The Emsisoft malware research team has discovered a new outbreak of the Smart Fortress 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartFortress2012.
Smart Fortress 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.
Create new files:
- %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\
- %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E
- %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe
- %UserProfile%\Desktop\Smart Fortress 2012.lnk
- %UserProfile%\Start Menu\Programs\Smart Fortress 2012\
- %UserProfile%\Start Menu\Programs\Smart Fortress 2012\Smart Fortress 2012.lnk
Create new registry entries:
- HKEY_CURRENT_USER\Software\Classes\.exe\
(Default) = B7E85
- HKEY_CURRENT_USER\Software\Classes\%s
(Default) = B7E85
- HKEY_CURRENT_USER\Software\Classes\B7E85\
(Default) = Application
Content Type = application/x-msdownload
- HKEY_CURRENT_USER\Software\Classes\B7E85\DefaultIcon
(Default) = %1
- HKEY_CURRENT_USER\Software\Classes\B7E85\shell\open\command\
(Default) = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe
IsolatedCommand = “%1″ %*
- HKEY_CURRENT_USER\Software\Classes\B7E85\shell\runas\command\
(Default) = “%1″ %*
IsolatedCommand = “%1″ %*
- HKEY_CURRENT_USER\Software\Classes\B7E85\shell\start\command\
(Default) = “%1″ %*
IsolatedCommand = “%1″ %*
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\
B7E85B320179A6C600266C1CD151FC4E = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Fortress 2012\
DisplayName = Smart Fortress 2012
ShortcutPath = “%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe” -u
UninstallString = “%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe” -u
DisplayIcon = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe,0
Screenshots:




To register this rogue application, you try the following serial number:
AA39754E-715219CE
How to remove the infection of Smart Fortress 2012 (Rogue.Win32.SmartFortress2012)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
The Emsisoft malware research team has discovered a new outbreak of the Antivirus Protection 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AntivirusProtection2012.
Antivirus Protection 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.
Create new files:
- %AppData%\Antivirus Protection\
- %AppData%\Antivirus Protection\IcoActivate.ico
- %AppData%\Antivirus Protection\IcoHelp.ico
- %AppData%\Antivirus Protection\IcoUninstall.ico
- %AppData%\Antivirus Protection\securityhelper.exe
- %AppData%\Antivirus Protection\securitymanager.exe
- %AppData%\Antivirus Protection\AntivirusProtection2012.exe
- %AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus Protection.lnk
- %UserProfile%\Desktop\Antivirus Protection.lnk
- %Temp%\472a10e2ebxd9.exe
- %Temp%\56493.exe
- %Temp%\ae0965a7157cd.exe
- %Temp%\al3erfa3.exe
- %Temp%\alerfa2.exe
- %Temp%\alerfa.exe
- %Temp%\altedf.exe
- %Temp%\aqfitrlxi2.exe
- %Temp%\backd-efq.exe
- %Temp%\brdss.exe
- %Temp%\bzqa43d.exe
- %Temp%\cffd4.exe
- %Temp%\cocksucker.exe
- %Temp%\cosock.exe
- %Temp%\cowceb.exe
- %Temp%\cunifuc.exe
- %Temp%\d20mes.exe
- %Temp%\dc_3.exe
- %Temp%\dd10x10.exe
- %Temp%\ddoll3342.exe
- %Temp%\destroyer.exe
- %Temp%\dffuck.exe
- %Temp%\dkfjd93.exe
- %Temp%\ds7hw.exe
- %Temp%\eelnvd13.exe
- %Temp%\exppdf_w.exe
- %Temp%\fadz43.exe
- %Temp%\fe.exe
- %Temp%\format.exe
- %Temp%\g_dx234.exe
- %Temp%\ggwwef9752.exe
- %Temp%\gpupz2a.exe
- %Temp%\hhbboll_2.exe
- %Temp%\hiphop.exe
- %Temp%\hodeme.exe
- %Temp%\htfad4.exe
- %Temp%\hvipws9.exe
- %Temp%\jdhellwo3.exe
- %Temp%\jkfuckfu.exe
- %Temp%\jofcdks.exe
- %Temp%\kjdh_gf_jjdhgd.exe
- %Temp%\kjh102k3.exe
- %Temp%\kn.a.exe
- %Temp%\kock.exe
- %Temp%\ljts-23.exe
- %Temp%\lkhgg_ea.exe
- %Temp%\lols.exe
- %Temp%\ploper.exe
- %Temp%\poertd.exe
- %Temp%\ppddfcfux.exxe
- %Temp%\protector2.exe
- %Temp%\pswwg3c.exe
- %Temp%\puzpup.exe
- %Temp%\qwedvor.exe
- %Temp%\qwklrvjhqlkj.exe
- %Temp%\r0life.exe
- %Temp%\rator.exe
- %Temp%\rtfme.exe
- %Temp%\safe.exe
- %Temp%\snowif.exe
- %Temp%\sycre.exe
- %Temp%\timem.exe
- %Temp%\tryh-blv.exe
- %Temp%\w32-reno-c.exe
- %Temp%\w32rim_mem.exe
- %Temp%\warsddd_w.exe
- %Temp%\wefgetn_00.exe
- %Temp%\wined.exe
- %Temp%\winifi.exe
- %Temp%\wrcud12.exe
- %Temp%\wrfwe_di.exe
- %Temp%\wwautrsd.exe
- %Temp%\wwwsssgen.exe
- %Temp%\_5.tmp
- %Temp%\1iowieoo.exe
- %Temp%2c9c3c35bdx5.exe
- %Temp%\8gmsed-bd.exe
- %Temp%\17dkf.exe
- %UserProfile%\Start Menu\Programs\Antivirus Protection.lnk
- %UserProfile%\Start Menu\Programs\Antivirus Protection\
- %UserProfile%\Start Menu\Programs\Antivirus Protection\Antivirus Protection.lnk
- %UserProfile%\Start Menu\Programs\Antivirus Protection\Help Antivirus Protection.lnk
- %UserProfile%\Start Menu\Programs\Antivirus Protection\How to Activate Antivirus Protection.lnk
- %UserProfile%\Start Menu\Programs\Antivirus Protection\Activate Antivirus Protection.lnk
Create new registry entries:
- HKEY_CURRENT_USER\software\Antivirus Protection\
(Default) = %AppData%\Antivirus Protection\
BuyUrl = B65B17E3F9DA41446905D3BE0E550632B225D0DB132371E38F96D84D2B2F0
uninstaller = %AppData%\Antivirus Protection\securityhelper.exe
ADVid = 390
InstallDir = %AppData%\Antivirus Protection\
SoftID = Antivirus Protection
ScanSystemOnStartup = 01000000
AutomaticallyUpdates = 01000000
BackgroundScan = 01000000
BackgroundScanTimeout = 01000000
tb = DC07020003001600060012002800BF02
InstNM = %AppData%\Antivirus Protection\AntivirusProtection2012.exe
LastTimeStamp = D9FFFFFF
LastUpdateDate = 2012/2/1
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus Protection\
DisplayName = Antivirus Protection
UninstallString = “%AppData%\Antivirus Protection\securityhelper.exe” /UNINSTALL
DisplayIcon = “%AppData%\Antivirus Protection\securityhelper.exe”,1
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\
cbrdwlurumf5 = D:\!Mal\123.exe
Antivirus Protection = “%AppData%\Antivirus Protection\AntivirusProtection2012.exe” /STARTUP
Antivirus Protection 2012 SM = %AppData%\Antivirus Protection\securitymanager.exe




To register and uninstall this rogue application, you can try the following serial number:
LIC-00A5-3F5G-BHA5-KJB8-579F-CVH9-M935-QW45-89M5-19AB
How to remove the infection of Antivirus Protection 2012 (Rogue.Win32.AntivirusProtection2012)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
The Emsisoft malware research team has discovered a new outbreak of the Home Malware Cleaner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.HomeMalwareCleaner.
Home Malware Cleaner is a rogue scanner application, another variant of SmartAntiMalwareProtection, Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.
Create new files:
- %AllUsersProfile%\Application Data\5c678c\
- %AllUsersProfile%\Application Data\5c678c\BackUp\
- %AllUsersProfile%\Application Data\5c678c\HMCSys\
- %AllUsersProfile%\Application Data\5c678c\Quarantine Items\
- %AllUsersProfile%\Application Data\5c678c\51.mof
- %AllUsersProfile%\Application Data\5c678c\HM5c6_8010.exe
- %AllUsersProfile%\Application Data\5c678c\HMC.ico
- %AllUsersProfile%\Application Data\5c678c\mozcrt19.dll
- %AllUsersProfile%\Application Data\5c678c\sqlite3.dll
- %AllUsersProfile%\Application Data\HMEMLLCC\
- %AllUsersProfile%\Application Data\HMEMLLCC\HMFLAAC.cfg
- %AppData%\Home Malware Cleaner\
- %AppData%\Home Malware Cleaner\cookies.sqlite
- %AppData%\Home Malware Cleaner\Instructions.ini
- %AppData%\Microsoft\Internet Explorer\Quick Launch\Home Malware Cleaner.lnk
- %UserProfile%\Desktop\Home Malware Cleaner.lnk
- %Temp%\scandsk211d_8010.exe
- %UserProfile%\Recent\energy.sys
- %UserProfile%\Start Menu\Home Malware Cleaner.lnk
- %UserProfile%\Start Menu\Programs\Home Malware Cleaner.lnk
Create/modify registry entries:
- HKEY_LOCAL_MACHINE\Software\Classes\HM5c6_8010.DocHostUIHandler
Default = Implements DocHostUIHandler
Clsid = {3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
Default = Implements DocHostUIHandler
LocalServer32 = %AllUsersProfile%\Application Data\5c678c\HM5c6_8010.exe
ProgID = HM5c6_8010.DocHostUIHandler
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\
Debugger = svchost.exe
- HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\
Debugger = svchost.exe
- HKEY_CURRENT_USER\software\3
- HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\
CheckExeSignatures = no
RunInvalidSignatures = 01000000
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\
Home Malware Cleaner = “%AllUsersProfile%\Application Data\5c678c\HM5c6_8010.exe” /s /d
- HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\
SAMP = “%Temp%\scandsk211d_8010.exe” /cs:0
Screenshots:




To register and uninstall this rogue application, you can try the following serial number:
U2FD-S2LA-H4KA-UEPB
How to remove the infection of Home Malware Cleaner (Rogue.Win32.HomeMalwareCleaner)?
To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.