ついでにTrendMicroの方も同検体でテストしたので報告します。(但し、s!ri-urz様のキーで弱体化済み)
ログ↓
##################
Fake Antivirus Remover 1.0.0.1016
Pattern version: 100008
Scan mode: Scan All Processes
Time elapsed: 02 minute(s), 39 second(s)
Summary
------------------------------------
Processes Detected: 2
Files Detected: 1
Folders Detected: 0
Registry Keys Detected: 0
Registry Values Detected: 0
Registry Data Detected: 17
Detailed Information
------------------------------------
Processes Detected:
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe -> Terminate (Quarantined and deleted successfully.)
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -> Terminate (Quarantined and deleted successfully.)
Files Detected:
C:\Documents and Settings\All Users\デスクトップ\COMODO Internet Security.lnk -> Delete (Quarantined and deleted successfully.)
Registry Data Detected:
HKCR\cplfile\shell\cplopen\command\""(Data:rundll32.exe shell32.dll,Control_RunDLL "%1",%*) -> Reset to default (Quarantined and deleted successfully.)
HKCR\jsefile\shell\open\command\""(Data:C:\WINDOWS\System32\WScript.exe "%1" %*) -> Reset to default (Quarantined and deleted successfully.)
HKCR\jsfile\shell\open\command\""(Data:C:\WINDOWS\System32\WScript.exe "%1" %*) -> Reset to default (Quarantined and deleted successfully.)
HKCR\vbefile\shell\open\command\""(Data:C:\WINDOWS\System32\WScript.exe "%1" %*) -> Reset to default (Quarantined and deleted successfully.)
HKCR\vbsfile\shell\open\command\""(Data:C:\WINDOWS\System32\WScript.exe "%1" %*) -> Reset to default (Quarantined and deleted successfully.)
HKCR\wsffile\shell\open\command\""(Data:C:\WINDOWS\System32\WScript.exe "%1" %*) -> Reset to default (Quarantined and deleted successfully.)
HKCR\wshfile\shell\open\command\""(Data:C:\WINDOWS\System32\WScript.exe "%1" %*) -> Reset to default (Quarantined and deleted successfully.)
HKCU\Control Panel\Desktop\WallPaper(Data:C:\WINDOWS\web\wallpaper\草原.bmp) -> Reset to default (Quarantined and deleted successfully.)
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\BackupWallpaper(Data:C:\WINDOWS\web\wallpaper\草原.bmp) -> Reset to default (Quarantined and deleted successfully.)
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\Wallpaper(Data:C:\WINDOWS\web\wallpaper\草原.bmp) -> Reset to default (Quarantined and deleted successfully.)
HKCU\Software\Microsoft\Internet Explorer\Main\Start page(Data:
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) -> Reset to default (Quarantined and deleted successfully.)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden(Data:2) -> Reset to default (Quarantined and deleted successfully.)
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt(Data:1) -> Reset to default (Quarantined and deleted successfully.)
HKLM\Software\Microsoft\Internet Explorer\Main\Start page(Data:
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home) -> Reset to default (Quarantined and deleted successfully.)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit(Data:rdpinit.exe) -> Reset to default (Quarantined and deleted successfully.)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\COMODO Internet Security(Data:"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h) -> Delete (Quarantined and deleted successfully.)
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall(Data:0) -> Reset to default (Quarantined and deleted successfully.)
##################
見ていただければわかると思いますが酷いことになっています。
肝心の偽セキュリティソフトを検出できないどころかWindows関連ファイル、果てにはCOMODO Internet Securityを誤検出しています。
ダメだこりゃ・・・