<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog</title>
	<atom:link href="http://www.anti-malware-blog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Antimalware news, new rogue/spyware/scareware alerts and infection removal help</description>
	<lastBuildDate>Fri, 07 Jun 2013 04:52:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>System Doctor 2014 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2013/06/07/system-doctor-2014-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2013/06/07/system-doctor-2014-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 07 Jun 2013 04:52:36 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Rogue.Win32.SystemDoctor2014]]></category>
		<category><![CDATA[System Doctor 2014]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6253</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Doctor 2014. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemDoctor2014. System Doctor 2014 is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/12/07/disk-doctor-adware-removal-instructions/"     class="crp_title">Disk Doctor Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/03/system-defragmenter-adware-removal-instructions/"     class="crp_title">System Defragmenter Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/"     class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/08/system-tool-adware-removal-instructions/"     class="crp_title">System Tool Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/28/hdd-low-adware-removal-instructions/"     class="crp_title">HDD Low Adware Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>System Doctor 2014</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SystemDoctor2014" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDoctor2014" target="_blank"><strong>Rogue.Win32.SystemDoctor2014.</strong></a></p>
<p><strong>System Doctor 2014</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\WindowsSecurityUpdate.exe</li>
<li>%AppData%\[random]\[random].exe</li>
<li>%AppData%\[random]\[random].ico</li>
<li>%AppData%\[random]\[random].ini</li>
<li>%AppData%\[random]\[random].log</li>
<li>%UserProfile%\Desktop\System Doctor 2014 support.url</li>
<li>%UserProfile%\Desktop\System Doctor 2014.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Doctor 2014\</li>
<li>%UserProfile%\Start Menu\Programs\System Doctor 2014\System Doctor 2014 support.url</li>
<li>%UserProfile%\Start Menu\Programs\System Doctor 2014\Uninstall System Doctor 2014.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Doctor 2014\System Doctor 2014.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
SD2014 = &#8220;%AppData%\[random]\[random].exe&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\System Doctor 2014<br />
DisplayName = &#8220;System Doctor 2014&#8243;<br />
InstallLocation = &#8220;%AppData%\[random]\&#8221;<br />
NoModify = dword:00000001<br />
NoRepair = dword:00000001<br />
UninstallString = &#8220;%AppData%\[random]\[random].exe -uninstall&#8221;<br />
DisplayIcon = &#8220;%AppData%\[random]\[random].ico,0&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_1.png"><img alt="Rogue.Win32.SystemDoctor2014_1" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_1-400x312.png" width="400" height="312" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_2.png"><img alt="Rogue.Win32.SystemDoctor2014_2" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_2-400x271.png" width="400" height="271" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_3.png"><img alt="Rogue.Win32.SystemDoctor2014_3" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_3-400x271.png" width="400" height="271" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_4.png"><img class="alignnone size-medium wp-image-6254" alt="Rogue.Win32.SystemDoctor2014_4" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_4-400x272.png" width="400" height="272" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_5.png"><img class="alignnone size-medium wp-image-6255" alt="Rogue.Win32.SystemDoctor2014_5" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_5-400x273.png" width="400" height="273" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_6.png"><img class="alignnone size-medium wp-image-6256" alt="Rogue.Win32.SystemDoctor2014_6" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_6-400x189.png" width="400" height="189" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_7.png"><img class="alignnone size-medium wp-image-6257" alt="Rogue.Win32.SystemDoctor2014_7" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_7-400x271.png" width="400" height="271" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_8.png"><img class="alignnone size-medium wp-image-6258" alt="Rogue.Win32.SystemDoctor2014_8" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_8-400x272.png" width="400" height="272" /></a></p>
<p><a href="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_9.png"><img class="alignnone size-medium wp-image-6259" alt="Rogue.Win32.SystemDoctor2014_9" src="http://www.anti-malware-blog.com/files/2013/06/Rogue.Win32.SystemDoctor2014_9-400x271.png" width="400" height="271" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><strong><span style="color: #ff0000">AA39754E-715219CE</span></strong></pre>
<p><strong>How to remove the infection of System Doctor 2014 (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDoctor2014" target="_blank">Rogue.Win32.SystemDoctor2014</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/12/07/disk-doctor-adware-removal-instructions/"     class="crp_title">Disk Doctor Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/03/system-defragmenter-adware-removal-instructions/"     class="crp_title">System Defragmenter Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/"     class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/08/system-tool-adware-removal-instructions/"     class="crp_title">System Tool Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/28/hdd-low-adware-removal-instructions/"     class="crp_title">HDD Low Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2013/06/07/system-doctor-2014-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Micorsoft Essential Security Pro 2013 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/11/01/micorsoft-essential-security-pro-2013-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/11/01/micorsoft-essential-security-pro-2013-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 01 Nov 2012 11:24:03 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Micorsoft Essential Security Pro 2013]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Rogue.Win32.SecurityPro2013]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6243</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Micorsoft Essential Security Pro 2013. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SecurityPro2013. Micorsoft Essential Security Pro 2013 is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/"     class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/"     class="crp_title">XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/"     class="crp_title">Windows Security System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/"     class="crp_title">XP Home Security 2012 Adware Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Micorsoft Essential Security Pro 2013</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SecurityPro2013" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityPro2013" target="_blank"><strong>Rogue.Win32.SecurityPro2013.</strong></a></p>
<p><strong>Micorsoft Essential Security Pro 2013</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%MalwareDir%\settings.data</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\WindowsSecurity = %MalwareFile%</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\WindowsSecurity = %MalwareFile%</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\classes\.exe<br />
(default) = exefile<br />
Content Type = application/x-msdownload<br />
DefaultIcon = %1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\classes\.exe\shell\open\command<br />
(default) = &#8220;%MalwareFile%&#8221; -a &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\classes\.exe\shell\runas\command<br />
(default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\classes\exefile<br />
(default) = Application<br />
Content Type = application/x-msdownload<br />
DefaultIcon  = %1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\classes\exefile\shell\open\command<br />
(default) = &#8220;%MalwareFile%&#8221; -a &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\classes\exefile\shell\runas\command<br />
(default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/11/01/micorsoft-essential-security-pro-2013-rogue-removal-instructions/rogue-win32-securitypro2013_1/" rel="attachment wp-att-6244"><img class="alignnone size-medium wp-image-6244" src="http://www.anti-malware-blog.com/files/2012/11/Rogue.Win32.SecurityPro2013_1-400x293.png" alt="Micorsoft Essential Security Pro 2013" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/11/01/micorsoft-essential-security-pro-2013-rogue-removal-instructions/rogue-win32-securitypro2013_2/" rel="attachment wp-att-6245"><img class="alignnone size-medium wp-image-6245" src="http://www.anti-malware-blog.com/files/2012/11/Rogue.Win32.SecurityPro2013_2-400x225.png" alt="Micorsoft Essential Security Pro 2013" width="400" height="225" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/11/01/micorsoft-essential-security-pro-2013-rogue-removal-instructions/rogue-win32-securitypro2013_3/" rel="attachment wp-att-6246"><img class="alignnone size-medium wp-image-6246" src="http://www.anti-malware-blog.com/files/2012/11/Rogue.Win32.SecurityPro2013_3-400x280.png" alt="Micorsoft Essential Security Pro 2013" width="400" height="280" /></a></p>
<p><strong>How to remove the infection of Micorsoft Essential Security Pro 2013 (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityPro2013" target="_blank">Rogue.Win32.SecurityPro2013</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/"     class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/"     class="crp_title">XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/"     class="crp_title">Windows Security System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/"     class="crp_title">XP Home Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/11/01/micorsoft-essential-security-pro-2013-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>File Restore Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/10/19/file-restore-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/10/19/file-restore-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 19 Oct 2012 16:41:58 +0000</pubDate>
		<dc:creator>evandorp</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[File Restore]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6230</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered an outbreak of the File Restore rogue.  Emsisoft Anti-Malware detects this malware as Rogue.Win32.FileRestore. File Restore is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results, which say that your computer has a problem, or is infected with viruses or trojans, but you [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/10/13/system-progressive-protection-rogue-removal-instructions/"     class="crp_title">System Progressive Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/"     class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/"     class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/"     class="crp_title">Windows Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered an outbreak of the <strong>File Restore</strong> rogue. <strong><a title="External link" href="http://www.emsisoft.com/en/software/antimalware/" rel="external"><br />
Emsisoft Anti-Malware</a></strong> detects this malware as <a title="External link" href="http://www.emsisoft.com/en/malware/?Rogue.Win32.FileRestore" rel="external"><strong>Rogue.Win32.FileRestore</strong></a>.</p>
<p><strong>File Restore</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results, which say that your computer has a problem, or is infected with viruses or trojans, but you will not be able to fix anything before you purchase the program.</p>
<p><strong>Creates new files:</strong></p>
<ul>
<li>%CommonAppData%\[random]</li>
<li>%CommonAppData%\[random].exe</li>
<li>%CommonAppData%\[random]</li>
<li>%CommonAppData%\-[random]</li>
<li>%UserProfile%\Start Menu\Programs\File Restore\</li>
<li>%UserProfile%\Start Menu\Programs\File Restore\File Restore.lnk</li>
<li>%UserProfile%\Start Menu\Programs\File Restore\Uninstall File Restore.lnk</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\File_Restore.lnk</li>
<li>%UserProfile%\Desktop\File Restore.lnk</li>
</ul>
<p><strong>Creates new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
[random] = %CommonAppData%\[random].exe</li>
</ul>
<p><strong>Screenshots:</strong><br />
<a id="ipb-attach-url-14669-0-02723100-1350664135" title="filerestore3.png - Size: 75.84K, Downloads: 1" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14669" rel="lightbox[60802]"><img src="http://support.emsisoft.com/uploads/monthly_10_2012/post-23145-0-16079700-1350663948_thumb.png" alt="filerestore3.png" width="100" height="83" /></a> <a id="ipb-attach-url-14670-0-02758500-1350664135" title="filerestore2.png - Size: 15.83K, Downloads: 0" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14670" rel="lightbox[60802]"><img src="http://support.emsisoft.com/uploads/monthly_10_2012/post-23145-0-44218500-1350663965_thumb.png" alt="filerestore2.png" width="100" height="60" /></a> <a id="ipb-attach-url-14671-0-02779700-1350664135" title="filerestore1.png - Size: 59.01K, Downloads: 0" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14671" rel="lightbox[60802]"><img src="http://support.emsisoft.com/uploads/monthly_10_2012/post-23145-0-09936000-1350663981_thumb.png" alt="filerestore1.png" width="100" height="83" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><strong><span style="color: #ff0000">08467206738602987934024759008355</span></strong></pre>
<p>How to remove the <strong>File Restore Rogue (<a title="External link" href="http://www.emsisoft.com/en/malware/?Rogue.Win32.FileRestore" rel="external">Rogue.Win32.FileRestore</a>)?</strong></p>
<p>To remove this malware infection, please download and install <strong><a title="External link" href="http://www.emsisoft.com/en/software/antimalware/" rel="external">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/10/13/system-progressive-protection-rogue-removal-instructions/"     class="crp_title">System Progressive Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/"     class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/"     class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/"     class="crp_title">Windows Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/10/19/file-restore-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Progressive Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/10/13/system-progressive-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/10/13/system-progressive-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Sat, 13 Oct 2012 18:37:21 +0000</pubDate>
		<dc:creator>evandorp</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6223</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered an outbreak of the System Progressive Protection rogue. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemProtection. System Progressive Protection is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results, which say that your computer has a problem, or is infected with viruses or trojans, but you will [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/10/19/file-restore-rogue-removal-instructions/"     class="crp_title">File Restore Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/"     class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/"     class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/"     class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/"     class="crp_title">Windows Security System Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered an outbreak of the <strong><strong><strong><strong><strong>System Progressive Protection</strong></strong></strong> rogue. <strong><a title="External link" href="http://www.emsisoft.com/en/software/antimalware/" rel="external">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="External link" href="http://www.emsisoft.com/en/malware/?Rogue.Win32.SystemProtection" rel="external"><strong>Rogue.Win32.SystemProtection</strong></a>.</strong></strong></p>
<p><strong><strong><strong><strong>System Progressive Protection</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results, which say that your computer has a problem, or is infected with viruses or trojans, but you will not be able to fix anything before you purchase the program.</strong></p>
<p><strong>Creates new files:</strong></p>
<ul>
<li>%CommonAppData%\[random]\[random].exe</li>
<li>%CommonAppData%\[random]\[random].ico</li>
<li>%CommonAppDAta%\[random]\[random]</li>
<li>%UserProfile%\Desktop\System Progressive Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Progressive Protection\System Progressive Protection.lnk</li>
</ul>
<p><strong><strong><strong><br />
<strong>Creates new registry entries:</strong><br />
</strong></strong></strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce<br />
[random] = %CommonAppData%\[random]\[random].exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\System Progressive Protection<br />
DisplayIcon = %CommonAppData%\[random]\[random].ico,0<br />
UninstallString = %CommonAppData%\[random]\[random].exe -u<br />
ShortcutPath = %CommonAppData%\[random]\[random].exe -u<br />
DisplayName = System Progressive Protection</li>
</ul>
<p><strong><strong><br />
<strong>Screenshots:</strong></strong></strong></p>
<p><a id="ipb-attach-url-14196-0-21951500-1350152194" title="System Progressive Protection 1.png - Size: 59.48K, Downloads: 40" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14196" rel="lightbox[58923]"><img src="http://support.emsisoft.com/uploads/monthly_09_2012/post-23145-0-61813600-1348686023_thumb.png" alt="System Progressive Protection 1.png" width="100" height="76" /></a> <a id="ipb-attach-url-14197-0-21997700-1350152194" title="System Progressive Protection 2.png - Size: 84.73K, Downloads: 55" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14197" rel="lightbox[58923]"><img src="http://support.emsisoft.com/uploads/monthly_09_2012/post-23145-0-47596600-1348686032_thumb.png" alt="System Progressive Protection 2.png" width="100" height="75" /></a> <a id="ipb-attach-url-14198-0-22023800-1350152194" title="System Progressive Protection 3.png - Size: 28.8K, Downloads: 50" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14198" rel="lightbox[58923]"><img src="http://support.emsisoft.com/uploads/monthly_09_2012/post-23145-0-49629700-1348686041_thumb.png" alt="System Progressive Protection 3.png" width="100" height="87" /></a> <a id="ipb-attach-url-14199-0-22039600-1350152194" title="System Progressive Protection 4.png - Size: 74.45K, Downloads: 29" href="http://support.emsisoft.com/index.php?app=core&amp;module=attach&amp;section=attach&amp;attach_rel_module=post&amp;attach_id=14199" rel="lightbox[58923]"><img src="http://support.emsisoft.com/uploads/monthly_09_2012/post-23145-0-93381100-1348686052_thumb.png" alt="System Progressive Protection 4.png" width="100" height="76" /></a></p>
<p><strong>How to remove the System Progressive Protection (<a title="External link" href="http://www.emsisoft.com/en/malware/?Rogue.Win32.SystemProtection" rel="external">Rogue.Win32.SystemProtection</a>)?</strong></p>
<p>To remove this malware infection, please download and install <strong><a title="External link" href="http://www.emsisoft.com/en/software/antimalware/" rel="external">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/10/19/file-restore-rogue-removal-instructions/"     class="crp_title">File Restore Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/"     class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/"     class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/"     class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/"     class="crp_title">Windows Security System Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/10/13/system-progressive-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Series Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 15 Aug 2012 11:16:31 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Series]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6207</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Series. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetySeries. Windows Safety Series is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/"     class="crp_title">Windows Recovery Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/"     class="crp_title">Windows Expert Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Series</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetySeries" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetySeries" target="_blank"><strong>Rogue.Win32.WindowsSafetySeries.</strong></a></p>
<p><strong>Windows Safety Series</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Series.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Series.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/rogue-win32-windowssafetyseries_1/" rel="attachment wp-att-6208"><img class="alignnone size-medium wp-image-6208" title="Rogue.Win32.WindowsSafetySeries" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSafetySeries_1-400x234.png" alt="Rogue.Win32.WindowsSafetySeries" width="400" height="234" /></a></p>
<div><a href="http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/rogue-win32-windowssafetyseries_2/" rel="attachment wp-att-6209"><img class="alignnone size-medium wp-image-6209" title="Rogue.Win32.WindowsSafetySeries" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSafetySeries_2-400x293.png" alt="Rogue.Win32.WindowsSafetySeries" width="400" height="293" /></a></div>
<div><a href="http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/rogue-win32-windowssafetyseries_3/" rel="attachment wp-att-6210"><img class="alignnone size-medium wp-image-6210" title="Rogue.Win32.WindowsSafetySeries" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSafetySeries_3-400x293.png" alt="Rogue.Win32.WindowsSafetySeries" width="400" height="293" /></a></div>
<div>
<p><a href="http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/rogue-win32-windowssafetyseries_4/" rel="attachment wp-att-6211"><img class="alignnone size-medium wp-image-6211" title="Rogue.Win32.WindowsSafetySeries" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSafetySeries_4-400x293.png" alt="Rogue.Win32.WindowsSafetySeries" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Safety Series (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetySeries" target="_blank">Rogue.Win32.WindowsSafetySeries</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/"     class="crp_title">Windows Recovery Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/"     class="crp_title">Windows Expert Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Secure Workshop Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 14 Aug 2012 17:12:27 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Secure Workshop]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6198</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Secure Workshop. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSecureWorkshop. Windows Secure Workshop is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/"     class="crp_title">Windows Secure Surfer Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/"     class="crp_title">Windows Secure Web Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Secure Workshop</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSecureWorkshop" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureWorkshop" target="_blank"><strong>Rogue.Win32.WindowsSecureWorkshop.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Secure Workshop</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Secure Workshop.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Secure Workshop.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/rogue-win32-windowssecureworkstation_1/" rel="attachment wp-att-6199"><img class="alignnone size-medium wp-image-6199" title="Rogue.Win32.WindowsSecureWorkstation" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSecureWorkstation_1-400x234.png" alt="Rogue.Win32.WindowsSecureWorkstation" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/rogue-win32-windowssecureworkstation_2/" rel="attachment wp-att-6200"><img class="alignnone size-medium wp-image-6200" title="Rogue.Win32.WindowsSecureWorkstation" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSecureWorkstation_2-400x293.png" alt="Rogue.Win32.WindowsSecureWorkstation" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/rogue-win32-windowssecureworkstation_3/" rel="attachment wp-att-6201"><img class="alignnone size-medium wp-image-6201" title="Rogue.Win32.WindowsSecureWorkstation" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSecureWorkstation_3-400x293.png" alt="Rogue.Win32.WindowsSecureWorkstation" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/rogue-win32-windowssecureworkstation_4/" rel="attachment wp-att-6202"><img class="alignnone size-medium wp-image-6202" title="Rogue.Win32.WindowsSecureWorkstation" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSecureWorkstation_4-400x238.png" alt="Rogue.Win32.WindowsSecureWorkstation" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/rogue-win32-windowssecureworkstation_5/" rel="attachment wp-att-6203"><img class="alignnone size-medium wp-image-6203" title="Rogue.Win32.WindowsSecureWorkstation" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsSecureWorkstation_5-400x293.png" alt="Rogue.Win32.WindowsSecureWorkstation" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Secure Workshop (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureWorkshop" target="_blank">Rogue.Win32.WindowsSecureWorkshop</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/"     class="crp_title">Windows Secure Surfer Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/"     class="crp_title">Windows Secure Web Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/14/windows-secure-workshop-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Anti-Malware Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 13 Aug 2012 09:50:28 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Anti-Malware Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6189</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Anti-Malware Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntiMalwarePatch. Windows Anti-Malware Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/"     class="crp_title">Windows Ultimate Security Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/"     class="crp_title">Windows Secure Web Patch Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Anti-Malware Patch</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntiMalwarePatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiMalwarePatch" target="_blank"><strong>Rogue.Win32.WindowsAntiMalwarePatch.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Anti-Malware Patch</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Anti-Malware Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Anti-Malware Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/rogue-win32-windowsantimalwarepatch_1/" rel="attachment wp-att-6190"><img class="alignnone size-medium wp-image-6190" title="Rogue.Win32.WindowsAntiMalwarePatch" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntiMalwarePatch_1-400x234.png" alt="Rogue.Win32.WindowsAntiMalwarePatch" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/rogue-win32-windowsantimalwarepatch_2/" rel="attachment wp-att-6191"><img class="alignnone size-medium wp-image-6191" title="Rogue.Win32.WindowsAntiMalwarePatch" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntiMalwarePatch_2-400x293.png" alt="Rogue.Win32.WindowsAntiMalwarePatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/rogue-win32-windowsantimalwarepatch_3/" rel="attachment wp-att-6192"><img class="alignnone size-medium wp-image-6192" title="Rogue.Win32.WindowsAntiMalwarePatch" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntiMalwarePatch_3-400x293.png" alt="Rogue.Win32.WindowsAntiMalwarePatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/rogue-win32-windowsantimalwarepatch_4/" rel="attachment wp-att-6193"><img class="alignnone size-medium wp-image-6193" title="Rogue.Win32.WindowsAntiMalwarePatch" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntiMalwarePatch_4-400x293.png" alt="Rogue.Win32.WindowsAntiMalwarePatch" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Anti-Malware Patch (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiMalwarePatch" target="_blank">Rogue.Win32.WindowsAntiMalwarePatch</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/"     class="crp_title">Windows Ultimate Security Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/"     class="crp_title">Windows Secure Web Patch Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/13/windows-anti-malware-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Virtual Security Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 10 Aug 2012 12:21:06 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Virtual Security]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6180</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Virtual Security. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsVirtualSecurity. Windows Virtual Security is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/"     class="crp_title">Windows Virtual Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/"     class="crp_title">Windows Virtual Angel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Virtual Security</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsVirtualSecurity" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirtualSecurity" target="_blank"><strong>Rogue.Win32.WindowsVirtualSecurity.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Virtual Security</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Virtual Security.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Virtual Security.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/rogue-win32-windowsvirtualsecurity_1/" rel="attachment wp-att-6181"><img class="alignnone size-medium wp-image-6181" title="Rogue.Win32.WindowsVirtualSecurity" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsVirtualSecurity_1-400x234.png" alt="Rogue.Win32.WindowsVirtualSecurity" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/rogue-win32-windowsvirtualsecurity_2/" rel="attachment wp-att-6182"><img class="alignnone size-medium wp-image-6182" title="Rogue.Win32.WindowsVirtualSecurity" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsVirtualSecurity_2-400x293.png" alt="Rogue.Win32.WindowsVirtualSecurity" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/rogue-win32-windowsvirtualsecurity_3/" rel="attachment wp-att-6183"><img class="alignnone size-medium wp-image-6183" title="Rogue.Win32.WindowsVirtualSecurity" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsVirtualSecurity_3-400x293.png" alt="Rogue.Win32.WindowsVirtualSecurity" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/rogue-win32-windowsvirtualsecurity_4/" rel="attachment wp-att-6184"><img class="alignnone size-medium wp-image-6184" title="Rogue.Win32.WindowsVirtualSecurity" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsVirtualSecurity_4-400x293.png" alt="Rogue.Win32.WindowsVirtualSecurity" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/rogue-win32-windowsvirtualsecurity_5/" rel="attachment wp-att-6185"><img class="alignnone size-medium wp-image-6185" title="Rogue.Win32.WindowsVirtualSecurity" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsVirtualSecurity_5-400x293.png" alt="Rogue.Win32.WindowsVirtualSecurity" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Virtual Security (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirtualSecurity" target="_blank">Rogue.Win32.WindowsVirtualSecurity</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/"     class="crp_title">Windows Virtual Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/"     class="crp_title">Windows Virtual Angel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Interactive Safety Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 09 Aug 2012 07:10:29 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Interactive Safety]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6172</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Interactive Safety. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsInteractiveSafety. Windows Interactive Safety is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Interactive Safety</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsInteractiveSafety" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInteractiveSafety" target="_blank"><strong>Rogue.Win32.WindowsInteractiveSafety.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Interactive Safety</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Interactive Safety.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Interactive Safety.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/rogue-win32-windowsinteractivesafety_1/" rel="attachment wp-att-6173"><img class="alignnone size-medium wp-image-6173" title="Rogue.Win32.WindowsInteractiveSafety" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsInteractiveSafety_1-400x234.png" alt="Rogue.Win32.WindowsInteractiveSafety" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/rogue-win32-windowsinteractivesafety_2/" rel="attachment wp-att-6174"><img class="alignnone size-medium wp-image-6174" title="Rogue.Win32.WindowsInteractiveSafety" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsInteractiveSafety_2-400x293.png" alt="Rogue.Win32.WindowsInteractiveSafety" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/rogue-win32-windowsinteractivesafety_3/" rel="attachment wp-att-6175"><img class="alignnone size-medium wp-image-6175" title="Rogue.Win32.WindowsInteractiveSafety" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsInteractiveSafety_3-400x293.png" alt="Rogue.Win32.WindowsInteractiveSafety" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/rogue-win32-windowsinteractivesafety_4/" rel="attachment wp-att-6176"><img class="alignnone size-medium wp-image-6176" title="Rogue.Win32.WindowsInteractiveSafety" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsInteractiveSafety_4-400x293.png" alt="Rogue.Win32.WindowsInteractiveSafety" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Interactive Safety (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInteractiveSafety" target="_blank">Rogue.Win32.WindowsInteractiveSafety</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antivirus Release Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 08 Aug 2012 18:41:29 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antivirus Release]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6164</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antivirus Release. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntivirusRelease. Windows Antivirus Release is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Rampart Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Machine Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Antivirus Release</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntivirusRelease" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusRelease" target="_blank"><strong>Rogue.Win32.WindowsAntivirusRelease.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Antivirus Release</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antivirus Release.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antivirus Release.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/rogue-win32-windowsantivirusrelease_1/" rel="attachment wp-att-6165"><img class="alignnone size-medium wp-image-6165" title="Rogue.Win32.WindowsAntivirusRelease" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusRelease_1-400x234.png" alt="Rogue.Win32.WindowsAntivirusRelease" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/rogue-win32-windowsantivirusrelease_2/" rel="attachment wp-att-6166"><img class="alignnone size-medium wp-image-6166" title="Rogue.Win32.WindowsAntivirusRelease" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusRelease_2-400x293.png" alt="Rogue.Win32.WindowsAntivirusRelease" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/rogue-win32-windowsantivirusrelease_3/" rel="attachment wp-att-6167"><img class="alignnone size-medium wp-image-6167" title="Rogue.Win32.WindowsAntivirusRelease" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusRelease_3-400x293.png" alt="Rogue.Win32.WindowsAntivirusRelease" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/rogue-win32-windowsantivirusrelease_4/" rel="attachment wp-att-6168"><img class="alignnone size-medium wp-image-6168" title="Rogue.Win32.WindowsAntivirusRelease" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusRelease_4-400x293.png" alt="Rogue.Win32.WindowsAntivirusRelease" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Antivirus Release (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusRelease" target="_blank">Rogue.Win32.WindowsAntivirusRelease</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Rampart Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Machine Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Ultimate Safeguard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 06 Aug 2012 12:19:00 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Ultimate Safeguard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6157</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Ultimate Safeguard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsUltimateSafeguard. Windows Ultimate Safeguard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/"     class="crp_title">Windows Ultimate Security Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/"     class="crp_title">Windows Safeguard Upgrade Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Ultimate Safeguard</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsUltimateSafeguard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUltimateSafeguard" target="_blank"><strong>Rogue.Win32.WindowsUltimateSafeguard.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Ultimate Safeguard</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Ultimate Safeguard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Ultimate Safeguard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/rogue-win32-windowsultimatesafeguard_1/" rel="attachment wp-att-6158"><img class="alignnone size-medium wp-image-6158" title="Rogue.Win32.WindowsUltimateSafeguard" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsUltimateSafeguard_1-400x234.png" alt="Rogue.Win32.WindowsUltimateSafeguard" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/rogue-win32-windowsultimatesafeguard_2/" rel="attachment wp-att-6159"><img class="alignnone size-medium wp-image-6159" title="Rogue.Win32.WindowsUltimateSafeguard" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsUltimateSafeguard_2-400x293.png" alt="Rogue.Win32.WindowsUltimateSafeguard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/rogue-win32-windowsultimatesafeguard_3/" rel="attachment wp-att-6160"><img class="alignnone size-medium wp-image-6160" title="Rogue.Win32.WindowsUltimateSafeguard" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsUltimateSafeguard_3-400x293.png" alt="Rogue.Win32.WindowsUltimateSafeguard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/rogue-win32-windowsultimatesafeguard_4/" rel="attachment wp-att-6161"><img class="alignnone size-medium wp-image-6161" title="Rogue.Win32.WindowsUltimateSafeguard" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsUltimateSafeguard_4-400x293.png" alt="Rogue.Win32.WindowsUltimateSafeguard" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Ultimate Safeguard (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUltimateSafeguard" target="_blank">Rogue.Win32.WindowsUltimateSafeguard</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/"     class="crp_title">Windows Ultimate Security Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/"     class="crp_title">Windows Safeguard Upgrade Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/06/windows-ultimate-safeguard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Ultra-Antivirus Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/02/windows-ultra-antivirus-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/02/windows-ultra-antivirus-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 02 Aug 2012 14:41:37 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Ultra-Antivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6150</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Ultra-Antivirus. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsUltraAntivirus. Windows Ultra Antivirus is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/"     class="crp_title">Windows Security System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/"     class="crp_title">Super AV Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/"     class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/08/09/antivirus-2010-adware-removal-instructions/"     class="crp_title">Antivirus 2010 Adware Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Ultra-Antivirus</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsUltraAntivirus" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUltraAntivirus" target="_blank"><strong>Rogue.Win32.WindowsUltraAntivirus.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Ultra Antivirus</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\drivers\[random].sys</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\[random]\<br />
Type = 0&#215;01000000<br />
Start = 0&#215;01000000<br />
DisplayName = &#8220;%MalwareFileName%&#8221;<br />
ImagePath = &#8220;C:\WINDOWS\system32\drivers\[random].sys&#8221;</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\run\<br />
wazibtuqtugp = %MalwareFilePath%</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\WinUltraAntivirus\</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/02/windows-ultra-antivirus-rogue-removal-instructions/rogue-win32-windowsultraantivirus_1/" rel="attachment wp-att-6151"><img class="alignnone size-medium wp-image-6151" title="Rogue.Win32.WindowsUltraAntivirus" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsUltraAntivirus_1-400x337.png" alt="Rogue.Win32.WindowsUltraAntivirus" width="400" height="337" /></a></p>
<p><strong>How to remove the infection of Windows Ultra Antivirus (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUltraAntivirus" target="_blank">Rogue.Win32.WindowsUltraAntivirus</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/"     class="crp_title">Windows Security System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/"     class="crp_title">Super AV Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/"     class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/08/09/antivirus-2010-adware-removal-instructions/"     class="crp_title">Antivirus 2010 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/02/windows-ultra-antivirus-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antivirus Machine Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 02 Aug 2012 14:21:05 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antivirus Machine]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6140</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antivirus Machine. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntivirusMachine. Windows Antivirus Machine is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Rampart Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Antivirus Machine</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntivirusMachine" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusMachine" target="_blank"><strong>Rogue.Win32.WindowsAntivirusMachine.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Antivirus Machine</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antivirus Machine.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antivirus Machine.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/rogue-win32-windowsantivirusmachine_1/" rel="attachment wp-att-6141"><img class="alignnone size-medium wp-image-6141" title="Rogue.Win32.WindowsAntivirusMachine" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusMachine_1-400x234.png" alt="Rogue.Win32.WindowsAntivirusMachine" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/rogue-win32-windowsantivirusmachine_2/" rel="attachment wp-att-6142"><img class="alignnone size-medium wp-image-6142" title="Rogue.Win32.WindowsAntivirusMachine" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusMachine_2-400x293.png" alt="Rogue.Win32.WindowsAntivirusMachine" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/rogue-win32-windowsantivirusmachine_3/" rel="attachment wp-att-6143"><img class="alignnone size-medium wp-image-6143" title="Rogue.Win32.WindowsAntivirusMachine" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusMachine_3-400x293.png" alt="Rogue.Win32.WindowsAntivirusMachine" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/rogue-win32-windowsantivirusmachine_4/" rel="attachment wp-att-6144"><img class="alignnone size-medium wp-image-6144" title="Rogue.Win32.WindowsAntivirusMachine" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusMachine_4-400x238.png" alt="Rogue.Win32.WindowsAntivirusMachine" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/rogue-win32-windowsantivirusmachine_5/" rel="attachment wp-att-6145"><img class="alignnone size-medium wp-image-6145" title="Rogue.Win32.WindowsAntivirusMachine" src="http://www.anti-malware-blog.com/files/2012/08/Rogue.Win32.WindowsAntivirusMachine_5-400x293.png" alt="Rogue.Win32.WindowsAntivirusMachine" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Antivirus Machine (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusMachine" target="_blank">Rogue.Win32.WindowsAntivirusMachine</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Rampart Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/08/windows-antivirus-release-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/08/02/windows-antivirus-machine-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Virtual Firewall Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 Jul 2012 19:03:32 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Virtual Firewall]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6132</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Virtual Firewall. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsVirtualFirewall. Windows Virtual Firewall is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/"     class="crp_title">Windows Firewall Constructor Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/"     class="crp_title">Windows Virtual Angel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Virtual Firewall</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsVirtualFirewall" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirtualFirewall" target="_blank"><strong>Rogue.Win32.WindowsVirtualFirewall.</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Virtual Firewall</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Virtual Firewall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Virtual Firewall.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/rogue-win32-windowsvirtualfirewall_1/" rel="attachment wp-att-6133"><img class="alignnone size-medium wp-image-6133" title="Rogue.Win32.WindowsVirtualFirewall" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualFirewall_1-400x234.png" alt="Rogue.Win32.WindowsVirtualFirewall" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/rogue-win32-windowsvirtualfirewall_2/" rel="attachment wp-att-6134"><img class="alignnone size-medium wp-image-6134" title="Rogue.Win32.WindowsVirtualFirewall" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualFirewall_2-400x293.png" alt="Rogue.Win32.WindowsVirtualFirewall" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/rogue-win32-windowsvirtualfirewall_3/" rel="attachment wp-att-6135"><img class="alignnone size-medium wp-image-6135" title="Rogue.Win32.WindowsVirtualFirewall" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualFirewall_3-400x293.png" alt="Rogue.Win32.WindowsVirtualFirewall" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/rogue-win32-windowsvirtualfirewall_4/" rel="attachment wp-att-6136"><img class="alignnone size-medium wp-image-6136" title="Rogue.Win32.WindowsVirtualFirewall" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualFirewall_4-400x293.png" alt="Rogue.Win32.WindowsVirtualFirewall" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Virtual Firewall (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirtualFirewall" target="_blank">Rogue.Win32.WindowsVirtualFirewall</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/"     class="crp_title">Windows Firewall Constructor Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/"     class="crp_title">Windows Virtual Angel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Home Patron Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 Jul 2012 18:52:11 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Home Patron]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6124</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Home Patron. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsHomePatron Windows Home Patron is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Home Patron</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsHomePatron" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHomePatron" target="_blank"><strong>Rogue.Win32.WindowsHomePatron</strong></a></p>
<p><strong>Windows Home Patron</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Home Patron.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Home Patron.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/rogue-win32-windowshomepatron_1/" rel="attachment wp-att-6125"><img class="alignnone size-medium wp-image-6125" title="Rogue.Win32.WindowsHomePatron" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsHomePatron_1-400x234.png" alt="Rogue.Win32.WindowsHomePatron" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/rogue-win32-windowshomepatron_2/" rel="attachment wp-att-6126"><img class="alignnone size-medium wp-image-6126" title="Rogue.Win32.WindowsHomePatron" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsHomePatron_2-400x293.png" alt="Rogue.Win32.WindowsHomePatron" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/rogue-win32-windowshomepatron_3/" rel="attachment wp-att-6127"><img class="alignnone size-medium wp-image-6127" title="Rogue.Win32.WindowsHomePatron" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsHomePatron_3-400x293.png" alt="Rogue.Win32.WindowsHomePatron" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/rogue-win32-windowshomepatron_4/" rel="attachment wp-att-6128"><img class="alignnone size-medium wp-image-6128" title="Rogue.Win32.WindowsHomePatron" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsHomePatron_4-400x238.png" alt="Rogue.Win32.WindowsHomePatron" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/rogue-win32-windowshomepatron_5/" rel="attachment wp-att-6129"><img class="alignnone size-medium wp-image-6129" title="Rogue.Win32.WindowsHomePatron" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsHomePatron_5-400x293.png" alt="Rogue.Win32.WindowsHomePatron" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Home Patron (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHomePatron" target="_blank">Rogue.Win32.WindowsHomePatron</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/27/windows-home-patron-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Security System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 Jul 2012 18:45:17 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Security System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6118</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Security  System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSecuritySystem Windows Security  System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/"     class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/"     class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/"     class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/02/windows-ultra-antivirus-rogue-removal-instructions/"     class="crp_title">Windows Ultra-Antivirus Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Security  System</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSecuritySystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecuritySystem" target="_blank"><strong>Rogue.Win32.WindowsSecuritySystem</strong></a></p>
<p><strong></strong><strong><strong><strong><strong>Windows Security  System</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\wss\</li>
<li>%ProgramFiles%\wss\Windows Security System.exe</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Windows Security System.lnk</li>
<li>%UserProfile%\Desktop\Windows Security System.lnk</li>
<li>%UserProfile%\Start Menu\Windows Security System\</li>
<li>%UserProfile%\Start Menu\Windows Security System\Windows Security System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Windows Security System<br />
%ProgramFiles%\wss\Windows Security System.exe</li>
<li>HKEY_CURRENT_USER\Software\[random]</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/rogue-win32-windowssecuritysystem_1/" rel="attachment wp-att-6119"><img class="alignnone size-medium wp-image-6119" title="Rogue.Win32.WindowsSecuritySystem" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecuritySystem_1-400x318.png" alt="Rogue.Win32.WindowsSecuritySystem" width="400" height="318" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/rogue-win32-windowssecuritysystem_2/" rel="attachment wp-att-6120"><img class="alignnone size-medium wp-image-6120" title="Rogue.Win32.WindowsSecuritySystem" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecuritySystem_2-280x400.png" alt="Rogue.Win32.WindowsSecuritySystem" width="280" height="400" /></a></p>
<p><strong>How to remove the infection of Windows Security System (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecuritySystem" target="_blank">Rogue.Win32.WindowsSecuritySystem</a>)?</strong></p>
<p><strong></strong>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/"     class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/"     class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/"     class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/02/windows-ultra-antivirus-rogue-removal-instructions/"     class="crp_title">Windows Ultra-Antivirus Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/27/windows-security-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Active Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Jul 2012 12:45:03 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Active Guard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=6108</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Active Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsActiveGuard Windows Active Guard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/"     class="crp_title">Windows Active Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/"     class="crp_title">Windows Guard Tools Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Active Guard</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsActiveGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActiveGuard" target="_blank"><strong>Rogue.Win32.WindowsActiveGuard</strong></a></p>
<p><strong>Windows Active Guard</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Active Guard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Active Guard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/rogue-win32-windowsactiveguard_1/" rel="attachment wp-att-6109"><img class="alignnone size-medium wp-image-6109" title="Rogue.Win32.WindowsActiveGuard" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsActiveGuard_1-400x234.png" alt="Rogue.Win32.WindowsActiveGuard" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/rogue-win32-windowsactiveguard_2/" rel="attachment wp-att-6110"><img class="alignnone size-medium wp-image-6110" title="Rogue.Win32.WindowsActiveGuard" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsActiveGuard_2-400x293.png" alt="Rogue.Win32.WindowsActiveGuard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/rogue-win32-windowsactiveguard_3/" rel="attachment wp-att-6111"><img class="alignnone size-medium wp-image-6111" title="Rogue.Win32.WindowsActiveGuard" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsActiveGuard_3-400x293.png" alt="Rogue.Win32.WindowsActiveGuard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/rogue-win32-windowsactiveguard_4/" rel="attachment wp-att-6112"><img class="alignnone size-medium wp-image-6112" title="Rogue.Win32.WindowsActiveGuard" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsActiveGuard_4-400x238.png" alt="Rogue.Win32.WindowsActiveGuard" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/rogue-win32-windowsactiveguard_5/" rel="attachment wp-att-6113"><img class="alignnone size-medium wp-image-6113" title="Rogue.Win32.WindowsActiveGuard" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsActiveGuard_5-400x325.png" alt="Rogue.Win32.WindowsActiveGuard" width="400" height="325" /></a></p>
<p><a href="http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/rogue-win32-windowsactiveguard_6/" rel="attachment wp-att-6114"><img class="alignnone size-medium wp-image-6114" title="Rogue.Win32.WindowsActiveGuard" src="http://www.anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsActiveGuard_6-400x293.png" alt="Rogue.Win32.WindowsActiveGuard" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Active Guard (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActiveGuard" target="_blank">Rogue.Win32.WindowsActiveGuard</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/"     class="crp_title">Windows Active Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/"     class="crp_title">Windows Guard Tools Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/25/windows-active-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Security Renewal Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 20 Jul 2012 09:40:29 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Security Renewal]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6098</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Security Renewal. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSecurityRenewal. Windows Security Renewal is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Security Renewal</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSecurityRenewal" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityRenewal" target="_blank"><strong>Rogue.Win32.WindowsSecurityRenewal</strong></a><strong>.</strong></p>
<p><strong>Windows Security Renewal</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Security Renewal.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Security Renewal.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/rogue-win32-windowssecurityrenewal_1/" rel="attachment wp-att-6099"><img class="alignnone size-medium wp-image-6099" title="Rogue.Win32.WindowsSecurityRenewal" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecurityRenewal_1-400x234.png" alt="Rogue.Win32.WindowsSecurityRenewal" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/rogue-win32-windowssecurityrenewal_2/" rel="attachment wp-att-6100"><img class="alignnone size-medium wp-image-6100" title="Rogue.Win32.WindowsSecurityRenewal" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecurityRenewal_2-400x293.png" alt="Rogue.Win32.WindowsSecurityRenewal" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/rogue-win32-windowssecurityrenewal_3/" rel="attachment wp-att-6101"><img class="alignnone size-medium wp-image-6101" title="Rogue.Win32.WindowsSecurityRenewal" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecurityRenewal_3-400x293.png" alt="Rogue.Win32.WindowsSecurityRenewal" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/rogue-win32-windowssecurityrenewal_4/" rel="attachment wp-att-6102"><img class="alignnone size-medium wp-image-6102" title="Rogue.Win32.WindowsSecurityRenewal" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecurityRenewal_4-400x238.png" alt="Rogue.Win32.WindowsSecurityRenewal" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/rogue-win32-windowssecurityrenewal_5/" rel="attachment wp-att-6103"><img class="alignnone size-medium wp-image-6103" title="Rogue.Win32.WindowsSecurityRenewal" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecurityRenewal_5-400x325.png" alt="Rogue.Win32.WindowsSecurityRenewal" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/rogue-win32-windowssecurityrenewal_6/" rel="attachment wp-att-6104"><img class="alignnone size-medium wp-image-6104" title="Rogue.Win32.WindowsSecurityRenewal" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsSecurityRenewal_6-400x293.png" alt="Rogue.Win32.WindowsSecurityRenewal" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Security Renewal (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityRenewal" target="_blank">Rogue.Win32.WindowsSecurityRenewal</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/20/windows-security-renewal-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Web Combat Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 19 Jul 2012 09:33:41 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Web Combat]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6089</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Web Combat. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsWebCombat. Windows Web Combat is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Web Combat</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsWebCombat" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWebCombat" target="_blank"><strong>Rogue.Win32.WindowsWebCombat</strong></a><strong>.</strong></p>
<p><strong>Windows Web Combat</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Web Combat.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Web Combat.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/rogue-win32-windowswebcombat_1/" rel="attachment wp-att-6090"><img class="alignnone size-medium wp-image-6090" title="Rogue.Win32.WindowsWebCombat" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCombat_1-400x234.png" alt="Rogue.Win32.WindowsWebCombat" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/rogue-win32-windowswebcombat_2/" rel="attachment wp-att-6091"><img class="alignnone size-medium wp-image-6091" title="Rogue.Win32.WindowsWebCombat" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCombat_2-400x293.png" alt="Rogue.Win32.WindowsWebCombat" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/rogue-win32-windowswebcombat_3/" rel="attachment wp-att-6092"><img class="alignnone size-medium wp-image-6092" title="Rogue.Win32.WindowsWebCombat" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCombat_3-400x293.png" alt="Rogue.Win32.WindowsWebCombat" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/rogue-win32-windowswebcombat_4/" rel="attachment wp-att-6093"><img class="alignnone size-medium wp-image-6093" title="Rogue.Win32.WindowsWebCombat" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCombat_4-400x238.png" alt="Rogue.Win32.WindowsWebCombat" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/rogue-win32-windowswebcombat_5/" rel="attachment wp-att-6094"><img class="alignnone size-medium wp-image-6094" title="Rogue.Win32.WindowsWebCombat" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCombat_5-400x325.png" alt="Rogue.Win32.WindowsWebCombat" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/rogue-win32-windowswebcombat_6/" rel="attachment wp-att-6095"><img class="alignnone size-medium wp-image-6095" title="Rogue.Win32.WindowsWebCombat" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCombat_6-400x293.png" alt="Rogue.Win32.WindowsWebCombat" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Web Combat (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWebCombat" target="_blank">Rogue.Win32.WindowsWebCombat</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/19/windows-web-combat-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Virtual Angel Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 19 Jul 2012 09:29:41 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Virtual Angel]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6080</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Virtual Angel. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsVirtualAngel. Windows Virtual Angel is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/"     class="crp_title">Windows Guardian Angel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/"     class="crp_title">Windows Virtual Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Virtual Angel</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsVirtualAngel" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirtualAngel" target="_blank"><strong>Rogue.Win32.WindowsVirtualAngel</strong></a><strong>.</strong></p>
<p><strong>Windows Virtual Angel</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Virtual Angel.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Virtual Angel.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/rogue-win32-windowsvirtualangel_1/" rel="attachment wp-att-6081"><img class="alignnone size-medium wp-image-6081" title="Rogue.Win32.WindowsVirtualAngel" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualAngel_1-400x234.png" alt="Rogue.Win32.WindowsVirtualAngel" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/rogue-win32-windowsvirtualangel_2/" rel="attachment wp-att-6082"><img class="alignnone size-medium wp-image-6082" title="Rogue.Win32.WindowsVirtualAngel" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualAngel_2-400x293.png" alt="Rogue.Win32.WindowsVirtualAngel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/rogue-win32-windowsvirtualangel_3/" rel="attachment wp-att-6083"><img class="alignnone size-medium wp-image-6083" title="Rogue.Win32.WindowsVirtualAngel" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualAngel_3-400x293.png" alt="Rogue.Win32.WindowsVirtualAngel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/rogue-win32-windowsvirtualangel_4/" rel="attachment wp-att-6084"><img class="alignnone size-medium wp-image-6084" title="Rogue.Win32.WindowsVirtualAngel" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualAngel_4-400x238.png" alt="Rogue.Win32.WindowsVirtualAngel" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/rogue-win32-windowsvirtualangel_5/" rel="attachment wp-att-6085"><img class="alignnone size-medium wp-image-6085" title="Rogue.Win32.WindowsVirtualAngel" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualAngel_5-400x325.png" alt="Rogue.Win32.WindowsVirtualAngel" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/rogue-win32-windowsvirtualangel_6/" rel="attachment wp-att-6086"><img class="alignnone size-medium wp-image-6086" title="Rogue.Win32.WindowsVirtualAngel" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirtualAngel_6-400x293.png" alt="Rogue.Win32.WindowsVirtualAngel" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Virtual Angel (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirtualAngel" target="_blank">Rogue.Win32.WindowsVirtualAngel</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/"     class="crp_title">Windows Guardian Angel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/07/27/windows-virtual-firewall-rogue-removal-instructions/"     class="crp_title">Windows Virtual Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/19/windows-virtual-angel-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Premium Defender Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 19 Jul 2012 09:18:23 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Premium Defender]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6073</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Premium Defender. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPremiumDefender. Windows Premium Defender is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/"     class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/"     class="crp_title">Windows Active Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Premium Defender</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPremiumDefender" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPremiumDefender" target="_blank"><strong>Rogue.Win32.WindowsPremiumDefender</strong></a><strong>.</strong></p>
<p><strong>Windows Premium Defender</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Premium Defender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Premium Defender.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/rogue-win32-windowspremiumdefender_1/" rel="attachment wp-att-6074"><img class="alignnone size-medium wp-image-6074" title="Rogue.Win32.WindowsPremiumDefender" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsPremiumDefender_1-400x234.png" alt="Rogue.Win32.WindowsPremiumDefender" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/rogue-win32-windowspremiumdefender_2/" rel="attachment wp-att-6075"><img class="alignnone size-medium wp-image-6075" title="Rogue.Win32.WindowsPremiumDefender" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsPremiumDefender_2-400x293.png" alt="Rogue.Win32.WindowsPremiumDefender" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/rogue-win32-windowspremiumdefender_3/" rel="attachment wp-att-6076"><img class="alignnone size-medium wp-image-6076" title="Rogue.Win32.WindowsPremiumDefender" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsPremiumDefender_3-400x293.png" alt="Rogue.Win32.WindowsPremiumDefender" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/rogue-win32-windowspremiumdefender_4/" rel="attachment wp-att-6077"><img class="alignnone size-medium wp-image-6077" title="Rogue.Win32.WindowsPremiumDefender" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsPremiumDefender_4-400x293.png" alt="Rogue.Win32.WindowsPremiumDefender" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Premium Defender (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPremiumDefender" target="_blank">Rogue.Win32.WindowsPremiumDefender</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/"     class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/"     class="crp_title">Windows Active Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/19/windows-premium-defender-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Profound Security Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 11 Jul 2012 03:23:04 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Profound Security]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6063</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Profound Security. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProfoundSecurity. Windows Profound Security is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Profound Security</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProfoundSecurity" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProfoundSecurity" target="_blank"><strong>Rogue.Win32.WindowsProfoundSecurity</strong></a><strong>.</strong></p>
<p><strong>Windows Profound Security</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Profound Security.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Profound Security.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/rogue-win32-windowsprofoundsecurity_1/" rel="attachment wp-att-6064"><img class="alignnone size-medium wp-image-6064" title="Rogue.Win32.WindowsProfoundSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProfoundSecurity_1-400x234.png" alt="Rogue.Win32.WindowsProfoundSecurity" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/rogue-win32-windowsprofoundsecurity_2/" rel="attachment wp-att-6065"><img class="alignnone size-medium wp-image-6065" title="Rogue.Win32.WindowsProfoundSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProfoundSecurity_2-400x293.png" alt="Rogue.Win32.WindowsProfoundSecurity" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/rogue-win32-windowsprofoundsecurity_3/" rel="attachment wp-att-6066"><img class="alignnone size-medium wp-image-6066" title="Rogue.Win32.WindowsProfoundSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProfoundSecurity_3-400x293.png" alt="Rogue.Win32.WindowsProfoundSecurity" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/rogue-win32-windowsprofoundsecurity_4/" rel="attachment wp-att-6067"><img class="alignnone size-medium wp-image-6067" title="Rogue.Win32.WindowsProfoundSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProfoundSecurity_4-400x238.png" alt="Rogue.Win32.WindowsProfoundSecurity" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/rogue-win32-windowsprofoundsecurity_5/" rel="attachment wp-att-6068"><img class="alignnone size-medium wp-image-6068" title="Rogue.Win32.WindowsProfoundSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProfoundSecurity_5-400x325.png" alt="Rogue.Win32.WindowsProfoundSecurity" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/rogue-win32-windowsprofoundsecurity_6/" rel="attachment wp-att-6069"><img class="alignnone size-medium wp-image-6069" title="Rogue.Win32.WindowsProfoundSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProfoundSecurity_6-400x293.png" alt="Rogue.Win32.WindowsProfoundSecurity" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Profound Security (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProfoundSecurity" target="_blank">Rogue.Win32.WindowsProfoundSecurity</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/"     class="crp_title">Windows Interactive Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/10/windows-virtual-security-rogue-removal-instructions/"     class="crp_title">Windows Virtual Security Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/11/windows-profound-security-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Expert Series Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Jul 2012 12:34:07 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Expert Series]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6053</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Expert Series. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsExpertSeries. Windows Expert Series is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/"     class="crp_title">Windows Recovery Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/"     class="crp_title">Windows Safety Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Expert Series</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsExpertSeries" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpertSeries" target="_blank"><strong>Rogue.Win32.WindowsExpertSeries</strong></a><strong>.</strong></p>
<p><strong>Windows Expert Series</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Expert Series.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Expert Series.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/rogue-win32-windowsexpertseries_1/" rel="attachment wp-att-6054"><img class="alignnone size-medium wp-image-6054" title="Rogue.Win32.WindowsExpertSeries" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsExpertSeries_1-400x234.png" alt="Rogue.Win32.WindowsExpertSeries" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/rogue-win32-windowsexpertseries_2/" rel="attachment wp-att-6055"><img class="alignnone size-medium wp-image-6055" title="Rogue.Win32.WindowsExpertSeries" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsExpertSeries_2-400x293.png" alt="Rogue.Win32.WindowsExpertSeries" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/rogue-win32-windowsexpertseries_3/" rel="attachment wp-att-6056"><img class="alignnone size-medium wp-image-6056" title="Rogue.Win32.WindowsExpertSeries" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsExpertSeries_3-400x293.png" alt="Rogue.Win32.WindowsExpertSeries" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/rogue-win32-windowsexpertseries_4/" rel="attachment wp-att-6057"><img class="alignnone size-medium wp-image-6057" title="Rogue.Win32.WindowsExpertSeries" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsExpertSeries_4-400x238.png" alt="Rogue.Win32.WindowsExpertSeries" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/rogue-win32-windowsexpertseries_5/" rel="attachment wp-att-6058"><img class="alignnone size-medium wp-image-6058" title="Rogue.Win32.WindowsExpertSeries" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsExpertSeries_5-400x293.png" alt="Rogue.Win32.WindowsExpertSeries" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Expert Series (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpertSeries" target="_blank">Rogue.Win32.WindowsExpertSeries</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/"     class="crp_title">Windows Recovery Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/08/15/windows-safety-series-rogue-removal-instructions/"     class="crp_title">Windows Safety Series Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/09/windows-expert-series-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Virus Hunter Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 06 Jul 2012 08:48:47 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Virus Hunter]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6044</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Virus Hunter. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsVirusHunter. Windows Virus Hunter is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Virus Hunter</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsVirusHunter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirusHunter" target="_blank"><strong>Rogue.Win32.WindowsVirusHunter</strong></a><strong>.</strong></p>
<p><strong>Windows Virus Hunter</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Virus Hunter.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Virus Hunter.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/rogue-win32-windowsvirushunter_1/" rel="attachment wp-att-6045"><img class="alignnone size-medium wp-image-6045" title="Rogue.Win32.WindowsVirusHunter" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirusHunter_1-400x234.png" alt="Rogue.Win32.WindowsVirusHunter" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/rogue-win32-windowsvirushunter_2/" rel="attachment wp-att-6046"><img class="alignnone size-medium wp-image-6046" title="Rogue.Win32.WindowsVirusHunter" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirusHunter_2-400x293.png" alt="Rogue.Win32.WindowsVirusHunter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/rogue-win32-windowsvirushunter_3/" rel="attachment wp-att-6047"><img class="alignnone size-medium wp-image-6047" title="Rogue.Win32.WindowsVirusHunter" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirusHunter_3-400x293.png" alt="Rogue.Win32.WindowsVirusHunter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/rogue-win32-windowsvirushunter_4/" rel="attachment wp-att-6048"><img class="alignnone size-medium wp-image-6048" title="Rogue.Win32.WindowsVirusHunter" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirusHunter_4-400x238.png" alt="Rogue.Win32.WindowsVirusHunter" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/rogue-win32-windowsvirushunter_5/" rel="attachment wp-att-6049"><img class="alignnone size-medium wp-image-6049" title="Rogue.Win32.WindowsVirusHunter" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirusHunter_5-400x325.png" alt="Rogue.Win32.WindowsVirusHunter" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/rogue-win32-windowsvirushunter_6/" rel="attachment wp-att-6050"><img class="alignnone size-medium wp-image-6050" title="Rogue.Win32.WindowsVirusHunter" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsVirusHunter_6-400x293.png" alt="Rogue.Win32.WindowsVirusHunter" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Web Commander (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVirusHunter" target="_blank">Rogue.Win32.WindowsVirusHunter</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/06/windows-virus-hunter-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Web Commander Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 04 Jul 2012 09:14:31 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Web Commander]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6035</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Web Commander. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsWebCommander. Windows Web Commander is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Web Commander</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsWebCommander" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWebCommander" target="_blank"><strong>Rogue.Win32.WindowsWebCommander</strong></a><strong>.</strong></p>
<p><strong>Windows Web Commander</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Web Commander.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Web Commander.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/rogue-win32-windowswebcommander_1/" rel="attachment wp-att-6036"><img class="alignnone size-medium wp-image-6036" title="Rogue.Win32.WindowsWebCommander" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCommander_1-400x234.png" alt="Rogue.Win32.WindowsWebCommander" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/rogue-win32-windowswebcommander_2/" rel="attachment wp-att-6037"><img class="alignnone size-medium wp-image-6037" title="Rogue.Win32.WindowsWebCommander" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCommander_2-400x293.png" alt="Rogue.Win32.WindowsWebCommander" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/rogue-win32-windowswebcommander_3/" rel="attachment wp-att-6038"><img class="alignnone size-medium wp-image-6038" title="Rogue.Win32.WindowsWebCommander" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCommander_3-400x293.png" alt="Rogue.Win32.WindowsWebCommander" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/rogue-win32-windowswebcommander_4/" rel="attachment wp-att-6039"><img class="alignnone size-medium wp-image-6039" title="Rogue.Win32.WindowsWebCommander" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCommander_4-400x238.png" alt="Rogue.Win32.WindowsWebCommander" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/rogue-win32-windowswebcommander_5/" rel="attachment wp-att-6040"><img class="alignnone size-medium wp-image-6040" title="Rogue.Win32.WindowsWebCommander" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCommander_5-400x325.png" alt="Rogue.Win32.WindowsWebCommander" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/rogue-win32-windowswebcommander_6/" rel="attachment wp-att-6041"><img class="alignnone size-medium wp-image-6041" title="Rogue.Win32.WindowsWebCommander" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsWebCommander_6-400x293.png" alt="Rogue.Win32.WindowsWebCommander" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Web Commander (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWebCommander" target="_blank">Rogue.Win32.WindowsWebCommander</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/04/windows-web-commander-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Interactive Security Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Jul 2012 11:12:14 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Interactive Security]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6027</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Interactive Security. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsInteractiveSecurity. Windows Interactive Security is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/"     class="crp_title">Windows Interactive Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Interactive Security</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsInteractiveSecurity" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInteractiveSecurity" target="_blank"><strong>Rogue.Win32.WindowsInteractiveSecurity</strong></a><strong>.</strong></p>
<p><strong>Windows Interactive Security</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Interactive Security.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Interactive Security.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/rogue-win32-windowsinteractivesecurity_1/" rel="attachment wp-att-6028"><img class="alignnone size-medium wp-image-6028" title="Rogue.Win32.WindowsInteractiveSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsInteractiveSecurity_1-400x234.png" alt="Rogue.Win32.WindowsInteractiveSecurity" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/rogue-win32-windowsinteractivesecurity_2/" rel="attachment wp-att-6029"><img class="alignnone size-medium wp-image-6029" title="Rogue.Win32.WindowsInteractiveSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsInteractiveSecurity_2-400x293.png" alt="Rogue.Win32.WindowsInteractiveSecurity" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/rogue-win32-windowsinteractivesecurity_3/" rel="attachment wp-att-6030"><img class="alignnone size-medium wp-image-6030" title="Rogue.Win32.WindowsInteractiveSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsInteractiveSecurity_3-400x293.png" alt="Rogue.Win32.WindowsInteractiveSecurity" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/rogue-win32-windowsinteractivesecurity_4/" rel="attachment wp-att-6031"><img class="alignnone size-medium wp-image-6031" title="Rogue.Win32.WindowsInteractiveSecurity" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsInteractiveSecurity_4-400x293.png" alt="Rogue.Win32.WindowsInteractiveSecurity" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Interactive Security (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInteractiveSecurity" target="_blank">Rogue.Win32.WindowsInteractiveSecurity</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/08/09/windows-interactive-safety-rogue-removal-instructions/"     class="crp_title">Windows Interactive Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/02/windows-interactive-security-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Proprietary Advisor Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Jul 2012 11:07:09 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Proprietary Advisor]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6019</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Proprietary Advisor. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProprietaryAdvisor. Windows Proprietary Advisor is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Proprietary Advisor</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProprietaryAdvisor" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProprietaryAdvisor" target="_blank"><strong>Rogue.Win32.WindowsProprietaryAdvisor</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Proprietary Advisor</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Proprietary Advisor.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Proprietary Advisor.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/rogue-win32-windowsproprietaryadvisor_1/" rel="attachment wp-att-6020"><img class="alignnone size-medium wp-image-6020" title="Rogue.Win32.WindowsProprietaryAdvisor" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProprietaryAdvisor_1-400x234.png" alt="Rogue.Win32.WindowsProprietaryAdvisor" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/rogue-win32-windowsproprietaryadvisor_2/" rel="attachment wp-att-6021"><img class="alignnone size-medium wp-image-6021" title="Rogue.Win32.WindowsProprietaryAdvisor" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProprietaryAdvisor_2-400x293.png" alt="Rogue.Win32.WindowsProprietaryAdvisor" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/rogue-win32-windowsproprietaryadvisor_3/" rel="attachment wp-att-6022"><img class="alignnone size-medium wp-image-6022" title="Rogue.Win32.WindowsProprietaryAdvisor" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProprietaryAdvisor_3-400x293.png" alt="Rogue.Win32.WindowsProprietaryAdvisor" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/rogue-win32-windowsproprietaryadvisor_4/" rel="attachment wp-att-6023"><img class="alignnone size-medium wp-image-6023" title="Rogue.Win32.WindowsProprietaryAdvisor" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProprietaryAdvisor_4-400x293.png" alt="Rogue.Win32.WindowsProprietaryAdvisor" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/rogue-win32-windowsproprietaryadvisor_5/" rel="attachment wp-att-6024"><img class="alignnone size-medium wp-image-6024" title="Rogue.Win32.WindowsProprietaryAdvisor" src="http://anti-malware-blog.com/files/2012/07/Rogue.Win32.WindowsProprietaryAdvisor_5-400x293.png" alt="Rogue.Win32.WindowsProprietaryAdvisor" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Proprietary Advisor (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProprietaryAdvisor" target="_blank">Rogue.Win32.WindowsProprietaryAdvisor</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/07/02/windows-proprietary-advisor-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Privacy Extension Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 29 Jun 2012 06:54:00 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Privacy Extension]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=6009</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Privacy Extension. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPrivacyExtension. Windows Privacy Extension is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/08/windows-privacy-module-rogue-removal-instructions/"     class="crp_title">Windows Privacy Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/"     class="crp_title">Windows Privacy Counsel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Privacy Extension</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPrivacyExtension" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivacyExtension" target="_blank"><strong>Rogue.Win32.WindowsPrivacyExtension</strong></a><strong>.</strong></p>
<p><strong>Windows Privacy Extension</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Privacy Extension.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Privacy Extension.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/rogue-win32-windowsprivacyextension_1/" rel="attachment wp-att-6010"><img class="alignnone size-medium wp-image-6010" title="Rogue.Win32.WindowsPrivacyExtension" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyExtension_1-400x234.png" alt="Rogue.Win32.WindowsPrivacyExtension" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/rogue-win32-windowsprivacyextension_2/" rel="attachment wp-att-6011"><img class="alignnone size-medium wp-image-6011" title="Rogue.Win32.WindowsPrivacyExtension" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyExtension_2-400x293.png" alt="Rogue.Win32.WindowsPrivacyExtension" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/rogue-win32-windowsprivacyextension_3/" rel="attachment wp-att-6012"><img class="alignnone size-medium wp-image-6012" title="Rogue.Win32.WindowsPrivacyExtension" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyExtension_3-400x293.png" alt="Rogue.Win32.WindowsPrivacyExtension" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/rogue-win32-windowsprivacyextension_4/" rel="attachment wp-att-6013"><img class="alignnone size-medium wp-image-6013" title="Rogue.Win32.WindowsPrivacyExtension" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyExtension_4-400x238.png" alt="Rogue.Win32.WindowsPrivacyExtension" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/rogue-win32-windowsprivacyextension_5/" rel="attachment wp-att-6014"><img class="alignnone size-medium wp-image-6014" title="Rogue.Win32.WindowsPrivacyExtension" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyExtension_5-400x293.png" alt="Rogue.Win32.WindowsPrivacyExtension" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Privacy Extension (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivacyExtension" target="_blank">Rogue.Win32.WindowsPrivacyExtension</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/08/windows-privacy-module-rogue-removal-instructions/"     class="crp_title">Windows Privacy Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/"     class="crp_title">Windows Privacy Counsel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/29/windows-privacy-extension-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Custom Management Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 29 Jun 2012 06:43:43 +0000</pubDate>
		<dc:creator>Arief Prabowo</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Custom Management]]></category>

		<guid isPermaLink="false">http://anti-malware-blog.com/?p=5999</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Custom Management. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCustomManagement. Windows Custom Management is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/11/windows-custom-safety-rogue-removal-instructions/"     class="crp_title">Windows Custom Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Custom Management</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCustomManagement" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomManagement" target="_blank"><strong>Rogue.Win32.WindowsCustomManagement</strong></a><strong>.</strong></p>
<p><strong>Windows Custom Management</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Custom Management.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Custom Management.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/rogue-win32-windowscustommanagement_1/" rel="attachment wp-att-6000"><img class="alignnone size-medium wp-image-6000" title="Rogue.Win32.WindowsCustomManagement" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomManagement_1-400x234.png" alt="Rogue.Win32.WindowsCustomManagement" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/rogue-win32-windowscustommanagement_2/" rel="attachment wp-att-6001"><img class="alignnone size-medium wp-image-6001" title="Rogue.Win32.WindowsCustomManagement" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomManagement_2-400x293.png" alt="Rogue.Win32.WindowsCustomManagement" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/rogue-win32-windowscustommanagement_3/" rel="attachment wp-att-6002"><img class="alignnone size-medium wp-image-6002" title="Rogue.Win32.WindowsCustomManagement" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomManagement_3-400x293.png" alt="Rogue.Win32.WindowsCustomManagement" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/rogue-win32-windowscustommanagement_4/" rel="attachment wp-att-6003"><img class="alignnone size-medium wp-image-6003" title="Rogue.Win32.WindowsCustomManagement" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomManagement_4-400x238.png" alt="Rogue.Win32.WindowsCustomManagement" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/rogue-win32-windowscustommanagement_5/" rel="attachment wp-att-6004"><img class="alignnone size-medium wp-image-6004" title="Rogue.Win32.WindowsCustomManagement" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomManagement_5-400x325.png" alt="Rogue.Win32.WindowsCustomManagement" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/rogue-win32-windowscustommanagement_6/" rel="attachment wp-att-6005"><img class="alignnone size-medium wp-image-6005" title="Rogue.Win32.WindowsCustomManagement" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomManagement_6-400x293.png" alt="Rogue.Win32.WindowsCustomManagement" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Custom Management (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomManagement" target="_blank">Rogue.Win32.WindowsCustomManagement</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/11/windows-custom-safety-rogue-removal-instructions/"     class="crp_title">Windows Custom Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/29/windows-custom-management-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Proactive Safety Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/20/windows-proactive-safety-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/20/windows-proactive-safety-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 20 Jun 2012 12:56:11 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Proactive Safety]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3647</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Proactive Safety. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProactiveSafety. Windows Proactive Safety is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Proactive Safety</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProactiveSafety" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProactiveSafety" target="_blank"><strong>Rogue.Win32.WindowsProactiveSafety</strong></a><strong>.</strong></p>
<p><strong>Windows Proactive Safety</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Proactive Safety.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Proactive Safety.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_1.png"><img class="alignnone size-medium wp-image-3648" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_1-400x234.png" alt="Rogue.Win32.WindowsProactiveSafety" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_2.png"><img class="alignnone size-medium wp-image-3649" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_2-400x293.png" alt="Rogue.Win32.WindowsProactiveSafety" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_3.png"><img class="alignnone size-medium wp-image-3650" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_3-400x293.png" alt="Rogue.Win32.WindowsProactiveSafety" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_4.png"><img class="alignnone size-medium wp-image-3651" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_4-400x238.png" alt="Rogue.Win32.WindowsProactiveSafety" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_5.png"><img class="alignnone size-medium wp-image-3652" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_5-400x325.png" alt="Rogue.Win32.WindowsProactiveSafety" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_6.png"><img class="alignnone size-medium wp-image-3653" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsProactiveSafety_6-400x293.png" alt="Rogue.Win32.WindowsProactiveSafety" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Proactive Safety (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProactiveSafety" target="_blank">Rogue.Win32.WindowsProactiveSafety</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/20/windows-proactive-safety-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Maintenance Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 19 Jun 2012 05:41:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Maintenance Guard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3638</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Maintenance Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsMaintenanceGuard. Windows Maintenance Guard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Suite Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Maintenance Guard</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsMaintenanceGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMaintenanceGuard" target="_blank"><strong>Rogue.Win32.WindowsMaintenanceGuard</strong></a><strong>.</strong></p>
<p><strong>Windows Maintenance Guard</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Maintenance Guard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Maintenance Guard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_1.png"><img class="alignnone size-medium wp-image-3639" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_1-400x234.png" alt="Rogue.Win32.WindowsMaintenanceGuard" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_2.png"><img class="alignnone size-medium wp-image-3640" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_2-400x293.png" alt="Rogue.Win32.WindowsMaintenanceGuard" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_3.png"><img class="alignnone size-medium wp-image-3641" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_3-400x293.png" alt="Rogue.Win32.WindowsMaintenanceGuard" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_4.png"><img class="alignnone size-medium wp-image-3642" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_4-400x238.png" alt="Rogue.Win32.WindowsMaintenanceGuard" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_5.png"><img class="alignnone size-medium wp-image-3643" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_5-400x325.png" alt="Rogue.Win32.WindowsMaintenanceGuard" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_6.png"><img class="alignnone size-medium wp-image-3644" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceGuard_6-400x293.png" alt="Rogue.Win32.WindowsMaintenanceGuard" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Maintenance Guard (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMaintenanceGuard" target="_blank">Rogue.Win32.WindowsMaintenanceGuard</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Suite Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Secure Web Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 18 Jun 2012 05:15:46 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Secure Web Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3629</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Secure Web Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSecureWebPatch. Windows Secure Web Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/"     class="crp_title">Windows Secure Surfer Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Secure Web Patch</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSecureWebPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureWebPatch" target="_blank"><strong>Rogue.Win32.WindowsSecureWebPatch</strong></a><strong>.</strong></p>
<p><strong>Windows Secure Web Patch</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Secure Web Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Secure Web Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_1.png"><img class="alignnone size-medium wp-image-3630" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_1-400x234.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_2.png"><img class="alignnone size-medium wp-image-3631" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_2-400x293.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_3.png"><img class="alignnone size-medium wp-image-3632" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_3-400x293.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_4.png"><img class="alignnone size-medium wp-image-3633" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_4-400x238.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_5.png"><img class="alignnone size-medium wp-image-3634" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_5-400x325.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_6.png"><img class="alignnone size-medium wp-image-3635" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_6-400x296.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="296" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_7.png"><img class="alignnone size-medium wp-image-3636" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSecureWebPatch_7-400x293.png" alt="Rogue.Win32.WindowsSecureWebPatch" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Secure Web Patch (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureWebPatch" target="_blank">Rogue.Win32.WindowsSecureWebPatch</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/"     class="crp_title">Windows Secure Surfer Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/18/windows-secure-web-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Active Defender Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 14 Jun 2012 10:11:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Active Defender]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3619</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Active Defender. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsActiveDefender. Windows Active Defender is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/"     class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Active Defender</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsActiveDefender" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActiveDefender" target="_blank"><strong>Rogue.Win32.WindowsActiveDefender</strong></a><strong>.</strong></p>
<p><strong>Windows Active Defender</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Active Defender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Active Defender.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_1.png"><img class="alignnone size-medium wp-image-3620" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_1-400x234.png" alt="Rogue.Win32.WindowsActiveDefender" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_2.png"><img class="alignnone size-medium wp-image-3621" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_2-400x293.png" alt="Rogue.Win32.WindowsActiveDefender" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_3.png"><img class="alignnone size-medium wp-image-3622" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_3-400x293.png" alt="Rogue.Win32.WindowsActiveDefender" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_4.png"><img class="alignnone size-medium wp-image-3623" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_4-400x238.png" alt="Rogue.Win32.WindowsActiveDefender" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_5.png"><img class="alignnone size-medium wp-image-3624" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_5-400x325.png" alt="Rogue.Win32.WindowsActiveDefender" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_6.png"><img class="alignnone size-medium wp-image-3625" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsActiveDefender_6-400x293.png" alt="Rogue.Win32.WindowsActiveDefender" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Active Defender (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActiveDefender" target="_blank">Rogue.Win32.WindowsActiveDefender</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/"     class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/14/windows-active-defender-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Instant Scanner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/13/windows-instant-scanner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/13/windows-instant-scanner-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 13 Jun 2012 06:13:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Instant Scanner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3609</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Instant Scanner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsInstantScanner. Windows Instant Scanner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Instant Scanner</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsInstantScanner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInstantScanner" target="_blank"><strong>Rogue.Win32.WindowsInstantScanner</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Instant Scanner</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Instant Scanner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Instant Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_1.png"><img class="alignnone size-medium wp-image-3612" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_1-400x234.png" alt="Rogue.Win32.WindowsInstantScanner" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_2.png"><img class="alignnone size-medium wp-image-3613" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_2-400x293.png" alt="Rogue.Win32.WindowsInstantScanner" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_3.png"><img class="alignnone size-medium wp-image-3614" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_3-400x293.png" alt="Rogue.Win32.WindowsInstantScanner" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_4.png"><img class="alignnone size-medium wp-image-3615" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_4-400x238.png" alt="Rogue.Win32.WindowsInstantScanner" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_5.png"><img class="alignnone size-medium wp-image-3616" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_5-400x325.png" alt="Rogue.Win32.WindowsInstantScanner" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_6.png"><img class="alignnone size-medium wp-image-3617" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsInstantScanner_6-400x293.png" alt="Rogue.Win32.WindowsInstantScanner" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Instant Scanner (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInstantScanner" target="_blank">Rogue.Win32.WindowsInstantScanner</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/13/windows-instant-scanner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Privacy Counsel Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 08:44:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Privacy Counsel]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3599</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Privacy Counsel. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPrivacyCounsel. Windows Privacy Counsel is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-defence-counsel-rogue-removal-instructions/"     class="crp_title">Windows Defence Counsel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Privacy Counsel</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPrivacyCounsel" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivacyCounsel" target="_blank"><strong>Rogue.Win32.WindowsPrivacyCounsel</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Privacy Counsel</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Privacy Counsel.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Privacy Counsel.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_1.png"><img class="alignnone size-medium wp-image-3600" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_1-400x234.png" alt="Rogue.Win32.WindowsPrivacyCounsel" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_2.png"><img class="alignnone size-medium wp-image-3601" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_2-400x293.png" alt="Rogue.Win32.WindowsPrivacyCounsel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_3.png"><img class="alignnone size-medium wp-image-3602" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_3-400x293.png" alt="Rogue.Win32.WindowsPrivacyCounsel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_4.png"><img class="alignnone size-medium wp-image-3603" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_4-400x238.png" alt="Rogue.Win32.WindowsPrivacyCounsel" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_5.png"><img class="alignnone size-medium wp-image-3604" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_5-400x325.png" alt="Rogue.Win32.WindowsPrivacyCounsel" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_6.png"><img class="alignnone size-medium wp-image-3605" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyCounsel_6-400x293.png" alt="Rogue.Win32.WindowsPrivacyCounsel" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Privacy Counsel (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivacyCounsel" target="_blank">Rogue.Win32.WindowsPrivacyCounsel</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-defence-counsel-rogue-removal-instructions/"     class="crp_title">Windows Defence Counsel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Custom Safety Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/11/windows-custom-safety-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/11/windows-custom-safety-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 08:37:54 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Custom Safety]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3590</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Custom Safety. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCustomSafety. Windows Custom Safety  is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Custom Safety</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCustomSafety" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSafety" target="_blank"><strong>Rogue.Win32.WindowsCustomSafety</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Custom Safety </strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Custom Safety.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Custom Safety.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_1.png"><img class="alignnone size-medium wp-image-3591" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_1-400x234.png" alt="Rogue.Win32.WindowsCustomSafety" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_2.png"><img class="alignnone size-medium wp-image-3592" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_2-400x293.png" alt="Rogue.Win32.WindowsCustomSafety" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_3.png"><img class="alignnone size-medium wp-image-3593" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_3-400x293.png" alt="Rogue.Win32.WindowsCustomSafety" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_4.png"><img class="alignnone size-medium wp-image-3594" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_4-400x238.png" alt="Rogue.Win32.WindowsCustomSafety" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_5.png"><img class="alignnone size-medium wp-image-3595" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_5-400x325.png" alt="Rogue.Win32.WindowsCustomSafety" width="400" height="325" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_6.png"><img class="alignnone size-medium wp-image-3596" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsCustomSafety_6-400x293.png" alt="Rogue.Win32.WindowsCustomSafety" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Custom Safety (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSafety" target="_blank">Rogue.Win32.WindowsCustomSafety</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/11/windows-custom-safety-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Privacy Module Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/08/windows-privacy-module-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/08/windows-privacy-module-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jun 2012 07:42:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Privacy Module]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3581</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Privacy Module. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPrivacyModule. Windows Privacy Module is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Privacy Module</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPrivacyModule" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivacyModule" target="_blank"><strong>Rogue.Win32.WindowsPrivacyModule</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Privacy Module</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Privacy Module.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Privacy Module.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_1.png"><img class="alignnone size-medium wp-image-3582" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_1-400x234.png" alt="Rogue.Win32.WindowsPrivacyModule" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_2.png"><img class="alignnone size-medium wp-image-3583" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_2-400x293.png" alt="Rogue.Win32.WindowsPrivacyModule" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_3.png"><img class="alignnone size-medium wp-image-3584" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_3-400x293.png" alt="Rogue.Win32.WindowsPrivacyModule" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_4.png"><img class="alignnone size-medium wp-image-3585" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_4-400x238.png" alt="Rogue.Win32.WindowsPrivacyModule" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_5.png"><img class="alignnone size-medium wp-image-3586" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_5-400x253.png" alt="Rogue.Win32.WindowsPrivacyModule" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_6.png"><img class="alignnone size-medium wp-image-3587" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPrivacyModule_6-400x293.png" alt="Rogue.Win32.WindowsPrivacyModule" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Privacy Module (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivacyModule" target="_blank">Rogue.Win32.WindowsPrivacyModule</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/08/windows-privacy-module-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Maintenance Suite Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jun 2012 07:36:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Maintenance Suite]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3572</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Maintenance Suite. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsMaintenanceSuite. Windows Maintenance Suite is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Maintenance Suite</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsMaintenanceSuite" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMaintenanceSuite" target="_blank"><strong>Rogue.Win32.WindowsMaintenanceSuite</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Maintenance Suite</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Maintenance Suite.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Maintenance Suite.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_1.png"><img class="alignnone size-medium wp-image-3573" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_1-400x234.png" alt="Rogue.Win32.WindowsMaintenanceSuite" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_2.png"><img class="alignnone size-medium wp-image-3574" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_2-400x293.png" alt="Rogue.Win32.WindowsMaintenanceSuite" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_3.png"><img class="alignnone size-medium wp-image-3575" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_3-400x293.png" alt="Rogue.Win32.WindowsMaintenanceSuite" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_4.png"><img class="alignnone size-medium wp-image-3576" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_4-400x238.png" alt="Rogue.Win32.WindowsMaintenanceSuite" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_5.png"><img class="alignnone size-medium wp-image-3577" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_5-400x253.png" alt="Rogue.Win32.WindowsMaintenanceSuite" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_6.png"><img class="alignnone size-medium wp-image-3578" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMaintenanceSuite_6-400x293.png" alt="Rogue.Win32.WindowsMaintenanceSuite" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Maintenance Suite (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMaintenanceSuite" target="_blank">Rogue.Win32.WindowsMaintenanceSuite</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows TurnKey Console Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/05/windows-turnkey-console-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/05/windows-turnkey-console-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jun 2012 15:24:30 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows TurnKey Console]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3563</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows TurnKey Console. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsTurnKeyConsole. Windows TurnKey Console is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows TurnKey Console</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsTurnKeyConsole" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTurnKeyConsole" target="_blank"><strong>Rogue.Win32.WindowsTurnKeyConsole</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows TurnKey Console</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows TurnKey Console.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows TurnKey Console.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_1.png"><img class="alignnone size-medium wp-image-3564" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_1-400x234.png" alt="Rogue.Win32.WindowsTurnKeyConsole" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_2.png"><img class="alignnone size-medium wp-image-3565" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_2-400x293.png" alt="Rogue.Win32.WindowsTurnKeyConsole" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_3.png"><img class="alignnone size-medium wp-image-3566" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_3-400x293.png" alt="Rogue.Win32.WindowsTurnKeyConsole" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_4.png"><img class="alignnone size-medium wp-image-3567" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_4-400x238.png" alt="Rogue.Win32.WindowsTurnKeyConsole" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_5.png"><img class="alignnone size-medium wp-image-3568" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_5-400x253.png" alt="Rogue.Win32.WindowsTurnKeyConsole" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_6.png"><img class="alignnone size-medium wp-image-3569" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsTurnKeyConsole_6-400x293.png" alt="Rogue.Win32.WindowsTurnKeyConsole" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows TurnKey Console (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCAid" target="_blank">Rogue.Win32.WindowsTurnKeyConsole</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/05/windows-turnkey-console-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Wizard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/05/windows-safety-wizard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/05/windows-safety-wizard-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jun 2012 15:19:13 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Wizard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3554</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Wizard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyWizard. Windows Safety Wizard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Wizard</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyWizard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyWizard" target="_blank"><strong>Rogue.Win32.WindowsSafetyWizard</strong></a><strong>.</strong></p>
<p><strong>Windows Safety Wizard</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Wizard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Wizard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_1.png"><img class="alignnone size-medium wp-image-3555" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_1-400x234.png" alt="Rogue.Win32.WindowsSafetyWizard" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_2.png"><img class="alignnone size-medium wp-image-3556" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_2-400x293.png" alt="Rogue.Win32.WindowsSafetyWizard" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_3.png"><img class="alignnone size-medium wp-image-3557" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_3-400x293.png" alt="Rogue.Win32.WindowsSafetyWizard" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_4.png"><img class="alignnone size-medium wp-image-3558" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_4-400x238.png" alt="Rogue.Win32.WindowsSafetyWizard" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_5.png"><img class="alignnone size-medium wp-image-3559" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_5-400x253.png" alt="Rogue.Win32.WindowsSafetyWizard" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_6.png"><img class="alignnone size-medium wp-image-3560" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsSafetyWizard_6-400x293.png" alt="Rogue.Win32.WindowsSafetyWizard" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Safety Wizard (<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCAid" target="_blank">Rogue.Win32.WindowsSafetyWizard</a>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/05/windows-safety-wizard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows PC Aid Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jun 2012 15:09:28 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows PC Aid]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3545</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows PC Aid. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPCAid. Windows PC Aid is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-turnkey-console-rogue-removal-instructions/"     class="crp_title">Windows TurnKey Console Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows PC Aid</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPCAid" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCAid" target="_blank"><strong>Rogue.Win32.WindowsPCAid</strong></a><strong>.</strong></p>
<p><strong>Windows PC Aid</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows PC Aid.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows PC Aid.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_1.png"><img class="alignnone size-medium wp-image-3546" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_1-400x234.png" alt="Rogue.Win32.WindowsPCAid" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_2.png"><img class="alignnone size-medium wp-image-3547" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_2-400x293.png" alt="Rogue.Win32.WindowsPCAid" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_3.png"><img class="alignnone size-medium wp-image-3548" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_3-400x293.png" alt="Rogue.Win32.WindowsPCAid" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_4.png"><img class="alignnone size-medium wp-image-3549" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_4-400x238.png" alt="Rogue.Win32.WindowsPCAid" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_5.png"><img class="alignnone size-medium wp-image-3550" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_5-400x253.png" alt="Rogue.Win32.WindowsPCAid" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_6.png"><img class="alignnone size-medium wp-image-3551" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsPCAid_6-400x293.png" alt="Rogue.Win32.WindowsPCAid" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong><strong>Windows PC Aid</strong></strong></strong></strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCAid" target="_blank">Rogue.Win32.WindowsPCAid</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-turnkey-console-rogue-removal-instructions/"     class="crp_title">Windows TurnKey Console Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Live Security Platinum Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/02/live-security-platinum-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/02/live-security-platinum-rogue-removal-instructions/#comments</comments>
		<pubDate>Sat, 02 Jun 2012 05:44:17 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Live Security Platinum]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3538</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Live Security Platinum. Emsisoft Anti-Malware detects this malware as Rogue.Win32.LiveSecurityPlatinum. Live Security Platinum is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/"     class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/08/system-tool-adware-removal-instructions/"     class="crp_title">System Tool Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/"     class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/"     class="crp_title">AV Security 2012 Adware Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Live Security Platinum</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.LiveSecurityPlatinum" href="http://www.emsisoft.com/en/malware/?Adware.Win32.LiveSecurityPlatinum" target="_blank"><strong>Rogue.Win32.LiveSecurityPlatinum</strong></a><strong>.</strong></p>
<p><strong>Live Security Platinum </strong><strong></strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\[random]\</li>
<li>%AllUsersProfile%\Application Data\[random]\[random]</li>
<li>%AllUsersProfile%\Application Data\[random]\[random].exe</li>
<li>%UserProfile%\Desktop\Live Security Platinum.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Live Security Platinum\</li>
<li>%UserProfile%\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
[random] = %AllUsersProfile%\Application Data\[random]\[random].exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum\<br />
DisplayName = Live Security Platinum<br />
ShortcutPath = “%AllUsersProfile%\Application Data\[random]\[random].exe” -u<br />
UninstallString = “%AllUsersProfile%\Application Data\[random]\[random].exe” -u<br />
DisplayIcon = &#8220;%AllUsersProfile%\Application Data\[random]\[random].exe,0&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_1.png"><img class="alignnone size-medium wp-image-3539" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_1-400x298.png" alt="Rogue.Win32.LiveSecurityPlatinum" width="400" height="298" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_2.png"><img class="alignnone size-medium wp-image-3540" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_2-400x342.png" alt="Rogue.Win32.LiveSecurityPlatinum" width="400" height="342" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_3.png"><img class="alignnone size-medium wp-image-3541" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_3-400x316.png" alt="Rogue.Win32.LiveSecurityPlatinum" width="400" height="316" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_4.png"><img class="alignnone size-medium wp-image-3542" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.LiveSecurityPlatinum_4-400x189.png" alt="Rogue.Win32.LiveSecurityPlatinum" width="400" height="189" /></a></p>
<p><strong>How to remove the infection of Live Security Platinum </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.LiveSecurityPlatinum" target="_blank">Rogue.Win32.LiveSecurityPlatinum</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/"     class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/08/system-tool-adware-removal-instructions/"     class="crp_title">System Tool Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/"     class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/"     class="crp_title">AV Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/02/live-security-platinum-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Malware Firewall Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/#comments</comments>
		<pubDate>Sat, 02 Jun 2012 04:21:25 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Malware Firewall]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3529</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Malware Firewall. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsMalwareFirewall. Windows Malware Firewall is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/"     class="crp_title">Windows Firewall Constructor Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Malware Firewall</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsMalwareFirewall" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMalwareFirewall" target="_blank"><strong>Rogue.Win32.WindowsMalwareFirewall</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong><strong><strong><strong><strong>Windows Malware Firewall</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Malware Firewall.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Malware Firewall.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_1.png"><img class="alignnone size-medium wp-image-3530" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_1-400x234.png" alt="Rogue.Win32.WindowsMalwareFirewall" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_2.png"><img class="alignnone size-medium wp-image-3531" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_2-400x293.png" alt="Rogue.Win32.WindowsMalwareFirewall" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_3.png"><img class="alignnone size-medium wp-image-3532" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_3-400x293.png" alt="Rogue.Win32.WindowsMalwareFirewall" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_4.png"><img class="alignnone size-medium wp-image-3533" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_4-400x238.png" alt="Rogue.Win32.WindowsMalwareFirewall" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_5.png"><img class="alignnone size-medium wp-image-3534" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_5-400x253.png" alt="Rogue.Win32.WindowsMalwareFirewall" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_6.png"><img class="alignnone size-medium wp-image-3535" src="http://anti-malware-blog.com/files/2012/06/Rogue.Win32.WindowsMalwareFirewall_6-400x293.png" alt="Rogue.Win32.WindowsMalwareFirewall" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong><strong>Windows Malware Firewall</strong></strong></strong></strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMalwareFirewall" target="_blank">Rogue.Win32.WindowsMalwareFirewall</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/"     class="crp_title">Windows Firewall Constructor Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antivirus Rampart Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 30 May 2012 07:25:52 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antivirus Rampart]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3519</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antivirus Rampart. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntivirusRampart. Windows Antivirus Rampart is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Antivirus Rampart</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntivirusRampart" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusRampart" target="_blank"><strong>Rogue.Win32.WindowsAntivirusRampart</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong><strong>Windows Antivirus Rampart</strong></strong></strong></strong></strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antivirus Rampart.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antivirus Rampart.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_1.png"><img class="alignnone size-medium wp-image-3520" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_1-400x234.png" alt="Rogue.Win32.WindowsAntivirusRampart" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_2.png"><img class="alignnone size-medium wp-image-3521" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_2-400x293.png" alt="Rogue.Win32.WindowsAntivirusRampart" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_3.png"><img class="alignnone size-medium wp-image-3522" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_3-400x293.png" alt="Rogue.Win32.WindowsAntivirusRampart" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_4.png"><img class="alignnone size-medium wp-image-3523" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_4-400x238.png" alt="Rogue.Win32.WindowsAntivirusRampart" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_5.png"><img class="alignnone size-medium wp-image-3524" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_5-400x253.png" alt="Rogue.Win32.WindowsAntivirusRampart" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_6.png"><img class="alignnone size-medium wp-image-3525" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAntivirusRampant_6-400x293.png" alt="Rogue.Win32.WindowsAntivirusRampart" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong><strong>Windows Antivirus Rampart</strong></strong></strong></strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusRampart" target="_blank">Rogue.Win32.WindowsAntivirusRampart</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Ultimate Security Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 30 May 2012 07:19:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Ultimate Security Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3510</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Ultimate Security Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsUltimateSecurityPatch. Windows Ultimate Security Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Ultimate Security Patch</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsUltimateSecurityPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUltimateSecurityPatch" target="_blank"><strong>Rogue.Win32.WindowsUltimateSecurityPatch</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong></strong></strong></strong></strong><strong><strong><strong><strong>Windows Ultimate Security Patch</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Ultimate Security Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Ultimate Security Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_1.png"><img class="alignnone size-medium wp-image-3511" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_1-400x234.png" alt="Rogue.Win32.WindowsUltimateSecurityPatch" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_2.png"><img class="alignnone size-medium wp-image-3512" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_2-400x293.png" alt="Rogue.Win32.WindowsUltimateSecurityPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_3.png"><img class="alignnone size-medium wp-image-3513" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_3-400x293.png" alt="Rogue.Win32.WindowsUltimateSecurityPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_4.png"><img class="alignnone size-medium wp-image-3514" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_4-400x238.png" alt="Rogue.Win32.WindowsUltimateSecurityPatch" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_5.png"><img class="alignnone size-medium wp-image-3515" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_5-400x253.png" alt="Rogue.Win32.WindowsUltimateSecurityPatch" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_6.png"><img class="alignnone size-medium wp-image-3516" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsUltimateSecurityPatch_6-400x293.png" alt="Rogue.Win32.WindowsUltimateSecurityPatch" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong>Windows Ultimate Security Patch </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUltimateSecurityPatch" target="_blank">Rogue.Win32.WindowsUltimateSecurityPatch</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Defence Counsel Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/30/windows-defence-counsel-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/30/windows-defence-counsel-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 30 May 2012 07:02:49 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Defence Counsel]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3501</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Defence Counsel. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsDefenceCounsel. Windows Defence Counsel is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/"     class="crp_title">Windows Privacy Counsel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Defence Counsel</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsDefenceCounsel" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCounsel" target="_blank"><strong>Rogue.Win32.WindowsDefenceCounsel</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong>Windows Defence Counsel</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Defence Counsel.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Defence Counsel.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_1.png"><img class="alignnone size-medium wp-image-3502" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_1-400x234.png" alt="Rogue.Win32.WindowsDefenceCounsel" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_2.png"><img class="alignnone size-medium wp-image-3503" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_2-400x293.png" alt="Rogue.Win32.WindowsDefenceCounsel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_3.png"><img class="alignnone size-medium wp-image-3504" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_3-400x293.png" alt="Rogue.Win32.WindowsDefenceCounsel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_4.png"><img class="alignnone size-medium wp-image-3505" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_4-400x238.png" alt="Rogue.Win32.WindowsDefenceCounsel" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_5.png"><img class="alignnone size-medium wp-image-3506" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_5-400x253.png" alt="Rogue.Win32.WindowsDefenceCounsel" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_6.png"><img class="alignnone size-medium wp-image-3507" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsDefenceCounsel_6-400x293.png" alt="Rogue.Win32.WindowsDefenceCounsel" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Defence Counsel</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCounsel" target="_blank">Rogue.Win32.WindowsDefenceCounsel</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/11/windows-privacy-counsel-rogue-removal-instructions/"     class="crp_title">Windows Privacy Counsel Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/30/windows-defence-counsel-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Guard Tools Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 25 May 2012 10:05:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Guard Tools]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3493</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Guard Tools. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsGuardTools. Windows Guard Tools is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/"     class="crp_title">Windows Cleaning Tools Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Guard Tools</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsGuardTools" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardTools" target="_blank"><strong>Rogue.Win32.WindowsGuardTools</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Guard Tools</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Guard Tools.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Guard Tools.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_1.png"><img class="alignnone size-medium wp-image-3494" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_1-400x234.png" alt="Rogue.Win32.WindowsGuardTools" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_2.png"><img class="alignnone size-medium wp-image-3495" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_2-400x293.png" alt="Rogue.Win32.WindowsGuardTools" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_3.png"><img class="alignnone size-medium wp-image-3496" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_3-400x293.png" alt="Rogue.Win32.WindowsGuardTools" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_4.png"><img class="alignnone size-medium wp-image-3497" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_4-400x238.png" alt="Rogue.Win32.WindowsGuardTools" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_5.png"><img class="alignnone size-medium wp-image-3498" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_5-400x253.png" alt="Rogue.Win32.WindowsGuardTools" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_6.png"><img class="alignnone size-medium wp-image-3499" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsGuardTools_6-400x293.png" alt="Rogue.Win32.WindowsGuardTools" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Guard Tools</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardTools" target="_blank">Rogue.Win32.WindowsGuardTools</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/"     class="crp_title">Windows Cleaning Tools Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Maintenance Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 24 May 2012 09:49:34 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Maintenance]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3485</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Maintenance. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyMaintenance. Windows Safety Maintenance is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Suite Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Guard Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Maintenance</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyMaintenance" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyMaintenance" target="_blank"><strong>Rogue.Win32.WindowsSafetyMaintenance</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Safety Maintenance</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Maintenance.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Maintenance.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_1.png"><img class="alignnone size-medium wp-image-3486" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_1-400x234.png" alt="Rogue.Win32.WindowsSafetyMaintenance" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_2.png"><img class="alignnone size-medium wp-image-3487" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_2-400x293.png" alt="Rogue.Win32.WindowsSafetyMaintenance" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_3.png"><img class="alignnone size-medium wp-image-3488" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_3-400x293.png" alt="Rogue.Win32.WindowsSafetyMaintenance" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_4.png"><img class="alignnone size-medium wp-image-3489" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_4-400x238.png" alt="Rogue.Win32.WindowsSafetyMaintenance" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_5.png"><img class="alignnone size-medium wp-image-3490" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_5-400x253.png" alt="Rogue.Win32.WindowsSafetyMaintenance" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_6.png"><img class="alignnone size-medium wp-image-3491" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyMaintenance_6-400x293.png" alt="Rogue.Win32.WindowsSafetyMaintenance" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Safety Maintenance</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyMaintenance" target="_blank">Rogue.Win32.WindowsSafetyMaintenance</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/06/08/windows-maintenance-suite-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Suite Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/19/windows-maintenance-guard-rogue-removal-instructions/"     class="crp_title">Windows Maintenance Guard Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Multi Control System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/23/windows-multi-control-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/23/windows-multi-control-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 23 May 2012 09:57:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Multi Control System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3476</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Multi Control System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsMultiControlSystem. Windows Multi Control System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/"     class="crp_title">Windows Managing System Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Multi Control System</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsMultiControlSystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMultiControlSystem" target="_blank"><strong>Rogue.Win32.WindowsMultiControlSystem</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong><strong>Windows Multi Control System</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Multi Control System.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Multi Control System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_1.png"><img class="alignnone size-medium wp-image-3477" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_1-400x234.png" alt="Rogue.Win32.WindowsMultiControlSystem" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_2.png"><img class="alignnone size-medium wp-image-3478" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_2-400x293.png" alt="Rogue.Win32.WindowsMultiControlSystem" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_3.png"><img class="alignnone size-medium wp-image-3479" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_3-400x293.png" alt="Rogue.Win32.WindowsMultiControlSystem" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_4.png"><img class="alignnone size-medium wp-image-3480" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_4-400x238.png" alt="Rogue.Win32.WindowsMultiControlSystem" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_5.png"><img class="alignnone size-medium wp-image-3481" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_5-400x253.png" alt="Rogue.Win32.WindowsMultiControlSystem" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_6.png"><img class="alignnone size-medium wp-image-3482" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsMultiControlSystem_6-400x293.png" alt="Rogue.Win32.WindowsMultiControlSystem" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Multi Control System</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMultiControlSystem" target="_blank">Rogue.Win32.WindowsMultiControlSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/"     class="crp_title">Windows Managing System Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/23/windows-multi-control-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Safety Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 22 May 2012 05:28:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Safety]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3467</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Safety. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSafety. Windows Pro Safety is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Safety</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSafety" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSafety" target="_blank"><strong>Rogue.Win32.WindowsProSafety</strong></a><strong>.</strong></p>
<p><strong>Windows Pro Safety</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Safety.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Safety.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_1.png"><img class="alignnone size-medium wp-image-3468" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_1-400x234.png" alt="Rogue.Win32.WindowsProSafety" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_2.png"><img class="alignnone size-medium wp-image-3469" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_2-400x293.png" alt="Rogue.Win32.WindowsProSafety" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_3.png"><img class="alignnone size-medium wp-image-3470" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_3-400x293.png" alt="Rogue.Win32.WindowsProSafety" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_4.png"><img class="alignnone size-medium wp-image-3471" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_4-400x238.png" alt="Rogue.Win32.WindowsProSafety" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_5.png"><img class="alignnone size-medium wp-image-3472" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_5-400x253.png" alt="Rogue.Win32.WindowsProSafety" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_6.png"><img class="alignnone size-medium wp-image-3473" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafety_6-400x293.png" alt="Rogue.Win32.WindowsProSafety" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Pro Safety</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSafety" target="_blank">Rogue.Win32.WindowsProSafety</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Private Shield Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/20/windows-private-shield-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/20/windows-private-shield-rogue-removal-instructions/#comments</comments>
		<pubDate>Sun, 20 May 2012 06:28:30 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Private Shield]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3457</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Private Shield. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPrivateShield. Windows Private Shield is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Private Shield</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPrivateShield" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivateShield" target="_blank"><strong>Rogue.Win32.WindowsPrivateShield</strong></a><strong>.</strong></p>
<p><strong>Windows Private Shield</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Private Shield.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Private Shield.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_1.png"><img class="alignnone size-medium wp-image-3458" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_1-400x234.png" alt="Rogue.Win32.WindowsPrivateShield" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_2.png"><img class="alignnone size-medium wp-image-3459" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_2-400x293.png" alt="Rogue.Win32.WindowsPrivateShield" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_3.png"><img class="alignnone size-medium wp-image-3460" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_3-400x293.png" alt="Rogue.Win32.WindowsPrivateShield" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_4.png"><img class="alignnone size-medium wp-image-3461" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_4-400x238.png" alt="Rogue.Win32.WindowsPrivateShield" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_5.png"><img class="alignnone size-medium wp-image-3462" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_5-400x253.png" alt="Rogue.Win32.WindowsPrivateShield" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_6.png"><img class="alignnone size-medium wp-image-3463" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsPrivateShield_6-400x293.png" alt="Rogue.Win32.WindowsPrivateShield" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Private Shield</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrivateShield" target="_blank">Rogue.Win32.WindowsPrivateShield</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/20/windows-private-shield-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Safety Release Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 18 May 2012 11:54:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Safety Release]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3447</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Safety Release. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSafetyRelease. Windows Pro Safety Release is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Safety Release</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSafetyRelease" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSafetyRelease" target="_blank"><strong>Rogue.Win32.WindowsProSafetyRelease</strong></a><strong>.</strong></p>
<p><strong>Windows Pro Safety Release</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Safety Release.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Safety Release.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_1.png"><img class="alignnone size-medium wp-image-3448" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_1-400x234.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_2.png"><img class="alignnone size-medium wp-image-3449" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_2-400x293.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_3.png"><img class="alignnone size-medium wp-image-3450" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_3-400x293.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_4.png"><img class="alignnone size-medium wp-image-3451" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_4-400x238.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_5.png"><img class="alignnone size-medium wp-image-3452" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_5-400x253.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_6.png"><img class="alignnone size-medium wp-image-3453" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSafetyRelease_6-400x293.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Pro Safety Release</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSafetyRelease" target="_blank">Rogue.Win32.WindowsProSafetyRelease</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safeguard Upgrade Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 17 May 2012 09:38:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safeguard Upgrade]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3438</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safeguard Upgrade. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafeguardUpgrade. Windows Safeguard Upgrade is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safeguard Upgrade</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafeguardUpgrade" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUpgrade" target="_blank"><strong>Rogue.Win32.WindowsSafeguardUpgrade</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong><strong><strong><strong><strong>Windows Safeguard Upgrade</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safeguard Upgrade.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safeguard Upgrade.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_1.png"><img class="alignnone size-medium wp-image-3439" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_1-400x234.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_2.png"><img class="alignnone size-medium wp-image-3440" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_2-400x293.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_3.png"><img class="alignnone size-medium wp-image-3441" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_3-400x293.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_4.png"><img class="alignnone size-medium wp-image-3442" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_4-400x238.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_5.png"><img class="alignnone size-medium wp-image-3443" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_5-400x253.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_6.png"><img class="alignnone size-medium wp-image-3444" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_6-400x293.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong></strong></strong></strong></strong></strong><strong><strong><strong><strong><strong><strong><strong>Windows Safeguard Upgrade</strong></strong></strong></strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUpgrade" target="_blank">Rogue.Win32.WindowsSafeguardUpgrade</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Secure Surfer Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 14 May 2012 02:21:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Secure Surfer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3429</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Secure Surfer. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSecureSurfer. Windows Secure Surfer is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Secure Surfer</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSecureSurfer" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureSurfer" target="_blank"><strong>Rogue.Win32.WindowsSecureSurfer</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Secure Surfer </strong></strong></strong></strong></strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Secure Surfer.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Secure Surfer.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_1.png"><img class="alignnone size-medium wp-image-3430" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_1-400x234.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_2.png"><img class="alignnone size-medium wp-image-3431" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_2-400x293.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_3.png"><img class="alignnone size-medium wp-image-3432" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_3-400x293.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_4.png"><img class="alignnone size-medium wp-image-3433" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_4-400x238.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_5.png"><img class="alignnone size-medium wp-image-3434" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_5-400x253.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_6.png"><img class="alignnone size-medium wp-image-3435" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSecureSurfer_6-400x293.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Secure Surfer </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureSurfer" target="_blank">Rogue.Win32.WindowsSecureSurfer</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Be-on Guard Edition Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/#comments</comments>
		<pubDate>Sun, 13 May 2012 03:36:59 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Be-on Guard Edition]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3421</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Be-on Guard Edition. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsBeOnGuardEdition. Windows Be-on Guard Edition is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Be-on Guard Edition</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsBeOnGuardEdition" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBeOnGuardEdition" target="_blank"><strong>Rogue.Win32.WindowsBeOnGuardEdition</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Be-on Guard Edition </strong></strong></strong></strong></strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Be-on-Guard Edition.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Be-on-Guard Edition.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_1.png"><img class="alignnone size-medium wp-image-3422" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_1-400x234.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_2.png"><img class="alignnone size-medium wp-image-3423" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_2-400x293.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_3.png"><img class="alignnone size-medium wp-image-3424" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_3-400x293.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_4.png"><img class="alignnone size-medium wp-image-3425" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_4-400x238.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_5.png"><img class="alignnone size-medium wp-image-3426" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_5-400x253.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_6.png"><img class="alignnone size-medium wp-image-3427" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_6-400x293.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Be-on Guard Edition </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBeOnGuardEdition" target="_blank">Rogue.Win32.WindowsBeOnGuardEdition</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Abnormality Checker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/11/windows-abnormality-checker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/11/windows-abnormality-checker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 11 May 2012 08:37:09 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Abnormality Checker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3413</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Abnormality Checker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAbnormalityChecker. Windows Abnormality Checker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Abnormality Checker</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAbnormalityChecker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAbnormalityChecker" target="_blank"><strong>Rogue.Win32.WindowsAbnormalityChecker</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Abnormality Checker</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Abnormality Checker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Abnormality Checker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_1.png"><img class="alignnone size-medium wp-image-3414" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_1-400x234.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_2.png"><img class="alignnone size-medium wp-image-3415" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_2-400x293.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_3.png"><img class="alignnone size-medium wp-image-3416" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_3-400x293.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_4.png"><img class="alignnone size-medium wp-image-3417" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_4-400x238.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_5.png"><img class="alignnone size-medium wp-image-3418" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_5-400x253.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="253" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_6.png"><img class="alignnone size-medium wp-image-3419" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAbnormalityChecker_6-400x293.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Abnormality Checker </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAbnormalityChecker" target="_blank">Rogue.Win32.WindowsAbnormalityChecker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/11/windows-abnormality-checker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Solutions Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 10 May 2012 10:53:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Solutions]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3405</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Solutions. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSolutions. Windows Pro Solutions is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Solutions</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSolutions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSolutions" target="_blank"><strong>Rogue.Win32.WindowsProSolutions</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Pro Solutions</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Solutions.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Solutions.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_1.png"><img class="alignnone size-medium wp-image-3406" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_1-400x234.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_2.png"><img class="alignnone size-medium wp-image-3407" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_2-400x293.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_3.png"><img class="alignnone size-medium wp-image-3408" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_3-400x293.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_4.png"><img class="alignnone size-medium wp-image-3409" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_4-400x238.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_5.png"><img class="alignnone size-medium wp-image-3410" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSolutions_5-400x253.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Pro Solutions </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSolutions" target="_blank">Rogue.Win32.WindowsProSolutions</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Sleek Performance Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 09 May 2012 11:26:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[WIndows Sleek Performance]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3398</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Sleek Performance. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSleekPerformance. Windows Sleek Performance is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/"     class="crp_title">Windows Performance Adviser Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Sleek Performance</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSleekPerformance" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSleekPerformance" target="_blank"><strong>Rogue.Win32.WindowsSleekPerformance</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Sleek Performance</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Sleek Performance.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Sleek Performance.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_1.png"><img class="alignnone size-medium wp-image-3399" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_1-400x234.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_2.png"><img class="alignnone size-medium wp-image-3400" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_2-400x293.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_3.png"><img class="alignnone size-medium wp-image-3401" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_3-400x293.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_4.png"><img class="alignnone size-medium wp-image-3402" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_4-400x238.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_5.png"><img class="alignnone size-medium wp-image-3403" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSleekPerformance_5-400x253.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Sleek Performance </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSleekPerformance" target="_blank">Rogue.Win32.WindowsSleekPerformance</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/"     class="crp_title">Windows Performance Adviser Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows ProSecurity Scanner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 08 May 2012 11:24:42 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows ProSecurity Scanner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3391</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows ProSecurity Scanner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSecurityScanner. Windows ProSecurity Scanner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/"     class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows ProSecurity Scanner</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSecurityScanner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSecurityScanner" target="_blank"><strong>Rogue.Win32.WindowsProSecurityScanner</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows ProSecurity Scanner</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows ProSecurity Scanner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows ProSecurity Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_1.png"><img class="alignnone size-medium wp-image-3392" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_1-400x234.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_2.png"><img class="alignnone size-medium wp-image-3393" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_2-400x293.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_3.png"><img class="alignnone size-medium wp-image-3394" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_3-400x293.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_4.png"><img class="alignnone size-medium wp-image-3395" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_4-400x238.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_5.png"><img class="alignnone size-medium wp-image-3396" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProSecurityScanner_5-400x253.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows ProSecurity Scanner </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSecurityScanner" target="_blank">Rogue.Win32.WindowsProSecurityScanner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/"     class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Total Anti Malware Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 09:00:27 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Total Anti Malware Protection]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3383</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Total Anti Malware Protection. Emsisoft Anti-Malware detects this malware as Rogue.Win32.TotalAntiMalwareProtection. Total Anti Malware Protection is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/"     class="crp_title">Best Antivirus Software Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/"     class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/"     class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/"     class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/"     class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Total Anti Malware Protection</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.TotalAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalAntiMalwareProtection" target="_blank"><strong>Rogue.Win32.TotalAntiMalwareProtection</strong></a><strong>.</strong></p>
<p><strong>Total Anti Malware Protection </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\2a967e\</li>
<li>%AllUsersProfile%\Application Data\2a967e\TAMPSys\</li>
<li>%AllUsersProfile%\Application Data\2a967e\BackUp\</li>
<li>%AllUsersProfile%\Application Data\2a967e\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\2a967e\84.mof</li>
<li>%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\TAMP.ico</li>
<li>%AllUsersProfile%\Application Data\TANAMNGQMP\</li>
<li>%AllUsersProfile%\Application Data\TANAMNGQMP\TASGMP.cfg</li>
<li>%AppData%\Total Anti Malware Protection\</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Total Anti Malware Protection.lnk</li>
<li>%UserProfile%\Desktop\Total Anti Malware Protection.lnk</li>
<li>%UserProfile%\Recent\CLSV.drv</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Recent\CLSV.tmp</li>
<li>%UserProfile%\Recent\energy.tmp</li>
<li>%UserProfile%\Recent\exec.tmp</li>
<li>%UserProfile%\Recent\fan.exe</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\kernel32.exe</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\ppal.exe</li>
<li>%UserProfile%\Recent\sld.exe</li>
<li>%UserProfile%\Recent\ANTIGEN.sys</li>
<li>%UserProfile%\Start Menu\Total Anti Malware Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Total Anti Malware Protection.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\TAe0e_8011.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe<br />
ProgID  = TAe0e_8011.DocHostUIHandler</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
Total Anti Malware Protection = “%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation<br />
MSCompatibilityMode = 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer<br />
IIL = 0×00000000<br />
ltHI = 0×00000000<br />
ltTST =0x00005f9f<br />
PRS = ”http://127.0.0.1:27777/?inj=%ORIGINAL%”<br />
RGF =0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
MigrateProxy = 0×00000001<br />
ProxyEnable = 0×00000000<br />
UID = “8001″</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap<br />
ProxyByPass = 0×00000001<br />
IntranetName = 0×00000001<br />
UNCAsIntranet = 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Anti Malware Protection<br />
DisplayName = “Total Anti Malware Protection”<br />
DisplayIcon = “%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe,0″<br />
DisplayVersion = “1.1.0.1010″<br />
InstallLocation = “%AllUsersProfile%\Application Data\2a967e\”<br />
Publisher = “UIS Inc.”<br />
UninstallString = “%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe” /del”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots</strong>:</p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.TotalAntiMalwareProtection_1.png"><img class="alignnone size-medium wp-image-3384" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.TotalAntiMalwareProtection_1-400x276.png" alt="Rogue.Win32.TotalAntiMalwareProtection" width="400" height="276" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.TotalAntiMalwareProtection_2.png"><img class="alignnone size-medium wp-image-3385" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.TotalAntiMalwareProtection_2-400x292.png" alt="Rogue.Win32.TotalAntiMalwareProtection" width="400" height="292" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.TotalAntiMalwareProtection_3.png"><img class="alignnone size-medium wp-image-3386" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.TotalAntiMalwareProtection_3-400x292.png" alt="Rogue.Win32.TotalAntiMalwareProtection" width="400" height="292" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Total Anti Malware Protection </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalAntiMalwareProtection" target="_blank">Rogue.Win32.TotalAntiMalwareProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/"     class="crp_title">Best Antivirus Software Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/"     class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/"     class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/"     class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/"     class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Antivirus Software Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 07:53:40 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Best Antivirus Software]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3376</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Best Antivirus Software. Emsisoft Anti-Malware detects this malware as Rogue.Win32.BestAntivirusSoftware. Best Antivirus Software is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/"     class="crp_title">Total Anti Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/"     class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/"     class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/"     class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/"     class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Best Antivirus Software</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.BestAntivirusSoftware" href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestAntivirusSoftware" target="_blank"><strong>Rogue.Win32.BestAntivirusSoftware</strong></a><strong>.</strong></p>
<p><strong>Best Antivirus Software </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\2a967e\</li>
<li>%AllUsersProfile%\Application Data\2a967e\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\2a967e\BackUp\</li>
<li>%AllUsersProfile%\Application Data\2a967e\BASSys\</li>
<li>%AllUsersProfile%\Application Data\2a967e\22.mof</li>
<li>%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\BAS.ico</li>
<li>%AllUsersProfile%\Application Data\2a967e\bestantivirus.exe</li>
<li>%AllUsersProfile%\Application Data\BASVS\</li>
<li>%AllUsersProfile%\Application Data\BASVS\BAYZS.cfg</li>
<li>%AppData%\Best Antivirus Software\</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Best Antivirus Software.lnk</li>
<li>%UserProfile%\Desktop\Best Antivirus Software.lnk</li>
<li>%UserProfile%\Recent\DBOLE.tmp</li>
<li>%UserProfile%\Recent\dudl.drv</li>
<li>%UserProfile%\Recent\eb.exe</li>
<li>%UserProfile%\Recent\energy.exe</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.dll</li>
<li>%UserProfile%\Recent\fan.exe</li>
<li>%UserProfile%\Recent\fix.dll</li>
<li>%UserProfile%\Recent\gid.dll</li>
<li>%UserProfile%\Recent\PE.exe</li>
<li>%UserProfile%\Recent\snl2w.tmp</li>
<li>%UserProfile%\Recent\std.dll</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Recent\cb.drv</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Start Menu\Best Antivirus Software.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Best Antivirus Software.lnk</li>
<li>%Temp%\scandsk211d_8001.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\BA2a9_8001.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe<br />
ProgID  = BA2a9_8001.DocHostUIHandler<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
BAS = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe&#8221; /s<br />
Best Antivirus Software = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe&#8221; /s /d</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation<br />
MSCompatibilityMode = 0&#215;00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer<br />
IIL = 0&#215;00000000<br />
ltHI = 0&#215;00000000<br />
ltTST =0x00005f9f<br />
PRS =&#8221;http://127.0.0.1:27777/?inj=%ORIGINAL%&#8221;<br />
RGF =0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
MigrateProxy = 0&#215;00000001<br />
ProxyEnable = 0&#215;00000000<br />
UID = &#8220;8001&#8243;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap<br />
ProxyByPass = 0&#215;00000001<br />
IntranetName = 0&#215;00000001<br />
UNCAsIntranet = 0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Best Antivirus Software<br />
DisplayName = &#8220;Best Antivirus Software&#8221;<br />
DisplayIcon = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe,0&#8243;<br />
DisplayVersion = &#8220;1.1.0.1010&#8243;<br />
InstallLocation = &#8220;%AllUsersProfile%\Application Data\2a967e\&#8221;<br />
Publisher = &#8220;UIS Inc.&#8221;<br />
UninstallString = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe&#8221; /del&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots</strong>:</p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.BestAntivirusSoftware_1.png"><img class="alignnone size-medium wp-image-3377" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.BestAntivirusSoftware_1-400x292.png" alt="Rogue.Win32.BestAntivirusSoftware" width="400" height="292" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.BestAntivirusSoftware_2.png"><img class="alignnone size-medium wp-image-3378" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.BestAntivirusSoftware_2-400x292.png" alt="Rogue.Win32.BestAntivirusSoftware" width="400" height="292" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.BestAntivirusSoftware_3.png"><img class="alignnone size-medium wp-image-3379" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.BestAntivirusSoftware_3-400x303.png" alt="Rogue.Win32.BestAntivirusSoftware" width="400" height="303" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Best Antivirus Software </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestAntivirusSoftware" target="_blank">Rogue.Win32.BestAntivirusSoftware</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/"     class="crp_title">Total Anti Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/"     class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/"     class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/"     class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/"     class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Advanced User Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 03:54:04 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Advanced User Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3368</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Advanced User Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAdvancedUserPatch. Windows Advanced User Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Advanced User Patch</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAdvancedUserPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAdvancedUserPatch" target="_blank"><strong>Rogue.Win32.WindowsAdvancedUserPatch</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Advanced User Patch </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Advanced User Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Advanced User Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_1.png"><img class="alignnone size-medium wp-image-3369" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_1-400x234.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_2.png"><img class="alignnone size-medium wp-image-3370" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_2-400x293.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_3.png"><img class="alignnone size-medium wp-image-3371" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_3-400x293.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_4.png"><img class="alignnone size-medium wp-image-3372" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_4-400x238.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_5.png"><img class="alignnone size-medium wp-image-3373" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_5-400x253.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Advanced User Patch </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAdvancedUserPatch" target="_blank">Rogue.Win32.WindowsAdvancedUserPatch</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Web Helper Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 03:41:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Web Helper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3360</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Web Helper. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProWebHelper. Windows Pro Web Helper is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/"     class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Web Helper</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProWebHelper" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProWebHelper" target="_blank"><strong>Rogue.Win32.WindowsProWebHelper</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Pro Web Helper </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Web Helper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Web Helper.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_1.png"><img class="alignnone size-medium wp-image-3361" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_1-400x234.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_2.png"><img class="alignnone size-medium wp-image-3362" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_2-400x293.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_3.png"><img class="alignnone size-medium wp-image-3363" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_3-400x293.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_4.png"><img class="alignnone size-medium wp-image-3364" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_4-400x238.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_5.png"><img class="alignnone size-medium wp-image-3365" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsProWebHelper_5-400x253.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Pro Web Helper </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProWebHelper" target="_blank">Rogue.Win32.WindowsProWebHelper</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/"     class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Internet Booster Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/windows-internet-booster-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/windows-internet-booster-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 03:28:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Internet Booster]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3352</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Internet Booster. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsInternetBooster. Windows Internet Booster is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Internet Booster</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsInternetBooster" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInternetBooster" target="_blank"><strong>Rogue.Win32.WindowsInternetBooster</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Internet Booster </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Internet Booster.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Internet Booster.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_1.png"><img class="alignnone size-medium wp-image-3353" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_1-400x234.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_2.png"><img class="alignnone size-medium wp-image-3354" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_2-400x293.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_3.png"><img class="alignnone size-medium wp-image-3355" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_3-400x293.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_4.png"><img class="alignnone size-medium wp-image-3356" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_4-400x238.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_5.png"><img class="alignnone size-medium wp-image-3357" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsInternetBooster_5-400x253.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Internet Booster </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInternetBooster" target="_blank">Rogue.Win32.WindowsInternetBooster</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/windows-internet-booster-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Module Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 01 May 2012 13:41:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Module]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3344</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Module. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyModule. Windows Safety Module is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Module</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyModule" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyModule" target="_blank"><strong>Rogue.Win32.WindowsSafetyModule</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Safety Module </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Module.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Module.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_1.png"><img class="alignnone size-medium wp-image-3345" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_1-400x234.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_2.png"><img class="alignnone size-medium wp-image-3346" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_2-400x293.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_3.png"><img class="alignnone size-medium wp-image-3347" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_3-400x293.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_4.png"><img class="alignnone size-medium wp-image-3348" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_4-400x238.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_5.png"><img class="alignnone size-medium wp-image-3349" src="http://anti-malware-blog.com/files/2012/05/Rogue.Win32.WindowsSafetyModule_5-400x253.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Safety Module </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyModule" target="_blank">Rogue.Win32.WindowsSafetyModule</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Recovery Series Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 09:26:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Recovery Series]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3336</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Recovery Series. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsRecoverySeries. Windows Recovery Series is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Recovery Series</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsRecoverySeries" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecoverySeries" target="_blank"><strong>Rogue.Win32.WindowsRecoverySeries</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Recovery Series </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Recovery Series.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Recovery Series.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_1.png"><img class="alignnone size-medium wp-image-3337" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_1-400x234.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_3.png"><img class="alignnone size-medium wp-image-3339" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_3-400x293.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_4.png"><img class="alignnone size-medium wp-image-3340" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_4-400x293.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_5.png"><img class="alignnone size-medium wp-image-3341" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_5-400x238.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_6.png"><img class="alignnone size-medium wp-image-3342" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsRecoverySeries_6-400x253.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Recovery Series </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecoverySeries" target="_blank">Rogue.Win32.WindowsRecoverySeries</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Recovery Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/30/data-recovery-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/30/data-recovery-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 03:49:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Data Recovery]]></category>
		<category><![CDATA[DataRecovery.b]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[FakeSysDef]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3328</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Data Recovery. Emsisoft Anti-Malware detects this malware as Rogue.Win32.DataRecovery.b. Data Recovery is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/"     class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/"     class="crp_title">System Check Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/"     class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/"     class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/"     class="crp_title">System Fix Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Data Recovery</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.DataRecovery.b" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery.b" target="_blank"><strong>Rogue.Win32.DataRecovery.b</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Data Recovery</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\peNIiagqcfvoe9</li>
<li>%AllUsersProfile%\Application Data\peNIiagqcfvoe9.exe</li>
<li>%AllUsersProfile%\Application Data\-peNIiagqcfvoe9</li>
<li>%AllUsersProfile%\Application Data\-peNIiagqcfvoe9r</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Data_Recovery.lnk</li>
<li>%UserProfile%\Desktop\Data_Recovery.lnk</li>
<li>%UserProfile%\Desktop\Data_Recovery_License.txt</li>
<li>%UserProfile%\Local Settings\Temp\license.dat</li>
<li>%UserProfile%\Local Settings\Temp\RZQQnkXDzMfhGS.exe.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\Data Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\<br />
nsreg = 00000000<br />
pth = 43003A005C0044006F00630075006D0065006E0074007300200061006E&#8230;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
TaskbarGlomming = empty<br />
TaskbarGlomLevel = 0&#215;02000000<br />
Hidden = empty<br />
ShowSuperHidden = empty<br />
Start_ShowUser = 0&#215;01000000<br />
Start_ShowControlPanel = 0&#215;01000000<br />
Start_ShowHelp = 0&#215;01000000<br />
Start_ShowMyComputer = 0&#215;01000000<br />
Start_ShowMyDocs = 0&#215;01000000<br />
Start_ShowMyMusic = 0&#215;01000000<br />
Start_ShowMyGames = 0&#215;01000000<br />
Start_ShowMyPics = 0&#215;01000000<br />
Start_ShowPrinters = 0&#215;01000000<br />
Start_ShowRecentDocs = 0&#215;01000000<br />
Start_ShowRun = 0&#215;01000000<br />
Start_ShowSearch = 0&#215;01000000<br />
Start_ShowSetProgramAccessAndDefaults = 0&#215;01000000<br />
Start_ShowNetConn = 0&#215;01000000<br />
Start_ShowNetPlaces = 0&#215;01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes = .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;&#8230;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation = 0&#215;01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
peNIiagqcfvoe9 = %AllUsersProfile%\Application Data\peNIiagqcfvoe9.exe</li>
</ul>
<p><strong>Screenshosts:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.DataRecovery.b_1.png"><img class="alignnone size-medium wp-image-3329" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.DataRecovery.b_1-400x331.png" alt="Rogue.Win32.DataRecovery.b" width="400" height="331" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.DataRecovery.b_2.png"><img class="alignnone size-medium wp-image-3330" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.DataRecovery.b_2-400x331.png" alt="Rogue.Win32.DataRecovery.b" width="400" height="331" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.DataRecovery.b_3.png"><img class="alignnone size-medium wp-image-3331" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.DataRecovery.b_3-400x240.png" alt="Rogue.Win32.DataRecovery.b" width="400" height="240" /></a></p>
<p>To register this rogue application you can try the following serial number and enter any email:</p>
<pre><span style="color: #ff0000"><strong>08869246386344953972969146034087</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of Data Recovery</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery.b" target="_blank">Rogue.Win32.DataRecovery.b</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/"     class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/"     class="crp_title">System Check Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/"     class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/"     class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/"     class="crp_title">System Fix Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/30/data-recovery-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Checkpoint Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 Apr 2012 13:01:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Checkpoint]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3321</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Checkpoint. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyCheckpoint. Windows Safety Checkpoint is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Checkpoint</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyCheckpoint" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyCheckpoint" target="_blank"><strong>Rogue.Win32.WindowsSafetyCheckpoint</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Safety Checkpoint </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Checkpoint.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Checkpoint.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_1.png"><img class="alignnone size-medium wp-image-3322" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_1-400x234.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_2.png"><img class="alignnone size-medium wp-image-3323" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_2-400x293.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_3.png"><img class="alignnone size-medium wp-image-3324" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_3-400x293.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_4.png"><img class="alignnone size-medium wp-image-3325" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_4-400x238.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_5.png"><img class="alignnone size-medium wp-image-3326" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_5-400x253.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Safety Checkpoint </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyCheckpoint" target="_blank">Rogue.Win32.WindowsSafetyCheckpoint</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Premium Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 06:44:16 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Premium Guard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3313</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Premium Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPremiumGuard. Windows Premium Guard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Premium Guard</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPremiumGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPremiumGuard" target="_blank"><strong>Rogue.Win32.WindowsPremiumGuard</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Premium Guard </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Premium Guard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Premium Guard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_1.png"><img class="alignnone size-medium wp-image-3314" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_1-400x234.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_2.png"><img class="alignnone size-medium wp-image-3315" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_2-400x293.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_3.png"><img class="alignnone size-medium wp-image-3316" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_3-400x293.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_4.png"><img class="alignnone size-medium wp-image-3317" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_4-400x238.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_5.png"><img class="alignnone size-medium wp-image-3318" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPremiumGuard_5-400x253.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Premium Guard </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPremiumGuard" target="_blank">Rogue.Win32.WindowsPremiumGuard</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/"     class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Efficiency Accelerator Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 14:03:46 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Efficiency Accelerator]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3305</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Efficiency Accelerator. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsEfficiencyAccelerator. Windows Efficiency Accelerator is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/"     class="crp_title">Windows Efficiency Reservoir Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Efficiency Accelerator</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsEfficiencyAccelerator" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyAccelerator" target="_blank"><strong>Rogue.Win32.WindowsEfficiencyAccelerator</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Efficiency Accelerator </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Efficiency Accelerator.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Efficiency Accelerator.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_1.png"><img class="alignnone size-medium wp-image-3306" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_1-400x234.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_2.png"><img class="alignnone size-medium wp-image-3307" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_2-400x293.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_3.png"><img class="alignnone size-medium wp-image-3308" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_3-400x293.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_4.png"><img class="alignnone size-medium wp-image-3309" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_4-400x238.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_5.png"><img class="alignnone size-medium wp-image-3310" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_5-400x253.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Efficiency Accelerator </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyAccelerator" target="_blank">Rogue.Win32.WindowsEfficiencyAccelerator</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/"     class="crp_title">Windows Efficiency Reservoir Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Performance Adviser Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 05:14:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Performance Adviser]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3297</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Performance Adviser. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPerformanceAdviser. Windows Performance Adviser is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/"     class="crp_title">Windows Sleek Performance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Performance Adviser</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPerformanceAdviser" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceAdviser" target="_blank"><strong>Rogue.Win32.WindowsPerformanceAdviser</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Performance Adviser</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Performance Adviser.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Performance Adviser.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_1.png"><img class="alignnone size-medium wp-image-3298" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_1-400x234.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_2.png"><img class="alignnone size-medium wp-image-3299" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_2-400x293.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_3.png"><img class="alignnone size-medium wp-image-3300" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_3-400x293.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_4.png"><img class="alignnone size-medium wp-image-3301" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_4-400x238.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_5.png"><img class="alignnone size-medium wp-image-3302" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsPerformanceAdviser_5-400x253.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="253" /></a></p>
<p>&nbsp;</p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Performance Adviser</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceAdviser" target="_blank">Rogue.Win32.WindowsPerformanceAdviser</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/"     class="crp_title">Windows Sleek Performance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Toolkit Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 02:59:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Toolkit]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3285</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Toolkit. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyToolkit. Windows Safety Toolkit is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Safety Toolkit</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyToolkit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyToolkit" target="_blank"><strong>Rogue.Win32.WindowsSafetyToolkit</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Safety Toolkit</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Toolkit.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Toolkit.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_1.png"><img class="alignnone size-medium wp-image-3286" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_1-400x234.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="234" /></a></div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_2.png"><img class="alignnone size-medium wp-image-3287" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_2-400x293.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_3.png"><img class="alignnone size-medium wp-image-3288" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_3-400x293.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_4.png"><img class="alignnone size-medium wp-image-3289" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_4-400x238.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="238" /></a></div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_5.png"><img class="alignnone size-medium wp-image-3290" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyToolkit_5-400x253.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="253" /></a></div>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Safety Toolkit</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyToolkit" target="_blank">Rogue.Win32.WindowsSafetyToolkit</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/"     class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Foolproof Protector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 08:49:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Foolproof Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3278</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Foolproof Protector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsFoolproofProtector. Windows Foolproof Protector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/"     class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Foolproof Protector</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsFoolproofProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFoolproofProtector" target="_blank"><strong>Rogue.Win32.WindowsFoolproofProtector</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Foolproof Protector</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Foolproof Protector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Foolproof Protector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_1.png"><img class="alignnone size-medium wp-image-3279" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_1-400x234.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_2.png"><img class="alignnone size-medium wp-image-3280" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_2-400x293.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_3.png"><img class="alignnone size-medium wp-image-3281" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_3-400x293.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_4.png"><img class="alignnone size-medium wp-image-3282" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_4-400x238.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_5.png"><img class="alignnone size-medium wp-image-3283" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFoolproofProtector_5-400x253.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Foolproof Protector</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFoolproofProtector" target="_blank">Rogue.Win32.WindowsFoolproofProtector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/"     class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Guard Solutions Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 11:12:11 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Guard Solutions]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3271</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Guard Solutions. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsGuardSolutions. Windows Guard Solutions is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Guard Solutions</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsGuardSolutions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardSolutions" target="_blank"><strong>Rogue.Win32.WindowsGuardSolutions</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong>Windows Guard Solutions</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Guard Solutions.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Guard Solutions.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_1.png"><img class="alignnone size-medium wp-image-3272" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_1-400x234.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_2.png"><img class="alignnone size-medium wp-image-3273" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_2-400x293.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_3.png"><img class="alignnone size-medium wp-image-3274" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_3-400x293.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_4.png"><img class="alignnone size-medium wp-image-3275" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_4-400x238.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_5.png"><img class="alignnone size-medium wp-image-3276" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsGuardSolutions_5-400x253.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong>Windows Guard Solutions</strong></strong></strong></strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardSolutions" target="_blank">Rogue.Win32.WindowsGuardSolutions</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/"     class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/"     class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Crucial Scanner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 02:22:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Crucial Scanner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3264</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Crucial Scanner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCrucialScanner. Windows Crucial Scanner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Crucial Scanner</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCrucialScanner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrucialScanner" target="_blank"><strong>Rogue.Win32.WindowsCrucialScanner</strong></a><strong>.</strong></p>
<p><strong>Windows Crucial Scanner</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Crucial Scanner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Crucial Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_1.png"><img class="alignnone size-medium wp-image-3265" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_1-400x234.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_2.png"><img class="alignnone size-medium wp-image-3266" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_2-400x293.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_3.png"><img class="alignnone size-medium wp-image-3267" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_3-400x293.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_4.png"><img class="alignnone size-medium wp-image-3268" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_4-400x238.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_5.png"><img class="alignnone size-medium wp-image-3269" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCrucialScanner_5-400x253.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
</div>
<div>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong>Windows Crucial Scanner</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrucialScanner" target="_blank">Rogue.Win32.WindowsCrucialScanner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/"     class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Manager Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 10:35:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Manager]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3255</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Manager. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyManager. Windows Safety Manager is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Safety Manager</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyManager" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyManager" target="_blank"><strong>Rogue.Win32.WindowsSafetyManager</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong><strong><strong><strong>Windows Safety Manager</strong></strong></strong> </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Manager.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Manager.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_1.png"><img class="alignnone size-medium wp-image-3256" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_1-400x234.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="234" /></a></p>
</div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_2.png"><img class="alignnone size-medium wp-image-3257" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_2-400x293.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_3.png"><img class="alignnone size-medium wp-image-3258" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_3-400x293.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_4.png"><img class="alignnone size-medium wp-image-3259" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_4-400x238.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="238" /></a></div>
<div></div>
<div>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_5.png"><img class="alignnone size-medium wp-image-3260" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsSafetyManager_5-400x253.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="253" /></a><br />To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Safety Manager </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyManager" target="_blank">Rogue.Win32.WindowsSafetyManager</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/"     class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/"     class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/"     class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/22/windows-pro-safety-rogue-removal-instructions/"     class="crp_title">Windows Pro Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/24/windows-safety-maintenance-rogue-removal-instructions/"     class="crp_title">Windows Safety Maintenance Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antivirus Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 05:23:28 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antivirus Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3248</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antivirus Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntivirusPatch. Windows Antivirus Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Rampart Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/"     class="crp_title">Windows Ultimate Security Patch Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Antivirus Patch</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntivirusPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusPatch" target="_blank"><strong>Rogue.Win32.WindowsAntivirusPatch</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Antivirus Patch</strong></strong> </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antivirus Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antivirus Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_1.png"><img class="alignnone size-medium wp-image-3249" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_1-400x234.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_2.png"><img class="alignnone size-medium wp-image-3250" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_2-400x293.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_3.png"><img class="alignnone size-medium wp-image-3251" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_3-400x293.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_4.png"><img class="alignnone size-medium wp-image-3252" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_4-400x238.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_5.png"><img class="alignnone size-medium wp-image-3253" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntivirusPatch_5-400x253.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Antivirus Patch </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusPatch" target="_blank">Rogue.Win32.WindowsAntivirusPatch</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/"     class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-antivirus-rampart-rogue-removal-instructions/"     class="crp_title">Windows Antivirus Rampart Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/30/windows-ultimate-security-patch-rogue-removal-instructions/"     class="crp_title">Windows Ultimate Security Patch Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Protection Unit Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/17/windows-protection-unit-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/17/windows-protection-unit-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 05:14:21 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Protection Unit]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3241</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Protection Unit. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProtectionUnit. Windows Protection Unit is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Protection Unit</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProtectionUnit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionUnit" target="_blank"><strong>Rogue.Win32.WindowsProtectionUnit</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Protection Unit</strong></strong> </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Protection Unit.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Protection Unit.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_1.png"><img class="alignnone size-medium wp-image-3242" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_1-400x234.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_2.png"><img class="alignnone size-medium wp-image-3243" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_2-400x293.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_3.png"><img class="alignnone size-medium wp-image-3244" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_3-400x293.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_4.png"><img class="alignnone size-medium wp-image-3245" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_4-400x238.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_5.png"><img class="alignnone size-medium wp-image-3246" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsProtectionUnit_5-400x253.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Protection Unit </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionUnit" target="_blank">Rogue.Win32.WindowsProtectionUnit</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/17/windows-protection-unit-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antibreaking System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 08:33:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antibreaking System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3231</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antibreaking System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntibreakingSystem. Windows Antibreaking System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/"     class="crp_title">Windows Managing System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/"     class="crp_title">Windows Warding System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Antibreaking System</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntibreakingSystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntibreakingSystem" target="_blank"><strong>Rogue.Win32.WindowsAntibreakingSystem</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows </strong></strong>Antibreaking System </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antibreaking System.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antibreaking System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_1.png"><img class="alignnone size-medium wp-image-3232" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_1-400x234.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_2.png"><img class="alignnone size-medium wp-image-3233" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_2-400x293.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_3.png"><img class="alignnone size-medium wp-image-3234" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_3-400x293.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_4.png"><img class="alignnone size-medium wp-image-3235" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_4-400x238.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_5.png"><img class="alignnone size-medium wp-image-3236" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsAntibreakingSystem_5-400x253.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Antibreaking System </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntibreakingSystem" target="_blank">Rogue.Win32.WindowsAntibreakingSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/"     class="crp_title">Windows Managing System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/"     class="crp_title">Windows Warding System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Component Protector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 10:13:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Component Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3223</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Component Protector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsComponentProtector. Windows Component Protector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/"     class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/"     class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Component Protector</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsComponentProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsComponentProtector" target="_blank"><strong>Rogue.Win32.WindowsComponentProtector</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Component Protector</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Component Protector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Component Protector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_1.png"><img class="alignnone size-medium wp-image-3224" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_1-400x234.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_2.png"><img class="alignnone size-medium wp-image-3225" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_2-400x293.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_3.png"><img class="alignnone size-medium wp-image-3226" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_3-400x293.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_4.png"><img class="alignnone size-medium wp-image-3227" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_4-400x238.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_5.png"><img class="alignnone size-medium wp-image-3228" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsComponentProtector_5-400x253.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Component Protector </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsComponentProtector" target="_blank">Rogue.Win32.WindowsComponentProtector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/"     class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/"     class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Stability Maximizer Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/09/windows-stability-maximizer-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/09/windows-stability-maximizer-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 14:42:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Stability Maximizer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3215</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Stability Maximizer. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsStabilityMaximizer. Windows Stability Maximizer is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/"     class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Stability Maximizer</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsStabilityMaximizer" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityMaximizer" target="_blank"><strong>Rogue.Win32.WindowsStabilityMaximizer</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Stability Maximizer</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Stability Maximizer.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Stability Maximizer.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_1.png"><img class="alignnone size-medium wp-image-3216" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_1-400x234.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_2.png"><img class="alignnone size-medium wp-image-3217" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_2-400x293.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_3.png"><img class="alignnone size-medium wp-image-3218" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_3-400x293.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_4.png"><img class="alignnone size-medium wp-image-3219" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsStabilityMaximizer_4-400x238.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="238" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Stability Maximizer </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityMaximizer" target="_blank">Rogue.Win32.WindowsStabilityMaximizer</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/"     class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/09/windows-stability-maximizer-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Cleaning Tools Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 13:45:30 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Cleaning Tools]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3209</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Cleaning Tools. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCleaningTools. Windows Cleaning Tools is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/"     class="crp_title">Windows Guard Tools Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Cleaning Tools</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCleaningTools" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCleaningTools" target="_blank"><strong>Rogue.Win32.WindowsCleaningTools</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Cleaning Tools</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Cleaning Tools.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Cleaning Tools.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_1.png"><img class="alignnone size-medium wp-image-3210" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_1-400x234.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_2.png"><img class="alignnone size-medium wp-image-3211" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_2-400x293.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_3.png"><img class="alignnone size-medium wp-image-3212" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_3-400x293.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_4.png"><img class="alignnone size-medium wp-image-3213" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCleaningTools_4-400x238.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="238" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Cleaning Tools </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCleaningTools" target="_blank">Rogue.Win32.WindowsCleaningTools</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/"     class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/25/windows-guard-tools-rogue-removal-instructions/"     class="crp_title">Windows Guard Tools Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Efficiency Reservoir Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 04:01:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malwar Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Efficiency Reservoir]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3202</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Efficiency Reservoir. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsEfficiencyReservoir. Windows Efficiency Reservoir is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/"     class="crp_title">Windows Efficiency Accelerator Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Efficiency Reservoir</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsEfficiencyReservoir" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyReservoir" target="_blank"><strong>Rogue.Win32.WindowsEfficiencyReservoir</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Efficiency Reservoir</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Efficiency Reservoir.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Efficiency Reservoir.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_1.png"><img class="alignnone size-medium wp-image-3203" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_1-400x234.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_2.png"><img class="alignnone size-medium wp-image-3204" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_2-400x293.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_3.png"><img class="alignnone size-medium wp-image-3205" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_3-400x293.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_4.png"><img class="alignnone size-medium wp-image-3206" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_4-400x238.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_5.png"><img class="alignnone size-medium wp-image-3207" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_5-400x253.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Efficiency Reservoir </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyReservoir" target="_blank">Rogue.Win32.WindowsEfficiencyReservoir</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/"     class="crp_title">Windows Efficiency Accelerator Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Care Taker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 03:31:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Care Taker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3194</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Care Taker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCareTaker. Windows Care Taker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/"     class="crp_title">Windows Trouble Taker Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Care Taker</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCareTaker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTaker" target="_blank"><strong>Rogue.Win32.WindowsCareTaker</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Care Taker</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Care Taker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Care Taker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_1.png"><img class="alignnone size-medium wp-image-3195" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_1-400x234.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_2.png"><img class="alignnone size-medium wp-image-3196" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_2-400x293.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_3.png"><img class="alignnone size-medium wp-image-3197" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_3-400x293.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_4.png"><img class="alignnone size-medium wp-image-3198" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_4-400x238.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_5.png"><img class="alignnone size-medium wp-image-3199" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCareTaker_5-400x253.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Care Taker </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTaker" target="_blank">Rogue.Win32.WindowsCareTaker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/"     class="crp_title">Windows Trouble Taker Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Custodian Utility Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 11:36:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Custodian Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3186</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Custodian Utility. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCustodianUtility. Windows Custodian Utility is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/"     class="crp_title">Windows Shielding Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Custodian Utility</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCustodianUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustodianUtility" target="_blank"><strong>Rogue.Win32.WindowsCustodianUtility</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Custodian Utility</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Custodian Utility.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Custodian Utility.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_1.png"><img class="alignnone size-medium wp-image-3187" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_1-400x234.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_3.png"><img class="alignnone size-medium wp-image-3189" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_3-400x293.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_4.png"><img class="alignnone size-medium wp-image-3190" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_4-400x238.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_5.png"><img class="alignnone size-medium wp-image-3191" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsCustodianUtility_5-400x253.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Custodian Utility </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustodianUtility" target="_blank">Rogue.Win32.WindowsCustodianUtility</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/"     class="crp_title">Windows Shielding Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Antispyware Solution Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 19:42:29 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Advanced Antispyware Solution]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3178</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Advanced Antispyware Solution. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AdvancedAntispywareSolution. Advanced Antispyware Solution is a rogue scanner application, another variant of Home Malware Cleaner, SmartAntiMalwareProtection, Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/"     class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/"     class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/"     class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/"     class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/"     class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Advanced Antispyware Solution</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AdvancedAntispywareSolution" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdvancedAntispywareSolution" target="_blank"><strong>Rogue.Win32.AdvancedAntispywareSolution</strong></a><strong>.</strong></p>
<p><strong>Advanced Antispyware Solution </strong><strong></strong>is a rogue scanner application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeMalwareCleaner"><strong>Home Malware Cleaner</strong></a>, <a title="Rogue.Win32.SmartAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank"><strong>SmartAntiMalwareProtection</strong></a><strong></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection"><strong>Antivirus Smart Protection</strong></a>, <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Advanced Antispyware Solution</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Advanced Antispyware Solution.lnk</li>
<li>%UserProfile%\Desktop\Advanced Antispyware Solution.lnk</li>
<li>%UserProfile%\Recent\ANTIGEN.sys</li>
<li>%UserProfile%\Recent\CLSV.dll</li>
<li>%UserProfile%\Recent\CLSV.drv</li>
<li>%UserProfile%\Recent\ddv.sys</li>
<li>%UserProfile%\Recent\dudl.tmp</li>
<li>%UserProfile%\Recent\eb.dll</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\FW.dll</li>
<li>%UserProfile%\Recent\grid.dll</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\pal.dll</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\PE.drv</li>
<li>%UserProfile%\Recent\ppal.tmp</li>
<li>%UserProfile%\Recent\SM.tmp</li>
<li>%UserProfile%\Recent\tempdoc.tmp</li>
<li>%UserProfile%\Start Menu\Advanced Antispyware Solution.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Advanced Antispyware Solution.lnk</li>
<li>%AllUsersProfile%\Application Data\2a967e</li>
<li>%AllUsersProfile%\Application Data\2a967e\75.mof</li>
<li>%AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\AAS.ico</li>
<li>%AllUsersProfile%\Application Data\2a967e\aasolution.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\AASSys</li>
<li>%AllUsersProfile%\Application Data\2a967e\Quarantine Items</li>
<li>%AllUsersProfile%\Application Data\AAETFS</li>
<li>%AllUsersProfile%\Application Data\AAETFS\AALYASUAS.cfg</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\AA2a9_8010.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe<br />
ProgID  = AA2a9_8010.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
AAS = &#8220;%AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe&#8221; /s<br />
Advanced Antispyware Solution = &#8220;%AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe&#8221; /s /d</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_1.png"><img class="alignnone size-medium wp-image-3179" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_1-400x202.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="202" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_2.png"><img class="alignnone size-medium wp-image-3180" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_2-400x288.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="288" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_3.png"><img class="alignnone size-medium wp-image-3181" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_3-400x288.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="288" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_4.png"><img class="alignnone size-medium wp-image-3182" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.AdvancedAntispywareSolution_4-400x299.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="299" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Advanced Antispyware Solution </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdvancedAntispywareSolution" target="_blank">Rogue.Win32.AdvancedAntispywareSolution</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/"     class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/"     class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/"     class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/"     class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/"     class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Shielding Utility Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 09:39:09 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Shielding Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3170</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Shielding Utility. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsShieldingUtility. Windows Shielding Utility is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/"     class="crp_title">Windows Custodian Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Shielding Utility</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsShieldingUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldingUtility" target="_blank"><strong>Rogue.Win32.WindowsShieldingUtility</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Shielding Utility</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Shielding Utility.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Shielding Utility.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_1.png"><img class="alignnone size-medium wp-image-3171" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_1-400x234.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_2.png"><img class="alignnone size-medium wp-image-3172" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_2-400x293.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_3.png"><img class="alignnone size-medium wp-image-3173" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_3-400x293.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_4.png"><img class="alignnone size-medium wp-image-3174" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_4-400x238.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_5.png"><img class="alignnone size-medium wp-image-3175" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsShieldingUtility_5-400x253.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Shielding Utility </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldingUtility" target="_blank">Rogue.Win32.WindowsShieldingUtility</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/"     class="crp_title">Windows Custodian Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/02/windows-malware-firewall-rogue-removal-instructions/"     class="crp_title">Windows Malware Firewall Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMART HDD Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 14:20:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[S.M.A.R.T HDD]]></category>
		<category><![CDATA[SMART HDD]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3164</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the SMART HDD. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartHDD.b. SMART HDD (or S.M.A.R.T HDD) is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/"     class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/16/smart-hdd-adware-removal-instructions/"     class="crp_title">Smart HDD Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/"     class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/01/06/hdd-fix-adware-removal-instructions/"     class="crp_title">HDD Fix Adware Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>SMART HDD</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SmartHDD.b" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD.b" target="_blank"><strong>Rogue.Win32.SmartHDD.b</strong></a><strong>.</strong></p>
<p><strong><strong><strong>SMART HDD </strong></strong></strong>(or <strong>S.M.A.R.T HDD</strong>) is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\-ch1+6T~]V&amp;zN,</li>
<li>%AllUsersProfile%\Application Data\-ch1+6T~]V&amp;zN,r</li>
<li>%AllUsersProfile%\Application Data\ch1+6T~]V&amp;zN,</li>
<li>%AllUsersProfile%\Application Data\ch1+6T~]V&amp;zN,.exe</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\SMART_HDD.lnk</li>
<li>%UserProfile%\Desktop\SMART_HDD.lnk</li>
<li>%UserProfile%\Desktop\SMART_HDD_License.txt</li>
<li>%UserProfile%\Start Menu\Programs\SMART HDD\</li>
<li>%UserProfile%\Start Menu\Programs\SMART HDD\SMART HDD.lnk</li>
<li>%UserProfile%\Start Menu\Programs\SMART HDD\Uninstall SMART HDD.lnk</li>
</ul>
<p><strong>Create / modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER|\Software\Microsoft\Windows\CurrentVersion\Run<br />
ch1+6T~]V&amp;zN, = %AllUsersProfile%\Application Data\ch1+6T~]V&amp;zN,.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
WarnOnZoneCrossing = 0&#215;00000000<br />
WarnonBadCertRecving = 0&#215;00000000<br />
CertificateRevocation = 0&#215;00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.SmartHDD.b_1.png"><img class="alignnone size-medium wp-image-3165" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.SmartHDD.b_1-400x331.png" alt="Rogue.Win32.SmartHDD.b" width="400" height="331" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.SmartHDD.b_2.png"><img class="alignnone size-medium wp-image-3166" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.SmartHDD.b_2-400x240.png" alt="Rogue.Win32.SmartHDD.b" width="400" height="240" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.SmartHDD.b_3.png"><img class="alignnone size-medium wp-image-3167" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.SmartHDD.b_3-400x175.png" alt="Rogue.Win32.SmartHDD.b" width="400" height="175" /></a></p>
<p>To register this rogue application you can try the following serial number and enter any email:</p>
<pre><span style="color: #ff0000"><strong>15801587234612645205224631045976</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of SMART HDD</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD.b" target="_blank">Rogue.Win32.SmartHDD.b</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/"     class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/"     class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/16/smart-hdd-adware-removal-instructions/"     class="crp_title">Smart HDD Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/"     class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/01/06/hdd-fix-adware-removal-instructions/"     class="crp_title">HDD Fix Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Warding System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:29:20 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Warding System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3157</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Warding System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsWardingSystem. Windows Warding System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/"     class="crp_title">Windows Managing System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/"     class="crp_title">Windows Antibreaking System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Warding System</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsWardingSystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWardingSystem" target="_blank"><strong>Rogue.Win32.WindowsWardingSystem</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Warding System</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Warding System.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Warding System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_1.png"><img class="alignnone size-medium wp-image-3158" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_1-400x234.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_2.png"><img class="alignnone size-medium wp-image-3159" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_2-400x293.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_3.png"><img class="alignnone size-medium wp-image-3160" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_3-400x293.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_4.png"><img class="alignnone size-medium wp-image-3161" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_4-400x238.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_5.png"><img class="alignnone size-medium wp-image-3162" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsWardingSystem_5-400x253.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Warding System </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWardingSystem" target="_blank">Rogue.Win32.WindowsWardingSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/"     class="crp_title">Windows Managing System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/"     class="crp_title">Windows Antibreaking System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows First-Class Protector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:23:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows First-Class Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3149</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows First-Class Protector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsFirstClassProtector. Windows First-Class Protector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/"     class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows First-Class Protector</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsFirstClassProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirstClassProtector" target="_blank"><strong>Rogue.Win32.WindowsFirstClassProtector</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows First-Class Protector</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows First-Class Protector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows First-Class Protector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_2.png"><img class="alignnone size-medium wp-image-3150" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_2-400x234.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_3.png"><img class="alignnone size-medium wp-image-3151" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_3-400x293.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_4.png"><img class="alignnone size-medium wp-image-3152" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_4-400x293.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_5.png"><img class="alignnone size-medium wp-image-3153" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_5-400x238.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_6.png"><img class="alignnone size-medium wp-image-3154" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsFirstClassProtector_6-400x253.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows First-Class Protector </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirstClassProtector" target="_blank">Rogue.Win32.WindowsFirstClassProtector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/"     class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Activity Debugger Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:05:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Activity Debugger]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3142</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Activity Debugger. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsActivityDebugger. Windows Activity Debugger is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Activity Debugger</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsActivityDebugger" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityDebugger" target="_blank"><strong>Rogue.Win32.WindowsActivityDebugger</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Activity Debugger</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Activity Debugger.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Activity Debugger.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_1.png"><img class="alignnone size-medium wp-image-3143" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_1-400x234.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_2.png"><img class="alignnone size-medium wp-image-3144" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_2-400x293.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_3.png"><img class="alignnone size-medium wp-image-3145" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_3-400x293.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_4.png"><img class="alignnone size-medium wp-image-3146" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_4-400x238.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_5.png"><img class="alignnone size-medium wp-image-3147" src="http://anti-malware-blog.com/files/2012/04/Rogue.Win32.WindowsActivityDebugger_5-400x253.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Activity Debugger </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityDebugger" target="_blank">Rogue.Win32.WindowsActivityDebugger</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Trouble Taker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 09:37:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Trouble Taker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3134</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Trouble Taker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsTroubleTaker. Windows Trouble Taker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/"     class="crp_title">Windows Care Taker Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Trouble Taker</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsTroubleTaker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroubleTaker" target="_blank"><strong>Rogue.Win32.WindowsTroubleTaker</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Trouble Taker</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Trouble Taker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Trouble Taker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_1.png"><img class="alignnone size-medium wp-image-3135" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_1-400x234.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_2.png"><img class="alignnone size-medium wp-image-3136" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_2-400x293.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_3.png"><img class="alignnone size-medium wp-image-3137" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_3-400x293.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_4.png"><img class="alignnone size-medium wp-image-3138" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_4-400x238.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_5.png"><img class="alignnone size-medium wp-image-3139" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsTroubleTaker_5-400x253.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Trouble Taker </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroubleTaker" target="_blank">Rogue.Win32.WindowsTroubleTaker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/"     class="crp_title">Windows Care Taker Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/06/05/windows-pc-aid-rogue-removal-instructions/"     class="crp_title">Windows PC Aid Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Defending Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/28/windows-defending-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/28/windows-defending-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 28 Mar 2012 08:49:31 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Defending Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3125</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Defending Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsDefendingCenter. Windows Defending Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/"     class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Defending Center</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsDefendingCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefendingCenter" target="_blank"><strong>Rogue.Win32.WindowsDefendingCenter</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Defending Center</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Defending Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Defending Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_0.png"><img class="alignnone size-medium wp-image-3126" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_0-400x276.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="276" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_1.png"><img class="alignnone size-medium wp-image-3127" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_1-400x234.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_3.png"><img class="alignnone size-medium wp-image-3128" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_3-400x293.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_4.png"><img class="alignnone size-medium wp-image-3129" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_4-400x238.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_5.png"><img class="alignnone size-medium wp-image-3130" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDefendingCenter_5-400x253.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="253" /></a></p>
<p>To register this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Defending Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefendingCenter" target="_blank">Rogue.Win32.WindowsDefendingCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/"     class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/"     class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/28/windows-defending-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows No-Risk Agent Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 13:14:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows No-Risk Agent]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3118</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows No-Risk Agent. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsNoRiskAgent. Windows No-Risk Agent is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows No-Risk Agent</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsNoRiskAgent" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsNoRiskAgent" target="_blank"><strong>Rogue.Win32.WindowsNoRiskAgent</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows No-Risk Agent</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows No-Risk Agent.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows No-Risk Agent.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_1.png"><img class="alignnone size-medium wp-image-3119" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_1-400x234.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_2.png"><img class="alignnone size-medium wp-image-3120" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_2-400x293.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_3.png"><img class="alignnone size-medium wp-image-3121" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_3-400x293.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_4.png"><img class="alignnone size-medium wp-image-3122" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_4-400x238.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_5.png"><img class="alignnone size-medium wp-image-3123" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsNoRiskAgent_5-400x253.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows No-Risk Agent </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsNoRiskAgent" target="_blank">Rogue.Win32.WindowsNoRiskAgent</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Debug Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 07:09:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Debug Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3110</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Debug Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsDebugCenter. Windows Debug Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Debug Center</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsDebugCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebugCenter" target="_blank"><strong>Rogue.Win32.WindowsDebugCenter</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Debug Center</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Debug Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Debug Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_1.png"><img class="alignnone size-medium wp-image-3111" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_1-400x234.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_2.png"><img class="alignnone size-medium wp-image-3112" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_2-400x293.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_3.png"><img class="alignnone size-medium wp-image-3113" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_3-400x293.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_4.png"><img class="alignnone size-medium wp-image-3114" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_4-400x238.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_5.png"><img class="alignnone size-medium wp-image-3115" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsDebugCenter_5-400x253.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Debug Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebugCenter" target="_blank">Rogue.Win32.WindowsDebugCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows AntiHazard Helper Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 06:58:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows AntiHazard Helper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3102</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows AntiHazard Helper. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntiHazardHelper. Windows AntiHazard Helper is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows AntiHazard Helper</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntiHazardHelper" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardHelper" target="_blank"><strong>Rogue.Win32.WindowsAntiHazardHelper</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows AntiHazard Helper</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows AntiHazard Helper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows AntiHazard Helper.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_1.png"><img class="alignnone size-medium wp-image-3103" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_1-400x234.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_2.png"><img class="alignnone size-medium wp-image-3104" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_2-400x293.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_3.png"><img class="alignnone size-medium wp-image-3105" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_3-400x293.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_4.png"><img class="alignnone size-medium wp-image-3106" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_4-400x238.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_5.png"><img class="alignnone size-medium wp-image-3107" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntiHazardHelper_5-400x253.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows AntiHazard Helper </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardHelper" target="_blank">Rogue.Win32.WindowsAntiHazardHelper</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/"     class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Software Saver Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 08:20:50 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Software Saver]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3094</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Software Saver. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSoftwareSaver. Windows Software Saver is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/"     class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Software Saver</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSoftwareSaver" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareSaver" target="_blank"><strong>Rogue.Win32.WindowsSoftwareSaver</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Software Saver</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Software Saver.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Software Saver.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_1.png"><img class="alignnone size-medium wp-image-3095" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_1-400x234.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_2.png"><img class="alignnone size-medium wp-image-3096" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_2-400x293.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_3.png"><img class="alignnone size-medium wp-image-3097" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_3-400x293.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_4.png"><img class="alignnone size-medium wp-image-3098" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_4-400x238.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_5.png"><img class="alignnone size-medium wp-image-3099" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsSoftwareSaver_5-400x253.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Software Saver </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareSaver" target="_blank">Rogue.Win32.WindowsSoftwareSaver</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/"     class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antihazard Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 11:50:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows AntiHazard Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3086</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows AntiHazard Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntiHazardCenter. Windows AntiHazard Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/"     class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/"     class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Windows AntiHazard Center</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntiHazardCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardCenter" target="_blank"><strong>Rogue.Win32.WindowsAntiHazardCenter</strong></a><strong>.</strong></p>
<p><strong><strong>Windows AntiHazard Center</strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows AntiHazard Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows AntiHazard Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_1.png"><img class="alignnone size-medium wp-image-3087" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_1-400x234.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_2.png"><img class="alignnone size-medium wp-image-3088" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_2-400x293.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_3.png"><img class="alignnone size-medium wp-image-3089" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_3-400x293.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_4.png"><img class="alignnone size-medium wp-image-3090" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_4-400x238.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_5.png"><img class="alignnone size-medium wp-image-3091" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsAntihazardCenter_5-400x253.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows AntiHazard Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardCenter" target="_blank">Rogue.Win32.WindowsAntiHazardCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/"     class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/"     class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/"     class="crp_title">Windows Antihazard Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Process Director Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/22/windows-process-director-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/22/windows-process-director-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 22 Mar 2012 08:03:14 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Process Director]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3079</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Process Director. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProcessDirector. Windows Process Director is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Process Director</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProcessDirector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessDirector" target="_blank"><strong>Rogue.Win32.WindowsProcessDirector</strong></a><strong>.</strong></p>
<p><strong>Windows Process Director</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Process Director.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Process Director.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_1.png"><img class="alignnone size-medium wp-image-3080" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_1-400x234.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_2.png"><img class="alignnone size-medium wp-image-3081" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_2-400x293.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_3.png"><img class="alignnone size-medium wp-image-3082" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_3-400x293.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_4.png"><img class="alignnone size-medium wp-image-3083" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_4-400x238.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_5.png"><img class="alignnone size-medium wp-image-3084" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsProcessDirector_5-400x253.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Process Director </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessDirector" target="_blank">Rogue.Win32.WindowsProcessDirector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/22/windows-process-director-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Guardian Angel Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 14:42:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Guardian Angel]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3070</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Guardian Angel. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsGuardianAngel. Windows Guardian Angel is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></description>
				<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Guardian Angel</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsGuardianAngel" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardianAngel" target="_blank"><strong>Rogue.Win32.WindowsGuardianAngel</strong></a><strong>.</strong></p>
<p><strong>Windows Guardian Angel</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Guardian Angel.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Guardian Angel.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_1.png"><img class="alignnone size-medium wp-image-3071" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_1-400x234.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="234" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_2.png"><img class="alignnone size-medium wp-image-3072" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_2-400x293.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_3.png"><img class="alignnone size-medium wp-image-3073" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_3-400x293.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="293" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_4.png"><img class="alignnone size-medium wp-image-3074" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_4-400x238.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="238" /></a></p>
<p><a href="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_5.png"><img class="alignnone size-medium wp-image-3075" src="http://anti-malware-blog.com/files/2012/03/Rogue.Win32.WindowsGuardianAngel_5-400x253.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Guardian Angel </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardianAngel" target="_blank">Rogue.Win32.WindowsGuardianAngel</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div class="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/"     class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/"     class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/"     class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/"     class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/"     class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
