<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; Uncategorized</title>
	<atom:link href="http://www.anti-malware-blog.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Antivirii 2011 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 08:03:19 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antivirii 2011]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2741</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antivirii 2011. Emsisoft Anti-Malware detects this malware as Rogue.Win32.Antivirii2011. Antivirii 2011 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Antivirii 2011</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.Antivirii2011" href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirii2011" target="_blank"><strong>Rogue.Win32.Antivirii2011</strong></a><strong>.</strong></p>
<p><strong>Antivirii 2011 </strong><strong> </strong>is                         a                                          rogue                                 application. A rogue application tries to trick  you    by     displaying false    positive or  misleading scan results  report,     which  says   that your    computer has a  problem, or infected  with     viruses or  trojan,   but    you will not be able to  fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\llwzhxdd.exe</li>
<li>%SystemRoot%\antivirii.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
Security = %SystemRoot%\llwzhxdd.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\xhergjui.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_1.png"><img class="alignnone size-medium wp-image-2742" title="Rogue.Win32.AntiVirii2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_1-400x326.png" alt="Rogue.Win32.AntiVirii2011" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_2.png"><img class="alignnone size-medium wp-image-2743" title="Rogue.Win32.AntiVirii2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_2-376x400.png" alt="Rogue.Win32.AntiVirii2011" width="376" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_3.png"><img class="alignnone size-medium wp-image-2744" title="Rogue.Win32.AntiVirii2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_3-400x185.png" alt="Rogue.Win32.AntiVirii2011" width="400" height="185" /></a></p>
<p><strong>How to remove the infection of Antivirii 2011 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirii2011" target="_blank">Rogue.Win32.Antivirii2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/" rel="bookmark" class="crp_title">Super AV Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/04/fakebitdef2011-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeBitDef2011 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Defragmenter Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/11/11/smart-defragmenter-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/11/11/smart-defragmenter-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 15:34:35 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SmartDefragmenter]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1136</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the Smart Defragmenter adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SmartDefragmenter. Smart Defragmenter is a rogue application, this is another variant of HDD Defragmenter, and System Defragmenter. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has  discoverd a new outbreak    of the <strong>Smart Defragmenter</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartDefragmenter" target="_blank">Adware.Win32.SmartDefragmenter</a></strong>.</p>
<p><strong>Smart Defragmenter </strong>is a rogue application, this is another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDefragmenter" target="_blank"><strong>HDD Defragmenter</strong></a>, and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong>System Defragmenter</strong></a>.      A  rogue   application  tries to trick you by displaying  false       positive/misleading   scan results  report, which says that your        computer has a problem, or infected with   viruses or  trojan, but you   will not be able      to fix it before you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Desktop\Smart Defragmenter.lnk</li>
<li>%UserProfile%\Local Settings\Temp\%random%.bmp</li>
<li>%UserProfile%\Local Settings\Temp\%random%.exe</li>
<li>%UserProfile%\Local Settings\Temp\%random%</li>
<li>%UserProfile%\Start Menu\Programs\Smart Defragmenter\</li>
<li>%UserProfile%\Start Menu\Programs\Smart Defragmenter\Smart Defragmenter.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Smart Defragmenter\Uninstall Smart Defragmenter.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
(String) %random% = %UserProfile%\Local Settings\Temp\%random%.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_1.png"><img class="alignnone size-medium wp-image-1137" title="Adware.Win32.SmartDefragmenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_1-400x269.png" alt="" width="400" height="269" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_2.png"><img class="alignnone size-medium wp-image-1138" title="Adware.Win32.SmartDefragmenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_2-400x203.png" alt="" width="400" height="203" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_4.png"><img class="alignnone size-medium wp-image-1140" title="Adware.Win32.SmartDefragmenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_4-400x229.png" alt="" width="400" height="229" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_5.png"><img class="alignnone size-medium wp-image-1141" title="Adware.Win32.SmartDefragmenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_5-400x269.png" alt="" width="400" height="269" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_6.png"><img class="alignnone size-medium wp-image-1142" title="Adware.Win32.SmartDefragmenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/11/Adware.Win32.SmartDefragmenter_6-400x256.png" alt="" width="400" height="256" /></a></p>
<p><strong>How to remove the infection of Smart Defragmenter </strong><strong>(Adware.Win32.</strong><strong>SmartDefragmenter</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/12/07/win-defragmenter-adware-removal-instructions/" rel="bookmark" class="crp_title">Win Defragmenter Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/22/defragmenter-adware-removal-instructions/" rel="bookmark" class="crp_title">Defragmenter Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/16/quick-defragmenter-adware-removal-instructions/" rel="bookmark" class="crp_title">Quick Defragmenter Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/16/smart-hdd-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart HDD Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/28/hdd-low-adware-removal-instructions/" rel="bookmark" class="crp_title">HDD Low Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/11/11/smart-defragmenter-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivir Solution Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 08:25:25 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AntivirSolutionPro]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=958</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the Antivir Solution Pro adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.AntivirSolutionPro. Antivir Solution Pro is a rogue security program, this is a new variant from AVSecuritySuite, Antivirus Suite, and Antivirus Soft. A rogue application tries to trick you by displaying false positive/misleading scan [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has   discoverd a new outbreak    of the <strong>Antivir Solution Pro</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft      Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirSolutionPro" target="_blank">Adware.Win32.AntivirSolutionPro</a></strong>.</p>
<p><strong>Antivir Solution Pro</strong> is a rogue security program, this  is  a new variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecuritySuite" target="_blank"><strong>AVSecuritySuite</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSuite" target="_blank"><strong>Antivirus Suite</strong></a>, and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSoft" target="_blank"><strong>Antivirus Soft</strong></a>. A rogue    application  tries to trick you by displaying  false positive/misleading    scan results  report, which says that your  computer is infected with    viruses or  trojan, but you will not be able  to delete them before  you   purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\%random%\%random%.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\AVSolution</li>
<li>HKEY_LOCAL_MACHINE\software\AVSuitE</li>
<li>HKEY_CURRENT_USER\software\AVSolution</li>
<li>HKEY_CURRENT_USER\software\AVSuitE</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;%random%&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;%random%&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
ProxyServer = http=127.0.0.1:5643<br />
ProxyOverride = &lt;local&gt;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\PhishingFilter<br />
EnabledV8 = 0&#215;00000000 (0)<br />
Enabled = 0&#215;00000000 (0)</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_1.png"><img class="alignnone size-full wp-image-959" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_1.png" alt="" width="362" height="142" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_2.png"><img class="alignnone size-medium wp-image-960" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_2-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_3.png"><img class="alignnone size-medium wp-image-961" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_3-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_4.png"><img class="alignnone size-medium wp-image-962" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_4-400x303.png" alt="" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_5.png"><img class="alignnone size-medium wp-image-963" title="Adware.Win32.AntivirSolutionPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/07/Adware.Win32.AntivirSolutionPro_5-400x297.png" alt="" width="400" height="297" /></a></p>
<p><strong>How to remove the infection of Antivir Solution Pro </strong><strong>(Adware.Win32.</strong><strong>Antivir Solution Pro</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                      Anti-Malware</a></strong>. Run a full scan on all drives   and       move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/12/av-security-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/15/antivirus-suite-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Suite Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/10/25/antivirus-action-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Action Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/05/antivirus-soft-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Soft Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/09/24/antivirus-is-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus IS Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/07/20/antivir-solution-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

