application
Thursday, August 7th, 2008Power Antivirus 2009 is another fake Antivirus application. Installer of Power Antivirus 2009 is signed by Verisign’s Thawte division. Here are some fake scanning pages:
DO NOT download any software from domain(s) of Power Antivirus 2009!
VirusTotal description of Antivirus 2009 loader
| File setup.exe received on 08.07.2008 13:54:37 (CET) | |||
| Antivirus | Version | Last Update | Result |
| AhnLab-V3 | 2008.8.7.0 | 2008.08.07 | - |
| AntiVir | 7.8.1.19 | 2008.08.07 | HEUR/Malware |
| Authentium | 5.1.0.4 | 2008.08.07 | - |
| Avast | 4.8.1195.0 | 2008.08.06 | - |
| AVG | 8.0.0.156 | 2008.08.07 | FakeAlert.BH |
| BitDefender | 7.2 | 2008.08.07 | - |
| CAT-QuickHeal | 9.50 | 2008.08.06 | - |
| ClamAV | 0.93.1 | 2008.08.07 | - |
| DrWeb | 4.44.0.09170 | 2008.08.07 | - |
| eSafe | 7.0.17.0 | 2008.08.06 | Suspicious File |
| eTrust-Vet | 31.6.6017 | 2008.08.07 | - |
| Ewido | 4.0 | 2008.08.07 | - |
| F-Prot | 4.4.4.56 | 2008.08.06 | - |
| F-Secure | 7.60.13501.0 | 2008.08.07 | FraudTool.Win32.PowerAntivirus2009.e |
| Fortinet | 3.14.0.0 | 2008.08.07 | - |
| GData | 2.0.7306.1023 | 2008.08.07 | - |
| Ikarus | T3.1.1.34.0 | 2008.08.07 | - |
| K7AntiVirus | 7.10.405 | 2008.08.07 | - |
| Kaspersky | 7.0.0.125 | 2008.08.07 | not-a-virus:FraudTool.Win32.PowerAntivirus2009.e |
| McAfee | 5355 | 2008.08.06 | - |
| Microsoft | 1.3807 | 2008.08.07 | Trojan:Win32/Killav.gen!A |
| NOD32v2 | 3336 | 2008.08.07 | - |
| Norman | 5.80.02 | 2008.08.06 | - |
| Panda | 9.0.0.4 | 2008.08.06 | - |
| PCTools | 4.4.2.0 | 2008.08.06 | - |
| Prevx1 | V2 | 2008.08.07 | Suspicious |
| Rising | 20.56.32.00 | 2008.08.07 | - |
| Sophos | 4.31.0 | 2008.08.07 | Sus/Dropper-R |
| Sunbelt | 3.1.1537.1 | 2008.08.07 | - |
| Symantec | 10 | 2008.08.07 | - |
| TheHacker | 6.2.96.393 | 2008.08.04 | - |
| TrendMicro | 8.700.0.1004 | 2008.08.07 | - |
| VBA32 | 3.12.8.2 | 2008.08.06 | - |
| ViRobot | 2008.8.7.1328 | 2008.08.07 | - |
| VirusBuster | 4.5.11.0 | 2008.08.06 | - |
| Webwasher-Gateway | 6.6.2 | 2008.08.07 | - |
Thawte sert of Power Antivirus 2009 loader
Host: scanner.power-antivirus-2009.com
IP: 91.208.0.233
Whois:
netname: STILLTRADE-NET
descr: Still Trade Ltd
country: RU
org: ORG-STIL1-RIPEperson: Perevitskiy Sergey
address: Russian Federation,
address: St. Petersburg, Fedosenko st, 30 liter A, 24-N
mnt-by: STILLTRADE-MNT
abuse-mailbox: abuse@still-trade.com
Host: e-statistic.com
IP: 207.226.175.78
Whois:
OrgName: Still Trade Ltd
, Inc.
OrgID: BNA-42
Address: 450 Springpark PL
Address: Suite 100
City: Herdon
StateProv: VA
PostalCode: 20170
Country: US
OrgAbuseHandle: PAD13-ARIN
OrgAbuseName: PCCW AUP Department
OrgAbusePhone: +1-703-621-1637
OrgAbuseEmail: probinson@pccwglobal.com












