The Emsisoft malware research team has discoverd a new outbreak of the Defense Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.ProtectionCenter.
Defense Center is a rogue security program. This is a new variant from Protection Center, Data Protection, Digital Protection, Your Protection, User Protection, Dr. Guard , and PaladinAntivirus. This rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase. This rogue also found bundled with TDSS rootkit.
Create new files:
- %ProgramFiles%\Defense Center\virus.mp3
- %ProgramFiles%\Defense Center\about.ico
- %ProgramFiles%\Defense Center\activate.ico
- %ProgramFiles%\Defense Center\buy.ico
- %ProgramFiles%\Defense Center\def.db
- %ProgramFiles%\Defense Center\defcnt.exe
- %ProgramFiles%\Defense Center\defext.dll
- %ProgramFiles%\Defense Center\defhook.dll
- %ProgramFiles%\Defense Center\help.ico
- %ProgramFiles%\Defense Center\scan.ico
- %ProgramFiles%\Defense Center\settings.ico
- %ProgramFiles%\Defense Center\splash.mp3
- %ProgramFiles%\Defense Center\Uninstall.exe
- %ProgramFiles%\Defense Center\update.ico
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Defense Center.lnk
- %UserProfile%\Desktop\Defense Center.lnk
- %UserProfile%\Desktop\Defense Center Support.lnk
- %UserProfile%\Local Settings\Temp\def.dat
- %UserProfile%\Local Settings\Temp\defr.dat
- %UserProfile%\Local Settings\Temp\dhdhtrdhdrtr5y
- %UserProfile%\Local Settings\Temp\3c08.tmp
- %UserProfile%\Local Settings\Temp\4a8f.tmp
- %UserProfile%\Local Settings\Temp\4otjesjty.mof
- %UserProfile%\Local Settings\Temp\23cd.tmp
- %UserProfile%\Local Settings\Temp\3764.tmp
- %UserProfile%\Local Settings\Temp\b8bc.tmp
- %UserProfile%\Start Menu\Programs\Defense Center\Defense Center.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\Scan.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\Settings.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\Update.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\About.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\Activate.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\Buy.lnk
- %UserProfile%\Start Menu\Programs\Defense Center\Defense Center Support.lnk
Create new/modify registry entries:
- HKEY_LOCAL_MACHINE\software\Classes\*\ShellEx\ContextMenuHandlers\SimpleShlExt
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32
- HKEY_LOCAL_MACHINE\software\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt
- HKEY_LOCAL_MACHINE\software\Defense Center
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Defense Center
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “Defense Center”
Screenshots:




How to remove the infection of Defense Center (Adware.Win32.DefenseCenter)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
The Emsi Software malware research team has discoverd a new outbreak of the AV Security Suite adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.AVSecuritySuite.
AV Security Suite is a rogue security program, this is a new variant from Antivirus Suite, and Antivirus Soft. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.
Create new file:
- %UserProfile%\Local Settings\Application Data\%random%\%random%.exe
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\avsoft
- HKEY_LOCAL_MACHINE\software\avsuite
- HKEY_CURRENT_USER\software\avsoft
- HKEY_CURRENT_USER\software\avsuite
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “%random%”
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “%random%”
Screenshots:

How to remove the infection of AV Security Suite (Adware.Win32.AVSecuritySuite)?
To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
The Emsisoft malware research team has discoverd a new outbreak of the Protection Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.ProtectionCenter.
Protection Center is a rogue security program. This is a new variant from Data Protection, Digital Protection, Your Protection, User Protection, Dr. Guard , and PaladinAntivirus. This rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase. This rogue also found bundled with TDSS rootkit.
Create new files:
- %ProgramFiles%\Protection Center\cntprot.exe
- %ProgramFiles%\Protection Center\help.ico
- %ProgramFiles%\Protection Center\scan.ico
- %ProgramFiles%\Protection Center\settings.ico
- %ProgramFiles%\Protection Center\splash.mp3
- %ProgramFiles%\Protection Center\Uninstall.exe
- %ProgramFiles%\Protection Center\update.ico
- %ProgramFiles%\Protection Center\virus.mp3
- %ProgramFiles%\Protection Center\about.ico
- %ProgramFiles%\Protection Center\activate.ico
- %ProgramFiles%\Protection Center\buy.ico
- %ProgramFiles%\Protection Center\cnt.db
- %ProgramFiles%\Protection Center\cntext.dll
- %ProgramFiles%\Protection Center\cnthook.dll
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Protection Center.lnk
- %UserProfile%\Desktop\Protection Center.lnk
- %UserProfile%\Desktop\Protection Center Support.lnk
- %UserProfile%\Local Settings\Temp\4otjesjty.mof
- %UserProfile%\Local Settings\Temp\451d.tmp
- %UserProfile%\Local Settings\Temp\3722.tmp
- %UserProfile%\Local Settings\Temp\7461.tmp
- %UserProfile%\Local Settings\Temp\cnt.dat
- %UserProfile%\Local Settings\Temp\cntr.dat
- %UserProfile%\Local Settings\Temp\dhdhtrdhdrtr5y
- %UserProfile%\Local Settings\Temp\2bf7.tmp
- %UserProfile%\Local Settings\Temp\4f4e.tmp
- %UserProfile%\Start Menu\Programs\Protection Center\Protection Center Support.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\Protection Center.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\Scan.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\Settings.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\Update.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\About.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\Activate.lnk
- %UserProfile%\Start Menu\Programs\Protection Center\Buy.lnk
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Protection Center
- HKEY_LOCAL_MACHINE\software\Protection Center
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “Protection Center”
Screenshots:

How to remove the infection of Protection Center (Adware.Win32.ProtectionCenter)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
The Emsisoft malware research team has discoverd a new outbreak of the SysAntivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SysAntivirus.
SysAntivirus is a rogue security program, this is a new variant of XJR Antivirus, AKM Antivirus 2010 Pro and RTS Antivirus 2010. The maker of this rogue give it name as Sysinternals Antivirus. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.
Create new files:
- %ProgramFiles%\wp3.dat
- %ProgramFiles%\wp4.dat
- %ProgramFiles%\wpp.exe
- %ProgramFiles%\adc_w32.dll
- %ProgramFiles%\alggui.exe
- %ProgramFiles%\nuar.old
- %ProgramFiles%\skynet.dat
- %ProgramFiles%\svchost.exe
- %ProgramFiles%\Sysinternals Antivirus\Sysinternals Antivirus.exe
- %UserProfile%\Desktop\Sysinternals Antivirus.lnk
- %UserProfile%\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk
- C:\Sysinternals Antivirus\Sysinternals Antivirus.lnk
Create new registry entries:
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}
- HKEY_LOCAL_MACHINE\software\Classes\CLSID\{149256D5-E103-4523-BB43-2CFB066839D6}\InprocServer32
- HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{149256D5-E103-4523-BB43-2CFB066839D6}
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AdbUpd
- HKEY_CURRENT_USER\software\Sysinternals Antivirus
- HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp
- HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp\Registration
- HKEY_CURRENT_USER\software\Sysinternals Antivirus\wpp\setdata
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus\Registration
- HKEY_USERS\S-1-5-18\Software\Sysinternals Antivirus\Sysinternals Antivirus\setdata
Screenshots:

How to remove the infection of SysAntivirus (Adware.Win32.SysAntivirus)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.